Computer Forensics as a Way of Investigation


Computer Forensics as a Way of Investigation
There are many criminal cases where investigation is required. Investigators make use of the latest science and technology during investigation to get some proof or evidence for legal purpose while dealing with criminal matters. Doing such investigation by making use of latest technology and science is often called forensics. While the art and science of applying computer science to retrieve evidence to use within criminal or civil courts of law is called computer forensics.

Computer forensics experts make use of advanced tools that goes above and beyond the normal data collection and are able to recover even damaged and deleted files. The art of computer forensics include various processes to examine the computer system carefully to search for evidence. Mostly, computer forensics experts carefully examine and check for suspected data in computer data storage devices including hard drives and portable data devices like Micro Drives, USB Drives External drives and many more. The process also involves reviewing the Windows registry for suspect information, discovering and cracking passwords, keyword searches for topics related to the crime, and extracting e-mail and images for examination.

The first step in obtaining computer forensic evidence is obtaining a search warrant to seize the suspect system. This warrant must include wording allowing the investigators to seize not only the computer, but also any peripherals thought to be connected with the crime. A suspected counterfeiter, for instance, may have used his computer, a scanner, and a printer to produce his counterfeit documents, in which case all three items would need to be seized to provide evidence.

A thorough Computer forensic examination and its subsequent analysis is not something that can be done by anyone, a specialist in the field will be required to examine any suspect computer system that has been seized for this purpose. He will be able examine it as a detective rather than as an IT expert, he will not chase after isolated piece of information; instead he will let the clues and the digital data as a whole tell the story. To do this, and ensure that the evidence is acceptable to a court, he needs a foot in both camps – IT expert and detective.

Computer forensics is done in a fashion that adheres to the standards of evidence that are admissible in a court of law. The main motto of computer forensic experts is not only to find the criminal but also to find out the evidence and the presentation of the evidence in a manner that leads to legal action of the culprit. They Identify sources of documentary or other digital evidence, preserve the evidence, analyze the evidence and finally present the findings. It can help companies track and recover millions of dollars of stolen digital assets. Many types of criminal and civil proceedings can and do make use of evidence revealed by computer forensics specialists including insurance companies, large corporations, criminal prosecutors, law enforcement offices, civil litigations and even individuals in support of possible claims of sexual harassment, wrongful termination or age discrimination.

Different countries each have their own computer forensic methods, standards, and laws. What is acceptable evidence in one country may not be in another. This is a serious problem when dealing with international crimes, as computer crime often is. The Internet may have no boundaries, but law enforcement does. Investigations that leap from server to server, from country to country, crossing many borders on the way are complicated not only by evidence handling differences, but also by political differences and legal differences.

Tags:

Related posts

Comments are closed.