研究目的
To present a methodology for the automated production of predetermined digital evidence that can be leveraged to forge a digital alibi, highlighting the challenges and implications of digital evidence in legal proceedings.
研究成果
The paper concludes that digital evidence should be considered circumstantial and must be supported by traditional investigation techniques to be reliable in court. It demonstrates that automated production of digital evidence can forge a digital alibi that is indistinguishable from genuine user activity, emphasizing the need for caution in relying solely on digital evidence in legal proceedings.
研究不足
The methodology requires technical expertise to implement effectively, and the automation may leave unwanted traces that could be detected by advanced forensic analysis. The approach is also limited by the need for physical access to the target system before forensic analysis.
The methodology involves the use of automation tools to simulate user activities on a target system, producing both wanted and unwanted digital evidence. The process includes designing, implementing, and executing the automation, followed by a forensic analysis to assess the evidence produced. The paper details the implementation of this methodology using VBScript on Windows 7, including the handling of unwanted evidence to avoid detection.
独家科研数据包,助您复现前沿成果,加速创新突破
获取完整内容-
TeamViewer
Portable
TeamViewer GmbH
Remote control software for piloting the target system from another computer.
-
RealVNC Server
Portable
RealVNC
Remote control software for piloting the target system from another computer.
-
GoTo VNC Server Java Applet
GSVNCJ
GoTo Servers
Remote control software for piloting the target system from another computer.
-
ProRat
PRO Group, Inc.
Backdoor trojan-horse for remote control of the target system.
-
Bandook
Nuclear Winter Crew
Backdoor trojan-horse for remote control of the target system.
-
IP-KVM
1001
Opengear, Inc.
Device for remote connection to the keyboard, video and mouse ports of the target system.
-
AutoIt
v3.3.6.1
AutoIt
Automation tool for recording and replaying user actions on Windows environments.
-
AutoHotkey
AutoHotkey
Open-source utility for automation tasks on Windows environments.
-
GNU Xnee
GNU
Automation tool for recording and replaying user events under the X11 environment.
-
Xautomation
Suite of command line programs for interacting with objects on the screen under the X11 environment.
-
xdotool
Application for advanced interaction with the X11 environment, including window management.
-
Automator
Apple Inc.
Automation tool for constructing automations by drag-and-dropping prede?ned actions on Mac OS.
-
VBScript
Microsoft
Scripting language for implementing automations on Windows systems.
-
AppleScript
Apple Inc.
Scripting language for implementing automations on Mac OS.
-
Robot
Oracle
Java package for simulating user actions in Java applications.
-
Process Monitor
Microsoft
Tool for monitoring real-time filesystem accesses, Registry changes, and process/thread activities on Windows.
-
lsof
Tool for listing open files, pipes, network sockets, and devices accessed by processes on *NIX systems.
-
DEFT
DEFT Linux
Live Linux distribution for digital forensics analysis.
-
CAINE
CAINE
Live Linux distribution for digital forensics analysis.
-
RegRipper
Tool for analyzing the Windows Registry in digital forensics.
-
登录查看剩余18件设备及参数对照表
查看全部