When finding nothing may be evidence of something: Anti-forensics and digital tool marks

Date

2019-06-03

Advisors

Journal Title

Journal ISSN

Volume Title

Publisher

Elsevier

Department

Type

Article

ISSN

1355-0306

item.page.extent-format

Citation

Horsman G, Errickson D. When finding nothing may be evidence of something: Anti-forensics and digital tool marks. Science and Justice, Volume 59, Issue 5, September 2019, pp. 565-572

Abstract

There are an abundance of measures available to the standard digital device users which provide the opportunity to act in an anti-forensic manner and conceal any potential digital evidence denoting a criminal act. Whilst there is a lack of empirical evidence which evaluates the scale of this threat to digital forensic investigations leaving the true extent of engagement with such tools unknown, arguably the field should take proactive steps to examine and record the capabilities of these measures. Whilst forensic science has long accepted the concept of toolmark analysis as part of criminal investigations, ‘digital tool marks’ (DTMs) are a notion rarely acknowledged and considered in digital investigations. DTMs are the traces left behind by a tool or process on a suspect system which can help to determine what malicious behaviour has occurred on a device. This article discusses and champions the need for DTM research in digital forensics highlighting the benefits of doing so.

Description

item.page.description-software

item.page.type-software-language

item.page.identifier-giturl

Keywords

Digital forensics, Anti forensics, Digital tool marks, Investigation, Crime

Rights

Attribution-NonCommercial-NoDerivatives 4.0 International

item.page.relationships

item.page.relationships

item.page.relation-supplements