官术网_书友最值得收藏!

Preserving the evidence

As evidence is collected, it must be preserved in a state that is acceptable in court. Working directly on the original copies of evidence might alter it. So, as soon as you recover a raw disk image or files, create a read-only master copy and duplicate it. In order for evidence to be admissible, there must be a scientific method to validate that the evidence submitted is exactly the same as the original collected. This can be accomplished by creating a forensic hash value of the image.

A forensic hash is used to ensure the integrity of an acquisition by calculating a cryptographically strong and non-reversible value of the image/data.

After duplicating the raw disk image or files, compute and verify the hash values for the original and the copy to ensure that the integrity of the evidence is maintained. Any changes in hash values should be documented and explicable. All further processing or examination should be performed on copies of the evidence. Any use of the device might alter the information stored on the handset. So, only perform the tasks that are absolutely necessary.

主站蜘蛛池模板: 保康县| 屏南县| 遂溪县| 昌邑市| 任丘市| 灌阳县| 靖州| 吉水县| 河南省| 自治县| 平顺县| 金门县| 许昌市| 桐柏县| 金乡县| 邻水| 巴中市| 濮阳县| 华安县| 兴隆县| 屏东市| 凤山市| 临澧县| 清徐县| 石景山区| 囊谦县| 东源县| 虎林市| 大方县| 安义县| 柞水县| 泰州市| 同仁县| 樟树市| 海口市| 大石桥市| 天柱县| 佛坪县| 伊宁县| 石狮市| 双柏县|