Forensic Focus - Computer Forensics, Computer Forensic Training, Digital Forensics
LoginRegisterForumsPapersEducationGraduate RecruitmentReviewsInterviewsNewsletterJobsEventsBlog
Search Forensic Focus
Custom Search
Graduate Recruitment

computer forensics graduate jobs

Join, Subscribe, Share

Join newsletter

Join LinkedIn group

Follow on Twitter

Subscribe to news

Subscribe to forums

Subscribe to blog

Subscribe to tweets

Members' blogs

External feeds

Bookmark & share: Bookmark and Share

Main Menu
MY ACCOUNT
COMMUNITY
EMPLOYMENT
EDUCATION
RESOURCES
MISC
Computer Forensics Newsletter
Newsletter

You must be a
registered user
to receive our newsletter

Register Now!
Forensic Focus

Forensic Focus

Copy and paste the text below to insert the button displayed above on your site. Thanks for your support!

Computer Forensics Survey
Which of the following do you usually use for imaging evidence?




Results :: Polls

Votes: 34417
Comments: 0


Interview with Gene Spafford, CERIAS - 12/9/08


Forensic Focus: Gene, can you tell us a little bit about your background and how you came to work at CERIAS?

Gene Spafford: My academic PhD was work in reliable operating systems. I then did a post-doc in software testing, which I viewed as a follow-on to my work in reliability. During all that time I worked part-time as a system administrator and consultant. I was interested in computer & network security, but was told that it was not an area for an academic career unless I wanted to work in formal methods or cryptography.

Gene Spafford
Professor Gene Spafford

I joined the faculty at Purdue in 1987. In 1988, the Morris Worm and some computer viruses became news. So did some of Cliff Stoll's exploits. I found myself playing a role in all of those, as one of the few academics who was actually working hands-on with systems. So, I began to explore topics in applied computer security for my "day job" -- including forensics. (I actually helped solve a computer crime (of sorts) back in 1983, so I've been involved in the area for longer than my time at Purdue.)

In 1992, I established the COAST Laboratory at Purdue, to share research resources with a few other faculty interested in what I was doing. In 1998, I established CERIAS as a university-wide research center. I've been director ever since (or executive director).


Forensic Focus: One of CERIAS' research focus areas is "Incident Detection, Response, and Investigation" - can you give us some insight into current activities?

Gene Spafford: We have at least a half-dozen projects that fit under this title -- basically, things we do to detect & investigate incidents.

- The ADEPTS project is based on a knowledge engine that gathers remote data about system performance and attacks, then makes predictive decisions for reconfiguration and containment

- Work in the VIPER lab is being conducted on traceback of digital images and imaging to the devices that created them (think of tracing ransom notes back to typewriters).

- I'm involved in a project using process "coloring" to detect intrusions into systems, and help to narrow the focus onto those files and processes that were actually affected by the intrusion in some way.

- We have a group working on devising special forensic tools for small devices, such as PDAs and cell phones.

- We have a project involving profiling of computer criminals to help investigators decide where to look. This might also prove useful in screening against potential insider attacks.

- We are doing some "live" assistance to state police and the FBI on cases, during which we are identifying characteristics worthy of new projects.

There have been other projects before these, and more to come. The above is not even a complete list, but gives a sense of scope -- OS to devices to tool building to psychology to "live" operations.


Forensic Focus: What do you think are the greatest challenges in store for the computer forensics community? How should these challenges be met?

Gene Spafford: The big challenges are volume (of data and cases), timeliness (getting actionable results quickly), and crossing jurisdictional boundaries. The latter is related to the attribution problem.

I'm not sure yet how we meet all these challenges. One thing I have been advocating (and working on) are methods we build into systems -- OS and applications -- that provide great fidelity forensics without requiring substantial postprocessing. "Baked in" if you need a phrase for it. There are things we can do that will thus quickly narrow focus and produce timely results. We are going to need similar mechanisms to examine live systems, too -- computing in the "cloud" with SaaS means we aren't going to be able to shut systems down and examine them at our leisure. Not all the issues will be solved with technology, obviously. Some will require political and human solutions. We need to understand what those are, and work towards those too.


Forensic Focus: What aspect of computer forensics as it is currently practiced would you most like to see changed or improved?

Gene Spafford: Almost everything we do is ad hoc and post hoc. We need a more formal framework (I started down this path with Brian Carrier, who did his PhD under my direction) to describe what we do and make it more of a science than a technology application area. We need a greater set of foundational tools and concepts so we aren't relying on products whose inner workings we don't understand and which may not be generalizable. And as part of that framework, we need to have structures and logs that support what we are trying to do better than inferring behavior from artifacts designed 20 years ago.

I guess I can summarize that as saying we need more focus on the underlying science and principles of cyber forensics, not simply more case studies and tool development.


Forensic Focus: Do you have a sense that computer criminals are becoming more sophisticated at covering their tracks?

Gene Spafford: Oh yes, this is clearly happening, and has been for some time. Most of the people we notice and catch are the ones who are either brazen (they are operating from a location with no fear of retribution), careless, or uninformed. The slow, stealthy ones who are after very high value targets are seldom caught. This includes some of the well-financed "for hire" types who target corporate information, and government-backed agents. Instead, we catch the bot-herders and phishers, and even then we don't seem to catch many of them. One result is that those lower-end criminals read the mailing lists and news to see when and how they are spotted, and they learn from that.

In many ways, it is like antibiotic resistant bacteria. If you hit the bacteria with a drug, but don't actually wipe it out, what is left develops resistance so the same drug won't work the next time. If we don't actually start getting some action to go with successful forensics, we almost might be better off not doing some of the forensics! Luckily, the supersophisticated attackers are few in numbers compared to the more mundane criminals. Unfortunately, the super criminals can cause much more damage if we don't find them.


Forensic Focus: What advice would you give to anyone considering a career in forensic computing?

Gene Spafford: It's a field with tremendous promise. It is multi-disciplinary, so study in several fields other than IT will help -- criminology, psychology, law, for instance. Also, creating a reputation by breaking into systems or finding and publicizing flaws is not the best path to a fulfilling career: many employers, and especially many in law enforcement, see such behavior as demonstrating that the individual is not trustworthy. Given the number of times "hackers" have reverted to old ways or done questionable things, this is probably a reasonable assessment.


Forensic Focus: What do you do to relax and unwind?

Gene Spafford: Listen to music. Watch bad movies. Some reading. Gardening. I'm usually too busy with family & work to relax, however!




--

Gene Spafford can be contacted as follows:


Email: spaf AT purdue.edu -OR- spaf AT acm.org


Phone: (+1) 765.494.7825


Further contact details: spaf.cerias.purdue.edu



Universities/Colleges

computer forensics education choices COURSE DIRECTORY

User Info

Welcome Anonymous

Nickname

Membership:
Latest: IvanZ
New Today: 8
New Yesterday: 18
Overall: 13164

People Online:
Members: 4
Visitors: 25
Bots: 7
Staff: 0
Staff Online:

No staff members are online!
Latest Jobs

e-Discovery Manager - London, Europe - iConect, Clearwell
Last post by RaviBans01 in Computer Forensics Job Vacancies on Feb 04, 2010 at 18:22:04

CYBER FORENSIC INVESTIGATORS - LONDON £40k - £65k + Bens
Last post by emma in Computer Forensics Job Vacancies on Jan 25, 2010 at 12:22:12

INTELLIGENCE ANALYST - LONDON - up to £50k
Last post by emma in Computer Forensics Job Vacancies on Jan 25, 2010 at 12:02:28

Computer Forensic Investigator - Phoenix, Arizona (USA)
Last post by DDDR in Computer Forensics Job Vacancies on Jan 22, 2010 at 18:05:29

Forensics, Pent Testing, IDS, Malware, C&A - Washington DC
Last post by jhup in Computer Forensics Job Vacancies on Jan 21, 2010 at 17:48:53

Digital Forensics Engineer (Boston, MA)
Last post by stacynu in Computer Forensics Job Vacancies on Jan 19, 2010 at 20:18:15

EDISCOVERY & OPERATIONS DIRECTOR, LONDON
Last post by ScottBurkeman in Computer Forensics Job Vacancies on Jan 19, 2010 at 14:49:38

E-DISCOVERY SPECIALIST - LONDON - £50k - £65k + Exc Bens
Last post by emma in Computer Forensics Job Vacancies on Jan 19, 2010 at 11:34:04

FORENSIC NETWORK ADMINISTRATOR - LONDON - £35k - £50k + Bens
Last post by emma in Computer Forensics Job Vacancies on Jan 19, 2010 at 11:27:41

COMPUTER FORENSIC MANAGER - LONDON-£50-£65k
Last post by ScottBurkeman in Computer Forensics Job Vacancies on Jan 19, 2010 at 11:16:56

Computer Forensics Blog
· Computer forensics education directory now online
· US academic institutions - final call for contact details!
· Hidden Hymn
· Adroit Photo Forensics review
· Interview with Russell May, 4N6 Investigation
· Forensic Computing PhD, UK
· The Value of Push Button Computer Forensics
· Academic institutions - updated
· Computer Forensics in the Geek Press – A Taxonomy
· Academic institutions - who are we missing?

read more...
Members' Blogs

Start Blogging

What is Computer Forensics?
Computer forensics (or forensic computing) is the use of specialized techniques for recovery, authentication, and analysis of electronic data with a view to presenting evidence in a court of law.
Computer Forensics Downloads
  1: Forensic Examination of Digital Evidence: A Guide for Law Enforcement (pdf)
  2: ACPO Good Practice Guide for Computer based Electronic Evidence
  3: Electronic Crime Scene Investigation: A Guide for First Responders (pdf)
  4: Ancysoft Data Recovery Software
  5: HELIX incident response CD
  6: PDA Forensic Tools:An Overview and Analysis
  7: Forensics Plan Guide & Forensic Cookbook
  8: Recover My Files
  9: Autopsy Forensic Browser Version 2.03 (source code)
  10: Handy Recovery

Use of this website signifies your agreement to the Terms of Use/Privacy Policy available here.

All logos and trademarks in this site are property of their respective owner. The comments are property of their posters, all the rest © 2010 Forensic Focus


Interactive software released under GNU GPL, Code Credits, Privacy Policy
.: fisubsilver shadow phpbb2 style by Daz :: CPG-Nuke port by norseman :: ported to CPG-Dragonfly by jamin :.