Computer forensics: On the cutting edge

 

Connecting state and local government leaders

A few miles outside Hamilton, N.J., in a sparkling facility that still smells of fresh paint and sawn wood, Larry Depew flips a switch and a blue light starts flashing overhead.

A few miles outside Hamilton, N.J., in a sparkling facility that still smells of fresh paint and sawn wood, Larry Depew flips a switch and a blue light starts flashing overhead.That's the signal that a visitor without a security clearance is on the premises of the FBI's brand new Regional Computer Forensics Laboratory. This facility is just one of 13 regional labs across the United States sponsored by the FBI.The RCFL is not, in the strictest sense, an FBI operation, but more like a federal and state law enforcement joint venture staffed by representatives from several agencies at both levels. Its sole purpose is the examination of digital evidence in support of criminal investigations being conducted by any of the 550 law enforcement agencies in the 21 counties of New Jersey.In fiscal 2004, the FBI's forensic examiners in New Jersey fielded 340 service requests. Depew estimated that the RCFL would handle about 500 requests in 2005.'We serve anybody in the state of New Jersey,' he said. 'Our clients are the courts, or the justice system.'But there are guidelines for determining which cases the RCFL will handle.'We have a prioritization schedule,' Depew said. 'First is an ongoing event that is likely to result in injury, death or serious property damage, such as kidnapping. Second is an event with the likelihood of injury or damage, like a planned terrorist event.'After that come all other cases going to court, requests to recover data, and R&D on forensic tools, he said.The RCFL is state-of-the-art when it comes to handling computer forensics. At one end of the building is a dedicated, automated evidence room. When law enforcement agencies want to submit technology for examination, they have to hold onto it until the RCFL notifies them it can be submitted.Once the devices arrive for examination, they are bar-coded and heat-sealed in plastic bags to maintain the chain of custody. There is a dedicated server in the evidence room just to keep the records of where materials are, who had access, who conducted the examinations and where the duplicates are kept.Down the hall from the evidence room is the forensics lab'a very large open room with tall chrome wire shelves sectioning off individual work areas. Each work area can have up to six forensic stations hooked up at once.'We have a storage area network connected to the review stations, with eight terabytes for each station,' Depew said. With that kind of capacity, 'agents can review case data at leisure.'The RCFL has the equipment to undertake analysis of images from surveillance cameras, Depew said, which is high-volume work requiring massive processing.One examiner, assigned from the New Jersey State Police, was distilling information from 196 hours of video fed from 32 different cameras.The video feed normally flashes still images from each of the cameras, he said, and it takes sophisticated software to 'filter' all the analog images and put all the images from one camera together.'We handle four or five a month,' the examiner said. 'In addition to analog, we're encountering more and more proprietary systems' with specialized chips.The use of custom chips and proprietary data architectures makes it more difficult to extract the information, the agent said, and requires contacting the system manufacturer for technical information.Another examiner said the RCFL might encounter a technology that is very specialized, requiring more groundwork before it can be analyzed. For example, he recently was given a 'skimmer,' a device that captures the information on the electronic stripe of a credit card and uses the data to encode a blank card. That was a first for him, he said.Depew created a configuration control process to provide a baseline for analysts as they start new cases. Everything begins with a complete wipe of the hard drive, so there is no pollution, so to speak, with data from one case spilling into another.All of the 22 examiners have to be certified in particular areas of forensic examination. 'Basic training' is in Wintel, or Microsoft Corp.'s Windows operating system and Intel Corp.'s chips, Depew said. Then there are specialty certifications in such subjects as Linux, Apple Computer Inc.'s operating systems, cell phones and personal data assistants. It takes 18 months to earn a certification.Depew has been certified in several specialties, most recently as a PDA examiner, one of the newest areas in computer forensics.'We keep telling [field agents], 'Don't overlook devices, but remember most have volatile memory [so] you have to keep it charged.' ' In other words, when law enforcement executes a search warrant and seizes a PDA or a cell phone, take the charger cord, he said.The certifications extend to old technologies, as well. Depew continues to hold a certification in DOS, for example.'It would hurt, but I could do it,' he said of the prospect of a DOS-based forensic exam.The RCFL also archives old applications, such as all the earlier versions of Windows and early word processing software, in case a criminal investigation turns up some obsolete equipment still in use.The government classifies a vast amount of information, including data turned up in investigations. The RCFL was built to meet the specifications for handling up to 'secret' level material'thus the flashing blue light.'If we hit something that's top secret, we ship it to another agency or another facility' able to handle that level, Depew said.The need for computer forensics in order to develop evidence of a crime is obvious, but the discipline has also improved the law enforcement process, Depew said.'Years ago we had a Russian organized crime case with 2,500 wiretap tapes, a lot of them international. Los Angeles wanted to use them, so we had to physically copy and send them,' he said.Today that would not be necessary. The RCFL effectively serves as 'an investigative data warehouse,' he said, and agents can be given access to targeted files.
New Jersey, FBI combine on forensics







Growing caseload




















































X
This website uses cookies to enhance user experience and to analyze performance and traffic on our website. We also share information about your use of our site with our social media, advertising and analytics partners. Learn More / Do Not Sell My Personal Information
Accept Cookies
X
Cookie Preferences Cookie List

Do Not Sell My Personal Information

When you visit our website, we store cookies on your browser to collect information. The information collected might relate to you, your preferences or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. However, you can choose not to allow certain types of cookies, which may impact your experience of the site and the services we are able to offer. Click on the different category headings to find out more and change our default settings according to your preference. You cannot opt-out of our First Party Strictly Necessary Cookies as they are deployed in order to ensure the proper functioning of our website (such as prompting the cookie banner and remembering your settings, to log into your account, to redirect you when you log out, etc.). For more information about the First and Third Party Cookies used please follow this link.

Allow All Cookies

Manage Consent Preferences

Strictly Necessary Cookies - Always Active

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data, Targeting & Social Media Cookies

Under the California Consumer Privacy Act, you have the right to opt-out of the sale of your personal information to third parties. These cookies collect information for analytics and to personalize your experience with targeted ads. You may exercise your right to opt out of the sale of personal information by using this toggle switch. If you opt out we will not be able to offer you personalised ads and will not hand over your personal information to any third parties. Additionally, you may contact our legal department for further clarification about your rights as a California consumer by using this Exercise My Rights link

If you have enabled privacy controls on your browser (such as a plugin), we have to take that as a valid request to opt-out. Therefore we would not be able to track your activity through the web. This may affect our ability to personalize ads according to your preferences.

Targeting cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.

Social media cookies are set by a range of social media services that we have added to the site to enable you to share our content with your friends and networks. They are capable of tracking your browser across other sites and building up a profile of your interests. This may impact the content and messages you see on other websites you visit. If you do not allow these cookies you may not be able to use or see these sharing tools.

If you want to opt out of all of our lead reports and lists, please submit a privacy request at our Do Not Sell page.

Save Settings
Cookie Preferences Cookie List

Cookie List

A cookie is a small piece of data (text file) that a website – when visited by a user – asks your browser to store on your device in order to remember information about you, such as your language preference or login information. Those cookies are set by us and called first-party cookies. We also use third-party cookies – which are cookies from a domain different than the domain of the website you are visiting – for our advertising and marketing efforts. More specifically, we use cookies and other tracking technologies for the following purposes:

Strictly Necessary Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Functional Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Performance Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Social Media Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Targeting Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.