THE ENHANCED DIGITAL INVESTIGATION ON CRIME SCENE

Similar documents
Survey on Different Phases of Digital Forensics Investigation Models

CRIME SCENE INVESTIGATION

1/26/15. Chapter 2 Crime Scene

COMMON PHASES OF COMPUTER FORENSICS INVESTIGATION MODELS

The Enhanced Digital Investigation Process Model

IAPE STANDARDS SECTION 16 DIGITAL EVIDENCE

Security and Law Enforcement Community of Interest 1811-Criminal Investigating Career Road Map

East Haven Police Department

CONCEPT MAPPING FOR DIGITAL FORENSIC INVESTIGATIONS

Using Your Pocket Notebook

Sufficiency of Windows Event log as Evidence in Digital Forensics

LAW ENFORCEMENT OFFICER

SAULT COLLEGE SAULT STE. MARIE, ONTARIO COURSE OUTLINE

Information Technology Audit & Forensic Techniques. CMA Amit Kumar

Lecture outline. Computer Forensics and Digital Investigation. Defining the word forensic. Defining Computer forensics. The Digital Investigation

Crime scene evidence who is involved? Police officer and SOCO (Scenes of Crime Officer) or CSI (Crime Scene Investigator)

Course Forensic Science. Unit II History

POLICE SCENE TECHNICIAN I POLICE SCENE TECHNICIAN II

Rules and Procedures. Rule 312 August 23, Rule CRIME LABORATORY - EVIDENCE AND CRIME SCENES

TASK LIST UTILITIES SERVICE INVESTIGATOR (CLASS CODE 1631)

Mobile Audio/Video Recorder Policy

Anti-human trafficking manual for criminal justice practitioners. Module 11

CITY OF CARLSBAD CLASS SPECIFICATION COMMUNITY SERVICE OFFICER I /II

Evidence Technician s School

CRIME SCENE INVESTIGATION AND FORENSIC SCIENCE TRAINING PROGRAMMES

Introduction to Crime Scene Dynamics

Crime Scene Search and Processing

Dudesville: A crime scene under the microscope. QUT Extreme Science

BOR 6432 Cybersecurity and the Constitution. Course Bibliography and Required Readings:

Computer Forensics: an approach to evidence in cyberspace

COMMUNITY SERVICES OFFICER

Copyright and Terms of Service

Reporting the crime to the police

Piecing Digital Evidence Together. Service Information

On Integrating Mobile Applications into the Digital Forensic Investigative Process

Florida Fish and Wildlife Conservation Commission Division of Law Enforcement ACCIDENT INVESTIGATIONS AND DEATH NOTIFICATION

CAREER: FORENSIC SCIENCE TECHNICIAN 1

EXAMINATION OUTLINE FOR PRIVATE INVESTIGATORS

A Victim s Guide to Understanding the Criminal Justice System

ILLINOIS DEPARTMENT OF CENTRAL MANAGEMENT SERVICES CLASS SPECIFICATION STATE POLICE EVIDENCE TECHNICIAN SERIES

Goal to recognize, document and collect evidence at a crime scene

How To Solve A Violent Home Invasion With A United Force

Guidelines on Digital Forensic Procedures for OLAF Staff

Spoliation of Evidence. Prepared for:

Ten Deadly Sins of Computer Forensics

Open Source Digital Forensics Tools

Digital and Cloud Forensics

8 Interpreting Crime Data and Statistics

STATE OF MONTANA DEPARTMENT OF CORRECTIONS POLICY DIRECTIVE

Comparative Analysis of Digital Forensic Models

Concepts of digital forensics

Digital Forensics for Attorneys Overview of Digital Forensics

Stages in a Capital Case from

Investigation Techniques

Framework for a Digital Forensic Investigation

Key Crime Analysis Data Sources. Crime

Cell Phone Forensics For Legal Professionals

Management of Crime Scenes

LAW ENFORCEMENT OFFICER, GS

RISK MANAGEMENT SERVICES Office of The Executive Vice President & COO Allan F. Brooks, M.A, CPCU, ARM, Director, Risk Management

Development of Forensic Nursing in Australia: Associate Professor Linda Saunders 4 th December 2008

Recording of Custodial Interrogations. Municipal Police Training Council. Model Policy.

TEXAS CRIME ANALYSIS 2

STATE OF NEVADA Department of Administration Division of Human Resource Management CLASS SPECIFICATION

Accident/Near Miss Investigation Guidelines

Digital Forensics. General Terms Cyber Crime, forensics models, Investigation, Analysis, digital devices.

HUNTINGTON WOODS DEPARTMENT OF PUBLIC SAFETY GOALS AND OBJECTIVES PROGRAM DETAIL

Cloud Digital Investigations based on a Virtual Machine Computer History Model

5) Familiarity of witness with exhibit for identification

CRIME SCENE MANAGEMENT: A GUIDE FOR LICENSEES

1. Redistributions of documents, or parts of documents, must retain the SWGIT cover page containing the disclaimer.

GLOBAL INCIDENT & AUDIT MANAGEMENT SOFTWARE

Massachusetts Digital Evidence Consortium. Digital Evidence Guide for First Responders

CTC Special Meeting on Communications and IT New York May Thank you very much. I am very pleased to be here to participate in

1. Abstract. 2. The Problem / Need for the Program

SECURITY THREATS TO CLOUD COMPUTING

Design and Implementation of a Live-analysis Digital Forensic System

70250 Graduate Certificate in Digital Forensics

To Catch a Thief: Computer Forensics in the Classroom

NEW IMPROVEMENT IN DIGITAL FORENSIC STANDARD OPERATING PROCEDURE (SOP)

Chapter TEXAS CRIME ANALYSIS

UML MODELLING OF DIGITAL FORENSIC PROCESS MODELS (DFPMs)

Cyber Forensic for Hadoop based Cloud System

IFS-8000 V2.0 INFORMATION FUSION SYSTEM

JOB TITLE JOB CODE PAY GRADE EFFECTIVE Medicaid Fraud Intake Officer 26140AG 29 11/15/2015

Voice and data recording Red Box makes it easier than you imagine

STATE POLICE TROOPER

Instructions for the Incident/Accident Investigation Form (SORM-703)

Republic of Latvia State Police Forensic Service Department

Model Policy on Eyewitness Identification

Chain of evidence refers to the continuity of custody of material and items collected as evidence.

White Paper Automated Digital Evidence Collection and Publishing: Reduce Investigation Time and Costs May 2011

Frequently Asked Questions - FAQ s

Digital Evidence Collection and Use. CS 585 Fall 2009

Contra Costa Community College District Business Procedure SECURITY CAMERA OPERATING PROCEDURE

Getting Physical with the Digital Investigation Process

Providing leading edge digital forensic services with proven experience and expertise

Crime in Arkansas 2001

Legal Framework to Combat Cyber Crimes in the Region: Qatar as a Model. Judge Dr. Ehab Elsonbaty Cyber Crime expert ehabelsonbaty@hotmail.

Transcription:

THE ENHANCED DIGITAL INVESTIGATION ON CRIME SCENE SHIVANAND S. ULLEGADDI 1 AND DR. SANTOSH L. DESHPANDE 2 1 M.Tech Scholar, Computer Network Engineering, Dept. Of PG Studies VTU, Belagavi, India 2 Professor, Computer Network Engineering, Dept Of PG Studies VTU, Belagavi, India Abstract The enhanced digital investigation provides tools and techniques that can be used to identify and analyze evidences on crime scene. The article introduces is a layered, consistent and secure approach to digital investigation. The digital investigation shall retrieve to obtain the evidences that will be acceptable by judiciary. The work focused on layered and consistent approach to digital investigation for law enforcement agencies. Present manual investigation process can be altered to get better result. The article deals with unique smart phone based software which aims at identifying activities that facilitate and improve investigation processes that involves in digital investigation like (a) Collection of crime evidences from possible sources of related data like images, video, audio records and notes related to crime in a tamper proof manner. (b)examination of collected evidences as per the investigation procedure which may involve noise removing, evidence extraction from images to gather accurate information.(c)analysis of evidences with legally justifiable methods and techniques of law enforcement agencies to get the relevant information of suspect or victim. (d) Reporting which is the outcome of analysis process which gives proper documentation. The article also provides law enforcement agencies a secure, accurate and consistent means for evidence gathering, including documentation with photographs, audio, video and scene notes. The enhanced digital investigation on crime scene shall eventually improve organization productivity, save time and reduce the number of other devises that investigating officers need to carry for documenting the crime scene. It would also provide scene of control, real time information and better understanding of crime scene to senior officers so they can make out smart decision and better allocate resources for effective crime scene investigation. The result from the evaluation is going to produce a new model to improve the whole investigation process. Keywords crime, evidence, investigation, scene. I. INTRODUCTION The Enhanced Digital investigation on Crime scene reporting is unique smart phone based software which aim to provides law enforcement agencies a secure, accurate and consistent means for evidence gathering, including documentation with photographs, audio, video and scene notes with the help of sensors and well advanced features of a smart phone. The goal of a Enhanced digital crime-scene investigation is to recognize, document and collect evidence at the scene of a crime. Solving the crime will then depend on piecing together the evidence to form a picture of what happened at the crime scene. Some of the evidences get lost soon after the occurrence; the other evidences disappear, gets contaminated or changed with further passage of time. The opportunity to examine the scene is available once, if the same is not fully exploited. The Wealth of information is lost forever. The report must be purely factual. The crime scene investing officials or evidence recovery technician should document what he/she sees, not what he/she thinks. A general description of the crime scene should be given just as the investigator sees it when he/she does the first walk through of the scene. The final report should tell a descriptive story. II. EXISTING INVESTIGATION MODELS The digital investigation is a process that can be modeled with some reasonably established levels. Most proposed digital models have focused on The investigation process and the different levels, they explained the complexity of an investigation and functionality of devices, and the most important principles of an investigation [1]. A. Digital Forensics Research Workshop Investigation Model (DFRWS) Digital Forensic Research Workshop (DFRWS) proposed a model on digital investigation this process has six phases. DFRWS Investigation starts with Identification phase which identify evidences which are available at the crime scene. The next phase comes is Preservation phase aim to setup a proper case management and manage the data from contamination. Evidences related to crime like images, audio, video, notes are preserved for further investigation. 465

III. PREFERRED INVESTIGATION MODEL Figure 1: DFRWS Investigation model. The next phase is known as collection where the relevant data are to be collected based on various recovery techniques. Examination and Analysis are the two important phases the task performed are evidence tracing, evidence validation and evidence recovery of hidden/encrypted data. The last phase is presentation phase which is related to documentation of all evidences and submitting to the court for judgment. B. Abstract Digital Investigation Model (ADIM) This model is based on DFRWS model but additional three phases are added this the total phases become nine; the additional phases are preparation, Approach strategy and Returning evidence. considering Preparation phase, activities such as preparing tools, identifying techniques and getting management that support for crime is done. Approach strategy has two major things one is to maximize the acquisition of unturned evidences and at the same time minimize any negative impact to the victim and surrounding people. Returning evidence phase tells us about submitting evidences to court for further investigation and judgment. Figure 2: Abstract digital investigation model. A. Enhanced Digital Investigation on Crime Scene Model (EDICS) There are four main considerations in digital investigation as per the standers shown in figure. 1. Collection: The first phase of investigation is to identify crime scene, label, record and gather data from possible sources of related data. 2. Examination: Data gathered is examined as per the investigation procedure which may be the regular for the investigation officials. 3. Analysis: The next phase is to analyze the result of the examination, using legally justifiable methods and techniques to get the relevant information of suspect or victim. Analysis may include noise removing, evidence extraction from images. Figure 3: Enhanced digital investigation model. 4. Reporting: The final phase is reporting the outcome of analysis, which may include describing the actions taken, describing what are the tools and procedures were selected on investigation [2]. A digital investigation follows certain stages and procedures when working on a case. First identify the crime, along with the object (victim) and other tools used to commit the crime then an investigation officer looking at all the digital evidences builds suitable chain of custody. Once officer recovers all evidences, after evidences has been analyzed the officer must act as an expert witness and present the evidence in court. The investigating officer becomes the tool which law enforcement must use to track and prosecute on criminals [3]. At the outset the crime investigation seems to be very crucial and difficult to solve the situation but the evidences that have to be taking at the crime scene are to be going to propose to find the suspect. At the crime scene, the case investigator and crime scene personal work to define the secure areas that may contain evidences: examine and document the scene; collect physical evidences and images, videos of whole crime scene and tools used to crime. Preserve all evidences for further investigation. Digital investigation will provide exact means of evidences which helps to examine and analyze the case on the basis of strong evidences at crime scene [4]. Digital evidences must be admissible, precise, authenticated and accurate in order to accept by court. Digital evidences are exact in nature and handled properly and carefully. A detailed digital investigation procedure provides important aspects to digital investigation as per the court law. A digital investigation carried out in the form of models this gives an advantage of finding the suspect related to crime. The model can also help to capture the 466

expertise of investigation as a basis to the development of advanced tools incorporating techniques such as automated evidence collection [3]. B. Digital Investigation Process (DIP) Figure 4: Digital investigation process. In Acquisition phase, evidences are to be gathered in acceptable manner with proper approval from the authority which is followed by identification phase where the task is to identify the evidences which leads to suspect and convert them to the format which is understood by human. The evaluation phase comprise of the task to determine whether the evidences identified in the previous phase is needed relevant to the case being investigated and the case further be lead to suspect. In final phase that is Admission the acquired and extracted evidences are presented in the court of law [4]. C. Ease of Use Collecting physical evidence from a scene can help an investigator recreate the crime scene and establish the sequence of events. Physical evidence can also corroborate statements made by the victim, suspects and witnesses [5]. Various Scene that can be documented while crime scene reporting Burglars Suicides Fires Auto thefts Auto accidents. Data transfer to server carried out through online or high speed data cable. B. Centralized Server The data collected using Mobile Application from the jurisdictions of various police stations will get accumulated in the central server, which Can be accessed by supervisors at any level from the Police Station up to state or country. Accordingly the reporting tool loaded in the central server provides the facility for analysis and generation of reports about the crime scene situation in the jurisdiction of a police station up to a state/province or the country as a whole. The user is free to choose the period for which the data is to be analyzed and reported. Thus this reporting tool provides a comprehensive report by cross classifying the crime data for the user selected period (duration) and selected jurisdiction (area/network: district, city, province, etc) including causal analysis. These secured and scientific data on crime scene, collected and managed with greater ease, are expected to revolutionize in solving the crimes. Server application from where all or selected cases can be viewed and can add the further instructions to the officers to proceed with case. List of all cases can be viewed: Location wise on MAP Category wise (Thefts, Murder, etc) Officer wise Case number wise / Date of Offence wise Data Transfer: Crime details collected from the scene of crime can be transferred online from mobile phone to server connecting through internet or can be transferred offline connecting mobile phone through data cable to server IV. PROPOSED WORK AND METHODOLOGY The proposed article explores a complete electronic record of all cases, scenes and ensures that you have a centralized place for all of your data in any environment. The regular routine of manual investigation pretended to a high magnified level which emphasis the real time investigation in better way. The work aimed to help the investigating agencies to be accurate and consistent means of evidence collection, examination, analysis and reporting. Because data is to be centralized, this gives all accumulated information to the investigating agencies which comes under jurisdictions of various police stations up to state or country. The proposed system will have two modules A. Mobile Application An android smart phone is an important aspect in which the proposed application is to be installed; this can be carried by police officer s on the field. Smart phone is expected to operate with a high speed, High resolution camera (audio/video), Smart storage capacity, 3G network facility to fetch location. The application is built in such a way that user pretend the case in all the directions and capture most possible evidences and put them to server with one touch. C. Schematic Diagram of Enhanced Digital Investigation on Crime scene System Figure 5: Architecture of Enhanced Digital Investigation System. D. Post implementation benefits and another features Productivity: once implemented would increase the productivity and reduce the time required to document the scene drastically. 467

Data security: From the instance evidence is collected is locked and transferred to the centralized server/cloud. Easy access to seniors: The data once transferred to the server/cloud can be easily accessed by the senior officers moreover the crime scenes can be searched by desired parameter like location, type of crime etc Empower filed force: system would reduce the need of carrying too many devices while caring out crime scene investigation. It would also reduce a lot of paper work and time spent on compiling reports. Transparency: Eliminate any possibility of manipulation of crime scene or evidence and give almost real time visibility to senior officers. E. Results and Discussions The enhanced digital investigation on crime scene gives perfect figures of crime with different analysis methods which give glance about the cases registered some of standard analysis techniques used are listed below. Severity level analysis Severity is mentioned while the case being registered. The graph deals with three severity levels high, low, medium. The analysis pretends the investigating officials to control over crime. Date crime analysis Case type analysis History of different case types like robbery, rape case, murder has been seen on one screen with graph. It clearly shows the comparison among different case category. This type of analysis over crime investigation helps investigating officials to analyze about different types of crime. V. CONCLUSION The enhanced digital crime scene investigation system will be an enhanced version is defined to redefine forensic process in crime scene. It describe the development right from the point when the initial infrastructure is put in place, to investigations when the incident is reported, through the trace back phases that would lead to the point where the crime was committed and finally to the ultimate investigations that would lead to conclusive interpretations of the evidence collected and also will helps law enforcement agencies (police) to monitor the crime scene on real time which will quickly gather the information of a crime and also higher authority will come to know the information of crime happened in particular area by sending auto generated message. Once the evidences are stored in cloud or at SP/IGP servers, the evidences are secured for longer time and no changes are made on the evidences. This proposed article is fully electronic way of investigating a crime which helps the officials to analyze the case and conclude it within less time efficiently. Thus Enhanced digital investigation on crime scene is best suitable for digital crime scene investigation. REFERENCES Date crime analysis gives detail idea about number of case registered on particular date. This helps investigating agencies to link with different crimes to get evidences. [1] Yunus Yusoff, Roshan Ismail and Zainuddin Hassan, Common Phases of Computer Forensics Investigation Models International Journal of Computer Science and Information Technology (IJCSIT), Vol 3, No 3, June 2011, pp 18,19. [2] Inkipo O. Ademu, Dr Chris O. Imfiden, Dr David S. Preston A new Approach of digital Forensics Model for Digital Forensics Investigation International Journal of advanced Computer science and Applications(IJACSA) Vol 2, No 12, 2011, pp 176. [3] Sabah Al-Fedaghi and Bashayer Al-Babtain Modeling the Forensics process, International Journal of Security and its Applications, Vol 6, No 4, October. 2012, pp 97-98. 468

[4] Norulzahrah M. Zainudin, Madjid merabti, David Llewellyn-Jones, ISBN: 978-902560-24-3@ 2010 PGNet A Digital Forensics Investigation Model for Online Social Networking unpublished. [5] Saferstein, Richard. A Simplified Guide to Crime Scene Investigation. 469