MN624 Digital Forensics

  • Subject Code :  

    MN624

  • Country :  

    AU

  • University :  

    Melbourne Institute of Technology

Answer:-

Introduction

As an examiner in computer forensics, the case has been assigned wherein a scenario needs to be investigation. The case that has been assigned deals with a matter that involves IP-theft in a corporate setting. The person named as   "Tom Johnson" would be a staffer of the bicycle business called "superior bicycles Inc" who has now been expelled for corrupt practices involving theft of intellectual property. He is suspected to be joined hands by another former employee of the company named 'Jim Shu' who also worked there but was fired due to unkown reasons.   The corporation's stockholder, "Bob Aspen," is an external consultant who receives unusual email messages from Terry Sadler about the new venture established by "Jim Shu." This same message received from Terry Sadder had been relayed to the president of said bicycle firm, "Chris Robinson," for something like the external funding of the special project which may be needed in the near future. The same email is again forwarded  general counsel "Ralph Benson," who will investigate the case. Ralph Benson relayed the message to Bob Swartz so that he may look at the unsolicited email as well as it's attachment. When there is an investigation after looking for an IT, this same email was forwarded back to Chris Robinson. This same USB drive had been discovered on Tom Johnson's work station. My mission is to protect the cycling company's private data, that may be disguised in the format of any photos on the Usb flash drive. Utilizing steganography, a few of the data from the superior bicycle Inc investigative process were discovered on an Usb flash drive that had been concealed earlier (Shekhanin et al., 2019). The header of the target file's hexadecimal codes were altered to conceal the file.

The current framework of the case is as follows:

The outline of actions to be taken for digital forensics and the expected outcomes are as follows:

  • There ought to be effective oversight over through the Usb flash drive that is discovered (Adams et al., 2013).
  • A proper framework and plan for what needs to happen after getting hold of the Usb flash drive must be provided.
  • What proof and observations do we get from the obtained drive? (André rnes, 2018)
  • Is all this Tom Johnson's motivation, or is someone attempting to frame him?
  • If there are any source documents that could be used that may violate company's policy ? 
  • Is there any other's involvement apart from the suspect? 

Forensics tools used 

  1. AutoSpy tool, which would be an open-source software provides a platform for forensic experts, is often used in several digital forensics research facility for investigation purposes (Casey, 2019). The above tool is primarily useful inside the armed forces, corporate investigators, and police departments for image retrieval from a assailant or victim’s computer that has been concealed, erased, or tainted. The app has the following features: it is quite simple to use, it is customizable and economically viable, and its analysis task performance is quite fast.
  2. WinHex is an open - sourced hexadecimal editor that is important for data recovering, handling IT infrastructure security, image analysis, and several other applications (Joakim Kävrestad, 2020). This same information can be analysed in hexadecimal method, allowing deep level access. The WinHex's features are as follows:–
  • Winhex offers a free trial, however a licence is expected to allow using it.
  • Winhex allows for acquisition of discs, files, and memory [10].
  • It also includes memory and storage evaluation.
  • It also features a built write-blocker, that also adds an added level of security to help protect the integrity of data being acquired
  • Winhex also includes a number of methods for retrieving records, such as hex, integer, file-type, as well as other methodologies (Kahvedi, 2018).
  1. The Hex Workshop Hex Editor is a collection of hexadecimal software products for Microsoft platform that combines advanced binary editor with both the simplicity as well as flexibility of something like a word processor. Hex Workshop allows users to edit, split, duplicate, insert, paste, and also delete hex codes, as well as print customised hex dumps as well as export to RTF as well as HTML for publication. 

Analysis

  • The USB was used as a forensic copy to reach the appropriate conclusion.
  • Files which could be used as proof are collected and may be needed for further inquiry or indictment in a courtroom.
  • This assessment maintains the integrity of the acquired images out from forensic investigation process and is validated against the data that was present at the time of acquirement (Mohamed & Khalid, 2019).
  • Significant and exact analysis is performed after observing and realising the data file obtained from Tom Johnson.
  • The prosecution's tools are clearly addressed so that they're used immediately for just about any technical purpose.
  • Autopsy, Hex Workshop, as well as WinHex are among the most prominent forensics tools used for cyber forensic analysis (Nelson et al., 2017).
  • Obfuscation is used throughout the case to recover and conceal the transmitted data from its original state. The study is conducted on the “C08InChp.dd” file; the obtained data files contain obfuscation techniques that is abnormal in size, as well as some photographs are concealed. This is done to avoid normal people from observing the files, and that could be argued that Tom Johnson, the accused in this case, did it on purpose.

Findings

  • Using various approaches and forensic tools such as Autopsy, Windows Photo Viewer, WinHex, as well as HexWorkshop, the investigation was able to locate a few images where its header extension had been changed from its original state in the ch08 file (C08InChp.dd)
  • The e - mail attachments specifically indicate that the headers of graphic files, excel files as well as text files have been removed to prevent being filtered by enterprise monitoring systems. 
  • Jim Shu went on a kayak production tour and took out pictures and thereafter modified using hexadecimal tools. 
  • Images hidden in XLS (excel documents): A few of the files containing image files were also discovered to be obfuscated as XLS documents in the Government Data directory.
  • However, using the WinHex editor, the txt file headers are re-translated to jpg files by FF D8 FF E0 and changing the text zFIF to JFIF.
  • Through the investigation using the tools and techniques mentioned earlier, the entire process was able to extract the files gametour2.exe, gametour3.exe, gametour4.exe (deposited in the Vacation Pictures directory) and odyssey11.txt with the metadata of revision, access, creation, and so forth by having to search the query ‘zzzz'.
  • It is essential to understand these files because they consist graphic files but also have the incorrectly but deliberately assigned .exe,.txt, and.xls extensions.
  • With said evidence, the said files were converted from the original.exe extension to a.jpg file extension and thereafter extracted. The observation here was that, only changing the extension to.jpg format will not allow users to view the file. To retrieve a picture from each file, the process involved utilizing WinHex and Hex Workshop and thereafter modifying a few specific bytes FF D8 Ff E0 as well as 4A. Once this is done, the files could then be seen using a picture viewer on any computer system (Steel, 2014).

Summary of Findings

Steganographic file - _51.xls

teganographic file - _1.xls

Steganographic file – gametour4.exe

Steganographic file – odyssey11.txt

Steganographic file – gametour3.exe

Steganographic file – gametour2.exe

Conclusion 

The effective implementation of digital forensics provides the case circumstance, and then the investigation was able to locate multiple files in support of the claim using the gathered evidence and correct evaluation. The email discussion in which Jim Shu transferred the photographs of the Kayaks by altering the header, as specifically stated in the mail. Steganography is employed in this situation to recover and conceal the transmitted data from its original condition. This is done to avoid regular individuals from reading the data as well as enterprise monitoring systems in triggering an alert and it may be argued that Tom John, the accused throughout this case, did so on purpose. To be seen, the stolen images must be remodified with the right file header as well as renamed utilising the correct extension so that the case can be trialled.  Tom Johnson stole Superior Bicycles, Inc.'s intellectual property, according to clear proof. It may be determined that Tom Johnson as well as his cousin Jim Shu were engaged in the business's intellectual property theft.

References

Adams, R., Hobbs, V., & Mann, G. (2013). The Advanced Data Acquisition Model (Adam): A Process Model for Digital Forensic Practice. Journal of Digital Forensics, Security and Law. https://doi.org/10.15394/jdfsl.2013.1154

André Årnes. (2018). Digital forensics : an academic introduction. John Wiley & Sons Inc.

Casey, E. (2019). Maturation of digital forensics. Digital Investigation, 29, A1–A2. https://doi.org/10.1016/j.diin.2019.05.002

Joakim Kävrestad. (2020). Fundamentals of digital forensics : theory, methods, and real-Life applications. Springer.

Kahvedžić, D. (2018). Correlating Orphaned Windows Registry Data Structures. Journal of Digital Forensics, Security and Law. https://doi.org/10.15394/jdfsl.2009.1057

Mohamed, A., & Khalid, C. (2019). Detection of Timestamps Tampering in NTFS using Machine Learning. Procedia Computer Science, 160, 778–784. https://doi.org/10.1016/j.procs.2019.11.011

Nelson, B., Phillips, A., & Steuart, C. (2017). Guide to Computer Forensics and Investigations + Mindtap Security Lab, 1 Term 6 Months Access Card for Nelson/Phillips/steuart’s Guide to Computer Forensics and Investigations Via Live Virtual Machines. Cengage Learning.

Sammons, J. (2015). Digital Forensics With the Accessdata Forensic Toolkit (Ftk). Mcgraw-Hill Osborne Media.

Shekhanin, K. Yu., Kolhatin, A. O., Demenko, E. E., & Kuznetsov, A. A. (2019). ON HIDING DATA INTO THE STRUCTURE OF THE FAT FAMILY FILE SYSTEM. Telecommunications and Radio Engineering, 78(11), 973–985. https://doi.org/10.1615/telecomradeng.v78.i11.50

Steel, C. (2014). Idiographic Digital Profiling: Behavioral Analysis Based On Digital Forensics. Journal of Digital Forensics, Security and Law. https://doi.org/10.15394/jdfsl.2014.1160

Tanenbaum, A. S., & Bos, H. (2015). Modern operating systems. Pearson Education.

Have you reached your limit trying to find dependable assignment help in London, Glasgow, Nottingham, Bristol, and Cardiff? Now, unlock top-quality dissertation help in the UK only on Myassignmenthelp.co.uk.

For over a decade, we have been resolving assignment problems for millions of students wondering, “Who can provide me with quality homework help?” Our priority is to maintain top-notch standards in every assignment we deliver.

As a result, when you look for law assignment help on our website, you can hire professional lawyers for a consultation. So, don't let your academic worries fester. Instead, hire our professional paper writers and increase your chances of securing an A+.

Why Student Prefer Us ?
Top quality papers

We do not compromise when it comes to maintaining high quality that our customers expect from us. Our quality assurance team keeps an eye on this matter.

100% affordable

We are the only company which offers qualitative and custom assignment writing services at low prices. Our charges will not burn your pocket.

Timely delivery

We never delay to deliver the assignments. We are very particular about this. We assure that you will receive your paper on the promised date.

Round the clock support

We assure 24/7 live support. Our customer care executives remain always online. You can call us anytime. We will resolve your issues as early as possible.

Privacy guaranteed

We assure 100% confidentiality of all your personal details. We will not share your information. You can visit our privacy policy page for more details.

Upload your Assignment and improve Your Grade

Boost Grades