Digital Forensics as a Big Data Challenge — Forensic Focus – Articles

Digital Forensics as a Big Data Challenge

 

Abstract

Digital Forensics, as a science and part of the forensic sciences, is facing new challenges that may well render established models and practices obsolete. The dimensions of potential digital evidence supports has grown exponentially, be it hard disks in desktops and laptops or solid state memories in mobile devices like smartphones and tablets, even while latency times lag behind. Cloud services are now sources of potential evidence in a vast range of investigations and network traffic also follows a growing trend, and in cyber security the necessity of sifting through vast amount of data quickly is now paramount. On a higher level investigations – and intelligence analysis – can profit from sophisticated analysis of such datasets as social network structures, corpora of text to be analysed for authorship and attribution. All of the above highlights the convergence between so-called data science and digital forensics, to take the fundamental challenge of analysing vast amounts of data (“big data”) in actionable time while at the same time preserving forensic principles in order for the results to be presented in acourt of law. The paper, after introducing digital forensics and data science, explores the challenges above and proceeds to propose how techniques and algorithms used in big data analysis can be adapted to the unique context of digital forensics, ranging from the managing of evidence via Map-Reduce to machine learning techniques for triage and analysis of big forensic disk images and network traffic dumps. In the conclusion the paper proposes a model to integrate this new paradigm into established forensic standards and best practices and tries to foresee future trends.

1 Introduction

1.1 Digital Forensics

What is digital forensics? We report here one of the most useful definitions of digital forensics formulated. It was developed during the first Digital Forensics Research Workshop (DFRWS) in 2001 and it is still very much relevant today:

Digital Forensics is the use of scientifically derived and proven methods toward the preservation, collection, validation, identification, analysis, interpretation, documentation and presentation of digital evidence derived from digital sources for the purpose of facilitating or furthering the reconstruction of events found to be criminal, or helping to anticipate unauthorized actions shown to be disruptive to planned operations. [Pear01]

This formulation stresses first and foremost the scientific nature of digital forensics methods, in a point in time when the discipline was transitioning from being a “craft” to an established field and rightful part of the forensic sciences. At that point digital forensics was also transitioning from being mainly practised in separated environments such as law enforcement bodies and enterprise audit offices to a unified field. Nowadays this process is very advanced and it can be said that digital forensics principles, procedures and methods are shared by a large part of its practitioners, coming from different backgrounds (criminal prosecution, defence consultants, corporate investigators and compliance officers). Applying scientifically valid methods implies important concepts and principles to be respected when dealing with digital evidence. Among others we can cite:

  • Previous validation of tools and procedures. Tools and procedures should be validated by experiment prior to their application on actual evidence.
  • Reliability. Processes should yield consistent results and tools should present consistent behaviour over time.
  • Repeatability. Processes should generate the same results when applied to the same test environment.
  • Documentation. Forensic activities should be well-documented, from the inception to the end of evidence life-cycle. On one hand strict chain-of-custody procedures should be enforced to assure evidence integrity and the other hand complete documentation of every activity is necessary to ensure repeatability by other analysts.
  • Preservation of evidence – Digital evidence is easily altered and its integrity must be preserved at all times, from the very first stages of operations, to avoid spoliation and degradation. Both technical (e.g. hashing) and organizational (e.g. clear accountabilityfor operators) measures are to be taken.

These basic tenets are currently being challenged in many ways by the shifting technologicaland legal landscape practitioners have to contend with. While this paper shall not dwell much on the legal side of things, this is also obviously something that is always to be considered in forensics.

Regarding the phases that usually make up the forensic workflow, we refer here again to the only international standard available [ISO12] and describe them as follows:

  • Identification. This process includes the search, recognition and documentation of the physical devices on the scene potentially containing digital evidence. [ISO12]
  • Collection – Devices identified in the previous phase can be collected and transferred to an analysis facility or acquired (next step) on site.
  • Acquisition – This process involves producing an image of a source of potential evidence, ideally identical to the original.
  • Preservation – Evidence integrity, both physical and logical, must be ensured at all times.
  • Analysis – Interpretation of the data from the evidence acquired. It usually depends onthe context, the aims or the focus of the investigation and can range from malware analysis to image forensics, database forensics, and a lot more of application-specific areas.On a higher level analysis could include content analysis via for instance forensics linguistics or sentiment analysis techniques.
  • Reporting – Communication and/or dissemination of the results of the digital investigation to the parties concerned.

1.2 Data Science

Data Science is an emerging field basically growing at the intersection between statistical techniques and machine learning, completing this toolbox with domain specific knowledge, having as fuel big datasets. Hal Varian gave a concise definition of the field:

[Data science is] the ability to take data – to be able to understand it, to process it, to extract value from it, to visualize it, to communicate it. [Vari09]

We can see here the complete cycle of data management and understand that data science in general is concerned with the collection, preparation, analysis, visualization, communication and preservation of large sets of information; this is a paraphrase of another insightful definition by Jeffrey Stanton of Syracuse University’s School of Information Studies. The parallels with the digital forensics workflow are clear but the mention in both definitions of visualization deserves to be stressed. Visualization is mostly never mentioned in digital forensics guidelines and standards but as the object of analysis moves towards “Big Data”, it will necessarily become one of the most useful tools in the analyst’s box, for instance in the prioritization phase but also for dissemination and reporting: visual communication is probably the most efficient way into a human’s brain but this channel is underused by most of today’s forensic practitioners.

If Data Science is concerned with “Big Data”, what is Big Data anyway? After all big is a relative concept and prone to change with time. Any data that is difficult to manage and work with, or in other words datasets so big that for them conventional tools – e.g. relational databases – are not practical or useful. [ISAC13] From the point of view of data science the challenges of managing big data can be summarized as three Vs: Volume (size), Velocity (needed for interactivity), Variety (different sources of data). In the next paragraph we shall see how these three challenges dovetail nicely with the digital forensics context.

2 Challenges

“Golden Age” is a common definition for the period in the history of digital forensics that went roughly from the 1990s to the first decade of the twenty-first century. During that period the technological landscape was dominated by the personal computer, and mostly by a single architecture – x86 plus Windows – and data stored in hard drives represented the vast majority of evidence, so much so that “Computer Forensics” was the accepted term for the discipline. Also the storage size allowed for complete bitwise forensic copies of the evidence for subsequent analysis in the lab. The relative uniformity of the evidence nature facilitated the development of the digital forensic principles outlined above and enshrined in several guidelines and eventually in the ISO/IEC 27037 standard. Inevitably anyway they lagged behind the real-world developments: recent years brought many challenges to the “standard model”, first among them the explosion in the average size of the evidence examined for a single case. Historical motivations for this include:

  • A dramatic drop in hard drive and solid state storage cost (currently estimated at $80 per Terabyte) and consequently an increase in storage size per computer or device;
  • Substantial increase in magnetic storage density and diffusion of solid-state removable media (USB sticks, SD and other memory cards etc) in smartphones, notebooks, cameras and many other kinds of devices;
  • Worldwide huge penetration of personal mobile devices like smartphones and tablets, not only in Europe and America, but also in Africa – where they constitute the main communication mode in many areas – and obviously in Asia;
  • Introduction and increasing adoption by individuals and businesses of cloud services – infrastructure services (IAAS), platform services (PAAS) and applications (SAAS) – made possible in part by virtualization technology enabled in turn by the modern multi-core processors;
  • Network traffic is ever more part of the evidence in cases and the sheer size of it has – again – obviously increased in the last decade, both on the Internet and on 3G-4G mobile networks, with practical but also ethical and political implications;
  • Connectivity is rapidly becoming ubiquitous and the “Internet of things” is near, especially considering the transition to IPv6 in the near future. Even when not networked, sensors are everywhere, from appliances to security cameras, from GPS receivers to embedded systems in cars, from smart meters to Industrial Control Systems.

To give a few quantitative examples of the trend, in 2008 the FBI Regional Computer Forensics Laboratories (RCFLs) Annual Report [FBI08] explained that the agency’s RCFLs processed 27 percent more data than they did during the preceding year; the 2010 Report gavean average case size of 0.4 Terabytes. According to a recent (2013) informal survey among forensic professionals on Forensic Focus, half of the cases involve more than on Terabyte of data, with one in five over five Terabytes in size.

The simple quantity of evidence associated to a case is not the only measure of its complexity and the growing in size is not the only challenge that digital forensics is facing: evidence is becoming more and more heterogeneous in nature and provenance, following the evolving trends in computing. The workflow phase impacted by this new aspect is clearly analysis where, even when proper prioritization is applied, it is necessary to sort through diverse categories and source of evidence, structured and unstructured. Data sources themselves are much more differentiated than in the past: it is common now for a case to include evidence originating from personal computers, servers, cloud services, phones and other mobile devices, digital cameras, even embedded systems and industrial control systems.

3 Rethinking Digital Forensics

In order to face the many challenges but also to leverage the opportunities it is encountering, the discipline of digital forensics will have to rethink in some ways established principles and reorganize well-known workflows, even include and use tools not previously considered viable for forensic use – concerns regarding the security of some machine learning algorithms has been voiced, for instance in [BBC+08]. On the other hand forensic analysts’ skills need to be rounded up to make better use of these new tools in the first place, but also to help integrate them in forensic best practices and validate them. The dissemination of “big data” skills will have to include all actors in the evidence lifecycle, starting with Digital Evidence First Responders (DEFRs), as identification and prioritization will see their importance increased and skilled operators will be needed from the very first steps of the investigation.

3.1 Principles

Well-established principles shall need to undergo at least a partial extension and rethinking because of the challenges of Big Data.

  • Validation and reliability of tools and methods gain even more relevance in a big data scenarios because of the size and variety of datasets, coupled with the use of cutting-edge algorithms that still need validation efforts, including a body of test work first on methods and then on tools in controlled environments and on test datasets before their use in court.
  • Repeatability has long been a basic tenet in digital forensics but most probably we will be forced to abandon it, at least in its strictest sense, for a significant part of evidence acquisition and analysis. Already repeatability stricto sensu is impossible to achieve in nearly all instances of forensic acquisition of mobile devices, and the same applies to cloud forensics. When Machine Learning tools and methods become widespread, reliance on previous validation will be paramount. As an aside, this stresses once more the importance of using open methods and tools that can be independently and scientifically validated as opposed to black box tools or – worse – LE-reserved ones.
  • As for documentation, its importance for a sound investigation is even greater when we see non-repeatable operations and live analysis routinely be part of the investigation process. Published data about validation results of tools and methods used – or at least pointers to it – should be an integral part of the investigation report.

3.2 Workflow

Keeping in mind how the forensic principles may need to evolve, we present here a brief summary of the forensics workflow and how each phase may have to adapt to big data scenarios. ISO/IEC 27037 International Standard covers the identification, collection, acquisition and preservation of digital evidence (or, literally, “potential” evidence). Analysis and disposal are not covered by this standard, but will be in future – in development – guidelines in the 27xxx series.

Identification and collection

Here the challenge is selecting evidence in a timely manner, right on the scene. Guidelines for proper prioritization of evidence should be further developed, abandoning the copy-all paradigm and strict evidence integrity in favour of appropriate triage procedures: this implies skimming through all the (potential) evidence right at the beginning and selecting relevant parts. First responders’ skills will be even more critical that they currently are and, in corporate environments, also preparation procedures.

Acquisition

When classic bitwise imaging is not feasible due to the evidence size, prioritization procedures or “triage” can be conducted, properly justified and documented because integrity is not absolute anymore and the original source has been modified, if only by selecting what to acquire. Visualization can be a very useful tool, both for low-level filesystem analysis and higher level content analysis. Volume of evidence is a challenge because dedicated hardware is required for acquisition – be it storage or online traffic – while in the not so distant past an acquisition machine could be built with off-the-shelf hardware and software. Variety poses achallenge of a slightly different kind, especially when acquiring mobile devices, due to the huge number of physical connectors and platforms.

Preservation

Again, preservation of all evidence in a secure way and complying with legal requirements calls for quite a substantial investment for forensic labs working on a significant number of cases.

Analysis

Integrating methods and tools from data science implies surpassing the “sausage factory” forensics still widespread today, where under-skilled operators rely heavily on point and click all-in-one tools to perform the analysis. Analysts shall need to include a plurality of tools in their panoply and not only that, but understand and evaluate the algorithms and implementations they are based upon. The absolute need for highly skilled analysts and operators is clear, and suitable professional qualifications will develop to certify this.

Reporting

The final report for an analysis conducted using data science concepts should contain accurate evaluations of tools, methods used, including data from the validation process and accurate documentation is even more fundamental as strict repeatability becomes very hard to uphold.

3.3 Some tools for tackling the Big Data Challenge

At this stage, due also to the fast-changing landscape in data science, it is hard to systematically categorize its tools and techniques. We review here some of them.

Map-Reduce is a framework used for massive parallel tasks. This works well when the data-sets do not involve a lot of internal correlation. This does not seem to be the case for digital evidence in general but a task like file fragment classification is suited to be modelled in aMap-Reduce paradigm. Attribution of file fragments – coming from a filesystem image or from unallocated space – to specific file types is a common task in forensics: machine learning classification algorithms – e.g. logistic regression, support vector machines – can be adapted toM-R if the analyst forgoes the possible correlations among single fragments. A combined approach where a classification algorithm is combined for instance with a decision tree method probably would yeld higher accuracy.

Decision trees and random forests are fruitfully brought to bear in fraud detection software, where the objective is to find in a vast dataset the statistical outliers – in this case anomalous transactions, or in another application, anomalous browsing behaviour.

In audio forensics unsupervised learning techniques under the general definition of “blind signal separation” give good results in separating two superimposed speakers or a voice from background noise. They rely on mathematical underpinning to find, among possible solutions, the least correlated signals.

In image forensics again classification techniques are useful to automatically review big sets of hundreds or thousands of image files, for instance to separate suspect images from the rest.

Neural Networks are suited for complex patter recognition in network forensics. A supervised approach is used, where successive snapshots of the file system are used to train the network to recognize normal behaviour of an application. After the event the system can be used to automatically build an execution timeline on a forensic image of a filesystem. [KhCY07] Neural Networks have also been used to analyse network traffic but in this case the results still do not present high levels of accuracy.

Natural Language Processing (NLP) techniques, including Bayesian classifiers and unsupervised algorithms for clustering like k-means, has been successfully employed for authorship verification or classification of large bodies of unstructured texts, emails in particular.

4 Conclusion

The challenges of big data evidence already at present highlight the necessity of revising tenets and procedures firmly established in digital forensics. New validation procedures, analysts’ training, and analysis workflow shall be needed in order to confront the mutated landscape. Furthermore, few forensic tools implement for instance machine learning algorithms or, from the other side, most machine learning tools and libraries are not suitable and/or validated for forensic work, so there still exists a wide space for development of innovative tools leveraging machine learning methods.

References

[BBC+08] Barreno, M. et al.: “Open Problems in the Security of Learning”. In: D. Balfanzand J. Staddon, eds., AISec, ACM, 2008, p.19-26
[FBI08] FBI: “RCFL Program Annual Report for Fiscal Year 2008”, FBI 2008. http://www.fbi.gov/news/stories/2009/august/rcfls_081809
[FBI10] FBI: “RCFL Program Annual Report fir Fiscal Year 2010”, FBI 2010.
[ISAC13] ISACA: “What Is Big Data and What Does It Have to Do with IT Audit?”,ISACA Journal, 2013, p.23-25
[ISO12] ISO/IEC 27037 International Standard
[KhCY07] Khan, M. and Chatwin, C. and Young, R.: “A framework for post-event timelinereconstruction using neural networks” Digital Investigation 4, 2007
[Pear01] Pearson, G.: “A Road Map for Digital Forensic Research”. In: Report fromDFRWS 2001, First Digital Forensic Research Workshop, 2001.
[Vari09] Varian, Hal in: “The McKinsey Quarterly”, Jan 2009

About the Author

Alessandro Guarino is a senior Information Security professional and independent researcher. He is the founder and principal consultant of StudioAG, a consultancy firm based in Italy and active since 2000, serving clients both in the private and public sector and providing cybersecurity, data protection and compliance consulting services. He is also a digital forensics analyst and consultant, as well as expert witness in Court. He holds an M.Sc in Industrial Engineering and a B.Sc. in economics, with a focus on Information Security Economics. He is an ISO active expert in JTC 1/SC 27 (IT Security Techniques committee) and contributed in particular to the development of cybersecurity and digital investigation standards. He represents Italy in the CEN-CENELEC Cybersecurity Focus Group and ETSI TC CYBER. He is the chair of the recently formed CEN/CENELEC TC 8 “Privacy management in products and services”. As an independent researcher, he delivered presentations at international conferences and published several peer-reviewed papers.

Find out more and get in touch with the author at StudioAG.

by Alessandro Guarino, StudioAG Abstract Digital Forensics, as a science and part of the forensic sciences, is facing new challenges that may well render established models and practices obsolete. The dimensions of potential digital evidence supports has grown exponentially, be it hard disks in desktops and laptops or solid state memories in mobile devices like smartphones […]

via Digital Forensics as a Big Data Challenge — Forensic Focus – Articles

Police cloned a Michigan murder victim’s fingerprint that unlocked his phone — Quartz

Cracking crime just got a lot more innovative.

Police and biometrics researchers at Michigan State University have successfully unlocked the smartphone of a murder victim by using a digitally enhanced print-out of his fingerprint.

Officers from the digital forensics and cyber-crime unit at MSU’s police department approached the college’s biometrics research lab last month, having become aware of the team’s research (pdf) on how printed fingerprints can spoof mobile-phone sensors.

Police had the fingerprints of the murder victim from a previous arrest, which they gave to the lab to 3D print in a bid to unlock the device—a Samsung Galaxy S6.

Unsure which finger was paired to the phone, the lab printed 2D and 3D replicas of all 10 of the slain man’s fingerprints. None of them unlocked the device, so the team then digitally enhanced the quality of prints by filling in the broken ridges and valleys. Rather than opting for a more expensive 3D model, they printed new 2D versions using a special conductive ink that would create an electrical circuit needed to spoof the phone sensor.

After multiple attempts—thanks to the device not requiring a passcode after a certain number of efforts—the team successfully unlocked the phone with one of the digitally enhanced 2D prints.

An MSU spokesperson told Quartz there were plans to print 3D models to test on other devices—there was no need to do so for the victim’s phone, as the 2D print was successful.

Professor Anil Jain, who led the research team at MSU, says the unlocking demonstrates “a weakness” in smartphones’ fingerprint authentication systems, and that he hoped it would “motivate phone developers to create advanced security measures for fingerprint liveness detection.” He added:

This shows that we need to understand what types of attacks are possible on fingerprint sensors, and biometrics in general, and how to fix them. If we don’t, the public will have less confidence in using biometrics. After all, biometric authentication was introduced in consumer devices to improve security.

According to MSU, this is the first time law enforcement has used such technology as part of an ongoing investigation. A spokesperson said the lead detective “even contacted the company that was asked to help with [unlocking] the San Bernardino shooter’s phone and he kept getting the same answer: can’t do it, the tech doesn’t exist. Well, the tech exists now!”

In a statement, Samsung said:

We are aware of the research from Michigan State University, but would like to remind users that it takes special equipment, supplies and conditions to simulate a person’s fingerprint, including actual possession of the fingerprint owner’s phone, to unlock the device. If there is a potential vulnerability or a new method that challenges our efforts to ensure security at any time, we will respond to issues as quickly as possible to investigate and resolve the issue

Cracking crime just got a lot more innovative. Police and biometrics researchers at Michigan State University have successfully unlocked the smartphone of a murder victim by using a digitally enhanced print-out of his fingerprint. Officers from the digital forensics and cyber-crime unit at MSU’s police department approached the college’s biometrics research lab last month, having become […]

via Police cloned a Michigan murder victim’s fingerprint that unlocked his phone — Quartz

Run, hide, fight: how to survive an active shooter situation

Who is Stephen Paddock? Police say suspect responsible for deadliest shooting in US history

via Fox2 News:

At least 50 people were killed late Sunday night in a mass shooting during a concert on the Las Vegas Strip. Here’s what we know about Stephen Paddock, the man police identified as the shooter:

Paddock, 64, is from Mesquite, Nevada, authorities said. Police stormed his hotel room from which they believe he fired the shots on the 32nd floor of the Mandalay Bay Resort and Casino.  They say he had over 10 rifles when police found his body.  The believe he killed himself prior to entry.  He checked into the hotel on September 28th.

Paddock was apparently targeting a crowd of 30,000 people attending the Route 91 Harvest music festival below.  Police believe he killed himself prior to entry into the hotel room.

Police are also at his home in Mesquite, Nevada.  They are methodically investigating the property.  The Mesquite Police Department had no prior contact with him, according to spokesman Quinn Averett, nor had there been any calls to Paddock’s home in Mesquite, which is about 80 miles northeast of Las Vegas. Officials did not know how long he had been living in the area.

This mass-shooting is not yet considered an act of terrorism.  Police are looking into a motive for the shooting before they can call it an act of terror.

So far, the massacre has no known link to overseas terrorism or terror groups, a US official with knowledge of the case said.

And a woman described as a “person of interest” after the attack is not believed to be involved in the shooting, police said in a statement.

“Marilou Danley is no longer being sought out as a person of interest,” the Las Vegas Metropolitan Police Department said. “LVMPD detectives have made contact with her and do not believe she is involved with the shooting on the strip.”

The suspect:

• Police have identified the shooter as Stephen Paddock, a 64-year-old man. He was earlier described as a “local resident.”

• Officers said they engaged the suspect at the Mandalay Bay hotel, and he was killed.

• Police do not believe there are additional shooters.

Casualties:

• Police report there are now at least 50 dead and some 200 injured, making this the deadliest shooting in modern US history. The 2016 Pulse nightclub shooting in Orlando, Florida, was previously the deadliest, with 49 killed.

• Two off-duty Las Vegas police officers were killed in the shooting, Sheriff Joseph Lombardo said at a news conference.

• Two other officers responding to the scene were wounded, the sheriff said. One of them is in critical condition.

Investigation:

• Police said they are confident they have located Marilou Danley, who was traveling with the suspect. She had been sought for questioning in connection with the shooting. She is not named as a suspect.

• Police also said they have located two vehicles they were searching for: a Hyundai Tucson Nevada with a Nevada plate, and a Chrysler Pacifica Touring with a Nevada plate.

• Police are urging patience: “I think it’s very important that you understand this investigation is going to be long and contracted before we get to the bottom of everything associated with it,” Sheriff Lombardo said.

How shooting unfolded:

• Just after 10 p.m. Sunday local time (1 a.m. ET Monday) the Route 91 Harvest Festival — a country music concert — was interrupted by the sound of gunfire, witnesses said.

• Police said the gunman fired on the crowd of about 30,000 people from the 32nd floor of the Mandalay Bay hotel, several hundred feet southwest of the concert grounds.

• Country music singer Jason Aldean was performing when the gunshots began, according to eyewitness cell phone video.

• “The gunshots lasted for 10 to 15 minutes. It didn’t stop,” said eyewitness Rachel de Kerf.

Reaction:

• President Trump tweeted, “My warmest condolences and sympathies to the victims and families of the terrible Las Vegas shooting. God bless you!”

• Las Vegas Airport diverts two dozen flights due to the shooting. Travelers are being urged to check with their airlines for flight status.

• Performer Jason Aldean released a statement that said: “Tonight has been beyond horrific.” On Instagram, Aldean said that he and his crew were safe.

 

After a deadly mass shooting in Las Vegas, local security experts are sharing advice on how to survive an active shooter situation.

A gunman opened fire on a crowd on the Las Vegas strip Sunday night, killing at least 58 and injuring hundreds more.

The best advice from law enforcement in an active shooter situation: run, hide, or fight.

If possible, experts say the best way is to run away from the threat. Always try to escape and evacuate, even if others are insisting on staying.

However, in certain situations it may be better to remain in place and try to avoid detection.

The last option, though the least preferable, is to fight the shooter with whatever means necessary.

In August, the Virginia Beach Police Department’s Crime Prevention Unit provided it’s Active Threat Citizen Defense in a public setting for the first time.

Master Police Officer David Nieves talked to News 3 after the training about surviving an active threat situation.

“You’ve got three choices. You either need to run, hide or fight. You just need to keep your head about yourself and understand that you only have a few seconds to understand what you’re going to do. You better have a plan before you need that plan because there are no seconds, you aren’t going to have time to make a plan,” he explained.

Experts say it’s also important to remain aware of your surroundings when in public.

“Things can happen anywhere. We don’t want [people] to have the mindset that it will never happen here. It will never happen to me. If you have that mindset then you’ve already lost,” MPO Nieves stated.

Police are searching for a woman named Marilou Danley who was traveling with the suspect, Lombardo said. He described Danley as an Asian woman, 4 ft 11 inches tall and 111 pounds. “We have not located her at this time and we are interested in talking to her,” he said.

Related: 

Class teaches how to survive an active shooting situation

Mass casualty drill takes place in Norfolk in preparation for the worst

In an active shooter situation, don’t just stand there…

This is how the FBI says civilians should react in an active shooter situation

via Latest updates: 58 killed, 515 hurt in Las Vegas Strip massacre — WTKR.com

Witness: Man Was Forced to Participate in 3 Slayings to ‘Dirty His Hands’ — TIME

Three people were strangled or smothered to death in a Kansas drug home over a rape allegation and one of the suspects was forced to participate to save his life, according to court testimony. The details about the case were revealed during a preliminary hearing that ended Wednesday with Shawnee County District Judge Nancy Parrish…

via Witness: Man Was Forced to Participate in 3 Slayings to ‘Dirty His Hands’ — TIME

This day in history. Girl raped, arms severed, and thrown from cliff survives

September 29, 1978Image result for lawrence singleton mary vincent
Berkeley, California 
Lawrence Singleton picks up 15-year-old Mary Vincent as she hitchhikes, raped her, cuts off her forearms with a hatchet, and throws her from a 30 foot cliff

Vincent was able to pull herself, naked, to safety and survived her attack. By the time Singleton was on trial, Vincent had prosthetic arms. Her testimony was vital to his conviction, though he was only sentenced to 14 years in prison, the maximum allowed by California state law at that time.

Singleton was paroled after 8 years and made several unsuccessful attempts to find a place to live in California. Each attempt was met by protestors and picketers. During one attempt, armed guards tried to escort Singleton to his new residence, another ended with Singleton escorted away while wearing a bulletproof vest. Eventually, Singleton moved to his home state of Florida.

He lived a relatively peaceful life there, though he was arrested twice in 1990 for theft, once for a $10 disposable camera, and once for a $3 hat. However, in 1997 Singleton murdered a woman, Roxanne Hayes, in his home. According to his testimony, Singleton invited Hayes to his home, paying her $20 for oral sex. Afterwards, Hayes became enraged and threatened to decapitate Singleton. The two struggled over the knife and, in the process, Hayes was accidentally stabbed 7 times in the face, chest, and stomach. He also testified that Hayes did not make any noises during each of the stabbing injuries.

At the trial for Hayes’ murder, Vincent once again testified against Singleton about her attack at trial. Singleton was sentenced to death but died on death row before his sentence could be carried out. Vincent’s attack changed state legislature regarding those who employ torture during their crimes, bumping the sentence from a maximum of 14 years to a term of 25 years to life. Singleton never admitted his guilt and went so far as to call Vincent a “ten dollar whore.”

OJ Simpson could be released Monday — CW33 NewsFix

NEVADA – The Juice could soon be loose. O.J. Simpson could be released from prison on Monday. Simpson has been behind bars in Nevada for the past nine years after being convicted of armed robbery and kidnapping. In July, a parole board ruled the former NFL player, movie star, and sportscaster would be eligible for…

via OJ Simpson could be released Monday — CW33 NewsFix

The Top Five Computer Forensic Tools — Cyber Incision

Forensic tools are something that are required to be updated on a regular basis. Whether because of patches, new hardware, or just a changing technological landscape, tools must be maintained in order to remain relevant. The ongoing support is just one of the reasons that the tools discussed in this article are the most used […]

via The Top Five Computer Forensic Tools — Cyber Incision

CHFI v9 Certified Hacking Forensic Investigator Certification — Cyber Incision

This certification is offered by EC-Council who claims that the average salary for CHFI certification holders is between $85,000 and $120,000. Sounds great right? Prep: Took a course of computer forensics, used Skillset.com to study for the exam and it is telling me that I am doing well enough to pass. Am I ready? After […]

via CHFI v9 Certified Hacking Forensic Investigator Certification — Cyber Incision

It was declared as ‘dishwashing liquid.’ It was really 4,020 litres of an MDMA precursor drug —

The Canada Border Services Agency (CBSA) seized over 4,000 litres of “dishwashing liquid” in Vancouver last year. Only, it wasn’t dishwashing liquid. It was MDP-2-P, a precursor used in the production of ecstasy and MDMA. Coverage of drug seizures on Globalnews.ca: The seizure happened when border services officers with the CBSA processed a container from…

via It was declared as ‘dishwashing liquid.’ It was really 4,020 litres of an MDMA precursor drug —