Wednesday, October 23, 2019
Business Continuity Plan
Data Sources in Digital Forensics March 17, 2013 Joana Achiampong CSEC 650 Introduction Four sources of data that stand out for forensic investigators in most criminal investigations are files, operating systems, routers and network traffic, and social network activity. Each data source presents a variety of opportunities and challenges for investigators, meaning that the more reliable data collection and analysis activity typically involves examination of a variety of sources.Digital forensics must cover the four basic phases of activity, which include: data collection, which describes the identification and acquisition of relevant data; data examination, which includes the processing of data through the use of automated and manual tools; analysis, which describes the evaluation and categorization of examined data into coherent groups, such as their usefulness in a court proceeding; and reporting, in which the results of analysis are described with careful attention paid to recommen dations (Marcella & Menendez, 2009).The viability of each data source to an investigation must be evaluated based on how they can contribute to each phase. For example, the ability of routers and switches as a data source to help investigators might be effective in one area, but not in the other three. An examination of router activity might yield a surfeit of observable data that fails to provide diverse analytical tools that cannot be relied upon in a forensic setting. Another example is network traffic, which may yield a large amount of data that is unreliable or has a high degree of volatility (Garfinkel, 2010).Time is often essential for forensic investigators, and it is often important to know in advance the dynamics of each data source. This helps investigators avoid wasted time, or spending time analyzing data that may of minimal help in a forensic setting. For these reasons, it is important to critically assess the pros and cons of each data source for their ability to prov ide contributions. A valid assessment of each data source should be made based on consistent factors such as costs, data sensitivity, and time investment.The overall costs of each data source depend on the equipment that will be required to collect and analyze data without corruption. Costs also refer to the training and labor required during the course of the collection and analysis, which may be higher for uncommon sources that require a unique process and chain of command pattern. Data sensitivity is critical is a forensic tool, but may be more questionable depending on the source. For example, network activity can provide a wealth of information depending on the device and setting upon which data is moved.However, a network environment with many devices and multiple configurations may provide unreliable data that cannot be recognized in court proceedings. In addition, chain-of-command issues regarding the contribution of outside network analysts could compromise a source that wo uld be otherwise valid. These issues have to be considered in any data source assessment. Data Files The most common data sources in a digital forensic examination are current and deleted files. Most forensic investigators in most data retrieval environments begin with an examination of the various media store on the hard drive of a computer, network, or mobile device.The variety of types of stored data in current and deleted files, in addition to partitioned packet files and the slack space of a deviceââ¬â¢s memory, can be massive and diverse. A typical first step in data retrieval is to shut down a system and create a data grab or forensic duplicate upon which collection and analysis can be made. This ensures the integrity of the original data, while allowing investigators the ability to manipulate data however they see fit. However, this process alone creates challenges for forensic investigators, including an inability to capture live system data.This might prevent investigat ors from catching a perpetrator in the act of altering or adding data to a device or system. One of the primary benefits of files as a data source is the ability to separate and analyze the types of files, which creates a specific signature based on the content and user (Marcella & Menendez, 2008). Data can be pulled from deleted files, slack space on a systemââ¬â¢s hard drive, or free space, all of which provides information that can be useful to investigators.The directory location and allocation type for each file informs the data that has been collected, including a time stamp and whether tools have been used to hide the data. Each of these characteristics provides investigators easy-to-access information about a system. In addition, there are a variety of hardware tools that can be used to access data. This technology is fairly common, meaning that associated costs tend to be minimal when retrieving data from files (Purita, 2006). File examination can yield a variety of type s of suspicious activity that tend to be helpful for investigators.One example is the presence of hidden evidence on file systems. This type of data can be hidden in deleted file spaces, slack spaces, and bad clusters. File space is marked as deleted when it is removed from an active directory. This data will continue to exist within a cluster of a hard disk can be identified and accessed by creating a file in Hex format and transferring the copied data. Data can also be hidden in many others ways, including by removing partitions that are created between data and by leveraging the slack space that exists between files.Attempts by users to hide data using these methods are quickly identifiable by investigators, who can then restore the data using a variety of inexpensive and efficient methods. For example, matching RAM slack to file slack identifies the size of a file and makes it easier to identify and retrieve (Sindhu & Meshram, 2012). This type of retrieval inherently emphasizes the importance of data integrity. This type of integrity is important in any forensic environment, and compromised data is usually rendered instantly unusable. The many opportunities for data retrieved from file space to be compromised are a drawback to this data source.For example, data retrieval using bit stream imaging provides a real-time copy onto a disk or similar medium. However, this can be compromised based on the fact that re-imagining of data is constantly changing during re-writing. Investigators will typically choose the type of data copy system based on what they are looking for. However, changes to data can occur if the appropriate safeguards are not taken. Write-blockers are often used to prevent an imaging process from providing data that has been compromised by writing to that media. Sindhu and Meshram 2012) stated that computing a message digest will create a verification of the copied data based on a comparison to the original. A message digest is an algorithm th at takes input data and produces an output digest. This comparison helps investigators ensure the integrity of data in many cases. There are additional pitfalls when it comes to using files as data sources. Users have different resources for eliminating or hindering data collection. One example is overwriting content by replacing it with constant values. This type of wiping function can be performed by a variety of utilities.Users can also demagnetize a hard drive to physically destroy the content stored there. Using files as a data source in this case will require a complex operation requiring different tools. Users can also purposefully misname files ââ¬â for example, giving them . jpg extensions when they are not image content files ââ¬â in order to confuse investigators. Investigators have to be familiar with strategies for circumventing these pitfalls, such as maintaining an up-to-date forensic toolkit and remaining committed to maintaining data integrity.In the end, fi les are very highly relied upon by investigators and are a strong source forensic data. However, investigators must be experienced and have the appropriate tools to ensure the viability of collected data. Operating Systems Generally speaking, the data that can be collected from Operating Systems (OS) is more diverse and rich than file systems data, and has greater potential to uncover application-specific events or vital volatile data specific to a network operation (Sindhu, Tribathi & Meshram, 2012).However, OS data mining can be more difficult and challenging, and often requires investigators to make quick decisions based on the type of data they are seeking. OS data mining is more case specific, in part because the retrieval of data is frequently connected to network configurations. Collecting volatile data can only occur from a live system that has not been shut down or rebooted (Marcella & Menendez, 2008). Additional activity that occurs over an individual network session is ve ry likely to compromise the OS data. For this reason, investigators have to be prepared and aware of what they are looking for.Time is of the essence in this case, and it is important to decide quickly whether or not the OS data should be preserved or if the system should be shut down. Keeping a system running during data extraction can also compromise data files. This also leaves data vulnerable to malware that has been installed by a user with bad intentions, determined to undermine the operations of investigators. The types of data that can be retrieved from the OS include network connections, network configurations, running processes, open files, and login sessions.In addition, the entire contents of the memory can be retrieved from the OS history, usually with little or no alteration of data when the footprint of retrieval activity is minimized. The order in which this data is collected typically runs in a standard succession, with network connections, login sessions, and memor y collection sitting at the top of the list or priorities. These sources are more important because they tend to change over time. For example, network connections tend to time out and login sessions can change as users log in or out.Network configurations and the files that are open in a system are less time-sensitive and fall further down the list of priorities for investigators. The forensic toolkit must be diverse to ensure that data retrieval is achieved with minimal alteration (Bui, Enyeart & Luong, 2003). In addition, the message digest of each tool should be documented, along with licensing and version information, and command logs. This careful documentation protects users from sudden loss of data or other disturbances during data retrieval.In addition, a number of accessibility issues can be implemented by users, including the placement of screen saver passwords, key remapping and log disabling features, all of which can disrupt the work by investigators, either providing unworkable obstacles or time-consuming hurdles that make complete transfer impossible. Ultimately, the use of OS as a data source is a case-by-case tool dependent on the availability of other sources and the specific needs and tools of investigators. Routers and Network TrafficAmong network configuration data sources, router activity and network sourcing has the potential to provide the most specific amount of incriminating activity for forensic use. Forensic equipment should have time stamping capabilities activated to provide an accurate time signature of network interaction between an end-user and a router or switch (Schwartz, 2011). Importantly, firewalls and routers that are tied to a network often provide network address translation which can offer additional information by clarifying configuration or additional IP addresses on a network (Huston, 2004).There are a number of tools available to people seeking an analysis of network activity, including packet sniffers and intrusi on detection systems (Marcella & Menendez, 2008). These tools help investigators examine all packets for suspicious IP addresses and special events that have occurred across a network. This data is usually recorded and analyzed so that investigators can compare unusual events to evaluate network weaknesses and special interests of would-be attackers.This is of great interests to security agents determined to identify and stop potential network intrusions. A number of technical, procedural, legal and ethical issues exist when examining and analyzing network data. It is imperative that investigators be sure to avoid disconnected from a network or rebooting a system during data retrieval. They should also rely on live data and persistent information. Finally, it is important to avoid running configuration commands that could corrupt a network or its activity (Gast, 2010).Issues such as storage of large amounts of data over a highly trafficked network and proper placement of a decryptio n device along a network can impact how data is available and whether or not it maintains integrity. It is also important to consider the ethical and legal issues of data retrieval along a network when it involves sensitive data, such as financial records and personal information like passwords. In many cases, ethical issues can be circumvented with careful documentation and the publication of organizational policies and procedures that are strictly followed.However, these are all issues that must be considered in the analysis of network trafficking as a data source. Social Network Activity The sheer volume of social network activity ââ¬â such as that on Facebook, Twitter, and Instragram ââ¬â makes examining it as a data source great potential as a forensic tool. To this point, the little available research on social network data has failed to come up with a comprehensive framework or set of standards for investigators. Social network tools across mobile platforms invariably have geolocation services.However, the use of these as a data source has been questioned from ethical and legal perspectives (Humaid, Yousif, & Said, 2011). The communication layer of social media applications on mobile devices can yield rich data, such as a browser cache and packet activity. Packet sniffing can expose unencrypted wifi use and third party intrusion across a social network. However, these tools are highly limited when they are restricted to social network activity. The best tools may be the ability to create a social footprint, which includes all friend activity, posted pictures and videos, communication habits, and periods of activity.For most people, this information is only available on social network websites and is not stored on a userââ¬â¢s hard drive. A certain climate of permissibility tends to apply to social network use, in which users are prone to making data available online that they would not otherwise expose. All of this strengthens the use of soci al networks as a data source. The greatest pitfall to social network activity is the malleability of the material. Users frequently change their habits, including the times of the day and the users with whom they connect.Cumulative social network data can be used to create a graph of all activity across a variety of factors, including time, space, usage, and devices (Mulazzani, Huber, & Weippl). But this is a rapidly changing field. There is little doubt that the cloud computing data storage and continued growth of social networks will change this field quickly, which could quickly undermine past data that has been retrieved. Potential Usefulness in Specific Events The usefulness of a data source is strictly tied to the event it is intended to investigate.It is imperative that investigators are clear on their goals prior to selecting a source to retrieve and analyze data from. For example, a network intrusion would be best tackled with an examination of network traffic, followed by social network analysis, Operating Systems, and data file systems. Network analysis is less prone to attacking strategies that can compromise file and OS data. It can observe network traffic to find anomalous entities and their entry point within a network. It can also identify source and destination data by data recovery and access to routers r other network access points (Aquilina, Casey & Malin, 2008). This is critical information for network intrusion investigations. Operating Systems enable access to volatile data, but this is limited by single-time use and data integrity issues. Most OS examinations look at network connections first, which is often another way of accessing the same data. File storage and social network analysis tend to offer peripheral views of the same material. Operating systems are the most helpful data source in malware installation investigation, followed by network traffic, data files, and social network activity.Examination of volatile data offers a ran ge of data, including network connections and login sessions, which are primary tools for finding the source of malware installation (Aquilina, Casey & Malin, 2008). Maintaining the integrity of data through quick retrieval and minimal footprints helps ensure its usefulness. At the same time, monitoring network traffic in a pro-active manner is often the surest way of pinpointing time signatures and matching them with network activity (Marcella & Menendez, 2008). The best data sources for identifying insider file deletion are data files, network traffic, social network activity and OS.Each source offers benefits for this type of investigation, but data file collection and analysis yields bad clusters and slack space, both of which pinpoint the likelihood of deleted files. Recovery can begin from this point. Network activity and OS data retrieval can lead investigators to unusual login attempts and anomalous activity in order to pinpoint the location of deleted files along a network. At the same time, social network examination can help investigators understand reasons for deleted files and even learn more about the habits and lifestyle of a likely perpetrator.In the end, a collection of each of these sources provides a rich, revealing glimpse at deleted file activity. Conclusion Network traffic, data files, operating systems, and social network activity are four common data sources in digital forensic. Each provides a unique opportunity and set of risks for investigators, and the source should be chosen based on clear objectives and awareness of all circumstances. In many cases, the best choice is a combination of sources to provide multiple opportunities to arrive at the relevant evidence.Another factor is whether the data search is reactive or pro-active, with network traffic often providing the best source of evidence in a pro-active, forward-thinking environment. The variable of time must also be considered, specifically with respect to how investigators a pproach volatile data. Each of these issues must be considered when evaluating data sources. References Aquilina, J. , Casey, E. & Malin, C. (2008). Malware forensics: Investigating and Analyzing Malicious Code. Burlington, MA: Syngress Publishing. Bui, S. , Enyeart, M. & Luong, J. (2003, May). Issues in Computer Forensics. Retrieved ttp://www. cse. scu. edu/~jholliday/COEN150sp03/projects/Forensic%20Investiga tion. pdf Garfinkel, S. (2010). Digital forensics research: The next 10 years. Digital Investigation, 7. 64-73. Gast, T. (2010). Forensic data handling. The Business Forum. Retrieved from http://www. bizforum. org/whitepapers/cybertrust-1. htm Humaid, H. , Yousif, A. & Said, H. (2011, December). Smart phones forensics and social networks. IEEE Multidisciplinary Engineering Education Magazine, 6(4). 7-14. Huston, G. (2004, September). Anatomy: A look inside network address translators. The Internet Protocol Journal, 7(3).Retrieved from http://www. cisco. com/web/about/ac123/ac1 47/archived_issues/ipj_7- 3/anatomy. html Marcella, A. & Menendez, D. (2008). Cyber Forensics: A Field Manual for Collecting, Examining, and Preserving Data. Boca Raton, FL: Auerbach Publications. Mulazzani, M. , Huber, M. & Weippl, E. (n. d. ). Social network forensics: Tapping the data pool of social networks. SBA-Research. Retrieved from http://www. sba- research. org/wp-content/uploads/publications/socialForensics_preprint. pdf Purita, R. (2006). Computer Forensics: A valuable audit tool. Internal Auditor. Retrieved from http://www. theiia. rg/intAuditor/itaudit/archives/2006/september/computer- forensics-a-valuable-audit-tool-1/ Schwartz, M. (2011, December). How digital forensics detects insider theft. InformationWeek Security. Retrieved from http://www. informationweek. com/security/management/how-digital-forensics- detects-insider-t/232300409 Sindhu, K. & Meshram, B. (2012). A digital forensic tool for cyber crime data mining. Engineering Science and Technology: An Internati onal Journal, 2(1). 117-123. Sindhu, K. , Tripathi, S. & Meshram, B. (2012). Digital forensic investigation on file system and database tampering. IOSR Journal of Engineering, 2(2). 214-221. Business Continuity Plan Data Sources in Digital Forensics March 17, 2013 Joana Achiampong CSEC 650 Introduction Four sources of data that stand out for forensic investigators in most criminal investigations are files, operating systems, routers and network traffic, and social network activity. Each data source presents a variety of opportunities and challenges for investigators, meaning that the more reliable data collection and analysis activity typically involves examination of a variety of sources.Digital forensics must cover the four basic phases of activity, which include: data collection, which describes the identification and acquisition of relevant data; data examination, which includes the processing of data through the use of automated and manual tools; analysis, which describes the evaluation and categorization of examined data into coherent groups, such as their usefulness in a court proceeding; and reporting, in which the results of analysis are described with careful attention paid to recommen dations (Marcella & Menendez, 2009).The viability of each data source to an investigation must be evaluated based on how they can contribute to each phase. For example, the ability of routers and switches as a data source to help investigators might be effective in one area, but not in the other three. An examination of router activity might yield a surfeit of observable data that fails to provide diverse analytical tools that cannot be relied upon in a forensic setting. Another example is network traffic, which may yield a large amount of data that is unreliable or has a high degree of volatility (Garfinkel, 2010).Time is often essential for forensic investigators, and it is often important to know in advance the dynamics of each data source. This helps investigators avoid wasted time, or spending time analyzing data that may of minimal help in a forensic setting. For these reasons, it is important to critically assess the pros and cons of each data source for their ability to prov ide contributions. A valid assessment of each data source should be made based on consistent factors such as costs, data sensitivity, and time investment.The overall costs of each data source depend on the equipment that will be required to collect and analyze data without corruption. Costs also refer to the training and labor required during the course of the collection and analysis, which may be higher for uncommon sources that require a unique process and chain of command pattern. Data sensitivity is critical is a forensic tool, but may be more questionable depending on the source. For example, network activity can provide a wealth of information depending on the device and setting upon which data is moved.However, a network environment with many devices and multiple configurations may provide unreliable data that cannot be recognized in court proceedings. In addition, chain-of-command issues regarding the contribution of outside network analysts could compromise a source that wo uld be otherwise valid. These issues have to be considered in any data source assessment. Data Files The most common data sources in a digital forensic examination are current and deleted files. Most forensic investigators in most data retrieval environments begin with an examination of the various media store on the hard drive of a computer, network, or mobile device.The variety of types of stored data in current and deleted files, in addition to partitioned packet files and the slack space of a deviceââ¬â¢s memory, can be massive and diverse. A typical first step in data retrieval is to shut down a system and create a data grab or forensic duplicate upon which collection and analysis can be made. This ensures the integrity of the original data, while allowing investigators the ability to manipulate data however they see fit. However, this process alone creates challenges for forensic investigators, including an inability to capture live system data.This might prevent investigat ors from catching a perpetrator in the act of altering or adding data to a device or system. One of the primary benefits of files as a data source is the ability to separate and analyze the types of files, which creates a specific signature based on the content and user (Marcella & Menendez, 2008). Data can be pulled from deleted files, slack space on a systemââ¬â¢s hard drive, or free space, all of which provides information that can be useful to investigators.The directory location and allocation type for each file informs the data that has been collected, including a time stamp and whether tools have been used to hide the data. Each of these characteristics provides investigators easy-to-access information about a system. In addition, there are a variety of hardware tools that can be used to access data. This technology is fairly common, meaning that associated costs tend to be minimal when retrieving data from files (Purita, 2006). File examination can yield a variety of type s of suspicious activity that tend to be helpful for investigators.One example is the presence of hidden evidence on file systems. This type of data can be hidden in deleted file spaces, slack spaces, and bad clusters. File space is marked as deleted when it is removed from an active directory. This data will continue to exist within a cluster of a hard disk can be identified and accessed by creating a file in Hex format and transferring the copied data. Data can also be hidden in many others ways, including by removing partitions that are created between data and by leveraging the slack space that exists between files.Attempts by users to hide data using these methods are quickly identifiable by investigators, who can then restore the data using a variety of inexpensive and efficient methods. For example, matching RAM slack to file slack identifies the size of a file and makes it easier to identify and retrieve (Sindhu & Meshram, 2012). This type of retrieval inherently emphasizes the importance of data integrity. This type of integrity is important in any forensic environment, and compromised data is usually rendered instantly unusable. The many opportunities for data retrieved from file space to be compromised are a drawback to this data source.For example, data retrieval using bit stream imaging provides a real-time copy onto a disk or similar medium. However, this can be compromised based on the fact that re-imagining of data is constantly changing during re-writing. Investigators will typically choose the type of data copy system based on what they are looking for. However, changes to data can occur if the appropriate safeguards are not taken. Write-blockers are often used to prevent an imaging process from providing data that has been compromised by writing to that media. Sindhu and Meshram 2012) stated that computing a message digest will create a verification of the copied data based on a comparison to the original. A message digest is an algorithm th at takes input data and produces an output digest. This comparison helps investigators ensure the integrity of data in many cases. There are additional pitfalls when it comes to using files as data sources. Users have different resources for eliminating or hindering data collection. One example is overwriting content by replacing it with constant values. This type of wiping function can be performed by a variety of utilities.Users can also demagnetize a hard drive to physically destroy the content stored there. Using files as a data source in this case will require a complex operation requiring different tools. Users can also purposefully misname files ââ¬â for example, giving them . jpg extensions when they are not image content files ââ¬â in order to confuse investigators. Investigators have to be familiar with strategies for circumventing these pitfalls, such as maintaining an up-to-date forensic toolkit and remaining committed to maintaining data integrity.In the end, fi les are very highly relied upon by investigators and are a strong source forensic data. However, investigators must be experienced and have the appropriate tools to ensure the viability of collected data. Operating Systems Generally speaking, the data that can be collected from Operating Systems (OS) is more diverse and rich than file systems data, and has greater potential to uncover application-specific events or vital volatile data specific to a network operation (Sindhu, Tribathi & Meshram, 2012).However, OS data mining can be more difficult and challenging, and often requires investigators to make quick decisions based on the type of data they are seeking. OS data mining is more case specific, in part because the retrieval of data is frequently connected to network configurations. Collecting volatile data can only occur from a live system that has not been shut down or rebooted (Marcella & Menendez, 2008). Additional activity that occurs over an individual network session is ve ry likely to compromise the OS data. For this reason, investigators have to be prepared and aware of what they are looking for.Time is of the essence in this case, and it is important to decide quickly whether or not the OS data should be preserved or if the system should be shut down. Keeping a system running during data extraction can also compromise data files. This also leaves data vulnerable to malware that has been installed by a user with bad intentions, determined to undermine the operations of investigators. The types of data that can be retrieved from the OS include network connections, network configurations, running processes, open files, and login sessions.In addition, the entire contents of the memory can be retrieved from the OS history, usually with little or no alteration of data when the footprint of retrieval activity is minimized. The order in which this data is collected typically runs in a standard succession, with network connections, login sessions, and memor y collection sitting at the top of the list or priorities. These sources are more important because they tend to change over time. For example, network connections tend to time out and login sessions can change as users log in or out.Network configurations and the files that are open in a system are less time-sensitive and fall further down the list of priorities for investigators. The forensic toolkit must be diverse to ensure that data retrieval is achieved with minimal alteration (Bui, Enyeart & Luong, 2003). In addition, the message digest of each tool should be documented, along with licensing and version information, and command logs. This careful documentation protects users from sudden loss of data or other disturbances during data retrieval.In addition, a number of accessibility issues can be implemented by users, including the placement of screen saver passwords, key remapping and log disabling features, all of which can disrupt the work by investigators, either providing unworkable obstacles or time-consuming hurdles that make complete transfer impossible. Ultimately, the use of OS as a data source is a case-by-case tool dependent on the availability of other sources and the specific needs and tools of investigators. Routers and Network TrafficAmong network configuration data sources, router activity and network sourcing has the potential to provide the most specific amount of incriminating activity for forensic use. Forensic equipment should have time stamping capabilities activated to provide an accurate time signature of network interaction between an end-user and a router or switch (Schwartz, 2011). Importantly, firewalls and routers that are tied to a network often provide network address translation which can offer additional information by clarifying configuration or additional IP addresses on a network (Huston, 2004).There are a number of tools available to people seeking an analysis of network activity, including packet sniffers and intrusi on detection systems (Marcella & Menendez, 2008). These tools help investigators examine all packets for suspicious IP addresses and special events that have occurred across a network. This data is usually recorded and analyzed so that investigators can compare unusual events to evaluate network weaknesses and special interests of would-be attackers.This is of great interests to security agents determined to identify and stop potential network intrusions. A number of technical, procedural, legal and ethical issues exist when examining and analyzing network data. It is imperative that investigators be sure to avoid disconnected from a network or rebooting a system during data retrieval. They should also rely on live data and persistent information. Finally, it is important to avoid running configuration commands that could corrupt a network or its activity (Gast, 2010).Issues such as storage of large amounts of data over a highly trafficked network and proper placement of a decryptio n device along a network can impact how data is available and whether or not it maintains integrity. It is also important to consider the ethical and legal issues of data retrieval along a network when it involves sensitive data, such as financial records and personal information like passwords. In many cases, ethical issues can be circumvented with careful documentation and the publication of organizational policies and procedures that are strictly followed.However, these are all issues that must be considered in the analysis of network trafficking as a data source. Social Network Activity The sheer volume of social network activity ââ¬â such as that on Facebook, Twitter, and Instragram ââ¬â makes examining it as a data source great potential as a forensic tool. To this point, the little available research on social network data has failed to come up with a comprehensive framework or set of standards for investigators. Social network tools across mobile platforms invariably have geolocation services.However, the use of these as a data source has been questioned from ethical and legal perspectives (Humaid, Yousif, & Said, 2011). The communication layer of social media applications on mobile devices can yield rich data, such as a browser cache and packet activity. Packet sniffing can expose unencrypted wifi use and third party intrusion across a social network. However, these tools are highly limited when they are restricted to social network activity. The best tools may be the ability to create a social footprint, which includes all friend activity, posted pictures and videos, communication habits, and periods of activity.For most people, this information is only available on social network websites and is not stored on a userââ¬â¢s hard drive. A certain climate of permissibility tends to apply to social network use, in which users are prone to making data available online that they would not otherwise expose. All of this strengthens the use of soci al networks as a data source. The greatest pitfall to social network activity is the malleability of the material. Users frequently change their habits, including the times of the day and the users with whom they connect.Cumulative social network data can be used to create a graph of all activity across a variety of factors, including time, space, usage, and devices (Mulazzani, Huber, & Weippl). But this is a rapidly changing field. There is little doubt that the cloud computing data storage and continued growth of social networks will change this field quickly, which could quickly undermine past data that has been retrieved. Potential Usefulness in Specific Events The usefulness of a data source is strictly tied to the event it is intended to investigate.It is imperative that investigators are clear on their goals prior to selecting a source to retrieve and analyze data from. For example, a network intrusion would be best tackled with an examination of network traffic, followed by social network analysis, Operating Systems, and data file systems. Network analysis is less prone to attacking strategies that can compromise file and OS data. It can observe network traffic to find anomalous entities and their entry point within a network. It can also identify source and destination data by data recovery and access to routers r other network access points (Aquilina, Casey & Malin, 2008). This is critical information for network intrusion investigations. Operating Systems enable access to volatile data, but this is limited by single-time use and data integrity issues. Most OS examinations look at network connections first, which is often another way of accessing the same data. File storage and social network analysis tend to offer peripheral views of the same material. Operating systems are the most helpful data source in malware installation investigation, followed by network traffic, data files, and social network activity.Examination of volatile data offers a ran ge of data, including network connections and login sessions, which are primary tools for finding the source of malware installation (Aquilina, Casey & Malin, 2008). Maintaining the integrity of data through quick retrieval and minimal footprints helps ensure its usefulness. At the same time, monitoring network traffic in a pro-active manner is often the surest way of pinpointing time signatures and matching them with network activity (Marcella & Menendez, 2008). The best data sources for identifying insider file deletion are data files, network traffic, social network activity and OS.Each source offers benefits for this type of investigation, but data file collection and analysis yields bad clusters and slack space, both of which pinpoint the likelihood of deleted files. Recovery can begin from this point. Network activity and OS data retrieval can lead investigators to unusual login attempts and anomalous activity in order to pinpoint the location of deleted files along a network. At the same time, social network examination can help investigators understand reasons for deleted files and even learn more about the habits and lifestyle of a likely perpetrator.In the end, a collection of each of these sources provides a rich, revealing glimpse at deleted file activity. Conclusion Network traffic, data files, operating systems, and social network activity are four common data sources in digital forensic. Each provides a unique opportunity and set of risks for investigators, and the source should be chosen based on clear objectives and awareness of all circumstances. In many cases, the best choice is a combination of sources to provide multiple opportunities to arrive at the relevant evidence.Another factor is whether the data search is reactive or pro-active, with network traffic often providing the best source of evidence in a pro-active, forward-thinking environment. The variable of time must also be considered, specifically with respect to how investigators a pproach volatile data. Each of these issues must be considered when evaluating data sources. References Aquilina, J. , Casey, E. & Malin, C. (2008). Malware forensics: Investigating and Analyzing Malicious Code. Burlington, MA: Syngress Publishing. Bui, S. , Enyeart, M. & Luong, J. (2003, May). Issues in Computer Forensics. Retrieved ttp://www. cse. scu. edu/~jholliday/COEN150sp03/projects/Forensic%20Investiga tion. pdf Garfinkel, S. (2010). Digital forensics research: The next 10 years. Digital Investigation, 7. 64-73. Gast, T. (2010). Forensic data handling. The Business Forum. Retrieved from http://www. bizforum. org/whitepapers/cybertrust-1. htm Humaid, H. , Yousif, A. & Said, H. (2011, December). Smart phones forensics and social networks. IEEE Multidisciplinary Engineering Education Magazine, 6(4). 7-14. Huston, G. (2004, September). Anatomy: A look inside network address translators. The Internet Protocol Journal, 7(3).Retrieved from http://www. cisco. com/web/about/ac123/ac1 47/archived_issues/ipj_7- 3/anatomy. html Marcella, A. & Menendez, D. (2008). Cyber Forensics: A Field Manual for Collecting, Examining, and Preserving Data. Boca Raton, FL: Auerbach Publications. Mulazzani, M. , Huber, M. & Weippl, E. (n. d. ). Social network forensics: Tapping the data pool of social networks. SBA-Research. Retrieved from http://www. sba- research. org/wp-content/uploads/publications/socialForensics_preprint. pdf Purita, R. (2006). Computer Forensics: A valuable audit tool. Internal Auditor. Retrieved from http://www. theiia. rg/intAuditor/itaudit/archives/2006/september/computer- forensics-a-valuable-audit-tool-1/ Schwartz, M. (2011, December). How digital forensics detects insider theft. InformationWeek Security. Retrieved from http://www. informationweek. com/security/management/how-digital-forensics- detects-insider-t/232300409 Sindhu, K. & Meshram, B. (2012). A digital forensic tool for cyber crime data mining. Engineering Science and Technology: An Internati onal Journal, 2(1). 117-123. Sindhu, K. , Tripathi, S. & Meshram, B. (2012). Digital forensic investigation on file system and database tampering. IOSR Journal of Engineering, 2(2). 214-221.
Tuesday, October 22, 2019
Voltaireââ¬â¢s Candide Essays
Voltaireââ¬â¢s Candide Essays Voltaireââ¬â¢s Candide Essay Voltaireââ¬â¢s Candide Essay Essay Topic: Candide Voltaire opens chapter three of Candide with our hero amidst a battle between the Aberes and the Bulgarians. The imagery depicted by the author speaks of cannons, gunfire, death of soldiers accompanied by martial drum rolls and trumpets. The two armies are both rejoicing the ââ¬Å"heroic debaucheryâ⬠and singing a song of thanksgiving. The protagonist finds himself not wanting to do anything with the whole affair and decided to escape while everyone else was preoccupied, so that he could just resolve to try to figure out the ââ¬Å"cause and effects.â⬠After encountering several dead and dismembered bodies he was able to reach a near by Abarian village, and was able to see the carnage left behind by the Bulgarian army. The wittiness of Voltaire appears once more when he says that such massacre is in accordance with international law. As such it criticizes the political justifications of war during his time that warrants the destruction and death of people their community simply because itââ¬â¢s consequential to a legitimized warfare. He hastily tries to leave this bloody scene and moves forward to another village, one which belongs to the Bulgarians. Unfortunately, he sees the same sort of tragedy; now brought about by the Aberians. He flees to Holland, where he initially felt optimistic in learning that the said country was inhabited by wealthy Christians. He was disillusioned the moment started to ask people for charity. The locals denied helping him even threatening to place him in a correctional where he would learn how to earn a living. He then opted to approach a sort of catholic orator who asked him whether or not he believed that the pope was an antichrist. Candide answered honestly that he had no idea who the pope was but nonetheless he only wants a piece of bread. The man curses Candide for this, while the wife who overheard the conversation dumped a pot full of feces over our hero. Candide was able to find momentary relief from his misfortunes when he meets an Anabaptist named James. The latter pitied our protagonist. James takes Candide home, feeds him, allows him to bathe, and gives him a Job. As a result Candide was able to redeem his beliefs of the teachings of his Master Pangloss. Everything works towards the greatest good, this world is the best of all possible worlds and all has sufficient reason for occurring. The era when Voltaire wrote his novella was marked with wars among states, the battles between the Bulgarians and Abares is said to be based on the seven years war occurring at the time he wrote the book.à We are able to see the anti-war sentiment the author had, as well find reason in his criticism against the laws that warrants an event that would result to nothing more but devastation on both sides of the field. We could see the irony of the two kings making their camp sing to the glory of god, and the terming of soldiers as heroes despite the fact that the latter are to certain extent murderers, rapists, and pillagers. It indeed reflects the world then governed supposedly by law and the divine, only to result to injustice and evil. The religion, Catholicism which at that time was becoming more and more powerful did not escape the satire pen of Voltaire. He pointed out the flaws of the said institutions and its believers. We could see the hypocrisy of those who claimed to be followers of the Catholic Church. This brings into question the validity of the said faithful in upholding the teachings of Jesus Christ regarding charity, love, and mercy. Historians may not be too pleased with the factuality of Voltaireââ¬â¢s account of the details regarding War. Voltaire was able to portray in Chapter three his sentiments and criticisms regarding the powers (war and religion) that existed during his time. It is the case that the story reveals the truth of the values upheld at the period the novel was written. References: Voltaire (1984). Candide. (Lowell Bair, Trans.). New York: Bantam Classics.
Monday, October 21, 2019
The New Wave of Populism essays
The New Wave of Populism essays Western democracies are experiencing a period of change because of a rising wave of right-wing populism. The populists already had success in Britain with Brexit and the United States with president Trump, and their success seems to be contagious in the rest of Europe. Political leaders Marine le Pen from Front National in France and Geert Wilders from the Party for Freedom in the Netherlands are the next right-wing populist candidates favored to win. Both of them are forces to be reckoned with in the coming elections. These populist want to rebuild state-egoism by laying emphasis on the national politics and stop mass-immigration. The established western elite, who have been the ruling power since the Second World War, are watching with fear to what this new period is going to bring. The sovereign rule of the people as a homogeneous body is the central idea in this thin-centered ideology or political doctrine (Abts, Koen and Stefan Rummens: ââ¬Å"Populism versus Democracyâ⬠. University of Leuven, 2007 vol. 55) The word populism comes from the Latin word ââ¬Å"populusâ⬠, which means the people. Populism comes in both right- and left-wing parties, but the current wave of populism is especially connected to the right-wing parties. The populist leader considers himself as the representative who knows the general will of the ââ¬Å"ordinary forgotten peopleâ⬠. Their goal is to unite ââ¬Å"the pure peopleâ⬠and to give the power back to them from ââ¬Å"the corrupt eliteâ⬠, who does not understand the middle-class (Mudde, Cas. Populist radical right parties in Europe. Cambridge: Cambridge U Press, 2007. Print.) For the people in the nation who say the populist leader does not represent them, he has a clear response: they do not belong to the nation. Only those who agree with this ââ¬Å"national willâ⬠do belong to the nation. They along with the elite form the ââ¬Å"enemyâ⬠of the people and are the reason for the problems within in the nation. Crea...
Sunday, October 20, 2019
Cute Guy Quotes
Cute Guy Quotes If you see a really cute guy and want to approach him, what would you do? Turn on your charm and hope that he notices you, or go right up to him and ask him out? Whatever you do, you need to know how guys think. Here are some cute guy quotes to get you started. Work your way into the mind of cute guys and you will never go wrong with your approach. Alphonse Karr: If men knew all that women think, they would be twenty times more daring.Mark Twain: Man is the only creature who has a nasty mind.William Shakespeare, Much Ado About Nothing: O, what men dare do! What men may do! What men daily do, not knowing what they do!Mason Cooley: Young men preen. Old men scheme.Robert Elliott Gonzales: Even the most staid and respectable husband likes for his wife to think he is a devil among the women.Francesca M. Cancian: Part of the reason that men seem so much less loving than women is that mens behavior is measured with a feminine ruler.George Bernard Shaw: Power does not corrupt men; fools, however, if they get into a position of power, corrupt power.Julius Charles Hare: The greatest truths are the simplest, and so are the greatest men.Karen Blixen: What is man, when you come to think upon him, but a minutely set, ingenious machine for turning, with infinite artfulness, the red wine of Shiraz into urine?Jean Giraudoux: When you see a woma n who can go nowhere without a staff of admirers, it is not so much because they think she is beautiful, it is because she has told them they are handsome. Buddha: A dog is not considered a good dog because he is a good barker. A man is not considered a good man because he is a good talker.Oscar Wilde: A man who marries his mistress leaves a vacancy in that position.Buddha: A wise man, recognizing that the world is but an illusion, does not act as if it is real, so he escapes the suffering.Will Cuppy: All modern men are descended from a worm-like creature, but it shows more on some people.Albert Einstein: Any man who reads too much and uses his own brain too little falls into lazy habits of thinking.Richard J. Needham: Every woman needs one man in her life who is strong and responsible. Given this security, she can proceed to do what she really wants to do fall in love with men who are weak and irresponsible.Anais Nin: I, with a deeper instinct, choose a man who compels my strength, who makes enormous demands on me, who does not doubt my courage or my toughness, who does not believe me naive or innocent, who has the courage to treat me like a woman. Linda Ellerbee: If men can run the world, why cant they stop wearing neckties? How intelligent is it to start the day by tying a little noose around your neck?Rita Mae Brown: If the world were a logical place, men would ride side saddle.Henry David Thoreau: In the long run, men hit only what they aim at. Therefore, they had better aim at something high.Helen Rowland: It takes a woman twenty years to make a man of her son, and another woman twenty minutes to make a fool of him.Groucho Marx: Man does not control his own fate. The women in his life do that for him.Jim Backus: Many a man owes his success to his first wife and his second wife to his success.Laura Swenson: Men are like a deck of cards. Youll find the occasional king, but most are jacks.Kathleen Mifsud: Men are like a fine wine. They all start out like grapes, and its our job to stomp on them and keep them in the dark until they mature into something youd like to have dinner with.Carrie Latet: Men like a woman with a daring tongue. Thats a double-entendre, which reminds me they also like a menage a trois. Ninon de Lenclos: Men lose more conquests by their own awkwardness than by any virtue in the woman.Roger Woddis: Men play the game; women know the score.E. H. Chapin, Living Words: Physically, man is but an atom in space and a pulsation in time. Spiritually, the entire outward universe receives significance from him, and the scope of his existence stretches beyond the stars.Maureen Murphy: Some men are so macho theyll get you pregnant just to kill a rabbit.Gloria Steinem: Some of us are becoming the men we wanted to marry.Francis Bacon: The desire of excessive power caused the angels to fall; the desire of knowledge caused men to fall.Natalie Wood: The only time a woman really succeeds in changing a man is when he is a baby.
Saturday, October 19, 2019
Tourism Policy of West London Essay Example | Topics and Well Written Essays - 1000 words
Tourism Policy of West London - Essay Example At the same time, the sustainable tourism policy says local people are partners in the revenue of tourism because they have to maintain the culture and heritage of the place to make it an attraction. Developmental policy focuses on the ecological and financial development of the society. It is necessary to take this perspective while forming the policy as a socio-economic factor, development, tourism, and sustainability are all interlinked. In London, tourism supports the economy, and generates jobs. The important tasks detailed by the Mayor say it all. He reiterates that London's economy should continue to be successful and only then, could it be distributed. It is a long term sustainable success dealing with the climate change and its necessities. "All Londoners must participate in this success. Not only for social justice but because without it the quality of life in the city will deteriorate and the consensus for London's internationalisation will break down" http://www.lda.gov.uk/server/show/ConWebDoc.1886 It is possible to present a vision with the right perspective of development, cultural atmosphere and socio-economic parameters because they are the main factors that govern tourism and its development. Cultural background is necessary to develop, retain and to present as an attraction, while socio-economic parameters are necessary for benefit and improvement. Development of London with the impending Olympics cannot develop without a vision of its own. What is tourism visioning Provide an example of a vision statement from your policy document. (Note it may be necessary to read between the lines if this is not immediately obvious) Why is it necessary to undertake such an exercise Tourism visioning has the social and economic conditions of the region in mind, while keeping the cultural perspective intact. It is more of eco tourism that sustains the tourism industry, but maintains the eco balance of the state, by not harming the tourist attractions or the region in any way and it will also combat the global warming. The Mayor's vision of London tourism says: "To develop London as an exemplary sustainable world city, based on interwoven themes: strong and diverse, long-term economic growth; social inclusion to give all Londoners the opportunity to share in London's future success; fundamental improvements in London's environment and use of resources. A Prosperous City: Making London a more prosperous city with strong and diverse economic growth. A City for People: Making London a better city for people to live in. An Accessible City: Improving London's transport and making it accessible to disabled users, women, children and the elderly; making the most sustainable and efficient use of the space in London; encouraging intensification and growth in areas of need and opportunity" A Fair City: Promoting social inclusion and tackling deprivation and discrimination A Green City: Making London a more attractive, well designed green city" . It is necessary because London must have better economic growth to remain a prosperous city and it has to remain eminently habitable without any adverse effects of tourism. It should be internally and externally suitably linked for all
Friday, October 18, 2019
Health Services Finance Assignment Example | Topics and Well Written Essays - 500 words
Health Services Finance - Assignment Example Moreover, the wages for the casual workers in the expansion process will also be categorized as direct cost. This example is justifiable since the cost expensed in paying salaries and wages in the expansion process will entirely benefit the expansion project. Indirect costs are services or activities that benefits more than one object (Wei-Yu, Dilip, and James 41). It is almost unfeasible to relate the indirect cost to a particular object. A good example of an indirect cost in Chiropractor organization includes the salaries of permanently employed managers who oversee operations in more than one organizationââ¬â¢s branch. It is sometimes difficult to relate how these organizational managers directly benefit a particular branch. The responsibility center in Chiropractor organization is incredibly indispensable and valuable. The organization has decentralized its operations to create efficient responsibility centers. Chiropractor has three main responsibility centers that include: investment, profit, and cost (Merkley 41). Cost responsibility center manager has the responsibility of relating the expenses incurred in an organization to the available revenues. Profit responsibility center is mandated with the responsibility of generating revenue from cash outlays. A profit responsibility center is expected to meet the set profitable goals in the organization. Finally, investment responsibility centerââ¬â¢s main role is to manage other responsibility centers. Additionally, the investment center has an obligation of managing the organizationââ¬â¢s assets. The other supplementary responsibility of the investment center entails regulating returns on invested resources. The Chiropractor community has over the yearââ¬â¢s experienced endless environmental catastrophes such as earthquakes and other artificial and natural accidents that interfere with their daily operations. This has as a result led to significant loss of lives and property (Chrysanthus 137). However, to counter
Data Analysis by SQL Essay Example | Topics and Well Written Essays - 1750 words
Data Analysis by SQL - Essay Example Based on the results obtained, it is evident that the highest value customers in terms of the revenue are mainly from Europe, including, Denmark, Germany and France. The total revenue from US customers amounts to $ 56,029, whereas the revenue from France is $ 68,011. By identifying the products bought by the customers, their preferences can be identified. This will enable the firm to create a customer profile and make the appropriate products readily available in the proper locations. It will also be beneficial to identify the most preferred shipping service of the customers. From the database, it is evident that the United Package has been chosen for 326 times, the Federal Express was preferred for around 255 orders, whereas Speedy Express for 249 orders. Hence it is evident that the three shipping services are equally important. The orders are analysed based on the products, in order to identify the most preferred and the highest revenue generating products.The high revenue generating categories are also identified and the role of discounts in the orders are also analysed. From the analysis, the highly sold product has been found as Gorgonzoo Telino whereas the product generating the highest revenue is Cote de Blaye.However, when analysing the categories, it is found that the best selling categories in terms of revenue and number of products are Beverages, Dairy products and Confections. It is imperative to note that the least revenue generating revenues include Produce and Grains and Cereals.
Subscribe to:
Posts (Atom)