SlideShare a Scribd company logo
1 of 10
Amity Institute of Forensic Science
1
AMITY INSTITUTE OF FORENSIC SCIENCE
B.Sc.(FS), 4-SEMESTER
DR. PRIYANLKA SINGH
Amity Institute of Forensic Science
PROACTIVE FORENSIC
FSIC-228
MODULE-1
INTODUCTION
TOPIC:PROACTIVE Vs REACTIVE
FORENSIC
2
Amity Institute of Forensic Science
PROACTIVE DIGITAL
FORENSICS
Proactive Digital Forensic Component has the
ability to proactively collect data, preserve it,
detect suspicious events, gather evidence,
carry out the analysis and build a case against
any questionable activities.
3
Amity Institute of Forensic Science
PHASES UNDER THE PROACTIVE
COMPONENT ARE DEFINED
• Proactive collection
• Proactive preservation
• Proactive event detection
• Proactive analysis
• Report
4
Amity Institute of Forensic Science
REACTIVE DIGITAL
FORENSICS
• It the traditional or post-mortem approach of
investigating a digital crime after an incident
has occurred.
5
Amity Institute of Forensic Science
TYPES OF EVIDENCE
GATHERED
• Active: Active evidence refers to collecting
all live (dynamic) evidence that exists after
an incident. An example of such evidence is
processes running in memory.
• Reactive : refers to collecting all the static
evidence remaining, such as an image of a
hard drive.
6
Amity Institute of Forensic Science
COMPLEXITY OF DIGITAL
FORENSICS INVESTIGATION
• Storage size and memory sizes,
• The use of parallelism,
• Virtualization and cloud
7
Amity Institute of Forensic Science
FIVE FUNDAMENTAL
PRINCIPLES
• Principle 1 Consider the entire system. This includes the user space as
well as the entire kernel space, file system, network stack, and other
related subsystems.
• Principle 2 Assumptions about expected failures, attacks, and attackers
should not control what is logged. Trust no user and trust no policy, as
we may not know what we want in advance.
• Principle 3 Consider the effects of events, not just the actions that
caused them, and how those effects may be altered by context and
environment.
• Principle 4 Context assists in interpreting and understanding the
meaning of an event.
• Principle 5 Every action and every result must be processed and
presented in a way that can be analyzed and understood by a human
forensic analyst.
8
Amity Institute of Forensic Science
A MODEL FOR PROACTIVE
DIGITAL FORENSICS
The model has two major parts
• Forward system
• Feedback system
9
Amity Institute of Forensic Science
THANK YOU
10

More Related Content

Similar to Tukam .2.ppt

cyberforensicsv2-191113184409.pptx
cyberforensicsv2-191113184409.pptxcyberforensicsv2-191113184409.pptx
cyberforensicsv2-191113184409.pptx
PrabithGupta1
 
Digital Forensics by William C. Barker (NIST)
Digital Forensics by William C. Barker (NIST)Digital Forensics by William C. Barker (NIST)
Digital Forensics by William C. Barker (NIST)
AltheimPrivacy
 

Similar to Tukam .2.ppt (20)

Incident Response: How To Prepare
Incident Response: How To PrepareIncident Response: How To Prepare
Incident Response: How To Prepare
 
PACE-IT: Basic Forensic Concepts
PACE-IT: Basic Forensic ConceptsPACE-IT: Basic Forensic Concepts
PACE-IT: Basic Forensic Concepts
 
Incident response
Incident responseIncident response
Incident response
 
Security Incident Handling for Schools
Security Incident Handling for Schools Security Incident Handling for Schools
Security Incident Handling for Schools
 
Digital Anti-Forensics: Emerging trends in data transformation techniques
Digital Anti-Forensics: Emerging trends in data transformation techniquesDigital Anti-Forensics: Emerging trends in data transformation techniques
Digital Anti-Forensics: Emerging trends in data transformation techniques
 
cyberforensicsv2-191113184409.pptx
cyberforensicsv2-191113184409.pptxcyberforensicsv2-191113184409.pptx
cyberforensicsv2-191113184409.pptx
 
Workshop incident response n handling-bssn 12 nop 2019-ignmantra
Workshop incident response n handling-bssn 12 nop 2019-ignmantraWorkshop incident response n handling-bssn 12 nop 2019-ignmantra
Workshop incident response n handling-bssn 12 nop 2019-ignmantra
 
cyberforensicsv2-191113184409.pptx
cyberforensicsv2-191113184409.pptxcyberforensicsv2-191113184409.pptx
cyberforensicsv2-191113184409.pptx
 
Automated Live Forensics Analysis for Volatile Data Acquisition
Automated Live Forensics Analysis for Volatile Data AcquisitionAutomated Live Forensics Analysis for Volatile Data Acquisition
Automated Live Forensics Analysis for Volatile Data Acquisition
 
IRP on a Budget
IRP on a BudgetIRP on a Budget
IRP on a Budget
 
180 184
180 184180 184
180 184
 
Cyber Incident Response Triage - CPX 360 Presentation
Cyber Incident Response Triage - CPX 360 PresentationCyber Incident Response Triage - CPX 360 Presentation
Cyber Incident Response Triage - CPX 360 Presentation
 
Review of Intrusion and Anomaly Detection Techniques
Review of Intrusion and Anomaly Detection Techniques Review of Intrusion and Anomaly Detection Techniques
Review of Intrusion and Anomaly Detection Techniques
 
Incident Response
Incident ResponseIncident Response
Incident Response
 
Incident handling.final
Incident handling.finalIncident handling.final
Incident handling.final
 
Digital Forensics by William C. Barker (NIST)
Digital Forensics by William C. Barker (NIST)Digital Forensics by William C. Barker (NIST)
Digital Forensics by William C. Barker (NIST)
 
Digital Forensics for Artificial Intelligence (AI ) Systems.pdf
Digital Forensics for Artificial Intelligence (AI ) Systems.pdfDigital Forensics for Artificial Intelligence (AI ) Systems.pdf
Digital Forensics for Artificial Intelligence (AI ) Systems.pdf
 
Review on Cyber Forensics - Copy.pptx
Review on Cyber Forensics - Copy.pptxReview on Cyber Forensics - Copy.pptx
Review on Cyber Forensics - Copy.pptx
 
Ids 014 anomaly detection
Ids 014 anomaly detectionIds 014 anomaly detection
Ids 014 anomaly detection
 
Ethical hacking
Ethical hackingEthical hacking
Ethical hacking
 

Recently uploaded

LECTURE maintenance management is important 1.pptx
LECTURE maintenance management is important 1.pptxLECTURE maintenance management is important 1.pptx
LECTURE maintenance management is important 1.pptx
shahzadnasim3
 
Disaster management for class 10 students
Disaster management for class 10 studentsDisaster management for class 10 students
Disaster management for class 10 students
madhav072009
 
Jual obat aborsi Subang ( 085657271886 ) Cytote pil telat bulan penggugur kan...
Jual obat aborsi Subang ( 085657271886 ) Cytote pil telat bulan penggugur kan...Jual obat aborsi Subang ( 085657271886 ) Cytote pil telat bulan penggugur kan...
Jual obat aborsi Subang ( 085657271886 ) Cytote pil telat bulan penggugur kan...
ZurliaSoop
 

Recently uploaded (13)

DrupalCamp Atlanta 2022 - Effective Project Management
DrupalCamp Atlanta 2022 - Effective Project ManagementDrupalCamp Atlanta 2022 - Effective Project Management
DrupalCamp Atlanta 2022 - Effective Project Management
 
LECTURE maintenance management is important 1.pptx
LECTURE maintenance management is important 1.pptxLECTURE maintenance management is important 1.pptx
LECTURE maintenance management is important 1.pptx
 
Leading People - Harvard Manage Mentor Certificate
Leading People - Harvard Manage Mentor CertificateLeading People - Harvard Manage Mentor Certificate
Leading People - Harvard Manage Mentor Certificate
 
Disaster management for class 10 students
Disaster management for class 10 studentsDisaster management for class 10 students
Disaster management for class 10 students
 
Jual obat aborsi Subang ( 085657271886 ) Cytote pil telat bulan penggugur kan...
Jual obat aborsi Subang ( 085657271886 ) Cytote pil telat bulan penggugur kan...Jual obat aborsi Subang ( 085657271886 ) Cytote pil telat bulan penggugur kan...
Jual obat aborsi Subang ( 085657271886 ) Cytote pil telat bulan penggugur kan...
 
Marketing Management 16 Global Edition by Philip Kotler test bank.docx
Marketing Management 16 Global Edition by Philip Kotler test bank.docxMarketing Management 16 Global Edition by Philip Kotler test bank.docx
Marketing Management 16 Global Edition by Philip Kotler test bank.docx
 
TEST BANK for Operations Management, 14th Edition by William J. Stevenson,.pdf
TEST BANK for Operations Management, 14th Edition by William J. Stevenson,.pdfTEST BANK for Operations Management, 14th Edition by William J. Stevenson,.pdf
TEST BANK for Operations Management, 14th Edition by William J. Stevenson,.pdf
 
Spring-2024-Priesthoods of Augustus Yale Historical Review
Spring-2024-Priesthoods of Augustus Yale Historical ReviewSpring-2024-Priesthoods of Augustus Yale Historical Review
Spring-2024-Priesthoods of Augustus Yale Historical Review
 
W.H.Bender Quote 63 You Must Plan T.O.P Take-Out Packaging
W.H.Bender Quote 63 You Must Plan T.O.P Take-Out PackagingW.H.Bender Quote 63 You Must Plan T.O.P Take-Out Packaging
W.H.Bender Quote 63 You Must Plan T.O.P Take-Out Packaging
 
Team Dynamics: A Journey to Excellence
Team Dynamics: A Journey to ExcellenceTeam Dynamics: A Journey to Excellence
Team Dynamics: A Journey to Excellence
 
Group work -meaning and definitions- Characteristics and Importance
Group work -meaning and definitions- Characteristics and ImportanceGroup work -meaning and definitions- Characteristics and Importance
Group work -meaning and definitions- Characteristics and Importance
 
Management 13th Edition by Richard L. Daft test bank.docx
Management 13th Edition by Richard L. Daft test bank.docxManagement 13th Edition by Richard L. Daft test bank.docx
Management 13th Edition by Richard L. Daft test bank.docx
 
Persuasive and Communication is the art of negotiation.
Persuasive and Communication is the art of negotiation.Persuasive and Communication is the art of negotiation.
Persuasive and Communication is the art of negotiation.
 

Tukam .2.ppt

  • 1. Amity Institute of Forensic Science 1 AMITY INSTITUTE OF FORENSIC SCIENCE B.Sc.(FS), 4-SEMESTER DR. PRIYANLKA SINGH
  • 2. Amity Institute of Forensic Science PROACTIVE FORENSIC FSIC-228 MODULE-1 INTODUCTION TOPIC:PROACTIVE Vs REACTIVE FORENSIC 2
  • 3. Amity Institute of Forensic Science PROACTIVE DIGITAL FORENSICS Proactive Digital Forensic Component has the ability to proactively collect data, preserve it, detect suspicious events, gather evidence, carry out the analysis and build a case against any questionable activities. 3
  • 4. Amity Institute of Forensic Science PHASES UNDER THE PROACTIVE COMPONENT ARE DEFINED • Proactive collection • Proactive preservation • Proactive event detection • Proactive analysis • Report 4
  • 5. Amity Institute of Forensic Science REACTIVE DIGITAL FORENSICS • It the traditional or post-mortem approach of investigating a digital crime after an incident has occurred. 5
  • 6. Amity Institute of Forensic Science TYPES OF EVIDENCE GATHERED • Active: Active evidence refers to collecting all live (dynamic) evidence that exists after an incident. An example of such evidence is processes running in memory. • Reactive : refers to collecting all the static evidence remaining, such as an image of a hard drive. 6
  • 7. Amity Institute of Forensic Science COMPLEXITY OF DIGITAL FORENSICS INVESTIGATION • Storage size and memory sizes, • The use of parallelism, • Virtualization and cloud 7
  • 8. Amity Institute of Forensic Science FIVE FUNDAMENTAL PRINCIPLES • Principle 1 Consider the entire system. This includes the user space as well as the entire kernel space, file system, network stack, and other related subsystems. • Principle 2 Assumptions about expected failures, attacks, and attackers should not control what is logged. Trust no user and trust no policy, as we may not know what we want in advance. • Principle 3 Consider the effects of events, not just the actions that caused them, and how those effects may be altered by context and environment. • Principle 4 Context assists in interpreting and understanding the meaning of an event. • Principle 5 Every action and every result must be processed and presented in a way that can be analyzed and understood by a human forensic analyst. 8
  • 9. Amity Institute of Forensic Science A MODEL FOR PROACTIVE DIGITAL FORENSICS The model has two major parts • Forward system • Feedback system 9
  • 10. Amity Institute of Forensic Science THANK YOU 10

Editor's Notes

  1. 1