Linux speeds up computer forensics for cops

Australian university students have developed a Linux-based data forensics tool to help police churn through a growing backlog of computer-related criminal investigations.

The tool was developed by students from Edith Cowan University's (ECU) School of Computing and Information Sciences and will help the Western Australian Police Computer Crime Squad process their forensic investigations.

Called SIMPLE or Simple Image Preview Live Environment, the software allows investigators to view and acquire forensic data at the scene of the crime without compromising the integrity of data as it is collected.

"It's a Linux Live CD that we have built from the ground up. We customised the kernel and the underlying operating system so that when it runs it's incapable of writing to the hard disk or any other storage," Peter Hannay, one of the software developers behind the forensic acquisition tool told ZDNet.com.au.

The operating system has had some features removed so that investigators can view data without affecting the host machine.

Want to know more?

For all the latest news, analysis and opinion on Linux, click here

"We stripped out a large amount of functionality because we want to maintain the integrity of data collected, so we removed all network support and the ability to write to disk. Also, if for some reason a disk is writeable, the system will halt automatically," he added.

"Our software will launch on top of the operating system and will interrogate the hard disk, locate all the images on system and then present those to the operator."

SIMPLE searches the system for specific file types like MPEG or JPEG files, saving time on the often lengthy search process.

Hoping to achieve even greater automation during the collection of evidence, SIMPLE will soon be equipped with skin tone analysis capabilities to help detect relevant files.

The idea for the tool first came when the Western Australian Police approached the university in 2006, since its investigators could not handle the amount of computer forensic data requests, which relate mostly to child pornography and bestiality.

Normally police need to take the PCs back to the station to begin acquiring forensic data, but with this tool, according to Hannay, police will be able to collect the data on the spot.

Advertisement

Talkback 5 comments

    Not new Anonymous -- 06/03/08

    Guys, seriously, there have been knoppix CDs kicking around for years that do just what WA are talking about. IACIS -the US based computer forensics accrediation organisation had training for SPADA- a similar CD and system from 2005, maybe earlier. That one was written in Queensland. It's just been updated with the latest knoppix kernel actualy.. I don't want to take anything away from the WA guys, great job! I just wish people would do some research before posting articles. :)

    Not cool Anonymous -- 07/03/08 (in reply to #320096871)

    Guy, seriously, take a look at the target audience for SIMPLE - people with only a few hours introduction to the system. You think authorities haven't researched what is on the market already? If police officers and the like knew how to use forensic tools that we all know are available, there wouldn't be any need for projects like this.
    Your comments do nothing but attempt to take away from the WA guys... I wish people would do some thinking before posting uninformed opinions in public places.

    It IS new actually... Anonymous -- 07/03/08 (in reply to #320096871)

    The article itself is misleading in that the tool is designed for untrained officers to use it, not the computer crime squad. SPADA was NOT designed for untrained users, and if used incorrectly can cause big problems as it is basically a Helix hack. I just wish people would do some research before posting comments. :)

    How would I obtain a copy of this distro? Anonymous -- 11/03/08

    Is this exclusively for PC use, or would I be able to download an iso for my work as a network integrator?

    Correction Anonymous -- 11/03/08 (in reply to #320097068)

    Sorry, I mean for Police use, or can a network engineer like myself download a copy to use for data recovery on our client PCs.

    Thanks.

Add your opinion

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Suzanne Tindal IT: Govt's cost-cutting bitch
    The government needs to stop looking at IT as a necessary evil or the place to remove costs when the Treasurer comes calling.
  • Array Can complaints on mobile content be cut?
    On 1 July this year the new Mobile Premium Services Code was introduced. It sounds like it's had a good impact, but is it enough?
  • Array NZ farmers: Bleating about broadband
    As we know, farmers are such bleaters. They bleat as much as the four-legged woolly things in their paddocks. If it's not the weather, it's the strength of the dollar! Nothing is ever right. Likewise with rural broadband.
  • More blogs »

Tags

Back to top

Featured