Leveraging Decentralization to Extend the Digital Evidence Acquisition Window: Case Study on Bittorrent Sync

<span style="color: #000000;">File synchronization services such as </span><span style="color: #000000;">Dropbox</span><span style="color: #000000;">, Google Drive, Microsoft </span><span style="color: #000000;">OneDri...

Full description

Bibliographic Details
Main Authors: Mark Scanlon, Jason Farina, Nhien An Le Khac, Tahar Kechadi
Format: Article
Language:English
Published: Association of Digital Forensics, Security and Law 2014-09-01
Series:Journal of Digital Forensics, Security and Law
Subjects:
Online Access:http://ojs.jdfsl.org/index.php/jdfsl/article/view/266
_version_ 1818027560756314112
author Mark Scanlon
Jason Farina
Nhien An Le Khac
Tahar Kechadi
author_facet Mark Scanlon
Jason Farina
Nhien An Le Khac
Tahar Kechadi
author_sort Mark Scanlon
collection DOAJ
description <span style="color: #000000;">File synchronization services such as </span><span style="color: #000000;">Dropbox</span><span style="color: #000000;">, Google Drive, Microsoft </span><span style="color: #000000;">OneDrive</span><span style="color: #000000;">, Apple </span><span style="color: #000000;">iCloud</span><span style="color: #000000;">, etc., are becoming increasingly popular in today's always-connected world. A popular alternative to the aforementioned services is </span><span style="color: #000000;">BitTorrent</span><span style="color: #000000;"> Sync. This is a decentralized/cloudless file synchronization service and is gaining significant popularity among Internet users with privacy concerns over where their data is stored and who has the ability to access it. The focus of this paper is the remote recovery of digital evidence pertaining to files identified as being accessed or stored on a suspect's computer or mobile device. A methodology for the identification, investigation, recovery and verification of such remote digital evidence is outlined. Finally, a proof-of-concept remote evidence recovery from </span><span style="color: #000000;">BitTorrent</span><span style="color: #000000;"> Sync shared folder highlighting a number of potential scenarios for the recovery and verification of such evidence.</span>
first_indexed 2024-12-10T04:49:51Z
format Article
id doaj.art-349d022baf8c4ca5a42cb8e013289dd9
institution Directory Open Access Journal
issn 1558-7215
1558-7223
language English
last_indexed 2024-12-10T04:49:51Z
publishDate 2014-09-01
publisher Association of Digital Forensics, Security and Law
record_format Article
series Journal of Digital Forensics, Security and Law
spelling doaj.art-349d022baf8c4ca5a42cb8e013289dd92022-12-22T02:01:39ZengAssociation of Digital Forensics, Security and LawJournal of Digital Forensics, Security and Law1558-72151558-72232014-09-019285100172Leveraging Decentralization to Extend the Digital Evidence Acquisition Window: Case Study on Bittorrent SyncMark Scanlon0Jason Farina1Nhien An Le Khac2Tahar Kechadi3School of Computer Science & Informatics University College DublinSchool of Computer Science & Informatics University College DublinSchool of Computer Science & Informatics University College DublinSchool of Computer Science & Informatics University College Dublin<span style="color: #000000;">File synchronization services such as </span><span style="color: #000000;">Dropbox</span><span style="color: #000000;">, Google Drive, Microsoft </span><span style="color: #000000;">OneDrive</span><span style="color: #000000;">, Apple </span><span style="color: #000000;">iCloud</span><span style="color: #000000;">, etc., are becoming increasingly popular in today's always-connected world. A popular alternative to the aforementioned services is </span><span style="color: #000000;">BitTorrent</span><span style="color: #000000;"> Sync. This is a decentralized/cloudless file synchronization service and is gaining significant popularity among Internet users with privacy concerns over where their data is stored and who has the ability to access it. The focus of this paper is the remote recovery of digital evidence pertaining to files identified as being accessed or stored on a suspect's computer or mobile device. A methodology for the identification, investigation, recovery and verification of such remote digital evidence is outlined. Finally, a proof-of-concept remote evidence recovery from </span><span style="color: #000000;">BitTorrent</span><span style="color: #000000;"> Sync shared folder highlighting a number of potential scenarios for the recovery and verification of such evidence.</span>http://ojs.jdfsl.org/index.php/jdfsl/article/view/266digital evidenceremote evidence recoveryBitTorrent syncmobile device forensics
spellingShingle Mark Scanlon
Jason Farina
Nhien An Le Khac
Tahar Kechadi
Leveraging Decentralization to Extend the Digital Evidence Acquisition Window: Case Study on Bittorrent Sync
Journal of Digital Forensics, Security and Law
digital evidence
remote evidence recovery
BitTorrent sync
mobile device forensics
title Leveraging Decentralization to Extend the Digital Evidence Acquisition Window: Case Study on Bittorrent Sync
title_full Leveraging Decentralization to Extend the Digital Evidence Acquisition Window: Case Study on Bittorrent Sync
title_fullStr Leveraging Decentralization to Extend the Digital Evidence Acquisition Window: Case Study on Bittorrent Sync
title_full_unstemmed Leveraging Decentralization to Extend the Digital Evidence Acquisition Window: Case Study on Bittorrent Sync
title_short Leveraging Decentralization to Extend the Digital Evidence Acquisition Window: Case Study on Bittorrent Sync
title_sort leveraging decentralization to extend the digital evidence acquisition window case study on bittorrent sync
topic digital evidence
remote evidence recovery
BitTorrent sync
mobile device forensics
url http://ojs.jdfsl.org/index.php/jdfsl/article/view/266
work_keys_str_mv AT markscanlon leveragingdecentralizationtoextendthedigitalevidenceacquisitionwindowcasestudyonbittorrentsync
AT jasonfarina leveragingdecentralizationtoextendthedigitalevidenceacquisitionwindowcasestudyonbittorrentsync
AT nhienanlekhac leveragingdecentralizationtoextendthedigitalevidenceacquisitionwindowcasestudyonbittorrentsync
AT taharkechadi leveragingdecentralizationtoextendthedigitalevidenceacquisitionwindowcasestudyonbittorrentsync