Search FCW


Subscribe Now!
Table of Contents
Sprint
Business
BPM
CXOs
Columns
Columnists
Defense
E-Government
Elections 2008
Enterprise Architecture
Funding
Homeland Security
Health IT
IPv6
LOB
Management
Procurement
Privacy
Policy
Program Management
State and Local
Security
Technology
Telework
Training and Certification
Workforce

More Topics
resourcecenter
Home
Letters to the Editor
Current Issue/Download
Print/Online Archives
Editorial Calendar
researchstore
resourcecenter
Communications for Continuity Operations

Oracle Resource Center
NEW! Transforming Data Center
Managed Services
Service Oriented Architecture
Training & Simulation
Networking Communications
Security Directives and Compliance
Data Center Virtualization
Air Force ELSG Contract Guide

More >>



Latest News
ADVERTISEMENT





 

Special Report | NIST’s goal: Keep digital evidence fresh

Lab offers tool-testing kit, builds reference library

By FCW Staff
Published on July 27, 2006

Comment

Click here to comment on this article


Newsletters

You might also be interested in these FCW newsletters:

Daily

To learn more, click here.


Scientists at the National Institute of Standards and Technology are known for sweating the nitty-gritty details of dull but vital standards for everything from bulletproof vests to medical measurement devices and IT encryption.

And now, agency experts are bringing the same precision to computer forensics, fully aware that the final say lies in the notoriously low-tech realm of the judicial system.

NIST’s efforts are two-pronged: a library of software applications and programs for testing the reliability of forensics tools.

Since 2001, it has maintained the National Software Reference Library, with support from the Justice Department’s National Institute of Justice and law-enforcement agencies. NSRL is an actual library of CDs for 7,120 software applications.

“We’ve got one of everything we could get our hands on,” said Douglas White, a computer scientist in NIST’s Information Technology Laboratory.

NIST runs algorithms against the disks to generate digital “fingerprints,” or hashes, of files, for which it then creates a metadata index. The two together form the Computer Forensic Reference Data Set (RDS) for digital evidence. In a trial, if a court questions the RDS, NIST can prove its authenticity by regenerating the hashes.

Evidence locker

CDs usually aren’t loaned out. Keeping the originals “is very important for evidentiary purposes,” said John Tebbutt, another NSRL computer scientist. “We do not lend it out because we have to keep it under evidence locker conditions.”

As of March, NIST reported, the RDS contained nearly 11 million hashes for three times as many files, and the Web site, www.nsrl.nist.gov, gets nearly a quarter-million hits a month.

Law enforcement agencies and other computer forensics specialists pay $90 a year for quarterly updates.

The RDS speeds investigations by identifying files that can be ignored—say, a Microsoft Office executable file. It also can highlight hidden and altered files.

NIST staff members say NSRL is such a normal part of the daily work of forensics labs that they don’t typically hear success stories from subscribers. Ubiquity can be a better measure: White said the FBI sends copies to all its field offices.

While the basic concept behind it hasn’t changed, NSRL is advancing in other ways. NIST is developing a process for hashing network files to address the increasing volume of evidence stored on servers, which are difficult to take into physical custody.

“You have to do what’s called a live acquisition—acquiring the forensic information from a machine that’s actually running,” Tebbutt said.

NIST also is working on hashes that operate on storage blocks, a potentially faster, more precise method than the black-and-white file hashes, which can be thrown off by minor file changes. White said block hashes will make it easier to exclude unimportant files. NIST has provided hashes to several states that hope to prevent software tampering in voting machines.


upcoming event

Program Management Summit 2008, Ronald Reagan Building, Washington, DC
November 18 - November 19, 2008

Defense and Intelligence Solutions for Business Transformation-DC, Grand Hyatt, Washington, D.C.
November 18, 2008

Building Sustainable Business Models in a Green World, The Willard Hotel 1401 PA Ave., NW Washington, DC
November 19, 2008, 8:00 AM - 10:00 AM

Security 2008, Ronald Reagan Building, Washington, DC
November 20 - November 21, 2008


 

head
fcw
issue
First Name State
Last Name Zip
Title Email