官术网_书友最值得收藏!

Preserving the evidence

As evidence is collected, it must be preserved in a state that is acceptable in court. Working directly on the original copies of evidence might alter it. So, as soon as you recover a raw disk image or files, create a read-only master copy and duplicate it. In order for evidence to be admissible, there must be a method to verify that the evidence presented is exactly the same as the original collected. This can be accomplished by creating a forensic hash value of the image. A forensic hash is used to ensure the integrity of an acquisition by calculating a cryptographically strong and non-reversible value of the image/data. After duplicating the raw disk image or files, compute and verify the hash values for the original and the copy to ensure that the integrity of the evidence is maintained. Any changes in hash values should be documented and explainable. All further processing or examination should be performed on copies of the evidence. Any use of the device might alter the information stored on the handset. So, only perform the tasks that are absolutely necessary.

主站蜘蛛池模板: 金川县| 南郑县| 巫溪县| 宁乡县| 黑水县| 东海县| 奉新县| 广宁县| 雷山县| 独山县| 理塘县| 濮阳市| 如东县| 西和县| 湖北省| 龙江县| 阳原县| 富顺县| 定远县| 财经| 团风县| 龙口市| 武山县| 平湖市| 金湖县| 镇远县| 寿阳县| 濮阳县| 城口县| 西盟| 玛曲县| 马鞍山市| 上饶县| 宁河县| 宣城市| 申扎县| 于田县| 大余县| 桂平市| 河池市| 绥阳县|