Protecting Digital Evidence Integrity and Preserving Chain of Custody

  • Shah M
  • Saleem S
  • Zulqarnain R
N/ACitations
Citations of this article
100Readers
Mendeley users who have this article in their library.

Abstract

Evidence is the key to solve any crime. Evidence integrity needs to be protected in order to make it admissible in the court of law. Digital evidence is more revealing, but it is fragile; it can easily be tampered with or modified. There are different techniques available to protect the integrity of digital evidence. Different automated digital evidence acquisition tools are available in the market. In this paper, we have analyzed two automated tools (EnCase and FTK Imager) that are used for disk imaging. These tools claim to protect the integrity of digital evidence. The techniques used by these tools are analyzed in this paper. Problems with their approaches are discussed and a solution is proposed to address the problems. A prototype of an automated tool is developed with an implementation of the proposed solution.

Cite

CITATION STYLE

APA

Shah, M., Saleem, S., & Zulqarnain, R. (2017). Protecting Digital Evidence Integrity and Preserving Chain of Custody. The Journal of Digital Forensics, Security and Law. https://doi.org/10.15394/jdfsl.2017.1478

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free