Home / Business and Politics / The Truth Hidden in E-Records: Digital Forensic Experts Uncover Criminals and Wrongdoers

The Truth Hidden in E-Records: Digital Forensic Experts Uncover Criminals and Wrongdoers

  • The FBI was the first to use computer forensics to investigate computer-related crimes.
  • Cliff Stoll is credited with the rise of the science, having investigated a problem related to a financial report in 1986.
  • Digital forensics does not improve business; it only helps when security fails or a crime occurs.

A ‘selfie’ from social media revealed a Russian diplomatic lie, a Word document from a floppy disk uncovered a mass murderer after thirty years of playing cat and mouse with American police, and a mistake in a financial report of less than one dollar exposed a German hacker who infiltrated systems and sold stolen data to a secret service… All these secrets were revealed by digital forensics.

Although Russia vehemently denied that its military units were present in Ukraine after the violent annexation of Crimea in 2014, a photograph of Russian army sergeant Alexander Sotkin published on Instagram exposed the diplomatic lie. While on duty, moving between a military base in Russia and Ukraine, Sotkin took a selfie and posted it with a geographical tag on the social network Instagram.

This is just one example of digital forensics and how digital forensic experts gather evidence. In another case, digital forensics played a crucial role in finding a mass American murderer, a case known as ‘BTK’. Dennis Rader tortured and killed at least ten people but remained undetected for three decades. For thirty years, he sent strange messages to the American police during his killing sprees, and he was only uncovered in 2005 when he sent them a Word document on a floppy disk. Digital forensic experts managed to trace the data from the disk, which helped reveal the true identity of the BTK killer, leading to Rader’s eventual arrest.

From Pornography to Espionage

Digital forensics is a branch of forensic science that involves the collection and processing of data stored in digital form, usually related to crimes involving the use of computers; it includes the collection of digital evidence from various devices, tools, or infrastructures such as computers, mobile devices, email, hard drives, and cloud storage systems. The term ‘computer forensics’ has been in use since 1984 – the FBI was the first to use it to investigate computer-related crimes when it launched the first computer forensics program (Magnet Media Program).

However, the rise of digital forensics is largely credited to Cliff Stoll from the Lawrence Berkeley National Laboratory, who investigated a problem related to a financial report in 1986. Although it involved an amount of less than a dollar, Cliff’s meticulous investigation led him to a German hacker who was infiltrating systems and selling the collected data to the Russian secret service, the KGB. This was the first discovery of digital forensics. Soon, it began to be used by American police to uncover child pornography and other criminal investigations, and then by the U.S. military in the wars in Iraq and Afghanistan.

After computer forensics gained momentum, primarily in combating child pornography, it expanded to all areas containing digital data. Today, companies also widely use it, where digital forensic experts uncover instances where employees mishandle sensitive information and the consequences of cyber attacks.

The First Policemen

Chad Gough, owner of the American computer forensics company 4Discovery, who has collaborated with Fortune 500 companies for over twenty years and led hundreds of digital forensic investigations, stated that ‘digital forensics is a forensic science just like toxicology because computer artifacts can be identified, examined, tested, replicated, and reviewed.’

According to the Vantage Market Research report on forensic technology markets for 2022, the global forensic industry is expected to generate around $27 billion by 2028. The digital forensics market is growing due to the fact that computers are an integral part of smartwatches, mobile phones, CCTV systems, and even smart sprinkler systems, making it impossible for any industry to progress without integrating digital technology into business processes.

The ministries of internal affairs (police) were the first institutions to start applying digital forensics, and later, once its usefulness was recognized and where it could be applied, it expanded to other law enforcement agencies: tax authorities, customs, competition protection agencies, financial police, state security agencies, the military…

Reading Digital Traces

In Croatia, several companies are engaged in digital forensics. One of them is INsig2, specialized in integrated security solutions and services related to digital forensics, which has been operating in the Croatian and foreign markets for nearly twenty years. It works for both the private and public sectors, from police and military to banking, pharmaceutical industries, healthcare, and the technology sector.

The head of digital forensics at the company, Krešimir Hausknecht, explains that after its early beginnings, digital forensics gained significant momentum with the greater availability of broadband internet, mobile devices, social networks, and, more recently, with cybercrime – primarily ransomware and data theft. It is divided into computer, mobile, network forensics, and cloud forensics. The main difference among these categories is where the data is located and how it is collected: the data source is powered off/on, the data is physically accessible, or it must be accessed remotely, or it is in transition.

– The digital forensics process consists of several steps: preparation, finding, collecting, analyzing, and documenting digital evidence. The order can vary depending on the type of case and who is conducting it, whether it is a law enforcement agency or a corporation. Today, most data is in digital form, and most of the work done leaves a digital trace. We are all dependent on mobile devices all day for communication, information, or using services necessary for daily life, such as banking.

And the whole world is going in that direction: you simply cannot function as a citizen without certain mobile applications or the internet – says Hausknecht, adding that digital evidence can provide an extremely large amount of data about each person: name and surname, their address, names of family members, interests, visited locations, friends, relatives, communication history, movement, education, banking data, business data and communication, purchase history… This data can later serve in an investigation and be matched with more data from other people or sources. Other sources relate to various databases, public video surveillance, ISP data (internet service providers), government institutions, archives…

– Digital forensics has also become part of IT security, i.e., corporate cybersecurity, and even smaller businesses. Digital forensic experts deal with it. The situation varies around the world. Generally, we have two sources of experts: police academies or specialized universities that are more oriented towards cybersecurity or cyber forensics.

At the same places, basic training is provided, but the main part of the education takes place within specialized training offered by INsig2; there is also training with equipment manufacturers used in this field. INsig2 offers various courses in different areas and levels: beginner, intermediate, and advanced – says Hausknecht, explaining that digital forensic experts can be investigators, analysts, technicians… If it is cyber forensics, a range of professions includes digital forensics: SOC analyst, incident response personnel, SIEM operator, etc.

Everything is Discovered

According to Hausknecht, the digital forensic process varies from case to case, and models differ depending on the investigation’s goal: law enforcement, auditing, or incident response, and on average, they last at least five days. When there are more data or devices, the analysis can take several months. Hausknecht cannot speak about which companies INsig2 has worked with on digital forensics and the reasons for that due to confidentiality agreements.

However, generally, every investigation has a goal or questions that need to be answered. For example, did A communicate with B, when did it happen, what was the content, was A at location B on a specific date; identifying a person from video surveillance, identifying the owner of a specific online account, proving that a person did something using a specific device, for example, created a document, stole it, or sent it to a third party, and whether data was manipulated…

There are countless questions that only digital forensics can answer, but it does not improve business as it is applied only when security fails or a problem or crime occurs.

Tagged: