How to store digital evidence paper

Step 1

In a recent study by Berkeley scientists, the reports show that 93 percent of the information never leaves the domain. This implies that the majority of the information can be created and consumed in digital form. The worldwide proliferation of the computers and growth of the internet have increased the demand for digital investigations. In fact, cybercriminals have been committing numerous computer crimes such as unethical hacking, email harassment and leaks of the property information. In an effort to fight the increasing computer crimes and collect the relevant digital evidence for such crimes, the investigating agencies usually incorporate the collection and analysis of digital evidence into their infrastructure.

Storing digital evidence

Digital evidence is usually stored or transmitted in binary form which can be relied on during the trial. This information can be found in computer hard disks, USB disks, personal digital assistants, CDs, mobile phones or flash cards. There are different types of digital evidence which include browser history, audio files and voice recordings, bookmarks and favorites, databases, cookies, documents, configuration and .ini files, emails messages, log files, backups, pictures or images, videos, hidden and compressed archives (ZIP, RAR, etc.). The digital evidence of the firm can be found in the USB stick, RAM and swap space of the live computers as well as the hard drive of the networked computers. The USB stick is the storage devices which comprises of flash storage integrated with USB interface. RAM is hardware in a computer where operating system, application programs and data in use are kept for quick access. The hard drive is hardware where the processor is kept.
The data capture from forensic analysis of these locations is useful because they can unveil where a breach of information occurred. The forensic examination of the USB sticks can reveal the current and deleted sensitive corporal or personal data. The forensic analysis of RAM and Swap space, as well as Hard disk, can show the information processed in the computer and the sensitive data deleted.

Don't use plagiarized sources. Get Your Custom Essay on
How to store digital evidence paper
Just from $9/Page
Order Essay

Types of data in these locations

There are three types of data which can be found in these locations; active data, archival data and latent data. The active data refers to the information which we can actually see. This includes data files and programs in the RAM and swap space of the live computers. The archival data refers to the information which has been backed up and stored. These involve the information in a USB stick or the hard drive of networked computers. Latent data involves the information in which an individual needs specialized tools to access. This may involve the information deleted from the RAM of live computers or the hard drive of the networked computers.
Digital evidence can be stored in different formats; Raw format, advanced forensics format and proprietary formats. The raw format makes it easy for an individual to write bit-stream data to files. This format is commonly used in Linux which uses command “dd”. This format has various advantages which include fast in data transfer, avoids minor errors of data read from the source and data can be read by various forensic tools. But it also two main disadvantages; requires much storage and tools might not collect marginal sectors. Advanced Forensic format uses various file extensions such as. E01, .E02, .E03 etc. for storage. Images are stored as “. afd” while metadata is stored as “.afm”. the main advantage of this form is that it’s open to all forensic tools. In propriety formats, every forensic tool has its own format. The main advantage of this format is that one can compress or not compress image files, can split images into segments and can integrate metadata into image files. However, one cannot share the image with different forensic tools.

Step 2

When conducting an investigation, the information in the disks must be hashed. I would use MD5 and SHA1 hashing algorithm. This ensures that correct information is received at the end for proper investigation. MD5 is a one-way function and produces information in size of 128 t0 256 bits. It enables the investigator to verify the integrity of data and identify possible corruption of data files by comparing hash values. SHA1 (secure hashing algorithm) produces a hash value of size 160 bits. These types of hashing will ensure that forensic copies are an exact replica of the original files.
It’s widely expected that the original data and the forensic copies should produce the same has values. If the hash values are not identical, it’s assumed that the files were corrupted during the data transfer. The main cause of different hash values is the corruption of files by hackers. The data has been altered on the transit and the receiver will get distorted information.
When the OS automatically mounts on the flash disk before creating a forensic duplicate, the information that an individual wants to keep unchanged can be altered or corrupted. One cannot know what the system may do when interacted with corrupt files. This could turn the digital evidence into unworkable and useless pieces of information. furthermore, it would be difficult to use forensic tools on such disk.
To know that OS has not automatically mounted on the disk, one should use Adepto tool. This tool creates driver images and files by creating forensic sound images from the hard drive. Using this tool, an individual can identify the logs of events which occurred in a particular computer. The logs provide proof of any unexpected operations which occurred on the computer. Thus, using these logs one can easily know when the OS has not automatically mounted on the disk.

Step 3

The analysis of the networked computer can be done through three main steps; extraction of information, identification and analysis. Before extracting the information, one should ensure the validation of all hardware and software. This seeks to ascertain that everything in the networked computer works perfectly. One should retest any update, patch or configuration. Using a forensic tool, Linux “dd”, I would sift through hard drives, email accounts, social networking sites, logs, browser history and other sources of digital evidence to retrieve and assess any information which can be used as viable evidence of the crime. The integrity of the data is determined through MD5 and SHA1 hashing algorithms. This helps in creating a forensic image which is a bit-to-bit copy of the data which exists in the networked computer, without any addition or deletion. After verifying the integrity of the data, the next step is extracting the data. I would organize and refine forensic questions which I would try to answer using the Linux “dd” tool. The questions are added to the “search list” which comprises of the list of requested items. For instance, the request might provide the lead “Search for zero bits concept”. As the questions are answered, they are marked as “proceed” or “done”. For each lead, the data is extracted and marked as “proceed”. The “extracted data” list is made to enable easy search of the leads.
In the identification phase, the extracted data is examined to know the kind of item in it. If any information outside the scope of the investigation is found in the extracted data, the supervisor will be informed. All the relevant items in the extracted data are grouped into a third list named as “Relevant data list”. This data would assist in answering the original forensic request, finding the sources of ZeroBit information leaks. This examination of the networked computer will be more focused on the firewall logs, browser history and building access logs. After accessing the extracted data, I would go back to the extraction process with new leads. This involves the process of obtaining and imaging new forensic data to find new evidence. If the extracted data is sufficient for the case, I would proceed to the analysis of extracted data.
In the analysis phase, all the links of the crime are connected to identify the source of ZeroBit information leakage. The relevant data list will be used to reveal the possible source of information leakage. This will determine when and where the ZeroBit data was created and corrupted. It also helps to connect the files on the storage devices to the online data transfers to examine how the information was leaked. After the analysis, the report is documented showing the integrity of data, the extracted data, possible leads to information leakage and solutions to prevent possible crimes.

Get Professional Assignment Help Cheaply

Buy Custom Essay

Are you busy and do not have time to handle your assignment? Are you scared that your paper will not make the grade? Do you have responsibilities that may hinder you from turning in your assignment on time? Are you tired and can barely handle your assignment? Are your grades inconsistent?

Whichever your reason is, it is valid! You can get professional academic help from our service at affordable rates. We have a team of professional academic writers who can handle all your assignments.

Why Choose Our Academic Writing Service?

  • Plagiarism free papers
  • Timely delivery
  • Any deadline
  • Skilled, Experienced Native English Writers
  • Subject-relevant academic writer
  • Adherence to paper instructions
  • Ability to tackle bulk assignments
  • Reasonable prices
  • 24/7 Customer Support
  • Get superb grades consistently

Online Academic Help With Different Subjects


Students barely have time to read. We got you! Have your literature essay or book review written without having the hassle of reading the book. You can get your literature paper custom-written for you by our literature specialists.


Do you struggle with finance? No need to torture yourself if finance is not your cup of tea. You can order your finance paper from our academic writing service and get 100% original work from competent finance experts.

Computer science

Computer science is a tough subject. Fortunately, our computer science experts are up to the match. No need to stress and have sleepless nights. Our academic writers will tackle all your computer science assignments and deliver them on time. Let us handle all your python, java, ruby, JavaScript, php , C+ assignments!


While psychology may be an interesting subject, you may lack sufficient time to handle your assignments. Don’t despair; by using our academic writing service, you can be assured of perfect grades. Moreover, your grades will be consistent.


Engineering is quite a demanding subject. Students face a lot of pressure and barely have enough time to do what they love to do. Our academic writing service got you covered! Our engineering specialists follow the paper instructions and ensure timely delivery of the paper.


In the nursing course, you may have difficulties with literature reviews, annotated bibliographies, critical essays, and other assignments. Our nursing assignment writers will offer you professional nursing paper help at low prices.


Truth be told, sociology papers can be quite exhausting. Our academic writing service relieves you of fatigue, pressure, and stress. You can relax and have peace of mind as our academic writers handle your sociology assignment.


We take pride in having some of the best business writers in the industry. Our business writers have a lot of experience in the field. They are reliable, and you can be assured of a high-grade paper. They are able to handle business papers of any subject, length, deadline, and difficulty!


We boast of having some of the most experienced statistics experts in the industry. Our statistics experts have diverse skills, expertise, and knowledge to handle any kind of assignment. They have access to all kinds of software to get your assignment done.


Writing a law essay may prove to be an insurmountable obstacle, especially when you need to know the peculiarities of the legislative framework. Take advantage of our top-notch law specialists and get superb grades and 100% satisfaction.

What discipline/subjects do you deal in?

We have highlighted some of the most popular subjects we handle above. Those are just a tip of the iceberg. We deal in all academic disciplines since our writers are as diverse. They have been drawn from across all disciplines, and orders are assigned to those writers believed to be the best in the field. In a nutshell, there is no task we cannot handle; all you need to do is place your order with us. As long as your instructions are clear, just trust we shall deliver irrespective of the discipline.

Are your writers competent enough to handle my paper?

Our essay writers are graduates with bachelor's, masters, Ph.D., and doctorate degrees in various subjects. The minimum requirement to be an essay writer with our essay writing service is to have a college degree. All our academic writers have a minimum of two years of academic writing. We have a stringent recruitment process to ensure that we get only the most competent essay writers in the industry. We also ensure that the writers are handsomely compensated for their value. The majority of our writers are native English speakers. As such, the fluency of language and grammar is impeccable.

What if I don’t like the paper?

There is a very low likelihood that you won’t like the paper.

Reasons being:

  • When assigning your order, we match the paper’s discipline with the writer’s field/specialization. Since all our writers are graduates, we match the paper’s subject with the field the writer studied. For instance, if it’s a nursing paper, only a nursing graduate and writer will handle it. Furthermore, all our writers have academic writing experience and top-notch research skills.
  • We have a quality assurance that reviews the paper before it gets to you. As such, we ensure that you get a paper that meets the required standard and will most definitely make the grade.

In the event that you don’t like your paper:

  • The writer will revise the paper up to your pleasing. You have unlimited revisions. You simply need to highlight what specifically you don’t like about the paper, and the writer will make the amendments. The paper will be revised until you are satisfied. Revisions are free of charge
  • We will have a different writer write the paper from scratch.
  • Last resort, if the above does not work, we will refund your money.

Will the professor find out I didn’t write the paper myself?

Not at all. All papers are written from scratch. There is no way your tutor or instructor will realize that you did not write the paper yourself. In fact, we recommend using our assignment help services for consistent results.

What if the paper is plagiarized?

We check all papers for plagiarism before we submit them. We use powerful plagiarism checking software such as SafeAssign, LopesWrite, and Turnitin. We also upload the plagiarism report so that you can review it. We understand that plagiarism is academic suicide. We would not take the risk of submitting plagiarized work and jeopardize your academic journey. Furthermore, we do not sell or use prewritten papers, and each paper is written from scratch.

When will I get my paper?

You determine when you get the paper by setting the deadline when placing the order. All papers are delivered within the deadline. We are well aware that we operate in a time-sensitive industry. As such, we have laid out strategies to ensure that the client receives the paper on time and they never miss the deadline. We understand that papers that are submitted late have some points deducted. We do not want you to miss any points due to late submission. We work on beating deadlines by huge margins in order to ensure that you have ample time to review the paper before you submit it.

Will anyone find out that I used your services?

We have a privacy and confidentiality policy that guides our work. We NEVER share any customer information with third parties. Noone will ever know that you used our assignment help services. It’s only between you and us. We are bound by our policies to protect the customer’s identity and information. All your information, such as your names, phone number, email, order information, and so on, are protected. We have robust security systems that ensure that your data is protected. Hacking our systems is close to impossible, and it has never happened.

How our Assignment  Help Service Works

1.      Place an order

You fill all the paper instructions in the order form. Make sure you include all the helpful materials so that our academic writers can deliver the perfect paper. It will also help to eliminate unnecessary revisions.

2.      Pay for the order

Proceed to pay for the paper so that it can be assigned to one of our expert academic writers. The paper subject is matched with the writer’s area of specialization.

3.      Track the progress

You communicate with the writer and know about the progress of the paper. The client can ask the writer for drafts of the paper. The client can upload extra material and include additional instructions from the lecturer. Receive a paper.

4.      Download the paper

The paper is sent to your email and uploaded to your personal account. You also get a plagiarism report attached to your paper.

smile and order essaysmile and order essay PLACE THIS ORDER OR A SIMILAR ORDER WITH US TODAY AND GET A PERFECT SCORE!!!

order custom essay paper