SlideShare a Scribd company logo
Program Studi Teknik Informatika
Fakultas Teknik – Universitas Surabaya
Social Media Forensics
Program Studi Teknik Informatika
Fakultas Teknik – Universitas Surabaya
Social Media Evidence: What you put on
Facebook or Instagram or Twitter or Youtube?
Background
Picture-Sharing
Social Media
Dating Social
Media
Direct Message Multiplayer Games
Professional Social
Media
Company
Collaboration
FACEBOOK
Facebook Produces Evidence
• Party Admissions – What Facebook data?
– Posts, E-mail, Friends
• State of Mind – What Facebook data?
– Status Updates
• Witness Credibility - What Facebook data?
– Posts, E-mail, Places, Friends, Contact Info
• Witness Character - What Facebook data?
– Photos, Videos, Likes, Apps
Why is Facebook the New Confessional?
• Speed and breadth amplify communication velocity
• Insecure communication
– Privacy controls constantly changing and often misunderstood
– Risk of impersonation by fake profiles – e.g. defamation
• Rapid, short and snappy communication
– Not reviewed, nor proofread; often grossly inaccurate
– Lacking context and precise meaning
– Interpretation often left to reader
• Lack of control over content – often ‘goes viral’
• Tacitly encourages candor as key social behavior
– Evidence often surprisingly relevant, incriminating, and powerful for
impeachment
“Frictionless Sharing” – Oversharing
Automatic, Passive, Real-Time Updates
• Logging into web sites with Facebook identity can trigger automatic
sharing on Facebook of activity on external sites:
– Yahoo! News, Washington Post, The Guardian
– Spotify, Rhapsody
– Netflix, Hulu
Facebook Graph Search
• Facebook Graph Search
SOCIAL MEDIA FORENSICS
Social Media – Law Enforcement
• “As a prosecutor, the first thing I do when I get a case is to Google
the victim, the suspect, and all the material witnesses. I run them all
through Facebook, MySpace, Twitter, Youtube, and see what I might
get. I also do a ‘Google image search’’ and see what pops up.
Sometimes there’s nothing, but other times I get the goods –
pictures, status updates, and better yet, blogs and articles they’ve
written.”
– A former deputy district attorney for Los Angeles County
• “You find out about people you never would have known”
– Dean Johnston, California Bureau of Narcotics Enforcement
Social Media Evidence
• What is Social Media Forensics?
• The application of computer investigation and analysis techniques to
gather information evidence from online sources, suitable for
presentation in a court of law.
Social Media Evidence
• Collection Methods:
– Screen scrape/ screen capture
– Manual documentation
– Open source tools (HTTrack)
– Commercial tool (X1)
– Web service (Pagefreezer)
– Forensics recovery
– Content subpoena
Social Media Case Investigations
• Analysis
• Information Bases
• Online Preservation and Collection
• Admissibility
Social Media - Discovery
• Electronically stored information (ESI) is data that is created,
altered, communicated and stored in digital form.
• What ESI available for review?
• Evidence strategies – computer and mobile devices
• Request for evidence
What ESI can we get for review?
content Pushed content metada
Friends, friends of friends,
connections, followers, etc.
E-mail notifications with
metadata
Site names
Status updates,
relationship status, etc.
RSS Feeds with Metadata Date/Time Stamps
Email, chat, text messages,
friend request, pokes, etc.
Uniform Resource Locators
(URLs)
Timeline (profile) – name,
picture, gender, contact,
birthday, etc.
Geoloaction information
(Check-ins)
Wall, posts, comments,
tags, etc.
IP Logs
Likes, reads, views, listens,
etc.
Login/Logout logs
Networks, groups, events,
etc.
Photos, videos, Audio,
Music, tags
Apps, App Data, Games
Evidence Strategies - Computer
• If target’s evidence is insufficient
– Social media evidence is missing
– Evidence destruction is suspected
• Should look outside Facebook
– E-mail notifications
– RSS containing content & time stamps pushed out by social media site
• Move for warrant/court order for computer forensics analysis of
opposition hard drives
• Recorver social media evidence
• What evidence? What will it look like?
SOCIAL MEDIA EVIDENCE
Exercise
Social Media Evidence
• Anatomy Twitter Tweet
– RT = re-tweet
– @xxxxx = a twitter user name
– #xxxxx = hashtag, a subject or reference identifier
– Htttp://xxx = a link, usually shortened to fit in tweet
– Max character for tweet?
– Twitter Feeds
Social Media Evidence
• Anatomy Facebook Post?
Social Media Evidence
• Anatomy LinkedIn Post & Data?
Social Media Evidence
• GeoLocation?
Social Media Evidence- Example
• Target Profile
• Profile (Timeline) information (e.g. contact information, interest, groups)
• Wall (timeline) posts and content that posted into profile (timeline)
• Photos and videos uploaded to account
• Friend list
• Notes created
• Events to which having RSVP
• Sent and received messages
• Any comments on Wall (timeline) posts, photos, and other profile content.
Evidence Elements
• IP addreses: any IP addresses that stored who accessed to account
• Login info: a list of logins that have stored
• Logout info: the ip address from which logged out
• Pending friend request: friend request that an account sent but have not accepted or rejected.
• Account status changes: dates when an account was reactivated, deactivated, disabled or
deleted.
• Poke info: information about the pokes exchanged
• Events info: events that accepted, declined, and responded maybe to by an account
• Other profile (timeline) info: the mobile phone numbers that added to an account
• City & hometown
• Family members
• Relationsship info (names and statuses)
• A list of the language that added to an account
• A history of any changes that have made to the name profile.
Social Media Evidence Recovery
• From an account  settings

More Related Content

Similar to Week 10 Social Media Forensics (3).pptx

Using social data in Academic Research
Using social data in Academic ResearchUsing social data in Academic Research
Using social data in Academic Researcheelcovandewiel
 
Deep Dive Into Social Media and Content Strategy
Deep Dive Into Social Media and Content StrategyDeep Dive Into Social Media and Content Strategy
Deep Dive Into Social Media and Content Strategy
Danielle Brigida
 
Open Analytics: Building Effective Frameworks for Social Media Analysis
Open Analytics: Building Effective Frameworks for Social Media AnalysisOpen Analytics: Building Effective Frameworks for Social Media Analysis
Open Analytics: Building Effective Frameworks for Social Media Analysisikanow
 
What Your Tweets Tell Us About You, Speaker Notes
What Your Tweets Tell Us About You, Speaker NotesWhat Your Tweets Tell Us About You, Speaker Notes
What Your Tweets Tell Us About You, Speaker NotesKrisKasianovitz
 
Open analytics social media framework
Open analytics   social media frameworkOpen analytics   social media framework
Open analytics social media framework
Open Analytics
 
Digital First Thinking and Working
Digital First Thinking and WorkingDigital First Thinking and Working
Digital First Thinking and Working
Steve Buttry
 
Womenin agsocialmedia
Womenin agsocialmediaWomenin agsocialmedia
Womenin agsocialmediaHolly Porter
 
Social and open journalism v3
Social and open journalism v3Social and open journalism v3
Social and open journalism v3
Chris Gordon
 
Fundamentals for the New Era PR Pro with Sarah Evans
Fundamentals for the New Era PR Pro with Sarah EvansFundamentals for the New Era PR Pro with Sarah Evans
Fundamentals for the New Era PR Pro with Sarah Evans
Cision
 
Social Media Risks
Social Media RisksSocial Media Risks
Social Media Risks
Jonathan Bacon
 
Online data sources and information exposure
Online data sources and information exposureOnline data sources and information exposure
Online data sources and information exposure
University of Southampton
 
Hashtag Conversations, Eventgraphs, and User Ego Neighborhoods: Extracting...
Hashtag Conversations,Eventgraphs, and User Ego Neighborhoods:  Extracting...Hashtag Conversations,Eventgraphs, and User Ego Neighborhoods:  Extracting...
Hashtag Conversations, Eventgraphs, and User Ego Neighborhoods: Extracting...
learjk
 
Hashtag Conversations,Eventgraphs, and User Ego Neighborhoods: Extracting So...
Hashtag Conversations,Eventgraphs, and User Ego Neighborhoods:  Extracting So...Hashtag Conversations,Eventgraphs, and User Ego Neighborhoods:  Extracting So...
Hashtag Conversations,Eventgraphs, and User Ego Neighborhoods: Extracting So...
Shalin Hai-Jew
 
Working and Thinking #digitalfirst
Working and Thinking #digitalfirstWorking and Thinking #digitalfirst
Working and Thinking #digitalfirst
Steve Buttry
 
Analysis of Cyberbullying Tweets in Trending World Events
Analysis of Cyberbullying Tweets in Trending World EventsAnalysis of Cyberbullying Tweets in Trending World Events
Analysis of Cyberbullying Tweets in Trending World Events
kcortis
 
New Methodologies for Capturing and Working with Publicly Available Twitter Data
New Methodologies for Capturing and Working with Publicly Available Twitter DataNew Methodologies for Capturing and Working with Publicly Available Twitter Data
New Methodologies for Capturing and Working with Publicly Available Twitter Data
Axel Bruns
 
NENA 2017 Doxing and Social Engineering
NENA 2017 Doxing and Social EngineeringNENA 2017 Doxing and Social Engineering
NENA 2017 Doxing and Social Engineering
Jack Kessler
 
‘Big Social Data’ in Context: Connecting Social Media Data and Other Sources
‘Big Social Data’ in Context: Connecting Social Media Data and Other Sources‘Big Social Data’ in Context: Connecting Social Media Data and Other Sources
‘Big Social Data’ in Context: Connecting Social Media Data and Other Sources
Axel Bruns
 
Bozeman Social Media Training
Bozeman Social Media TrainingBozeman Social Media Training
Bozeman Social Media Training
Danielle Brigida
 
Social media &_technology_revised[1]
Social media &_technology_revised[1]Social media &_technology_revised[1]
Social media &_technology_revised[1]
University of West Florida
 

Similar to Week 10 Social Media Forensics (3).pptx (20)

Using social data in Academic Research
Using social data in Academic ResearchUsing social data in Academic Research
Using social data in Academic Research
 
Deep Dive Into Social Media and Content Strategy
Deep Dive Into Social Media and Content StrategyDeep Dive Into Social Media and Content Strategy
Deep Dive Into Social Media and Content Strategy
 
Open Analytics: Building Effective Frameworks for Social Media Analysis
Open Analytics: Building Effective Frameworks for Social Media AnalysisOpen Analytics: Building Effective Frameworks for Social Media Analysis
Open Analytics: Building Effective Frameworks for Social Media Analysis
 
What Your Tweets Tell Us About You, Speaker Notes
What Your Tweets Tell Us About You, Speaker NotesWhat Your Tweets Tell Us About You, Speaker Notes
What Your Tweets Tell Us About You, Speaker Notes
 
Open analytics social media framework
Open analytics   social media frameworkOpen analytics   social media framework
Open analytics social media framework
 
Digital First Thinking and Working
Digital First Thinking and WorkingDigital First Thinking and Working
Digital First Thinking and Working
 
Womenin agsocialmedia
Womenin agsocialmediaWomenin agsocialmedia
Womenin agsocialmedia
 
Social and open journalism v3
Social and open journalism v3Social and open journalism v3
Social and open journalism v3
 
Fundamentals for the New Era PR Pro with Sarah Evans
Fundamentals for the New Era PR Pro with Sarah EvansFundamentals for the New Era PR Pro with Sarah Evans
Fundamentals for the New Era PR Pro with Sarah Evans
 
Social Media Risks
Social Media RisksSocial Media Risks
Social Media Risks
 
Online data sources and information exposure
Online data sources and information exposureOnline data sources and information exposure
Online data sources and information exposure
 
Hashtag Conversations, Eventgraphs, and User Ego Neighborhoods: Extracting...
Hashtag Conversations,Eventgraphs, and User Ego Neighborhoods:  Extracting...Hashtag Conversations,Eventgraphs, and User Ego Neighborhoods:  Extracting...
Hashtag Conversations, Eventgraphs, and User Ego Neighborhoods: Extracting...
 
Hashtag Conversations,Eventgraphs, and User Ego Neighborhoods: Extracting So...
Hashtag Conversations,Eventgraphs, and User Ego Neighborhoods:  Extracting So...Hashtag Conversations,Eventgraphs, and User Ego Neighborhoods:  Extracting So...
Hashtag Conversations,Eventgraphs, and User Ego Neighborhoods: Extracting So...
 
Working and Thinking #digitalfirst
Working and Thinking #digitalfirstWorking and Thinking #digitalfirst
Working and Thinking #digitalfirst
 
Analysis of Cyberbullying Tweets in Trending World Events
Analysis of Cyberbullying Tweets in Trending World EventsAnalysis of Cyberbullying Tweets in Trending World Events
Analysis of Cyberbullying Tweets in Trending World Events
 
New Methodologies for Capturing and Working with Publicly Available Twitter Data
New Methodologies for Capturing and Working with Publicly Available Twitter DataNew Methodologies for Capturing and Working with Publicly Available Twitter Data
New Methodologies for Capturing and Working with Publicly Available Twitter Data
 
NENA 2017 Doxing and Social Engineering
NENA 2017 Doxing and Social EngineeringNENA 2017 Doxing and Social Engineering
NENA 2017 Doxing and Social Engineering
 
‘Big Social Data’ in Context: Connecting Social Media Data and Other Sources
‘Big Social Data’ in Context: Connecting Social Media Data and Other Sources‘Big Social Data’ in Context: Connecting Social Media Data and Other Sources
‘Big Social Data’ in Context: Connecting Social Media Data and Other Sources
 
Bozeman Social Media Training
Bozeman Social Media TrainingBozeman Social Media Training
Bozeman Social Media Training
 
Social media &_technology_revised[1]
Social media &_technology_revised[1]Social media &_technology_revised[1]
Social media &_technology_revised[1]
 

Recently uploaded

The Challenger.pdf DNHS Official Publication
The Challenger.pdf DNHS Official PublicationThe Challenger.pdf DNHS Official Publication
The Challenger.pdf DNHS Official Publication
Delapenabediema
 
Normal Labour/ Stages of Labour/ Mechanism of Labour
Normal Labour/ Stages of Labour/ Mechanism of LabourNormal Labour/ Stages of Labour/ Mechanism of Labour
Normal Labour/ Stages of Labour/ Mechanism of Labour
Wasim Ak
 
Delivering Micro-Credentials in Technical and Vocational Education and Training
Delivering Micro-Credentials in Technical and Vocational Education and TrainingDelivering Micro-Credentials in Technical and Vocational Education and Training
Delivering Micro-Credentials in Technical and Vocational Education and Training
AG2 Design
 
Unit 8 - Information and Communication Technology (Paper I).pdf
Unit 8 - Information and Communication Technology (Paper I).pdfUnit 8 - Information and Communication Technology (Paper I).pdf
Unit 8 - Information and Communication Technology (Paper I).pdf
Thiyagu K
 
ANATOMY AND BIOMECHANICS OF HIP JOINT.pdf
ANATOMY AND BIOMECHANICS OF HIP JOINT.pdfANATOMY AND BIOMECHANICS OF HIP JOINT.pdf
ANATOMY AND BIOMECHANICS OF HIP JOINT.pdf
Priyankaranawat4
 
MATATAG CURRICULUM: ASSESSING THE READINESS OF ELEM. PUBLIC SCHOOL TEACHERS I...
MATATAG CURRICULUM: ASSESSING THE READINESS OF ELEM. PUBLIC SCHOOL TEACHERS I...MATATAG CURRICULUM: ASSESSING THE READINESS OF ELEM. PUBLIC SCHOOL TEACHERS I...
MATATAG CURRICULUM: ASSESSING THE READINESS OF ELEM. PUBLIC SCHOOL TEACHERS I...
NelTorrente
 
MASS MEDIA STUDIES-835-CLASS XI Resource Material.pdf
MASS MEDIA STUDIES-835-CLASS XI Resource Material.pdfMASS MEDIA STUDIES-835-CLASS XI Resource Material.pdf
MASS MEDIA STUDIES-835-CLASS XI Resource Material.pdf
goswamiyash170123
 
PCOS corelations and management through Ayurveda.
PCOS corelations and management through Ayurveda.PCOS corelations and management through Ayurveda.
PCOS corelations and management through Ayurveda.
Dr. Shivangi Singh Parihar
 
Biological Screening of Herbal Drugs in detailed.
Biological Screening of Herbal Drugs in detailed.Biological Screening of Herbal Drugs in detailed.
Biological Screening of Herbal Drugs in detailed.
Ashokrao Mane college of Pharmacy Peth-Vadgaon
 
Natural birth techniques - Mrs.Akanksha Trivedi Rama University
Natural birth techniques - Mrs.Akanksha Trivedi Rama UniversityNatural birth techniques - Mrs.Akanksha Trivedi Rama University
Natural birth techniques - Mrs.Akanksha Trivedi Rama University
Akanksha trivedi rama nursing college kanpur.
 
Group Presentation 2 Economics.Ariana Buscigliopptx
Group Presentation 2 Economics.Ariana BuscigliopptxGroup Presentation 2 Economics.Ariana Buscigliopptx
Group Presentation 2 Economics.Ariana Buscigliopptx
ArianaBusciglio
 
BÀI TẬP BỔ TRỢ TIẾNG ANH GLOBAL SUCCESS LỚP 3 - CẢ NĂM (CÓ FILE NGHE VÀ ĐÁP Á...
BÀI TẬP BỔ TRỢ TIẾNG ANH GLOBAL SUCCESS LỚP 3 - CẢ NĂM (CÓ FILE NGHE VÀ ĐÁP Á...BÀI TẬP BỔ TRỢ TIẾNG ANH GLOBAL SUCCESS LỚP 3 - CẢ NĂM (CÓ FILE NGHE VÀ ĐÁP Á...
BÀI TẬP BỔ TRỢ TIẾNG ANH GLOBAL SUCCESS LỚP 3 - CẢ NĂM (CÓ FILE NGHE VÀ ĐÁP Á...
Nguyen Thanh Tu Collection
 
Lapbook sobre os Regimes Totalitários.pdf
Lapbook sobre os Regimes Totalitários.pdfLapbook sobre os Regimes Totalitários.pdf
Lapbook sobre os Regimes Totalitários.pdf
Jean Carlos Nunes Paixão
 
Digital Artifact 1 - 10VCD Environments Unit
Digital Artifact 1 - 10VCD Environments UnitDigital Artifact 1 - 10VCD Environments Unit
Digital Artifact 1 - 10VCD Environments Unit
chanes7
 
How to Add Chatter in the odoo 17 ERP Module
How to Add Chatter in the odoo 17 ERP ModuleHow to Add Chatter in the odoo 17 ERP Module
How to Add Chatter in the odoo 17 ERP Module
Celine George
 
Landownership in the Philippines under the Americans-2-pptx.pptx
Landownership in the Philippines under the Americans-2-pptx.pptxLandownership in the Philippines under the Americans-2-pptx.pptx
Landownership in the Philippines under the Americans-2-pptx.pptx
JezreelCabil2
 
PIMS Job Advertisement 2024.pdf Islamabad
PIMS Job Advertisement 2024.pdf IslamabadPIMS Job Advertisement 2024.pdf Islamabad
PIMS Job Advertisement 2024.pdf Islamabad
AyyanKhan40
 
June 3, 2024 Anti-Semitism Letter Sent to MIT President Kornbluth and MIT Cor...
June 3, 2024 Anti-Semitism Letter Sent to MIT President Kornbluth and MIT Cor...June 3, 2024 Anti-Semitism Letter Sent to MIT President Kornbluth and MIT Cor...
June 3, 2024 Anti-Semitism Letter Sent to MIT President Kornbluth and MIT Cor...
Levi Shapiro
 
Digital Artifact 2 - Investigating Pavilion Designs
Digital Artifact 2 - Investigating Pavilion DesignsDigital Artifact 2 - Investigating Pavilion Designs
Digital Artifact 2 - Investigating Pavilion Designs
chanes7
 
Pride Month Slides 2024 David Douglas School District
Pride Month Slides 2024 David Douglas School DistrictPride Month Slides 2024 David Douglas School District
Pride Month Slides 2024 David Douglas School District
David Douglas School District
 

Recently uploaded (20)

The Challenger.pdf DNHS Official Publication
The Challenger.pdf DNHS Official PublicationThe Challenger.pdf DNHS Official Publication
The Challenger.pdf DNHS Official Publication
 
Normal Labour/ Stages of Labour/ Mechanism of Labour
Normal Labour/ Stages of Labour/ Mechanism of LabourNormal Labour/ Stages of Labour/ Mechanism of Labour
Normal Labour/ Stages of Labour/ Mechanism of Labour
 
Delivering Micro-Credentials in Technical and Vocational Education and Training
Delivering Micro-Credentials in Technical and Vocational Education and TrainingDelivering Micro-Credentials in Technical and Vocational Education and Training
Delivering Micro-Credentials in Technical and Vocational Education and Training
 
Unit 8 - Information and Communication Technology (Paper I).pdf
Unit 8 - Information and Communication Technology (Paper I).pdfUnit 8 - Information and Communication Technology (Paper I).pdf
Unit 8 - Information and Communication Technology (Paper I).pdf
 
ANATOMY AND BIOMECHANICS OF HIP JOINT.pdf
ANATOMY AND BIOMECHANICS OF HIP JOINT.pdfANATOMY AND BIOMECHANICS OF HIP JOINT.pdf
ANATOMY AND BIOMECHANICS OF HIP JOINT.pdf
 
MATATAG CURRICULUM: ASSESSING THE READINESS OF ELEM. PUBLIC SCHOOL TEACHERS I...
MATATAG CURRICULUM: ASSESSING THE READINESS OF ELEM. PUBLIC SCHOOL TEACHERS I...MATATAG CURRICULUM: ASSESSING THE READINESS OF ELEM. PUBLIC SCHOOL TEACHERS I...
MATATAG CURRICULUM: ASSESSING THE READINESS OF ELEM. PUBLIC SCHOOL TEACHERS I...
 
MASS MEDIA STUDIES-835-CLASS XI Resource Material.pdf
MASS MEDIA STUDIES-835-CLASS XI Resource Material.pdfMASS MEDIA STUDIES-835-CLASS XI Resource Material.pdf
MASS MEDIA STUDIES-835-CLASS XI Resource Material.pdf
 
PCOS corelations and management through Ayurveda.
PCOS corelations and management through Ayurveda.PCOS corelations and management through Ayurveda.
PCOS corelations and management through Ayurveda.
 
Biological Screening of Herbal Drugs in detailed.
Biological Screening of Herbal Drugs in detailed.Biological Screening of Herbal Drugs in detailed.
Biological Screening of Herbal Drugs in detailed.
 
Natural birth techniques - Mrs.Akanksha Trivedi Rama University
Natural birth techniques - Mrs.Akanksha Trivedi Rama UniversityNatural birth techniques - Mrs.Akanksha Trivedi Rama University
Natural birth techniques - Mrs.Akanksha Trivedi Rama University
 
Group Presentation 2 Economics.Ariana Buscigliopptx
Group Presentation 2 Economics.Ariana BuscigliopptxGroup Presentation 2 Economics.Ariana Buscigliopptx
Group Presentation 2 Economics.Ariana Buscigliopptx
 
BÀI TẬP BỔ TRỢ TIẾNG ANH GLOBAL SUCCESS LỚP 3 - CẢ NĂM (CÓ FILE NGHE VÀ ĐÁP Á...
BÀI TẬP BỔ TRỢ TIẾNG ANH GLOBAL SUCCESS LỚP 3 - CẢ NĂM (CÓ FILE NGHE VÀ ĐÁP Á...BÀI TẬP BỔ TRỢ TIẾNG ANH GLOBAL SUCCESS LỚP 3 - CẢ NĂM (CÓ FILE NGHE VÀ ĐÁP Á...
BÀI TẬP BỔ TRỢ TIẾNG ANH GLOBAL SUCCESS LỚP 3 - CẢ NĂM (CÓ FILE NGHE VÀ ĐÁP Á...
 
Lapbook sobre os Regimes Totalitários.pdf
Lapbook sobre os Regimes Totalitários.pdfLapbook sobre os Regimes Totalitários.pdf
Lapbook sobre os Regimes Totalitários.pdf
 
Digital Artifact 1 - 10VCD Environments Unit
Digital Artifact 1 - 10VCD Environments UnitDigital Artifact 1 - 10VCD Environments Unit
Digital Artifact 1 - 10VCD Environments Unit
 
How to Add Chatter in the odoo 17 ERP Module
How to Add Chatter in the odoo 17 ERP ModuleHow to Add Chatter in the odoo 17 ERP Module
How to Add Chatter in the odoo 17 ERP Module
 
Landownership in the Philippines under the Americans-2-pptx.pptx
Landownership in the Philippines under the Americans-2-pptx.pptxLandownership in the Philippines under the Americans-2-pptx.pptx
Landownership in the Philippines under the Americans-2-pptx.pptx
 
PIMS Job Advertisement 2024.pdf Islamabad
PIMS Job Advertisement 2024.pdf IslamabadPIMS Job Advertisement 2024.pdf Islamabad
PIMS Job Advertisement 2024.pdf Islamabad
 
June 3, 2024 Anti-Semitism Letter Sent to MIT President Kornbluth and MIT Cor...
June 3, 2024 Anti-Semitism Letter Sent to MIT President Kornbluth and MIT Cor...June 3, 2024 Anti-Semitism Letter Sent to MIT President Kornbluth and MIT Cor...
June 3, 2024 Anti-Semitism Letter Sent to MIT President Kornbluth and MIT Cor...
 
Digital Artifact 2 - Investigating Pavilion Designs
Digital Artifact 2 - Investigating Pavilion DesignsDigital Artifact 2 - Investigating Pavilion Designs
Digital Artifact 2 - Investigating Pavilion Designs
 
Pride Month Slides 2024 David Douglas School District
Pride Month Slides 2024 David Douglas School DistrictPride Month Slides 2024 David Douglas School District
Pride Month Slides 2024 David Douglas School District
 

Week 10 Social Media Forensics (3).pptx

  • 1. Program Studi Teknik Informatika Fakultas Teknik – Universitas Surabaya Social Media Forensics
  • 2. Program Studi Teknik Informatika Fakultas Teknik – Universitas Surabaya Social Media Evidence: What you put on Facebook or Instagram or Twitter or Youtube?
  • 8. Facebook Produces Evidence • Party Admissions – What Facebook data? – Posts, E-mail, Friends • State of Mind – What Facebook data? – Status Updates • Witness Credibility - What Facebook data? – Posts, E-mail, Places, Friends, Contact Info • Witness Character - What Facebook data? – Photos, Videos, Likes, Apps
  • 9. Why is Facebook the New Confessional? • Speed and breadth amplify communication velocity • Insecure communication – Privacy controls constantly changing and often misunderstood – Risk of impersonation by fake profiles – e.g. defamation • Rapid, short and snappy communication – Not reviewed, nor proofread; often grossly inaccurate – Lacking context and precise meaning – Interpretation often left to reader • Lack of control over content – often ‘goes viral’ • Tacitly encourages candor as key social behavior – Evidence often surprisingly relevant, incriminating, and powerful for impeachment
  • 10. “Frictionless Sharing” – Oversharing Automatic, Passive, Real-Time Updates • Logging into web sites with Facebook identity can trigger automatic sharing on Facebook of activity on external sites: – Yahoo! News, Washington Post, The Guardian – Spotify, Rhapsody – Netflix, Hulu
  • 11. Facebook Graph Search • Facebook Graph Search
  • 13. Social Media – Law Enforcement • “As a prosecutor, the first thing I do when I get a case is to Google the victim, the suspect, and all the material witnesses. I run them all through Facebook, MySpace, Twitter, Youtube, and see what I might get. I also do a ‘Google image search’’ and see what pops up. Sometimes there’s nothing, but other times I get the goods – pictures, status updates, and better yet, blogs and articles they’ve written.” – A former deputy district attorney for Los Angeles County • “You find out about people you never would have known” – Dean Johnston, California Bureau of Narcotics Enforcement
  • 14. Social Media Evidence • What is Social Media Forensics? • The application of computer investigation and analysis techniques to gather information evidence from online sources, suitable for presentation in a court of law.
  • 15. Social Media Evidence • Collection Methods: – Screen scrape/ screen capture – Manual documentation – Open source tools (HTTrack) – Commercial tool (X1) – Web service (Pagefreezer) – Forensics recovery – Content subpoena
  • 16. Social Media Case Investigations • Analysis • Information Bases • Online Preservation and Collection • Admissibility
  • 17. Social Media - Discovery • Electronically stored information (ESI) is data that is created, altered, communicated and stored in digital form. • What ESI available for review? • Evidence strategies – computer and mobile devices • Request for evidence
  • 18. What ESI can we get for review? content Pushed content metada Friends, friends of friends, connections, followers, etc. E-mail notifications with metadata Site names Status updates, relationship status, etc. RSS Feeds with Metadata Date/Time Stamps Email, chat, text messages, friend request, pokes, etc. Uniform Resource Locators (URLs) Timeline (profile) – name, picture, gender, contact, birthday, etc. Geoloaction information (Check-ins) Wall, posts, comments, tags, etc. IP Logs Likes, reads, views, listens, etc. Login/Logout logs Networks, groups, events, etc. Photos, videos, Audio, Music, tags Apps, App Data, Games
  • 19. Evidence Strategies - Computer • If target’s evidence is insufficient – Social media evidence is missing – Evidence destruction is suspected • Should look outside Facebook – E-mail notifications – RSS containing content & time stamps pushed out by social media site • Move for warrant/court order for computer forensics analysis of opposition hard drives • Recorver social media evidence • What evidence? What will it look like?
  • 21. Social Media Evidence • Anatomy Twitter Tweet – RT = re-tweet – @xxxxx = a twitter user name – #xxxxx = hashtag, a subject or reference identifier – Htttp://xxx = a link, usually shortened to fit in tweet – Max character for tweet? – Twitter Feeds
  • 22. Social Media Evidence • Anatomy Facebook Post?
  • 23. Social Media Evidence • Anatomy LinkedIn Post & Data?
  • 25. Social Media Evidence- Example • Target Profile • Profile (Timeline) information (e.g. contact information, interest, groups) • Wall (timeline) posts and content that posted into profile (timeline) • Photos and videos uploaded to account • Friend list • Notes created • Events to which having RSVP • Sent and received messages • Any comments on Wall (timeline) posts, photos, and other profile content.
  • 26. Evidence Elements • IP addreses: any IP addresses that stored who accessed to account • Login info: a list of logins that have stored • Logout info: the ip address from which logged out • Pending friend request: friend request that an account sent but have not accepted or rejected. • Account status changes: dates when an account was reactivated, deactivated, disabled or deleted. • Poke info: information about the pokes exchanged • Events info: events that accepted, declined, and responded maybe to by an account • Other profile (timeline) info: the mobile phone numbers that added to an account • City & hometown • Family members • Relationsship info (names and statuses) • A list of the language that added to an account • A history of any changes that have made to the name profile.
  • 27. Social Media Evidence Recovery • From an account  settings