Anti-computer forensics
K. Hausknecht, S. Gruicic · 2017
Generally speaking, anti-computer forensics is a set of techniques used as countermeasures to digital forensic analysis. When put into information and data perspective, it is a practice of making it hard to understand or find. Typical example being when programming code is often encoded to protect intellectual property and prevent an attacker from reverse engineering a proprietary software program. Through this paper the focus will be on anti-forensics methods which in sense is how information obfuscation is affecting digital forensic investigation. The paper will describe some of the many anti-forensics methods used under the broad classifications of data hiding, artefact wiping, trail obfuscation and finally attacks on the forensic tools themselves. With any modern-day investigation relying more and more on digital forensics, investigators are required to deal with antiforensics methods on a daily basis. This paper will explore the challenges investigators and forensic practitioners are facing when conducting investigations. The methods used will be separated into low-tech and high-tech techniques, how they are being used, how they are affecting digital forensic investigation and what the mitigation possibilities are. Focus will be on hightech techniques that will not stop the investigation but rather prolong or make the process extremely time consuming and therefore not possible to complete in a timely manner or be cost effective.