DocumentCode :
3429964
Title :
Seizure of digital data and “selective suppression” of digital evidence
Author :
Kuntze, Nicolai ; Rudolph, Carsten ; Schilling, Hendrik ; Alva, Aaron ; Brisbois, Brooke ; Endicott-Popovsky, Barbara
Author_Institution :
Fraunhofer SIT, Germany
fYear :
2013
fDate :
21-22 Nov. 2013
Firstpage :
1
Lastpage :
6
Abstract :
The search and gathering of potential digital evidence often includes taking images of hard-drives and other storage media. Instead of actually taking the physical hard-drive, only the data contained on the drive is mirrored, stored and then used for investigations. This article discusses the legal context in Germany and in the U.S. and compares the actual legal situation with the current practice based on the available software products for forensic evaluations. In spite of large differences between both countries, the investigation shows that in both cases current technology needs to be improved or even is in contradiction with basic laws. The proposed solution can provide a suitable implementation without changing the actual process of evaluating the digital evidence. For investigations in Germany, the new process proposes a selective partial deletion of images, thus removing all inadmissible data. For the U.S. the process proposes a selective suppression of data so that it can be recovered if a case is appealed.
Keywords :
digital forensics; legislation; digital data seizure; digital evidence; forensic evaluations; legal situation; selective data suppression; software products; Computers; Entertainment industry; Forensics; Government; Media;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Systematic Approaches to Digital Forensic Engineering (SADFE), 2013 Eighth International Workshop on
Conference_Location :
Hong Kong
Type :
conf
DOI :
10.1109/SADFE.2013.6911545
Filename :
6911545
Link To Document :
بازگشت