Discovering spoliation of evidence through identifying traces on deleted files in macOS

FORENSIC SCIENCE INTERNATIONAL-DIGITAL INVESTIGATION(2023)

引用 0|浏览0
暂无评分
摘要
Spoliation of evidence is a critical concern in various crimes such as information leakage, digital sexual crimes, accounting fraud, and copyright infringement. Several traditional digital forensic investigation methods such as recovery, carving, and anti-forensic behavior tracking are used to investigate these crimes. However, as technology has advanced, recovery and carving have become increasingly challenging. Shortly, data recovery will reach its technological limit, and it will be essential to obtain as much circumstantial evidence as possible based on traces of data left in suspect systems. However, no existing method can systematically track the spoliation of evidence; contemporary investigations typically depend solely on investigators' skills and knowledge. This paper proposes a method to track deleted files by identifying and analyzing various sources that manage file-related metadata in macOS systems. (c) 2023 The Author(s). Published by Elsevier Ltd on behalf of DFRWS
更多
查看译文
关键词
Digital forensics,Document forensics,macOS,Spoliation of evidence,e-discovery
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要