Friday, September 06, 2013

September 2013

This month several students start on several research projects that I am coaching, ranging from camera identification, heart beat detection, veins in faces and automated biometric comparison of hand, feet and faces. As always I am looking forward to the results and challenges within these projects.

Also we are writing proposals for research funding, which is getting more important. The ENFSI Forensic IT Working group the conference of the Forensic IT Working group in Linkoping, Sweden was very nice with three proficiency tests finished on camera identification, imaging of NTFS and chip extraction with very nice results.

In 2014 also the DFWRS EU will be organized in Amsterdam, so that is nice to have it nearby.

For the journal Digital Investigation working on a special issue for Big data and data analysis, so several topics keep me busy, as well as some casework and a proficiency test. This summer in August I was working on several cases, and it appeared I could finish them in time.

Since I have to keep up with lowering my blood sugar I decided to do a test with High Intensity Interval Training (HITT) and of course a low carb diet. It is a part of a scientific study where I will do this for 12 weeks 3 days a week, and they have a hypothesis that it lowers the blood sugar and a higher VO2 Max is resulted from this.

Furthermore, I am preparing a presentation at the Interpol Symposium in Lyon a review on forensic imaging in October.

Since we sold our apartment near the sea in Zandvoort, we live for a while in the Jordaan in Amsterdam, so lots to see and do there !


Indonesian diplomatic reception to commemorate the 68th Anniversary of the Independence of Indonesia that I attended, where our prime Minister Rutte was guest of honor and gave an excellent speech


Sunday, July 21, 2013

July 2013

This month appears to be somewhat hectic, several issues had to be solved together. We bought a new house and sold our previous apartment within 3 weeks (and actually had to leave it within 2 weeks), so it was a somewhat hectic month. Before August 1st I also submit a workshop proposal on morphometrics and one or two papers on camera identification in big data and maybe some research on biometric comparison of hands.

I also reviewed several nice papers, and see that the field of digital investigation is attracting lots of attention and some good research of universities is being conducted. Also I did several proficiency tests and it appears that you always learn something of doing these. I think for any forensic scientist it is good to do a proficiency test at least once a year. Also casework and reports, and in the summer I will continue to be at the office.

This month I also received new medical equipment that I had to use. A glucose meter which can be connected to the internet, very easy for telemedicine. It seems many of those meters are sold, and they also might provide forensic information. One sees that the number of medical devices to be used at homes is growing rapidly, however what happens if the meter is hacked from distance. As we can see from http://www.youtube.com/watch?v=ZjwuA60jIDI the meter can be hacked and this might cause wrong readings. When driving a car a hypo might occur due to that and this might in theory cause a fatal accident. We can see more devices such as ICDs where these scenarios are discussed http://blog.ioactive.com/2013/02/broken-hearts-how-plausible-was.html . Also with CPAP-devices for sleeping disorders possibilities exist to reprogram them, which also might cause as least a change of mood. In the information of the manufacturer no information is given yet on possibilities of these attacks.

Perhaps these scenarios are somewhat remote, however from 31 July to 4 August in the Netherlands the hacking conference OHM2013 is organized. There will be a forensic track from the NFI at https://ohm2013.org/wiki/Village:Garrison and I am looking forward to be there, however will not bring any medical electronic devices there, since you never know.

Saturday, June 08, 2013

June 2013

On 7 June 2013 I attended a very nice meeting of the Amsterdam Center of Forensic Science of the University of Amsterdam, where Huub Hardy was the guest of honor. Nice discussions on the use of by Ian Evett, where it appears that the use of Bayes Theorem in the United Kingdom is in jeopardy. This concerns to major concern of forensic scientists, as can also be seen in several ENFSI guidelines where this is the advised method of reporting . One of the issues is that conclusions in report are more difficult to read, and that it is not easy to understand.  However once the court (at least in the Netherlands) the judges, advocates and prosecutors gets used to these conclusions, they appear to be of additional value especially for combining and interpreting the value of the evidence.

During this meeting there were also good discussions on error rates in forensic science. In the past Jonathan Koehler presented issues of concerns. For that reason it is obvious that error rates in specific areas and labs should be stated in the reports somewhere, or at least should be published, similar as we see this development in comparison of hospitals. During proficiency tests and collaborative test they can be determined (at least for a specific kind of case), however I think there also the uncertainty of the error rate should be given. Last time when I testified in a court of appeal in The Hague the question was asked how I personally scored on those, as well as how the group and the whole ENFSI group scored. This is also one of the issues mentioned by Ian Evett, and he stated it as calibration between persons and groups, which should be done such that the conclusions are harmonized between labs.

Also a new development that was presented was forensic assistants at the court who can answer the most common questions on forensic methods, as well ask helping the courts in combining evidence based on the reports.




Tuesday, May 21, 2013

Saint Petersburg International Legal Forum 2013

At the St. Petersburg International Legal Forum I gave a presentation on forensic investigation digital evidence within Europe also from our ENFSI Forensic IT Working group perspective. This conference was very well attended. Prime Minister Dmitry Medvedev opened the conference and our Minister of Security and Justice Ivo Opstelten gave a presentation from the celebration of 400 years collaboration between the Netherlands and Russia. 

Many questions where asked during the forum meetings, and lots of discussion. Also the standardization of Digital Evidence and the ISO 17025 with the new ISO-standards on digital evidence where seen as an important step on harmonization. 



In the meantime I was also looking in bitcoin mining and the properties of bitcoins as well as cloud computing on virtual machines, since there were some questions concerning forensic investigations. I installed some mining software on different cloud virtual machines of different vendors, however as mentioned, it is not cost effective, and certainly energy waisting. Buying ASIC hardware might be more cost effective in the short term, however I assume that either the exchange rate of bitcoins will drop if it gets to easy or the complexity is improved in the meantime. It is interesting to see some of the discussions on forensic investigation of these bitcoins. One can pay with them at Amazon, and at conferences such as Ohm 2013. However bitcoins might disappear according to strategists.

Friday, May 03, 2013

May 2013

It appears to become a nice month, with some project proposals that appear. Last month I invited Nick Goldman at the NFI for a presentation on storage of data  on DNA. At the moment it somewhat costly, however DNA can store the information for thousands of years, something that current digital storage devices are not able to. Since one can store on 1 gram of DNA 2.2 million gigabits of information, this would be 468.000 DVDs, so it is in theory big data. Also developments of data storage in graphene or interesting to watch. Retrieving digital evidence might get more challenging if these developments continue.

This month, I am looking forward since I was invited for the Legal Forum in St Petersburg Russia, to give a presentation there and also in Shanghai, China to a forensic conference on some developments in forensic digital and multimedia evidence. Currently we are also working on the ENFSI Forensic IT Working group meeting in September in Linköping, Sweden, where new developments will be presented.

Currently working on different project proposals for R&D, some casework, reviews, and looking into collaboration and funding possibilities.


 

Monday, April 01, 2013

April 2013

During eastern some time to review reports and papers, and also to have a look at my website and do some updates and further work.

Currently working on several cases and applying for some funds for R&D projects, however as usual not always successful (since many people apply for funding and there is competition, and moreover it is a challenge to write understandable proposals for evaluators, however we learn from every comment).

In April we will also prepare for the conference in September of the ENFSI Forensic IT Working group which will be held from 24-27 September in Linkoping, Sweden.

For R&D projects we also have some intern-ships  and I prefer to have more students working on the same topic, since it appears to me often more efficient.They are available for universities and sometimes we also have students from outside the EU, however it takes somewhat more time for getting approval. Also looking for further collaboration with the University of Amsterdam.

As you can see below, it is interesting to see the number of threats and the countries that they originate from to my website according to the software that I use. I can see also the more complicated captcha protection does not work always that well, and see several dictionary attacks so 2-step verification methods should be used. Currently I use more open source software, however it is important to keep them updated.


In response to growing international interest, DFRWS.org is working with our European colleagues to organize a conference in Amsterdam in Spring 2014. The DFRWS Europe Conference will he held in addition to the DFRWSConference that is held in North America every August.

To help the DFRWS grow, please complete the following survey:

Survey - DFRWS Europe Conference in Amsterdam
http://www.surveymonkey.com/s/3QR85TS

Thursday, March 07, 2013

March 2013

As usual making some new planning and development with three highlights of this month

1. Currently I am working on a Research and Development plan for Digital Evidence and Biometrics in forensic science. When writing down the issues,  there seem to exist some paradoxes in the forensics and creativity of humans.We have the risk paradox, risks have to be taken to develop a new method which fits also in agile careers, and besides that we also have the automation paradox as we saw in airline industry. If we would like to have the newest methods implemented by engineers and scientist, we always take some risk. Mostly in forensic science this will be covered by validation and verification experiments in the real world, though sometimes judges ask for methods that are experimental and not completely validated yet (this should always be stated in the report).

2. For ENFSI new best practice guides are developed in many different field. Sometimes people ask me best practice, does it mean good practice or the best practice. Of course in reality it means good practice, however best practice is a management term which is used in ISO 9000. We try to write best practice as such, to the best effort we have. Smart practice is another means of making it more efficient for a lower price, however in forensic science this is not often used to my knowledge, since the goal is minimizing the errors in the findings. Best practice methods can change from one day on another due to rapid developments, and certainly in digital evidence.

3. When looking in my website  www.forensic.to I see that there appear to happen more sophisticated attacks to the website itself and they also try to make some exploits for mobile phones. So I used some additional shields, mostly it appears to be iframe-injection and vulnerabilities in old scripts that I have used, so I have updated all of them. I also see that the attacks are becoming better, since they appear to be adapt quickly to some filtering methods I use. For that reason I use a combination of off the shelf methods and own developments. Intelligent logging analysis methods remain important to use to watch exploits that are not yet detected by commercial software, so it keeps me busy :)