Persuasive and Communication is the art of negotiation.
Tukam .2.ppt
1. Amity Institute of Forensic Science
1
AMITY INSTITUTE OF FORENSIC SCIENCE
B.Sc.(FS), 4-SEMESTER
DR. PRIYANLKA SINGH
2. Amity Institute of Forensic Science
PROACTIVE FORENSIC
FSIC-228
MODULE-1
INTODUCTION
TOPIC:PROACTIVE Vs REACTIVE
FORENSIC
2
3. Amity Institute of Forensic Science
PROACTIVE DIGITAL
FORENSICS
Proactive Digital Forensic Component has the
ability to proactively collect data, preserve it,
detect suspicious events, gather evidence,
carry out the analysis and build a case against
any questionable activities.
3
4. Amity Institute of Forensic Science
PHASES UNDER THE PROACTIVE
COMPONENT ARE DEFINED
• Proactive collection
• Proactive preservation
• Proactive event detection
• Proactive analysis
• Report
4
5. Amity Institute of Forensic Science
REACTIVE DIGITAL
FORENSICS
• It the traditional or post-mortem approach of
investigating a digital crime after an incident
has occurred.
5
6. Amity Institute of Forensic Science
TYPES OF EVIDENCE
GATHERED
• Active: Active evidence refers to collecting
all live (dynamic) evidence that exists after
an incident. An example of such evidence is
processes running in memory.
• Reactive : refers to collecting all the static
evidence remaining, such as an image of a
hard drive.
6
7. Amity Institute of Forensic Science
COMPLEXITY OF DIGITAL
FORENSICS INVESTIGATION
• Storage size and memory sizes,
• The use of parallelism,
• Virtualization and cloud
7
8. Amity Institute of Forensic Science
FIVE FUNDAMENTAL
PRINCIPLES
• Principle 1 Consider the entire system. This includes the user space as
well as the entire kernel space, file system, network stack, and other
related subsystems.
• Principle 2 Assumptions about expected failures, attacks, and attackers
should not control what is logged. Trust no user and trust no policy, as
we may not know what we want in advance.
• Principle 3 Consider the effects of events, not just the actions that
caused them, and how those effects may be altered by context and
environment.
• Principle 4 Context assists in interpreting and understanding the
meaning of an event.
• Principle 5 Every action and every result must be processed and
presented in a way that can be analyzed and understood by a human
forensic analyst.
8
9. Amity Institute of Forensic Science
A MODEL FOR PROACTIVE
DIGITAL FORENSICS
The model has two major parts
• Forward system
• Feedback system
9