Linux speeds up computer forensics for cops

Australian university students have developed a Linux-based data forensics tool to help police churn through a growing backlog of computer-related criminal investigations.

The tool was developed by students from Edith Cowan University's (ECU) School of Computing and Information Sciences and will help the Western Australian Police Computer Crime Squad process their forensic investigations.

Called SIMPLE or Simple Image Preview Live Environment, the software allows investigators to view and acquire forensic data at the scene of the crime without compromising the integrity of data as it is collected.

"It's a Linux Live CD that we have built from the ground up. We customised the kernel and the underlying operating system so that when it runs it's incapable of writing to the hard disk or any other storage," Peter Hannay, one of the software developers behind the forensic acquisition tool told ZDNet.com.au.

The operating system has had some features removed so that investigators can view data without affecting the host machine.

Want to know more?

For all the latest news, analysis and opinion on Linux, click here

"We stripped out a large amount of functionality because we want to maintain the integrity of data collected, so we removed all network support and the ability to write to disk. Also, if for some reason a disk is writeable, the system will halt automatically," he added.

"Our software will launch on top of the operating system and will interrogate the hard disk, locate all the images on system and then present those to the operator."

SIMPLE searches the system for specific file types like MPEG or JPEG files, saving time on the often lengthy search process.

Hoping to achieve even greater automation during the collection of evidence, SIMPLE will soon be equipped with skin tone analysis capabilities to help detect relevant files.

The idea for the tool first came when the Western Australian Police approached the university in 2006, since its investigators could not handle the amount of computer forensic data requests, which relate mostly to child pornography and bestiality.

Normally police need to take the PCs back to the station to begin acquiring forensic data, but with this tool, according to Hannay, police will be able to collect the data on the spot.

Talkback 5 comments

    Not new Anonymous -- 06/03/08

    Guys, seriously, there have been knoppix CDs kicking around for years that do just what WA are talking about. IACIS -the US based computer forensics accrediation organisation had training for SPADA- a similar CD and system from 2005, maybe earlier. That one was written in Queensland. It's just been updated with the latest knoppix kernel actualy.. I don't want to take anything away from the WA guys, great job! I just wish people would do some research before posting articles. :)

    Not cool Anonymous -- 07/03/08 (in reply to #320096871)

    Guy, seriously, take a look at the target audience for SIMPLE - people with only a few hours introduction to the system. You think authorities haven't researched what is on the market already? If police officers and the like knew how to use forensic tools that we all know are available, there wouldn't be any need for projects like this.
    Your comments do nothing but attempt to take away from the WA guys... I wish people would do some thinking before posting uninformed opinions in public places.

    It IS new actually... Anonymous -- 07/03/08 (in reply to #320096871)

    The article itself is misleading in that the tool is designed for untrained officers to use it, not the computer crime squad. SPADA was NOT designed for untrained users, and if used incorrectly can cause big problems as it is basically a Helix hack. I just wish people would do some research before posting comments. :)

    How would I obtain a copy of this distro? Anonymous -- 11/03/08

    Is this exclusively for PC use, or would I be able to download an iso for my work as a network integrator?

    Correction Anonymous -- 11/03/08 (in reply to #320097068)

    Sorry, I mean for Police use, or can a network engineer like myself download a copy to use for data recovery on our client PCs.

    Thanks.

Add your opinion

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Phil Dobbie Do we need the legislative blackmail?
    Virtually everyone in the telecommunications industry has their say in the Senate Standing Committee's public hearing into the pending legislation to split up Telstra, in this week's Twisted Wire podcast.
  • Array Give Tax a break for a Change
    Considering the circumstances the Australian Taxation Office's (ATO) Change Program has been operating in over the last few years, it really hasn't been going too badly.
  • Array Ubuntu can't cut geek support umbilical
    Ubuntu 9.10 Karmic Koala was officially released overnight and marked the eleventh release of the distribution. It's attractive, polished and measured, but fails "the grandma test".
  • More blogs »

Tags

Back to top

Featured