Comprehensive Study of Digital Forensics Branches and Tools
Comprehensive Study of Digital Forensics Branches and Tools
Abstract: In today’s world, digital devices are being integral part of our life and these digital
devices are evolving with new technology. Some people make use of new technology for their
personal gain. Cybercrimes are growing rapidly due to evolving technology. Digital forensics is the
science which encompasses, identify, analyze, recover and investigate digital evidences found in
digital devices. To make the forensic process effective the discipline is subdivided into various
branches, where specialized tools are available for a particular branch. Every forensic tool is
associated with some of the limitations which disturb the investigation process. Hence, proper forensic
tool which satisfies the requirement of the case is required to be used.
Key words: Digital Forensics, digital forensic branches, digital forensics tool
___________________________________
Paper submitted on: May 14th, 2018
____________________________________________ Prachi Ankush Zinge, and Madhumita Chatterjee 23
Digital Forensics is “the use of scientifically preserved to maintain and guarantee the Chain of
derived and proven methods for the Custody. For this, service providers are needed
preservation, collection, validation, identification, who will ensure that the evidence offered in court
analysis, interpretation and presentation of digital is the same as that was collected and there was
evidence for the purpose of facilitating or no tampering with it while it was in the custody.
furthering the reconstruction of events of a
criminal nature or helping to facilitate the Analysis: Analysis phase plays an
unauthorized actions shown to be disruptive to important role because the result obtained after
planned actions”[11]. Nowadays, significant the analysis of the evidences using digital
changes have taken place in the digital forensics forensic tools helps the investigators to identify
process. the cause of the incident and provide them
effective results sufficient to be submitted in the
court for justice. This phase includes recovery of
deleted content and examining the system
2.1 Objective of Digital Forensic content.
With the advancement of the computer, there is a Presentation: This phase consists of
revolution in the way humans live, work and play. coming to the conclusions on the basis of
Businesses are growing with the help of the evidences obtained from the forensic
computers rapidly. But there is a dark side of investigation. In this phase, acquired data is
computers also. Cybercriminals use them to carry processed to derive relevant information as per
out malicious assaults. These assaults are need and is based entirely on policy and law.
varying from fraud and identity theft to hacking,
The above process is generally recognized and
embezzlement and many such activities.
followed across the world in the investigation of
Evidence can be derived from computers and
cybercrimes
used in a court against suspected accused.
Initially, the judges accepted such computer
evidence as any other type of evidence smoothly.
But, as data became more ambiguous with the
3.BRANCHES OF DIGITAL FORENSICS
advancement of digital devices, computer-derived Digital Forensics emerged because of the
evidence lost its reliability gradually. cybercrimes carried out by use of IT infrastructure
or technology by cyber criminals. Below are given
Hence, for preserving the integrity of the evidence it’s subdisplines.
and to have a subject matter expert opinion,
cybercrimes are investigated for identifying,
generating, analyzing, verifying and presenting Computer
forensic
digital evidences in the court using standard
tools. As a precaution, certain policies,
guidelines, standards, laws which are acceptable
Mobile Memory
to the jurisdictional process are followed for forensic forensic
getting hold of the criminal. It generally comprises Digital
forensic
of four major processes: