Topic 7 Student
Topic 7 Student
CONTENTS
❖Introduction
❖Forensic analysis Techniques
❖Law in Malaysia
❖Challenges
INTRODUCTION
•Evidence: anything that demonstrates, clarifies or shows the truth of a fact or
point in question.
•Electronic evidence: any probative information stored or transmitted
in digital form that a party to a court case may use at trial.
•Digital forensics: sometimes known as digital forensic science, is a branch of
forensic science encompassing the recovery and investigation of material found
in digital devices.
•The term digital forensics was originally used as a synonym for computer
forensics but has expanded to cover investigation of all devices capable of
storing digital data.
FORENSIC ANALYSIS TECHNIQUES
Evidence Acquisition
•This step is where policies related to preserving the integrity of potential evidence are most
applicable.
Evidence Examination
•Investigators typically examine data from designated archives, using a variety of methods and
approaches to analyze information.
o"Catch-it-as-you-can" systems
All packets passing through a certain traffic point are captured and written to
storage with analysis being done subsequently in batch mode.
However…
Section 2(1) of Computer Crime Act 1997
• The definitions are different
Therefore…
•Evidence (Amendment) (No 2) Act 2012
Admissibility of ‘computer-generated documents’
•Sections 90C of Evidence Act 1950 (affirms ss90A and 90B and shall be
determined by EA 1950)
•Sections 114A of Evidence Act 1950 (presumed to be the publisher unless the
contrary is proved)
CASES
•Gnanasegaran a/l Perarajasigam v PP [1997]
3 MLJ 1
•Public Prosecutor v Hanafi Mat Hassan [2006]
4 MLJ 134
CHALLENGES
Identity Management Challenge
Who Is the Author of the Records?
Reliability
Is the Computer Program That Generated the Records Reliable? Was the output of
the computer what it is purported to be?
Alteration
Were the records altered, manipulated, or damaged after they were created?
Incompleteness
Is the evidence the entire record or conversation?
United States v. Jackson, 2007 WL 1381772 (D. Neb. 2007)