DocumentCode
1616398
Title
Characteristic Evidence, Counter Evidence and Reconstruction Problems in Forensic Computing
Author
Dewald, Andreas
Author_Institution
Dept. of Comput. Sci., Univ. of Erlangen-Nuremberg (FAU), Erlangen, Germany
fYear
2015
Firstpage
77
Lastpage
82
Abstract
Historically, forensic computing (as digital forensics) developed pragmatically, driven by specific technical needs. Indeed, in comparison with other forensic sciences the field still is rather immature and has many deficits, such as the unclear terminology used in court. In this paper, we introduce notions of (digital) evidence, characteristic evidence, and (characteristic) counter evidence, as well as the definitions of two fundamental forensic reconstruction problems. We show the relation of the observability of the different types of evidence to the solvability of those problems. By doing this, we wish to exemplify the usefulness of formalization in the establishment of a precise terminology. While this will not replace all terminological shortcomings, it (1) may provide the basis for a better understanding between experts, and (2) helps to understand the significance of different types of digital evidence to answer questions in an investigation.
Keywords
digital forensics; characteristic evidence; counter evidence; digital evidence; digital forensics; forensic computing; forensic reconstruction problems; forensic sciences; Computational modeling; Computers; Digital forensics; Electronic mail; Hard disks; Radiation detectors; characteristic evidence; counter evidence; digital forensics; evidence; reconstruction; terminology;
fLanguage
English
Publisher
ieee
Conference_Titel
IT Security Incident Management & IT Forensics (IMF), 2015 Ninth International Conference on
Conference_Location
Magdeburg
Print_ISBN
978-1-4799-9902-6
Type
conf
DOI
10.1109/IMF.2015.15
Filename
7195808
Link To Document