官术网_书友最值得收藏!

Preserving the evidence

As evidence is collected, it must be preserved in a state that is acceptable in court. Working directly on the original copies of evidence might alter it. So, as soon as you recover a raw disk image or files, create a read-only master copy and duplicate it. In order for evidence to be admissible, there must be a scientific method to validate that the evidence submitted is exactly the same as the original collected. This can be accomplished by creating a forensic hash value of the image.

A forensic hash is used to ensure the integrity of an acquisition by calculating a cryptographically strong and non-reversible value of the image/data.

After duplicating the raw disk image or files, compute and verify the hash values for the original and the copy to ensure that the integrity of the evidence is maintained. Any changes in hash values should be documented and explicable. All further processing or examination should be performed on copies of the evidence. Any use of the device might alter the information stored on the handset. So, only perform the tasks that are absolutely necessary.

主站蜘蛛池模板: 古田县| 沿河| 龙陵县| 龙海市| 星座| 西藏| 安庆市| 大厂| 民县| 巴楚县| 钟祥市| 辽阳县| 聂荣县| 南汇区| 郎溪县| 梧州市| 锡林郭勒盟| 白河县| 青浦区| 宝丰县| 班戈县| 清丰县| 柳江县| 石嘴山市| 桦南县| 长岛县| 尤溪县| 枝江市| 江津市| 洪江市| 徐闻县| 高青县| 旌德县| 华池县| 石楼县| 徐州市| 浏阳市| 台安县| 丹凤县| 宣城市| 碌曲县|