Federal Forensics Group
Federal Forensics Group
Forensic Computer Investigations and Analysis
Federal Forensics Group
Company News
Using Keywords To Unlock Your Case
December 11th, 2009

If you’re working in litigation, I’m sure you’ve frequently wondered how to get your vendor to conduct the most effective keyword searches and not break the bank. How can you find information that might be critical to the case? We’ve learned that keyword searching is an art as much as it is a science. Every project has some kind of resource limitation, so we have developed search strategies to make the most of real-life budgets, time and computing power.

Keyword searches for a typical e-discovery production yield more predictable results because the searches are conducted on complete documents and files that remain intact on the system. However, many of the cases we work on involve data that has been deleted, requiring computer forensic techniques to recover. Simply searching the ‘unallocated space’ of the hard drive (where deleted documents reside) can be helpful, but often retrieves far too much information to be useful. This is because the data is no longer organized as individual files. It’s like hunting through a land fill in search of a penny.

Let’s look at a sample case involving Bill Smith. Bill Smith works for LP Corporation and is suspected of embezzling funds.  Counsel requests information such as Office documents, Acrobat files, emails, and web activity. An initial search for keywords such as “Smith”, “LP Corporation”, and “bill@lpcorporation” would return several hundred thousand hits when run across deleted and regular files. If we limit the search to only saved files, valuable information may never be found. However, when searching the ‘unallocated’ part of the hard drive we might see hundreds of thousands hits -  too many to review. In Bill Smith’s case, we have 678,354 hits that might represent deleted documents, fragments of documents, emails and web activity. This data is all in unallocated space and can only be retrieved using forensic techniques.

Many folks simply ‘carve’ through unallocated space to resurrect any dead files. This can result in a high number of corrupted or irrelevant hits. How do we avoid this problem? We use keywords as we’re recovering deleted files. This technique provides us with live files that contain relevant keywords. These are now much easier to search than the land fill of unallocated files.

These live files can then be loaded into a forensic application. They are much easier to deal with and we can run additional searches on them producing information that may have been missed on the first pass. We keep searching and filtering down by relevant criteria until we come closer to finding the needle in the haystack. For example, we might search all the documents containing Bill Smith,from that set, we may eliminate all those that don’t contain relevancy to embezzlement. Reducing the search criteria further will reduce our hits so that the original 678,354 hits are now 1,200.

By only restoring deleted information that contains relevant keywords, we dramatically reduce the amount of work performed. By turning deleted information into live files, we can then easily search them and filter criteria yielding a compact, highly relevant set of data. This technique allows us to work more efficiently and save valuable computing and financial resources.

Pirates Get a Taste of Microsoft COFEE. Microsoft’s Computer Online Forensic Evidence Extractor (COFEE) software, which helps law enforcement officials grab data from password protected or encrypted sources, has leaked.

Facebook Privacy Changes Draw Mixed Reviews. Facebook’s revamped privacy settings will push more user data onto the Internet and, in some cases, make privacy protection harder for Facebook users, digital civil liberties experts said.

Hackers Pillage Jailbroken iPhones. Hackers are plundering personal data from jailbroken iPhones using the tactic demonstrated last week by an Australian programmer’s self-described “prank,” researchers said today.

Social Networking Explodes and The Law Will Follow. Inevitably, we will see lawsuits where people allege that they have been defamed by false information about them posted on social networking pages.

Crafting a More Effective Keyword Search Despite the insight of Facciola, Grimm and Peck, lawyers still don’t know what to do when it comes to effective, defensible keyword search.

Police say hacker stole phone time from AT&T, others The investigation began in May 2007 following a tip-off from the FBI that a group of hackers based in the Philippines had violated the IT security of major international phone companies.

Don’t Mess With System Metadata. Sometimes a computer holds evidence, and sometimes a computer is evidence. It’s a distinction with a difference when deciding whether to act in ways that will stomp on data essential to computer forensic examination.

How Facebook mucks up office life. Managing a workforce is already a challenging job; now Facebook and other social networks raise a host of sticky new situations.

Linux group seeks to discredit Microsoft patents in TomTom case. A Linux group is hoping to discredit three Microsoft Corp. patents that were at the heart of the software vendor’s recent lawsuit against GPS device maker TomTom NV.

Laid-off workers as data thieves? A growing crime wave where laid-off workers exact vengeance on their former employers by walking out the door with sensitive customer data and other proprietary information.

As Jurors Turn to Web, Mistrials Are Popping Up. The use of BlackBerrys and iPhones by jurors gathering and sending out information about cases is wreaking havoc on trials around the country, upending deliberations and infuriating judges.

e-Discovery Rules - Interpreting ESI from Federal to State Courts. Is it email? Certainly, but what about the email stored on inaccessible backup tapes or legacy systems from 15 years ago? What about voicemail, instant messages or random access memory (RAM)?

 
Federal Forensics Group
5777 W. Century Blvd., Ste. 1015, Los Angeles, CA 90045 •  310.318.1073 direct  310.388.1523 fax
Home | Services | Process | Resources | Contact