Computer Science, asked by kunde5396, 8 months ago

Several graphics files were transmitted via email from an unknown source to a suspect in an ongoing investigation. The lead investigator gives you these graphics files and tells you that at least four messages should be embedded in them. Use your problem-solving and brainstorming skills to determine a procedure to follow. Write a short report outlining what to do.

Answers

Answered by diksha254134
10

Hey dude here is your answer...

Computer forensics

Graphic Files Investigation Procedure

When investigating electronic forensic evidence. It is important to note that email log records can be manipulated. Each time an email account is accessed either by the authorised or by an unauthorised entity, a fresh log record is created (Sidhu et al, 2012). These log records form an audit trail that investigators can use to conduct their investigations. The procedure for forensics investigation and analysis is as follows;

Data Collection

The data collection phase involves collection and assembly of various types of, electronic evidence vital to the investigation. Information from the internet, webserver and proxy server history is important to the investigator since it offers a correlation of the log records and the emails. The integrity of forensic evidence ought to be paramount.

Data Normalization

The data normalization phase involves data sorting, filtering and data parsing. This is done in order to reveal additional meta data. This helps in the extraction of vital information that is key to the investigation.

Data Analysis

In data analysis. The investigator reviews all the log records that have been availed as forensic evidence. Since the data to be analysed cis in large volumes. The investigator may use the phased approach of analysis to perform relevant reviews.

Correlation

During the correlation phase, the reviewed data is compared and confirmed for common records and variety of activity in the log records that may be representative of unwanted activity (Lim et al, 2012). The most important point in data correlation is the relationship between the major concepts of the investigation and the evidence contained in the retrieved data sets.

Reporting

The report contains the analysis, conclusions and the recommendations in a summarized manner accompanied by supporting documents which form the basis for the conclusions.

hope it helps u..if it is then thank me...

Similar questions