Digital evidence & forensics
Master Thesis
Author
Δημόπουλος, Σταύρος
Dimopoulos, Stavros
Date
2021-02View/ Open
Keywords
Cyber ; Cybercrime ; Computer ; Investigation ; Ψηφιακή εγκληματολογία ; Έρευνα ; Κυβερνοέγκλημα ; ΥπολογιστήςAbstract
Digital forensics (sometimes known as digital forensic science) is a branch of forensic science encompassing the recovery and investigation of material found in digital devices, often in relation to cybercrime. The technical aspect of an investigation is divided into several branches, relating to the type of digital devices involved that is computer forensics, network forensics, forensic data analysis and mobile device forensics. The examination of digital media is covered by national and international legislation.
The prerequisite for digital forensics is the electronic evidence gathering which is a process that involves the assessment of a given situation and the identification and recovery of relevant sources of data that could be of evidential value to the investigation. When gathering any form of evidence, including digital evidence, it is of vital importance that appropriate procedures and guidelines are strictly followed and adhered to.
For the longest time, law enforcement and other organizations performing digital forensic tasks associated with incident investigations often relied on methodologies that focused on evidence contained within the hard drive. This overlooked the wealth of information that was contained within the Random Access Memory (RAM) of the targeted system. In the last section of this thesis we are going to present a lab experiment of memory (RAM) acquisition and investigation.