ASTM E3016-2018 Standard Guide for Establishing Confidence in Digital and Multimedia Evidence Forensic Results by Error Mitigation Analysis.pdf
《ASTM E3016-2018 Standard Guide for Establishing Confidence in Digital and Multimedia Evidence Forensic Results by Error Mitigation Analysis.pdf》由会员分享,可在线阅读,更多相关《ASTM E3016-2018 Standard Guide for Establishing Confidence in Digital and Multimedia Evidence Forensic Results by Error Mitigation Analysis.pdf(11页珍藏版)》请在麦多课文档分享上搜索。
1、Designation: E3016 18Standard Guide forEstablishing Confidence in Digital and Multimedia EvidenceForensic Results by Error Mitigation Analysis1This standard is issued under the fixed designation E3016; the number immediately following the designation indicates the year oforiginal adoption or, in the
2、 case of revision, the year of last revision. A number in parentheses indicates the year of last reapproval. Asuperscript epsilon () indicates an editorial change since the last revision or reapproval.1. Scope1.1 This guide provides a process for recognizing anddescribing both errors and limitations
3、 associated with tools,techniques, and methods used to support digital and multime-dia evidence forensics. This is accomplished by explaininghow the concepts of errors and error rates should be addressedin digital and multimedia evidence forensics. It is important forpractitioners and stakeholders t
4、o understand that digital andmultimedia evidence forensic techniques and tools have knownlimitations, but those limitations have differences from errorsand error rates in other forensic disciplines. This guide pro-poses that confidence in digital and multimedia evidenceforensic results is best achie
5、ved by using an error mitigationanalysis approach that focuses on recognizing potential sourcesof error and then applying techniques used to mitigate them,including trained and competent personnel using tested andvalidated methods and practices. Sources of error not directlyrelated to tool usage are
6、 beyond the scope of this guide.1.2 This international standard was developed in accor-dance with internationally recognized principles on standard-ization established in the Decision on Principles for theDevelopment of International Standards, Guides and Recom-mendations issued by the World Trade O
7、rganization TechnicalBarriers to Trade (TBT) Committee.2. Referenced Documents2.1 ISO Standard:2ISO/IEC 17025 General Requirements for the Competenceof Testing and Calibration Laboratories2.2 SWGDE Standards:3SWGDE Model Quality Assurance Manual for Digital Evi-denceSWGDE Standards and Controls Posi
8、tion PaperSWGDE/SWGIT Proficiency Test Program GuidelinesSWGDE/SWGIT Guidelines however, they often struggle toestablish their confidence on a scientific basis. Some forensicdisciplines use an error rate to describe the chance of falsepositives, false negatives, or otherwise inaccurate results whend
9、etermining whether two samples actually come from the samesource. But in digital and multimedia evidence forensics, thereare fundamental differences in the nature of many processesthat can make trying to use statistical error rates inappropriateor misleading.4.2 The key point to keep in mind is the
10、difference betweenrandom errors and systematic errors. Random errors arecharacterized by error rates because they are based in naturalprocesses and the inability to perfectly measure them. System-atic errors, in contrast, are caused by many different factors. Incomputer software, for example, an imp
11、erfect implementationcan produce an incorrect result when a particular condition,usually unknown, is met. Digital forensics being based oncomputer science is far more prone to systematic thanrandom errors.4.3 Digital and multimedia forensics includes multiple taskswhich, in turn, use multiple types
12、of automated tools.4.4 For each digital and multimedia evidence forensic tool,there is an underlying algorithm (how the task should be done)and an implementation of the algorithm (how the task is donein software by a tool). There can be different errors and errorrates with both the algorithm and the
13、 implementation. Forexample, hash algorithms used to determine if two files areidentical have an inherent false positive rate, but the rate is sosmall as to be essentially zero.4.5 Once an algorithm is implemented in software, inaddition to the inherent error rate of the algorithm, theimplementation
14、 may introduce systematic errors that are notstatistical in nature. Software errors manifest when somecondition is present either in the data or in the executionenvironment. It is often misleading to try to characterizesoftware errors in a statistical manner since such errors are notthe result of va
15、riations in measurement or sampling. Forexample, the hashing software could be poorly written and mayproduce the same hash every time an input file starts with thesymbol “$”.4.6 The primary types of errors found in digital and multi-media evidence forensic tool implementations are:4.6.1 Incompletene
16、ssAll the relevant information has notbeen acquired or found by the tool. For example, an acquisitionmight be incomplete or not all relevant artifacts identified froma search.4.6.2 InaccuracyThe tool does not report accurate infor-mation. Specifically, the tool should not report things that arenot t
17、here, should not group together unrelated items, andshould not alter data in a way that changes the meaning.Assessment of accuracy in digital and multimedia evidenceforensic tool implementations can be categorized as follows:4.6.2.1 ExistenceAre all reported artifacts reported aspresent actually pre
18、sent? For example, a faulty tool might adddata that was not present in the original.4.6.2.2 AlterationDoes a forensic tool alter data in a waythat changes its meaning, such as updating an existing date-time stamp (for example, associated with a file or e-mailmessage) to the current date.4.6.2.3 Asso
19、ciationDo all items associated together actu-ally belong together? A faulty tool might incorrectly associateinformation pertaining to one item with a different, unrelateditem. For instance, a tool might parse a web browser history fileand incorrectly report that a web search on “how to murderyour wi
20、fe” was executed 75 times when in fact it was onlyexecuted once while “history of Rome” (the next item in thehistory file) was executed 75 times, erroneously associating thecount for the second search with the first search.4.6.2.4 CorruptionDoes the forensic tool detect and com-pensate for missing a
21、nd corrupted data? Missing or corruptdata can arise from many sources, such as bad sectorsencountered during acquisition or incomplete deleted filerecovery or file carving. For example, a missing piece of datafrom an incomplete carving of the above web history file couldalso produce the same incorre
22、ct association.4.6.3 MisinterpretationThe results have been incorrectlyunderstood. Misunderstandings of what certain informationmeans can result from a lack of understanding of the underly-ing data or from ambiguities in the way digital and multimediaevidence forensic tools present information.4.7 T
23、he basic strategy to develop confidence in the digitaland multimedia evidence forensic results is to identify likelysources of error and mitigate them. This is done by applyingtool testing and sound quality control measures as described inthis guide including:4.7.1 Tool Testing:4.7.1.1 Determine app
24、licable scenarios that have been con-sidered in tool testing.4.7.1.2 Assess known tool anomalies and how they apply tothe current case.4.7.1.3 Find untested scenarios that introduce uncertainty intool results.4.7.2 Sound Quality Control Procedures:4.7.2.1 Tool performance verification.4.7.2.2 Person
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
5000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- ASTME30162018STANDARDGUIDEFORESTABLISHINGCONFIDENCEINDIGITALANDMULTIMEDIAEVIDENCEFORENSICRESULTSBYERRORMITIGATIONANALYSISPDF

链接地址:http://www.mydoc123.com/p-532245.html