With continuous advancements in everyday technology and the rapid development of artificial intelligence, opportunities to manipulate devices and systems to falsify evidence are becoming more prevalent and can therefore result in potential miscarriages of justice. With this, there is a greater requirement for a heightened understanding of digital evidence and its validity for all stakeholders across the legal sector.
Daren Greener, Managing Director at SYTECH – the UK’s longest-established digital forensics services provider (FSP), which has been diligently serving the Criminal Justice System since 1978 – shares insight into how digital forensic evidence is used to support a fair judicial process and explores the key challenges of producing credible evidential value within digital forensics.
Once upon a time, not so long ago, the simple mobile phone device was just that, quite simple. It only had a couple of functions; you could make and receive calls or send and receive text messages up to 160 characters long. After a short while, mobile phones also became digital cameras, then video cameras and not long after that sat-nav devices. Then, the simple mobile phone became Smart with internet access, social media accounts, banking and payments, before becoming self-aware and communicating with other digital devices around the home and the outside world. Similar evolutions have been taking place all over, turning once mundane items such as cars, watches, televisions, fridges and doorbells into potential evidence storage devices full of video, audio and data artefacts which may – or may not – prove useful to an investigation or litigation.
The practice of digital forensics is an integral part of the criminal justice process across all areas of crime from serious and organised crime such as county lines and trafficking, to major investigations for murder, kidnapping, terrorism, child abuse, hate crime etc.
To enable meaningful evidence to be recovered, investigated, and presented, it is of utmost importance to follow a meticulous process to the highest of standards. This is not only in the detailed mechanics of digital forensics processes but, also in ensuring the fully documented continuity of the evidential asset and the data assets derived from a device.
Following the acquisition of a device or asset, a process that in itself can present various issues or obstacles, the digital forensics analyst will need to securely gain working access to the device, which could include a requirement for security bypassing or even repair work. As the RAW data becomes available, this can then be processed and relevant evidential artefacts carved. It is imperative that the review and evaluation of these evidential artefacts is conducted in accordance with the defined forensic strategy, before being presented and entered into the criminal justice process.
Device Complexity and Evolution
Supporting a fair judicial process by producing credible evidential value within digital forensics can present many challenges. For example, the complexity of device architecture, both in the parts of the component and the software. In addition to constantly keeping pace with the emergence of new and differing devices, extensive expertise in mobile phones, computers, software, databases, electronics, and many other disciplines at a technical level is required.
Device Capacity – The Increasing Data Mountain
The vast increase in the capacity of devices now enables them to store huge volumes of data both locally and remotely in cloud storage. Everyday devices such as phones, tablets and laptops, are capable of storing 10s of thousands of images, 100s of messages etc, thus presenting a ‘needle in a haystack’ issue.
Burden of Proof
Then there is the challenge of attributing a device and the data derived from it to a particular individual at a relevant time or place. All too often, a suspect may denounce ownership or use of a device, even when recovered from their person, with the onus on the skill and capability of the digital analyst/investigator to prove otherwise, beyond reasonable doubt.
Questions such as ‘who used that mobile phone’, ‘Who sent those messages’, ‘Who drove that car’, are often and easily challenged without robust analytics. This also may involve the requirements of other specialisms such as audio forensics, image analysis, facial recognition, gate analysis and geolocation analysis.
The Rise of Misinformation and Manipulation
Data provenance is a key component, but it is complex and challenging. A common encounter is the ease with which devices and systems can be manipulated to produce falsified evidence. With leading forensic tools not keeping pace, falsified data can often go undetected.
There is a widespread lack of understanding of the capabilities of falsification; deep faking and shallow faking, for example, are a common cause of falsified evidence. The practice refers to the digital manipulation of images, video or sound to change the narrative – done so in an alarmingly realistic way, and often undetectable to the unaided observer. The rise of deep fakes and shallow fakes results from several factors, including the rapid development of artificial intelligence technologies, and the proliferation and development of apps and online services including voice-changing technology. With the media awash with fake news, the erosion of faith in the digital device or the evidence is a constant challenge.
SMS spoofing and the masking of mobile phone numbers causes further issues, whereby the communications trail is falsified. The process is simplistic, often taking just seconds to achieve with no expertise or specialist knowledge required. There are a large number of web-based services available, with no user or subscriber verification required making it difficult to trace the originating source.
We are seeing a vast increase in anti-forensic tactics and mechanisms so, the key challenge lies in keeping pace with the ingenuity of criminality.
Attaining and Maintaining Competency and Proficiency
Notably, the plethora of differing device types requiring digital forensic analysis drives the need for an extensive armoury of up-to-date tools, skills, and competency. The vast variety of differing approaches according to what device, what operating system, what application, what data type, and what status of data (live deleted, fragmented), place a large burden on the forensic unit/practitioner to attain and maintain all appropriate skill levels. There is a requirement for constant development and training of the digital forensics practitioner, alongside the continuing burden of existing workloads.
There is a wide market of tool manufacturers and developers producing apparatus with various differing capabilities. Often there is too much reliance on the forensic tool/software, usually without relevant assurance or validation that it is fit for purpose. SYTECH tests software/hardware through stringent validation tests in accordance with its laboratory testing accreditation and often finds issues that cause concern. Where updates to software have results in the loss of previous capability.
There isn’t a ubiquitous, one-tool-fits-all solution and therefore, the ‘equality of arms’ can be imbalanced across providers due to the inequality of available tools, techniques and expertise.
Competency and proficiency within a validated method of application are essential to ensure a fair process and result.
Avoiding Bias, Maintaining Impartiality and the Presentation of Findings
I believe there is a lack of independence in the current adversarial system. Ultimately, when a case gets to court, the prosecution seeks to convict, and the defence seeks to acquit; it’s all too easy for stakeholders in prosecution/policing to form a prosecution bias and vice-versa.
Furthermore, in the process, there is often an imbalance in the ‘quality of arms’ between the prosecution and defence. In response to the burden of quantity faced by policing those tasked with the digital forensics process may not be suitable, competent or proficient, relying on technicians, intelligence analysis, or even just a software tool to complete complex and challenging tasks. In contrast, the defence will instruct Expert Witnesses to scrutinise, critique and challenge the credibility of the evidence or those having performed tasks in the DF process, who also lack the skill to counter-challenge the expert opinion.
The model in Civil Justice is for both opposing sides to appoint a single joint expert to adjudicate on arguments and differing hypotheses of both parties. In my view, the criminal justice sector could benefit from suitable accredited independent resources to adjudicate or ratify digital forensic evidence on behalf of both prosecution and defence, and to provide single representation for the presentation of such evidence.
The Requirement of Accreditation
ISO 17025 (laboratory accreditation) and Forensic Science Regulator’s Codes of Practice and Conduct are paramount, providing much-needed assurance benefits for the criminal justice system. Significantly, the international standard is a mandatory requirement for forensic providers who are putting evidence into the Criminal Justice System, outlining the robust requirements for testing and calibration in laboratories. It sets our guidelines for quality management, technical competence and the ability to produce accurate and reliable test and calibration data. In order to achieve ISO 17025, the facility will undergo a rigorous audit process, involving a detailed review of the facilities quality management system.
ISO 17025 accreditation is not a one-time achievement, it requires ongoing effort and improvement. By maintaining the accreditation, it will be assured that the provider is consistently striving to improve.