A Digital Evidence Certainty Descriptors (DECDs) for digital forensics

Research output: Contribution to journalArticle

Abstract

Whilst many other traditional forensic science disciplines are encouraged to describe the weight of their evidence in some form of quantifiable measurement/expression, this is rarely done in digital forensics. There are calls to rectify this situation, suggesting that the field should begin to develop more robust, scientific methods for evaluating the digital evidence presented by it’s practitioners. Whilst such a recommendation carries a number of potential benefits, caution must be exercised as at present there are no available satisfactory methods for achieving this. This work suggests that attaining such methods may not actually be possible due to the intricacies of digital data and the difficulties involved with the fine-grained interpretation of events. As a result it is argued that attempts to quantify any uncertainty should be abandoned in favour of methods which reliably describe when uncertainty exists and in what capacity. Here, the Digital Evidence Certainty Descriptors (DECDs) framework is offered as a method for conveying when uncertainty exists in a set of digital findings. The DECDs framework is discussed and applied to working examples to demonstrate the difficulties involved with determining the authenticity of a given hypothesis regarding digital evidence.
Original languageEnglish
JournalForensic Science International: Digital Investigation
Publication statusAccepted/In press - 17 Nov 2019

Fingerprint

Uncertainty
evidence
uncertainty
Conveying
Forensic Sciences
authenticity
Digital forensics
Weights and Measures
interpretation
event
present
science
Forensic science

Cite this

@article{8c32d2160a894d2a97bbeea5491fd33b,
title = "A Digital Evidence Certainty Descriptors (DECDs) for digital forensics",
abstract = "Whilst many other traditional forensic science disciplines are encouraged to describe the weight of their evidence in some form of quantifiable measurement/expression, this is rarely done in digital forensics. There are calls to rectify this situation, suggesting that the field should begin to develop more robust, scientific methods for evaluating the digital evidence presented by it’s practitioners. Whilst such a recommendation carries a number of potential benefits, caution must be exercised as at present there are no available satisfactory methods for achieving this. This work suggests that attaining such methods may not actually be possible due to the intricacies of digital data and the difficulties involved with the fine-grained interpretation of events. As a result it is argued that attempts to quantify any uncertainty should be abandoned in favour of methods which reliably describe when uncertainty exists and in what capacity. Here, the Digital Evidence Certainty Descriptors (DECDs) framework is offered as a method for conveying when uncertainty exists in a set of digital findings. The DECDs framework is discussed and applied to working examples to demonstrate the difficulties involved with determining the authenticity of a given hypothesis regarding digital evidence.",
author = "Graeme Horsman",
year = "2019",
month = "11",
day = "17",
language = "English",
journal = "Digital Investigation",
issn = "1742-2876",
publisher = "Elsevier",

}

TY - JOUR

T1 - A Digital Evidence Certainty Descriptors (DECDs) for digital forensics

AU - Horsman, Graeme

PY - 2019/11/17

Y1 - 2019/11/17

N2 - Whilst many other traditional forensic science disciplines are encouraged to describe the weight of their evidence in some form of quantifiable measurement/expression, this is rarely done in digital forensics. There are calls to rectify this situation, suggesting that the field should begin to develop more robust, scientific methods for evaluating the digital evidence presented by it’s practitioners. Whilst such a recommendation carries a number of potential benefits, caution must be exercised as at present there are no available satisfactory methods for achieving this. This work suggests that attaining such methods may not actually be possible due to the intricacies of digital data and the difficulties involved with the fine-grained interpretation of events. As a result it is argued that attempts to quantify any uncertainty should be abandoned in favour of methods which reliably describe when uncertainty exists and in what capacity. Here, the Digital Evidence Certainty Descriptors (DECDs) framework is offered as a method for conveying when uncertainty exists in a set of digital findings. The DECDs framework is discussed and applied to working examples to demonstrate the difficulties involved with determining the authenticity of a given hypothesis regarding digital evidence.

AB - Whilst many other traditional forensic science disciplines are encouraged to describe the weight of their evidence in some form of quantifiable measurement/expression, this is rarely done in digital forensics. There are calls to rectify this situation, suggesting that the field should begin to develop more robust, scientific methods for evaluating the digital evidence presented by it’s practitioners. Whilst such a recommendation carries a number of potential benefits, caution must be exercised as at present there are no available satisfactory methods for achieving this. This work suggests that attaining such methods may not actually be possible due to the intricacies of digital data and the difficulties involved with the fine-grained interpretation of events. As a result it is argued that attempts to quantify any uncertainty should be abandoned in favour of methods which reliably describe when uncertainty exists and in what capacity. Here, the Digital Evidence Certainty Descriptors (DECDs) framework is offered as a method for conveying when uncertainty exists in a set of digital findings. The DECDs framework is discussed and applied to working examples to demonstrate the difficulties involved with determining the authenticity of a given hypothesis regarding digital evidence.

M3 - Article

JO - Digital Investigation

JF - Digital Investigation

SN - 1742-2876

ER -