论文标题
零信任数字取证的情况
The case for Zero Trust Digital Forensics
论文作者
论文摘要
对于所有利益相关者,数字取证调查都必须产生可靠的结果,以确保该领域为全球追求正义提供积极贡献。这些调查的某些方面不可避免地取决于信任,但是并非总是明确考虑或进行严格评估。错误地将调查的特征视为受信任的特征可能会对调查结果的总体可靠性以及外部利益相关者对此的信心产生巨大损害。例如,可以通过对设备上留下的数字文物进行篡改来操纵数字犯罪现场,但最近的研究表明,检测出这种情况的努力很少见,并认为这会使数字取证调查受到不准确性指控的影响。在本文中,根据零信任的概念,考虑了一种新的数字取证方法,这是网络安全方面越来越流行的设计。零信任描述了从业者的心态和原则,从而消除了对网络组件的信任的依赖,而支持网络交互的动态验证。将提出对零信任数字取证的初步定义,然后考虑一个特定的示例,并考虑到如何将该策略应用于数字法医调查,以减轻篡改证据的特定风险。提出了零信任数字取证的定义,特别是它是调查人员采用的一种策略,即调查的每个方面都被认为是不可靠的,直到验证。将引入一个新的原则,即对数字文物的多方面验证,这些验证可以由希望在调查过程中采用零信任的数字取证策略的从业人员使用...
It is imperative for all stakeholders that digital forensics investigations produce reliable results to ensure the field delivers a positive contribution to the pursuit of justice across the globe. Some aspects of these investigations are inevitably contingent on trust, however this is not always explicitly considered or critically evaluated. Erroneously treating features of the investigation as trusted can be enormously damaging to the overall reliability of an investigations findings as well as the confidence that external stakeholders can have in it. As an example, digital crime scenes can be manipulated by tampering with the digital artefacts left on devices, yet recent studies have shown that efforts to detect occurrences of this are rare and argue that this leaves digital forensics investigations vulnerable to accusations of inaccuracy. In this paper a new approach to digital forensics is considered based on the concept of Zero Trust, an increasingly popular design in network security. Zero Trust describes the practitioner mindset and principles upon which the reliance on trust in network components is eliminated in favour of dynamic verification of network interactions. An initial definition of Zero Trust Digital Forensics will be proposed and then a specific example considered showing how this strategy can be applied to digital forensic investigations to mitigate against the specific risk of evidence tampering. A definition of Zero Trust Digital Forensics is proposed, specifically that it is a strategy adopted by investigators whereby each aspect of an investigation is assumed to be unreliable until verified. A new principle will be introduced, namely the multifaceted verification of digital artefacts that can be used by practitioners who wish to adopt a Zero Trust Digital Forensics strategy during their investigations...