Leveraging Decentralization to Extend the Digital Evidence Acquisition Window: Case Study on Bittorrent Sync

<span style="color: #000000;">File synchronization services such as </span><span style="color: #000000;">Dropbox</span><span style="color: #000000;">, Google Drive, Microsoft </span><span style="color: #000000;">OneDri...

Full description

Bibliographic Details
Main Authors: Mark Scanlon, Jason Farina, Nhien An Le Khac, Tahar Kechadi
Format: Article
Language:English
Published: Association of Digital Forensics, Security and Law 2014-09-01
Series:Journal of Digital Forensics, Security and Law
Subjects:
Online Access:http://ojs.jdfsl.org/index.php/jdfsl/article/view/266
id doaj-349d022baf8c4ca5a42cb8e013289dd9
record_format Article
spelling doaj-349d022baf8c4ca5a42cb8e013289dd92020-11-25T01:10:23ZengAssociation of Digital Forensics, Security and LawJournal of Digital Forensics, Security and Law1558-72151558-72232014-09-019285100172Leveraging Decentralization to Extend the Digital Evidence Acquisition Window: Case Study on Bittorrent SyncMark Scanlon0Jason Farina1Nhien An Le Khac2Tahar Kechadi3School of Computer Science & Informatics University College DublinSchool of Computer Science & Informatics University College DublinSchool of Computer Science & Informatics University College DublinSchool of Computer Science & Informatics University College Dublin<span style="color: #000000;">File synchronization services such as </span><span style="color: #000000;">Dropbox</span><span style="color: #000000;">, Google Drive, Microsoft </span><span style="color: #000000;">OneDrive</span><span style="color: #000000;">, Apple </span><span style="color: #000000;">iCloud</span><span style="color: #000000;">, etc., are becoming increasingly popular in today's always-connected world. A popular alternative to the aforementioned services is </span><span style="color: #000000;">BitTorrent</span><span style="color: #000000;"> Sync. This is a decentralized/cloudless file synchronization service and is gaining significant popularity among Internet users with privacy concerns over where their data is stored and who has the ability to access it. The focus of this paper is the remote recovery of digital evidence pertaining to files identified as being accessed or stored on a suspect's computer or mobile device. A methodology for the identification, investigation, recovery and verification of such remote digital evidence is outlined. Finally, a proof-of-concept remote evidence recovery from </span><span style="color: #000000;">BitTorrent</span><span style="color: #000000;"> Sync shared folder highlighting a number of potential scenarios for the recovery and verification of such evidence.</span>http://ojs.jdfsl.org/index.php/jdfsl/article/view/266digital evidenceremote evidence recoveryBitTorrent syncmobile device forensics
collection DOAJ
language English
format Article
sources DOAJ
author Mark Scanlon
Jason Farina
Nhien An Le Khac
Tahar Kechadi
spellingShingle Mark Scanlon
Jason Farina
Nhien An Le Khac
Tahar Kechadi
Leveraging Decentralization to Extend the Digital Evidence Acquisition Window: Case Study on Bittorrent Sync
Journal of Digital Forensics, Security and Law
digital evidence
remote evidence recovery
BitTorrent sync
mobile device forensics
author_facet Mark Scanlon
Jason Farina
Nhien An Le Khac
Tahar Kechadi
author_sort Mark Scanlon
title Leveraging Decentralization to Extend the Digital Evidence Acquisition Window: Case Study on Bittorrent Sync
title_short Leveraging Decentralization to Extend the Digital Evidence Acquisition Window: Case Study on Bittorrent Sync
title_full Leveraging Decentralization to Extend the Digital Evidence Acquisition Window: Case Study on Bittorrent Sync
title_fullStr Leveraging Decentralization to Extend the Digital Evidence Acquisition Window: Case Study on Bittorrent Sync
title_full_unstemmed Leveraging Decentralization to Extend the Digital Evidence Acquisition Window: Case Study on Bittorrent Sync
title_sort leveraging decentralization to extend the digital evidence acquisition window: case study on bittorrent sync
publisher Association of Digital Forensics, Security and Law
series Journal of Digital Forensics, Security and Law
issn 1558-7215
1558-7223
publishDate 2014-09-01
description <span style="color: #000000;">File synchronization services such as </span><span style="color: #000000;">Dropbox</span><span style="color: #000000;">, Google Drive, Microsoft </span><span style="color: #000000;">OneDrive</span><span style="color: #000000;">, Apple </span><span style="color: #000000;">iCloud</span><span style="color: #000000;">, etc., are becoming increasingly popular in today's always-connected world. A popular alternative to the aforementioned services is </span><span style="color: #000000;">BitTorrent</span><span style="color: #000000;"> Sync. This is a decentralized/cloudless file synchronization service and is gaining significant popularity among Internet users with privacy concerns over where their data is stored and who has the ability to access it. The focus of this paper is the remote recovery of digital evidence pertaining to files identified as being accessed or stored on a suspect's computer or mobile device. A methodology for the identification, investigation, recovery and verification of such remote digital evidence is outlined. Finally, a proof-of-concept remote evidence recovery from </span><span style="color: #000000;">BitTorrent</span><span style="color: #000000;"> Sync shared folder highlighting a number of potential scenarios for the recovery and verification of such evidence.</span>
topic digital evidence
remote evidence recovery
BitTorrent sync
mobile device forensics
url http://ojs.jdfsl.org/index.php/jdfsl/article/view/266
work_keys_str_mv AT markscanlon leveragingdecentralizationtoextendthedigitalevidenceacquisitionwindowcasestudyonbittorrentsync
AT jasonfarina leveragingdecentralizationtoextendthedigitalevidenceacquisitionwindowcasestudyonbittorrentsync
AT nhienanlekhac leveragingdecentralizationtoextendthedigitalevidenceacquisitionwindowcasestudyonbittorrentsync
AT taharkechadi leveragingdecentralizationtoextendthedigitalevidenceacquisitionwindowcasestudyonbittorrentsync
_version_ 1725175048050835456