Linux speeds up computer forensics for cops

Australian university students have developed a Linux-based data forensics tool to help police churn through a growing backlog of computer-related criminal investigations.

The tool was developed by students from Edith Cowan University's (ECU) School of Computing and Information Sciences and will help the Western Australian Police Computer Crime Squad process their forensic investigations.

Called SIMPLE or Simple Image Preview Live Environment, the software allows investigators to view and acquire forensic data at the scene of the crime without compromising the integrity of data as it is collected.

"It's a Linux Live CD that we have built from the ground up. We customised the kernel and the underlying operating system so that when it runs it's incapable of writing to the hard disk or any other storage," Peter Hannay, one of the software developers behind the forensic acquisition tool told ZDNet.com.au.

The operating system has had some features removed so that investigators can view data without affecting the host machine.

Want to know more?

For all the latest news, analysis and opinion on Linux, click here

"We stripped out a large amount of functionality because we want to maintain the integrity of data collected, so we removed all network support and the ability to write to disk. Also, if for some reason a disk is writeable, the system will halt automatically," he added.

"Our software will launch on top of the operating system and will interrogate the hard disk, locate all the images on system and then present those to the operator."

SIMPLE searches the system for specific file types like MPEG or JPEG files, saving time on the often lengthy search process.

Hoping to achieve even greater automation during the collection of evidence, SIMPLE will soon be equipped with skin tone analysis capabilities to help detect relevant files.

The idea for the tool first came when the Western Australian Police approached the university in 2006, since its investigators could not handle the amount of computer forensic data requests, which relate mostly to child pornography and bestiality.

Normally police need to take the PCs back to the station to begin acquiring forensic data, but with this tool, according to Hannay, police will be able to collect the data on the spot.

Advertisement

Talkback 5 comments

    Not newAnonymous -- 06/03/08

    Guys, seriously, there have been knoppix CDs kicking around for years that do just what WA are talking about. IACIS -the US based computer forensics accrediation organisation had training for SPADA- a similar CD and system from 2005, maybe earlier. That one was written in Queensland. It's just been updated with the latest knoppix kernel actualy.. I don't want to take anything away from the WA guys, great job! I just wish people would do some research before posting articles. :)

    Not coolAnonymous -- 07/03/08 (in reply to #320096871)

    Guy, seriously, take a look at the target audience for SIMPLE - people with only a few hours introduction to the system. You think authorities haven't researched what is on the market already? If police officers and the like knew how to use forensic tools that we all know are available, there wouldn't be any need for projects like this.
    Your comments do nothing but attempt to take away from the WA guys... I wish people would do some thinking before posting uninformed opinions in public places.

    It IS new actually...Anonymous -- 07/03/08 (in reply to #320096871)

    The article itself is misleading in that the tool is designed for untrained officers to use it, not the computer crime squad. SPADA was NOT designed for untrained users, and if used incorrectly can cause big problems as it is basically a Helix hack. I just wish people would do some research before posting comments. :)

    How would I obtain a copy of this distro?Anonymous -- 11/03/08

    Is this exclusively for PC use, or would I be able to download an iso for my work as a network integrator?

    CorrectionAnonymous -- 11/03/08 (in reply to #320097068)

    Sorry, I mean for Police use, or can a network engineer like myself download a copy to use for data recovery on our client PCs.

    Thanks.

Add your opinion


Latest Videos

Blogs

  • David Braue Will Rudd's bush backhaul bonanza deliver?
    Rural areas will be welcoming the government's decision to put its money where its politicising is, funnelling $250m into a regional fibre upgrade to six rural centres. Remedying over a decade of near-neglect at the hands of telecoms privatisation, the investment could be the firmest step yet for Labor's NBN dream — but with inevitable political questions and a looming election, Rudd and Conroy need to deliver, and quickly, to preserve the NBN's credibility.
  • Array Doing for AV what VoIP did for telephony
    Sydney-based start-up Audinate is making traditional analog cabling obsolete in favour of TCP/IP-based networking technology. And it's doing a pretty good job so far, with its technology used by World Youth Day and the Sydney Opera House.
  • Array WiMax in Australia: Part two
    WiMax could be the standard that drives the next phase of mobile broadband, it provides an opportunity for players wanting to establish a pure IP network to carry voice and data effectively — but is this what operators want?
  • More blogs »

Tags

Back to top

Featured