Linux speeds up computer forensics for cops

Australian university students have developed a Linux-based data forensics tool to help police churn through a growing backlog of computer-related criminal investigations.

The tool was developed by students from Edith Cowan University's (ECU) School of Computing and Information Sciences and will help the Western Australian Police Computer Crime Squad process their forensic investigations.

Called SIMPLE or Simple Image Preview Live Environment, the software allows investigators to view and acquire forensic data at the scene of the crime without compromising the integrity of data as it is collected.

"It's a Linux Live CD that we have built from the ground up. We customised the kernel and the underlying operating system so that when it runs it's incapable of writing to the hard disk or any other storage," Peter Hannay, one of the software developers behind the forensic acquisition tool told ZDNet.com.au.

The operating system has had some features removed so that investigators can view data without affecting the host machine.

Want to know more?

For all the latest news, analysis and opinion on Linux, click here

"We stripped out a large amount of functionality because we want to maintain the integrity of data collected, so we removed all network support and the ability to write to disk. Also, if for some reason a disk is writeable, the system will halt automatically," he added.

"Our software will launch on top of the operating system and will interrogate the hard disk, locate all the images on system and then present those to the operator."

SIMPLE searches the system for specific file types like MPEG or JPEG files, saving time on the often lengthy search process.

Hoping to achieve even greater automation during the collection of evidence, SIMPLE will soon be equipped with skin tone analysis capabilities to help detect relevant files.

The idea for the tool first came when the Western Australian Police approached the university in 2006, since its investigators could not handle the amount of computer forensic data requests, which relate mostly to child pornography and bestiality.

Normally police need to take the PCs back to the station to begin acquiring forensic data, but with this tool, according to Hannay, police will be able to collect the data on the spot.

Advertisement

Talkback 5 comments

  1. Not new Anonymous -- 06/03/08

    Guys, seriously, there have been knoppix CDs kicking around for years that do just what WA are talking about. IACIS -the US based computer forensics accrediation organisation had training for SPADA- a similar CD and system from 2005, maybe earlier. That one was written in Queensland. It's just been updated with the latest knoppix kernel actualy.. I don't want to take anything away from the WA guys, great job! I just wish people would do some research before posting articles. :)

    1. Not cool Anonymous -- 07/03/08

      Guy, seriously, take a look at the target audience for SIMPLE - people with only a few hours introduction to the system. You think authorities haven't researched what is on the market already? If police officers and the like knew how to use forensic tools that we all know are available, there wouldn't be any need for projects like this.
      Your comments do nothing but attempt to take away from the WA guys... I wish people would do some thinking before posting uninformed opinions in public places.

    2. It IS new actually... Anonymous -- 07/03/08

      The article itself is misleading in that the tool is designed for untrained officers to use it, not the computer crime squad. SPADA was NOT designed for untrained users, and if used incorrectly can cause big problems as it is basically a Helix hack. I just wish people would do some research before posting comments. :)

  2. How would I obtain a copy of this distro? Anonymous -- 11/03/08

    Is this exclusively for PC use, or would I be able to download an iso for my work as a network integrator?

    1. Correction Anonymous -- 11/03/08

      Sorry, I mean for Police use, or can a network engineer like myself download a copy to use for data recovery on our client PCs.

      Thanks.

Add your opinion


ZDNet's CIO Vision Series

Customs | Murray Harrison, CIO

Australian Customs CIO Murray Harrison dislikes SLAs and runs away if a vendor talks to him about innovation. In this interview, he also explains why getting excited about gadgets can be dangerous and talks about how Customs' outsourcing strategy has evolved.

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Munir Kotadia iPhone suckers test our patience
    So how many of you have bought a 3G iPhone? Do you feel like a sucker? If you don't, maybe you will once your first bill arrives.
  • Array Westpac bank: AVG's toughest competitor
    The next time you're buying antivirus software, don't go direct to Symantec or McAfee. Don't download free antivirus. And definitely don't see Harvey Norman. Ask your bank — they're quite literally giving the stuff away.
  • Array Will you manage in the exabyte era?
    Mammoth growth in storage volumes is a fact of life, but even so it's helpful to pause occasionally and try and work out whether our information strategies have fallen hopelessly out of step with the pace of technological growth and changes in costs.
  • More blogs »

Tags

Back to top

Featured