
Top Challenges and Changes in the Use of Digital Intelligence Forensic Evidence
- State and local law enforcement “first responders” are responsible for the disposition of approximately 97% – 98% of all US criminal cases.
- Each year more cases are handled in the Manhattan D.A.’s office than in the entire federal judicial system.
- Digital evidence is present in 80%-90% of all criminal cases, including child pornography, network intrusion, murder, white-collar, gang, drug terrorism.
- Increased Use of Digital Data in Criminal Investigations
- Challenges and Value of Collecting, Extracting and Analyzing New Forms of Digital Data
- Challenges to the Admissibility of Digital Data and the Changing Rules of Evidence
- What types of Use Restriction policies are on the horizon?
- How should digital evidence be transported and documented?
- What should investigators be considering during the document collection stage, that will become important to their courtroom presentation?
- National Terrorism Case: Search of an Apple iPhone seized during the execution of a search warrant in San Bernardino.
- Drug Trafficking Case: U.S. vs. Jung Feng: Order requiring Apple, Inc. to assist in the execution of a search warrant issued by the court.
- Burglary Case: The State of Minnesota vs. Matthew Vaughn Diamond. Defendant appealed the conviction, arguing that order requiring him to unlock his phone with a fingerprint violated his 5th amendment right against self-incrimination.
- Challenges and Value of Collecting, Extracting and Analyzing New Sources of Digital Data Here we will give you a big picture view of what we are seeing from a national and international standpoint, regarding the growing amount of digital evidence in criminal cases. We take a look at the specs of mobile device data capacities in terms of hard drives, flash drives, memory, and more. You will also understand what to do with intentionally damaged devices.Discover 6 new sources of digital evidence:
- Black box (Automobile) – Collects Speed, braking pressure, seat belt usage, etc.
- GPS data – from the permanent mount and hand-held devices
- Fitness Trackers (ie. Fitbit)
- Pacemakers
- Drones and digital controllers
- Cloud extraction – public domain (no search warrant) and private (with a warrant)
- Physical Extraction: Understand forensically sound capabilities that access the full file system for both Apple iOS and Samsung Android devices. Eliminate jailbreaking, rooting or flashing the device and learn how to bypass Apple iTunes backup encryption.
- Data Recovery: We will cover the downloading of emails, third-party application data, Geolocation data and System logs.
- Challenges to the Admissibility of Digital Data and the Changing Rules of Evidence The law is trying to keep up with the changing landscape of evolving data and devices, including how we collect both. Here, we will explain new amendments to Rule 902 Evidence that is self-authenticating, in the Federal Rules of Evidence, FRE. These changes pertain to records generated by an electronic process or system, and data copied from an electronic device, storage medium or file, effective December 1st, 2017. We will also discuss why the rules are changing in regards to needing a witness to authenticate an item of electronic evidence and what this means for you in terms of certification, qualified persons and notice requirements. You will understand the impact of rule changes on streamlining the admission of digital evidence, incentives to follow practices and forensic collection of digital evidence with a “digital footprint”.Get practical answers to the following questions answered by our experts during the final Q&A session:
- How would you handle an agency whose supervisors and detectives ask you to extract data from mobile devices in contradiction to one’s digital forensics training?
- How effective is taking out the SIM card in the instance when a faraday bag is not available?
- The cases of interest show a varying degree of law enforcement capability to compel and unlock a phone in different federal and state districts. Are there any measures being discussed to unify policy on unlocks across the federal and state boundaries?
- What are the latest trends for data analytics in law enforcement? Is there any movement in consolidating acquired digital forensic data for future investigations analysis?