13.09.2016 Views

BATTLEFIELD DIGITAL FORENSICS

BDF_Battlefield_Digital_Forensics_final

BDF_Battlefield_Digital_Forensics_final

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

If any marks of explosives are detected from the electronic evidence in any phase, the evidence should be left<br />

behind. After returning from the theatre, there is more time to analyse possible use of anti-forensics<br />

techniques. For example, possible booby-traps should analysed and they should not be directly connected into<br />

the most valuable forensics analysis devices.<br />

As mentioned already, certain activities might or might not be initiated simultaneously with others. Discovered<br />

anti-forensics measures are presented as red arrows in the flowchart. Examples are identified booby-traps, killswitches,<br />

fake networks, and hidden or obfuscated devices. Black arrows, on the other hand, mean that antiforensics<br />

techniques have not been discovered (in that part). For example, if there are no wireless networks<br />

visible or detected, it is still possible to identify powered-off stand-alone devices. These devices might have<br />

wireless interfaces that can be used to control devices remotely (after they have been powered on).<br />

40

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!