Investigative Uses of Technology: Devices, Tools, and Techniques
Total Page:16
File Type:pdf, Size:1020Kb
U.S. Department of Justice Office of Justice Programs OCT. 07 OCT. National Institute of Justice Special REPORT Investigative Uses of Technology: Devices, Tools, and Techniques www.ojp.usdoj.gov/nij U.S. Department of Justice Office of Justice Programs 810 Seventh Street N.W. Washington, DC 20531 Peter D. Keisler Acting Attorney General Cybele K. Daley Acting Assistant Attorney General David W. Hagy Acting Principal Deputy Director, National Institute of Justice This and other publications and products of the National Institute of Justice can be found at: National Institute of Justice www.ojp.usdoj.gov/nij Office of Justice Programs Innovation • Partnerships • Safer Neighborhoods www.ojp.usdoj.gov 01-Chap 1 InvestigTech 10/10/07 12:41 PM Page i OCT. 07 Investigative Uses of Technology: Devices,Tools, and Techniques NCJ 213030 01-Chap 1 InvestigTech 10/10/07 12:41 PM Page ii David W. Hagy Acting Principal Deputy Director, National Institute of Justice This document is not intended to create, does not create, and may not be relied upon to create any rights, substantive or procedural, enforceable by law by any party in any matter civil or criminal. Photos used in this document are taken from public Web sites; they are in no way an endorse ment of the product illustrated. Opinions or points of view expressed in this document represent a consensus of the authors and do not necessarily reflect the official position or policies of the U.S. Department of Justice. The products, manufacturers, and organizations discussed in this document are presented for informational purposes only and do not constitute product approval or endorsements by the U.S. Department of Justice. This material should not be relied upon as legal advice. Those considering legal issues related to the use of high-tech materials should consult with their legal counsel. This document was prepared under Interagency Agreement #2003–IJ–R–029 between the National Institute of Justice and the National Institute of Standards and Technology, Office of Law Enforcement Standards. The National Institute of Justice is a component of the Office of Justice Programs, which also includes the Bureau of Justice Assistance; the Bureau of Justice Statistics; the Community Capacity Development Office; the Office for Victims of Crime; the Office of Juvenile Justice and Delinquency Prevention; and the Office of Sex Offender Sentencing, Monitoring, Apprehending, Registering, and Tracking (SMART). 01-Chap 1 InvestigTech 10/10/07 12:41 PM Page iii Technology Working Group for Investigative Uses of High Technology* Planning panel Phillip Osborn Senior Special Agent James R. Doyle National Program Manager First Group Associates Cyber Crimes Center (C3) New York, New York Bureau of Immigration and Customs Enforcement (ICE) Joseph Duke U.S. Department of Homeland Security Drive-Spies, LLC Fairfax, Virginia Clarkston, Michigan John Otero Barry Grundy Lieutenant Computer Crime Investigator/ Computer Crimes Squad Special Agent New York Police Department NASA Office of the Inspector General New York, New York Office of Investigations Computer Crimes Division David Poole Goddard Space Flight Center Chief Greenbelt, Maryland Information Operations and Investigations Air Force Office of Special Investigations Keith Hodges Andrews Air Force Base, Maryland Senior Instructor, Legal Division Federal Law Enforcement Training Center Michael Weil Glynco, Georgia Huron Consulting Group Chicago, Illinois Dan Mares President Mares and Company Technology working group Lawrenceville, Georgia members Mark J. Menz Todd Abbott M. J. Menz and Associates Vice President Folsom, California Corporate Information Security Bank of America Robert Morgester Charlotte, North Carolina Deputy Attorney General State of California Department of Justice Abigail Abraham Office of the Attorney General Assistant Attorney General Criminal Law Division Illinois Attorney General’s Office Sacramento, California Chicago, Illinois David Arnett Detective Arizona Department of Public Safety Phoenix, Arizona iii 01-Chap 1 InvestigTech 10/10/07 12:41 PM Page iv Dave Ausdenmoore Don Flynn Detective Attorney Advisor Regional Electronics and Computer Department of Defense Investigation Section Cyber Crime Center Hamilton County Sheriff’s Office/ Linthicum, Maryland Cincinnati Police Department Cincinnati, Ohio G.D. Griffin Assistant Inspector in Charge Rick Ayers Digital Evidence Unit National Institute of Standards and U.S. Postal Inspection Service Technology Dulles, Virginia Gaithersburg, Maryland Amber Haqqani Ken Basore Director, Digital Evidence Director of Professional Services American Academy of Applied Forensics Guidance Software (EnCase) Central Piedmont Community College Reston, Virginia Charlotte, North Carolina David Benton Dave Heslep Chief Systems Engineer Sergeant Home Depot Technical Assistance Section Supervisor Atlanta, Georgia Maryland State Police Technical Investigation Division Walter E. Bruehs Columbia, Maryland Forensics Examiner Forensic Audio, Video and Imaging Chip Johnson Analysis Unit Lieutenant Federal Bureau of Investigation South Carolina Computer Crime Center Quantico, Virginia Columbia, South Carolina Carleton Bryant Nigel Jones Staff Attorney NSLEC Centre for National High Tech Knox County Sheriff’s Office Crime Training Knoxville, Tennessee Wyboston Lakes Business and Leisure Centre Scott Christensen Bedfordshire, England Sergeant Computer Crimes/ICDC Unit Keith Kelly Nebraska State Patrol Telecommunication Specialist Omaha, Nebraska Washington, D.C. Bill Crane Tom Kolpacki Assistant Director Detective National White Collar Crime Center Ann Arbor Police Fairmont, West Virginia Livonia, Michigan iv 01-Chap 1 InvestigTech 10/10/07 12:41 PM Page v Al Lewis Henry (Dick) Reeve Special Agent General Counsel Investigator/DE Examiner Deputy District Attorney USSS Electronic Crimes Task Force Denver District Attorney’s Office Chicago, Illinois Denver, Colorado Glenn Lewis Jim Riccardi, Jr. Computer Training Specialist Electronic Crime Specialist Training Services CyberScience Lab SEARCH Group, Inc National Law Enforcement and Sacramento California Corrections Technology Center–Northeast Rome, New York Thomas Musheno Forensic Examiner Richard Salgado Forensic Audio, Video and Image Analysis Senior Counsel Federal Bureau of Investigation Computer Crime and Intellectual Engineering Research Facility Property Section Quantico, Virginia U.S. Department of Justice Washington, D.C. Larissa O’Brien Chief, Research and Development Chris Stippich Information Operations and Investigations President Air Force Office of Special Investigations Digital Intelligence, Inc. Andrews Air Force Base, Maryland Waukesha, Wisconsin Timothy O’Shea Assistant U.S. Attorney Facilitators Western District of Wisconsin Susan Ballou Senior Litigation Counsel Program Manager for Forensic Sciences Computer Crime and Office of Law Enforcement Standards Telecommunications Coordinator National Institute of Standards and Madison, Wisconsin Technology Gaithersburg, Maryland Thom Quinn Program Manager Anjali R. Swienton California Department of Justice President & CEO Advanced Training Center SciLawForensics, Ltd. Rancho Cordova, California Germantown, Maryland *This information reflects each panel member’s professional affiliation during the time that the majority of the technology working group’s work was performed. v 01-Chap 1 InvestigTech 10/10/07 12:41 PM Page vii Contents Technology Working Group for Investigative Uses of High Technology. iii Introduction. 1 Chapter 1. Techniques . 3 Introduction . 3 Investigative assistance . 3 Information gathering . 3 Digital evidence. 6 Electronic communications . 8 Telecommunications . 11 Video surveillance . 12 Consensual monitoring . 13 Tracking . 13 Practical example. 14 Chapter 2. Tools and Devices . 21 Introduction . 21 Power concerns with battery-operated devices . 21 Access-control devices . 22 Answering machines and voice mail systems (digital and analog) . 24 Audio: Digital tools used to conduct examinations of audio formats . 26 Caller ID devices . 28 Cell phones . 30 Computers (desktops and laptops) . 34 Credit card fraud devices . 36 vii 01-Chap 1 InvestigTech 10/10/07 12:41 PM Page viii SPECIAL REPORT / OCT. 07 Customer or user cards and devices. 38 Data preservation (duplicating, imaging, copying). 40 Detection and interception (wireless) . 44 Digital cameras and Web cameras . 46 Digital security cameras . 48 Encryption tools and passphrase protection . 50 Facsimile (fax) . 53 Global positioning system devices . 55 Home entertainment. 57 Internet tools. 59 Internet tools to identify users and Internet connections (investigative) . 61 Keystroke monitoring . 68 Mass media copiers and duplicators. 73 Pagers . 74 Pens and traps. 76 Personal digital assistants . 77 Removable storage media and players . 80 Sniffers . 84 Steganography . 86 Vehicle black boxes and navigation systems. 87 Video and digital image analysis tools. 89 Voice recorder (digital). 91 viii 01-Chap 1 InvestigTech 10/10/07 12:41 PM Page ix INVESTIGATIVE USES OF TECHNOLOGY: DEVICES, TOOLS, AND TECHNIQUES Chapter 3. Legal Issues for the Use of High Technology. 93 Introduction . 93 Constitutional issues . 93 Searches and seizures pursuant to warrants. 94 Warrantless searches . 96 Statutes that affect the seizure and search of electronic evidence. 98 Appendix A. Glossary . 107 Appendix B. Technical Resources List . 117 Appendix C. Hacked Devices . 131 Appendix D. Disclosure Rules of ECPA . 135 Appendix E. Sample Forms . 137 Appendix