01.model Forensik
01.model Forensik
Evidence Form
Label everything, start carving evidence
Log make, model, and serial numbers
Investigator activity log and records
Hardware: motherboards, power, RAM, printer, scanner, fax, mobile devices
OS/Apps: Microsoft, Red Hat, UNIX, Forensic Tools, MS Office, HTML etc.
Chain of Custody
Who, What, Where, When, Why, How
Copy stays with evidence at all times
Always make copies, never work on original
AKUISISI BUKTI ELEKTRONIK #2
CONTOH PROSES IMAGING
To take an exact copy including deleted files and areas of the hard drive that
a normal backup would not copy
Never boot off of the hard drive
Use write protection software to protect the original evidence (source). Make
a copy of the original evidence and do all work off of the copy
Document all aspects of the hard drive
Tag and store original evidence
Best evidence is original evidence
MEDIA TO MEDIA IMAGING
ENCASE EVIDENCE FILE FORMAT (.E01B ATAU .E01X), RAW IMAGE FILE FORMAT
(.DD, .RAW, .IMG), AFF, AFF4, DAN LOGICAL EVIDENCE FILE TERGANTUNG
JENIS/MERK APLIKASI DAN/ATAU PERANGKAT YANG DIGUNAKAN (OPEN
SOURCE/PROPRIETARY).
SEMUA FORMAT STANDAR HARUS DAPAT SALING MENGENAL (INTEROPARIBILITY).
DI DALAM FILE IMAGE TERSIMPAN DAN TERPETAKAN STRUKTUR FILE SYSTEM
TERMASUK INFORMASI PADA BOOT SECTOR DAN AREA YANG RUSAK. SETIAP
CLUSTER DISALIN SETIAP BIT-NYA DAN TERMASUK BERKAS YANG RUSAK (TIDAK
TERBACA), PERNAH TERHAPUS/TERPOTONG/TERTINDAS OLEH BERKAS BARU.
INI MEMUNGKINKAN PROSES RECOVERY DATA APABILA DIPERLUKAN UNTUK
MEMULIHKAN BERKAS YANG RUSAK, PERNAH TERHAPUS ATAU MEREKONSTRUKSI
AREA YANG TERPOTONG/TERTINDAS OLEH BERKAS BARU SEHINGGA DAPAT
DIPEROLEH/DIBACA KEMBALI.
DEVICE TO IMAGE
KERAGAMAN INTERFACE
COPY N1
TARGET EVIDENCE
WORKING COPY 1
TARGETED
/ SPLICE
MASTER COPY
Email. Temporary Files, Recycle Bin, Info File Fragments, Recent Link Files,
Spool (printed) files, Internet History (INDEX.DAT), Registry
Unallocated Space-free space on the hard drive
File Slack-free space between the end of the logical file and the end of
physical file (cluster)
RAM Slack-free space between the end of the logical file and the end of the
containing sector
Sector-the smallest group that can be accessed on the disk. A group of disk
sectors as assigned by the operating system are known as clusters
TERIMA KASIH!
ID-SIRTII/CC
MENARA RAVINDO LT. 17
KEBON SIRIH RAYA 75
JAKARTA PUSAT, 10340
TELEPON +62 21 3192 5551 ; FAX +62 21 3193 5556
info@idsirtii.or.id ; www.idsirtii.or.id