• Title/Summary/Keyword: Forensic Evidence

Search Result 230, Processing Time 0.13 seconds

Development Comparative Experiments of Blood Prints Enhancement Reagent (Fuchsin Acid, Eosin-Y, Acid Yellow 7) (배경에 따른 혈문증강 시약(Fuchsin Acid, Eosin-Y, Acid Yellow 7) 적용의 현출도 비교실험)

  • Kim, A-Ram;Kim, Woo-Joong;Jung, Hey-Young
    • The Journal of the Korea Contents Association
    • /
    • v.13 no.6
    • /
    • pp.194-201
    • /
    • 2013
  • In serious crimes, bloody fingerprints are crucial evidence that make links between suspects and victims. There have been many studies related to bloody fingerprints for a long time. There are many comparative studies for effectiveness of Acid Fuchsin and Acid Yellow 7, but nothing about Eosin-Y in this country. Acid Fuchsin is a useful reagent that has unique red color distinguishing from light colored background. but it is useless on dark surfaces. In order to make it visible, we should use BVDA Gel lifters. On the contrary this, Acid Yellow 7 makes stronger fluorescence on a dark background. In this study, we got the conclusion that Eosin-Y is more useful than the others not only on dark background but also light background.

A File Recovery Technique for Digital Forensics on NAND Flash Memory (NAND 플래시 메모리에서 디지털 포렌식을 위한 파일 복구기법)

  • Shin, Myung-Sub;Park, Dong-Joo
    • Journal of KIISE:Databases
    • /
    • v.37 no.6
    • /
    • pp.292-299
    • /
    • 2010
  • Recently, as flash memory is used as digital storage devices, necessity for digital forensics is growing in a flash memory area for digital evidence analysis. For this purpose, it is important to recover crashed files stored on flash memory efficiently. However, it is inefficient to apply the hard disk based file recovery techniques to flash memory, since hard disk and flash memory have different characteristics, especially flash memory being unable to in-place update. In this paper, we propose a flash-aware file recovery technique for digital forensics. First, we propose an efficient search technique to find all crashed files. This uses meta-data maintained by FTL(Flash Translation Layer) which is responsible for write operation in flash memory. Second, we advise an efficient recovery technique to recover a crashed file which uses data location information of the mapping table in FTL. Through diverse experiments, we show that our file recovery technique outperforms the hard disk based technique.

Study on Adopting EDR Report for Traffic Accident Analysis (교통사고분석에서 EDR 기록정보의 채택에 관한 고찰)

  • Park, Jongjin;Park, Jeongman;Lee, Yeonsub
    • Journal of Auto-vehicle Safety Association
    • /
    • v.12 no.3
    • /
    • pp.52-60
    • /
    • 2020
  • Usage of EDR(Event Data Recorder) report for traffic accident analysis is currently increasing due to government regulation of EDR data release. Nevertheless, a lot of investigators simply adopt by comparing the number of ignition cycles(crash) at event to the number of ignition cycles(download) without an exact judgment whether event data occurred by this accident or not. In the EDR report, besides ignition cycles, there are many factors such as event record type, algorithm active(rear/rollover/side/frontal), time between events, event severity status(rollover/rear/right side/reft side/frontal), belt switch circuit status, driver/passenger pretensioner/air-bag deployment, PDOF(Principal Direction of Force) by ΔV to be able to decide whether or not to adopt. also the event data is considered enough to vehicle damaged state, accident situation at the scene of the accident. and there is described in "all data should be examined in conjunction with other available physical evidence from the vehicle and scene" in the CDR(Crash Data Retrieval) report. Therefore many investigators have to decide whether or not to adopt after they consider sufficiently to above factors when they are the traffic accident analysis and investigate the causes of a accident on the adopted event data. In this paper, we report to traffic accident investigators notable points and analysis methods on the basis of thousands of cases and the results of one's own experiment in NFS(National Forensic Service).

The study of bloody fingerprint enhancement on paper with chemical reagents (화학시약들을 이용한 지류에서 혈흔지문 증강에 관한 연구)

  • Lim, Seung;Kim, Im-Soon;Noh, Jong-Yun;Kim, Sang-Il;Yu, Je-Sul
    • Analytical Science and Technology
    • /
    • v.25 no.5
    • /
    • pp.284-291
    • /
    • 2012
  • Bloody fingerprint is a very important evidence. In this study, we confirmed the enhancement effects of ninhydrin, leucocrystal violet (LCV), fuchsin acid, iodine and dimethylaminocinnamaldehyde (DMAC) on bloody fingerprints which were deposited on paper. Bloody fingerprint were deposited on paper sequentially and used after drying at room temperature. If a ridge of bloody fingerprint was clear, ninhydrin and LCV was the most effective but was not good for invisible ridge. Fuchsin acid reagent dyed paper surface so that the contrast of enhanced bloody fingerprint was decreased. Although bloody fingerprint was enhanced with iodine reagent, but the developed color was very weak after reaction. We thought that the enhancement effect of iodine to bloody fingerprint was negligible. Also, the enhancement effect of DMAC reagent to relatively clear bloody fingerprint was not good. However, it was very effective to faint or invisible ridge. By washing with methanol, contrast of enhanced bloody fingerprint was increased.

Comparing Recoverability of Deleted Data According to Original Source Collection Methods on Microsoft SQL Server (Microsoft SQL Server의 원본 수집 방식에 따른 삭제 데이터의 복구 가능성 비교)

  • Shin, Jiho
    • Journal of the Korea Institute of Information Security & Cryptology
    • /
    • v.28 no.4
    • /
    • pp.859-868
    • /
    • 2018
  • Previous research related to recovering deleted data in database has been mainly based on transaction logs or detecting and recovering data using original source files by physical collection method. However there was a limit to apply if the transaction log does not exist in the server or it is not possible to collect the original source file because a database server owner does not permit stopping the database server because of their business loss or infringement at the scene. Therefore it is necessary to examine various collection methods and check the recoverability of the deleted data in order to handling the constraints of evidence collection situation. In this paper we have checked an experiment that the recoverability of deleted data in the original database source according to logical and physical collection methods on digital forensic investigation of Microsoft SQL Server database.

Generation of Forensic Evidence Data from Script (무선 WiGig 전송 연구)

  • Choi, Sang-hyeon;Park, Dea-woo
    • Proceedings of the Korean Institute of Information and Commucation Sciences Conference
    • /
    • 2017.10a
    • /
    • pp.356-359
    • /
    • 2017
  • According to the plan of operation of the Ministry of Education, IWB (Interactive White Board) was distributed to one or two classrooms per school. Therefore, instead of the overhead projector (OHP) and the screen, the visual presenter and the IWB replaced the role. However, the development speed of the imaging device and the display device could not keep up, and the utilization was often lowered. In this study, we study to obtain a high resolution image using the camera of smartphone. It uses WiGig(Wireless Gigabit) technology to transmit the acquired high-resolution images to IWB or large-screen TV without delay in wireless communication. In addition, while the smartphone camera is equipped with a lens of a wide field of view(FOV), the microscope lens can be used to magnify and magnify a specific portion of a smartphone 400 times. As s result of this study it will be used as active material for real-time 400 times magnification in education and research field.

  • PDF

Quantitative Analysis of Cancer-associated Gene Methylation Connected to Risk Factors in Korean Colorectal Cancer Patients

  • Kang, Ho-Jin;Kim, Eun-Jeong;Kim, Byoung-Gwon;You, Chang-Hun;Lee, Sang-Yong;Kim, Dong-Il;Hong, Young-Seoub
    • Journal of Preventive Medicine and Public Health
    • /
    • v.45 no.4
    • /
    • pp.251-258
    • /
    • 2012
  • Objectives: The purpose of this paper was to elucidate the potential methylation levels of adjacent normal and cancer tissues by comparing them with normal colorectal tissues, and to describe the correlations between the methylation and clinical parameters in Korean colorectal cancer (CRC) patients. Methods: Hypermethylation profiles of nine genes (RASSF1, APC, $p16^{INK4a}$, Twist1, E-cadherin, TIMP3, Smad4, COX2, and ABCB1) were examined with 100 sets of cancer tissues and 14 normal colorectal tissues. We determined the hypermethylation at a given level by a percent of methylation ratio value of 10 using quantitative methylation real-time polymerase chain reaction. Results: Nine genes' hypermethylation levels in Korean CRC patient tissues were increased more higher than normal colorectal tissues. However, the amounts of $p16^{INK4a}$ and E-cadherin gene hypermethylation in normal and CRC tissues were not significantly different nor did TIMP3 gene hypermethylation in adjacent normal and cancer tissues differ significantly. The hypermethylation of TIMP3, Ecadherin, ABCB1, and COX2 genes among other genes were abundantly found in normal colorectal tissues. The hypermethylation of nine genes' methylation in cancer tissues was not significantly associated with any clinical parameters. In Cohen's kappa test, it was moderately observed that RASSF1 was related with E-cadherin, and Smad4 with ABCB1 and COX2. Conclusions: This study provides evidence for different hypermethylation patterns of cancer-associated genes in normal and CRC tissues, which may serve as useful information on CRC cancer progression.

The Effect of Investigator's Belief about Veracity of Suspect on Distortions of Paper Records (수사관의 심증이 조서의 왜곡에 미치는 영향)

  • Lee, Hyoung Keun;Jo, Eunkyung;Yi, Mi Sun
    • Korean Journal of Forensic Psychology
    • /
    • v.11 no.3
    • /
    • pp.267-285
    • /
    • 2020
  • The Statement evidence is an important method of proof in the criminal investigation and trial. Under certain conditions set by Korean Criminal Procedure Law, paper records of interrogations are admissible in criminal courts. However, it is shown that distortions are ever-present in paper records. Therefore, this study attempted to examine the effect of the investigator's belief about the veracity of a suspect on distortions of paper records. Ninety police investigators were randomly allocated into one of the three conditions('guilty belief', 'innocent belief', 'neutral belief'), and all the investigators were then asked to document a paper record while watching a prefilmed interrogation interview of the crime. The results showed that (1) the investigator's belief had significant effects on distortions. (2) All groups did more commissions than omissions. (3) matters subject to interrogation also had significant effects on distortions. In the conclusion, implications and limitations of the study were disscussed.

  • PDF

Effects of Stress Coping Strategy, Previous History, and Parental Preparation on Children's Memory of a Stressful Event (아동의 스트레스 대처 전략과 사전 경험의 질적 특성 및 부모의 준비성 정도가 아동 기억의 신뢰성에 미치는 영향)

  • Seungjin Lee
    • Korean Journal of Culture and Social Issue
    • /
    • v.18 no.2
    • /
    • pp.215-234
    • /
    • 2012
  • The purpose of this study was to explore linkages between stress and a range of individual difference factors on children's memory for a potentially stressful event. Children (N=63) aged from 4 to 10 years, who undergone a minor dental operative procedure were evaluated. Overall, the results of this study replicated and extended previous findings of the related literature, providing some further evidence for a negative relation between stress and children's recall. More considerable variation in individual difference variables, in particular, children 's stress coping strategies, quality of previous experiences, amount of the advanced parental preparation were existed among the children, influencing the relation between the level of stress and children's remembering of a stressful event. Future inquiries for understanding theoretical, clinical, and forensic issues in children's remembering of a stressful event were discussed.

  • PDF

Decryption of KakaoTalk Database for macOS (macOS용 카카오톡 데이터베이스 복호화 방안)

  • Beomjun Park;Sangjin Lee
    • Journal of the Korea Institute of Information Security & Cryptology
    • /
    • v.33 no.5
    • /
    • pp.753-760
    • /
    • 2023
  • KakaoTalk has the highest market share among domestic messengers. As such, KakaoTalk's conversation content is an important evidence in digital forensics, and the conversation is stored in the form of an encrypted database on a user's device. In addition, macOS has the characteristic that it is difficult to access because the disk encryption function is basically activated. The decryption method of the KakaoTalk database for Windows has been studied, but the decryption method has not been studied for KakaoTalk for macOS. In this paper, research the decryption method of the KakaoTalk database for macOS and a way to Brute-Force plan using the characteristics of KakaoTalk's UserID and compare it with KakaoTalk for Windows to examine the commonalities and differences. The results of this paper are expected to be used to analyze users' actions and events when investigating crimes using macOS.