TY - JOUR
T1 - When finding nothing may be evidence of something:
T2 - Anti-forensics and digital tool marks
AU - Horsman, Graeme
AU - Errickson, David
PY - 2019/9/30
Y1 - 2019/9/30
N2 - There are an abundance of measures available to the standard digital device users which provide the opportunity to act in an anti-forensic manner and conceal any potential digital evidence denoting a criminal act. Whilst there is a lack of empirical evidence which evaluates the scale of this threat to digital forensic investigations leaving the true extent of engagement with such tools unknown, arguably the field should take proactive steps to examine and record the capabilities of these measures. Whilst forensic science has long accepted the concept of toolmark analysis as part of criminal investigations, ‘digital tool marks’ (DTMs) are a notion rarely acknowledged and considered in digital investigations. DTMs are the traces left behind by a tool or process on a suspect system which can help to determine what malicious behaviour has occurred on a device. This article discusses and champions the need for DTM research in digital forensics highlighting the benefits of doing so.
AB - There are an abundance of measures available to the standard digital device users which provide the opportunity to act in an anti-forensic manner and conceal any potential digital evidence denoting a criminal act. Whilst there is a lack of empirical evidence which evaluates the scale of this threat to digital forensic investigations leaving the true extent of engagement with such tools unknown, arguably the field should take proactive steps to examine and record the capabilities of these measures. Whilst forensic science has long accepted the concept of toolmark analysis as part of criminal investigations, ‘digital tool marks’ (DTMs) are a notion rarely acknowledged and considered in digital investigations. DTMs are the traces left behind by a tool or process on a suspect system which can help to determine what malicious behaviour has occurred on a device. This article discusses and champions the need for DTM research in digital forensics highlighting the benefits of doing so.
UR - http://www.scopus.com/inward/record.url?scp=85067423863&partnerID=8YFLogxK
U2 - 10.1016/j.scijus.2019.06.004
DO - 10.1016/j.scijus.2019.06.004
M3 - Article
VL - 59
SP - 565
EP - 572
JO - Science and Justice - Journal of the Forensic Science Society
JF - Science and Justice - Journal of the Forensic Science Society
SN - 1355-0306
IS - 5
ER -