How Police Officers Are Tackling The Data Backlog With Digital Forensics

Police forces across the globe are struggling with unprecedented volumes of data. In the UK, 90 percent of crimes now feature some digital element and officers across England and Wales claim cybercrime data is doubling every 18 months. Yet the way in which this data is collected, processed and reviewed is time consuming and resource intensive, with an overdependency on hardware and bottlenecks caused by the need to physically get the data to Digital Forensics Units (DFUs). 

Those forces that do have the capability to process data digitally are now finding themselves hampered by the speed with which this can occur. Some cases produce such massive amounts of data that they overwhelm existing equipment.

For instance, one European federal police agency needed to process seven terabytes of data from a Mac image, including a back-up folder and several PST email files – a process that would have taken days, if not weeks, particularly with respect to then indexing the data. Being able to divide and conquer this data has therefore become paramount.

Increasingly, police forces are seeking to empower their officers on the ground through remote collection. Digital kiosks, for instance, allow them to quickly extract and process evidence. However, any subsequent data that then comes to light has to be submitted directly to the DFU which may mean evidence is not analysed side by side, leading to connections being missed, pointing to the need for a collaborative environment.

But, putting police officers in the role of the investigator requires significant adjustments to be made to ensure that the process if defensible, the chain of custody is maintained, and that the officer is also protected. Controls would therefore need to be built-in to ensure certain aspects were automated, that officers weren’t subjected to graphic material unnecessarily, and that connections were made between seemingly unrelated pieces of evidence.

Cloud-based Digital Forensics

There’s long been an awareness that the digital forensics process needed modernising. The Digital Forensic Science Strategy makes the case for a cloud-based solution to centralise data management, enable collaboration between officers and digital forensics investigators, automate and streamline processes and rationalise data storage. This would make it possible for digital evidence to be collected remotely from anywhere but was seen as unachievable until 2025 at the earliest.

Despite the challenges involved, however, West Midlands Police became one of the first forces worldwide to deploy a cloud-based digital forensics service earlier this year.

Using Exterro’s FTK Central platform housed in Microsoft Azure, the force is now collecting, processing and reviewing extremely large volumes of data at speed, whilst also centralising access allowing officers and digital forensic investigators to work on evidential data simultaneously.

Forensic and legal review workflows delivered via a single collaborative, web-based tool gives users a real-time view into their assigned cases. As the solution requires minimal training, front line officers can work with forensic reviewers, examiners, and investigators to collect, process, and review key case-evidence. 

Protecting The Police

Built-in controls help protect the user, such as Explicit Image Detection which incorporates a mental health shield for investigators by guarding against unnecessary exposure to graphic material during forensic review. The AI-powered Video Recognition and Explicit Image Detection also interfaces with CAID and Project Vic, a comprehensive unified missing/exploited children database to identify victims while cross-case analytics also helps to identify possible connections, helping to safeguard children sooner. 

Other forces stand to gain the same benefits with officers and investigators able to work flexibly and collaboratively, freeing up resource and eliminating the delays that have allowed case load data to accumulate. Forces will also be much better placed to deal with future change, with the ability to access data over a variety of endpoints and help maintain accreditation with the ISO17025 quality standard for their forensic science activities which is now a mandatory requirement. 

On the continent, the European federal police agency referred to earlier, has also been able to use the same technology to tackle its data mountain. It processed the seven terabytes of data in just an hour and 40 minutes and indexed that data in under 12 hours by configuring one Distributed Processing Manager to manage 11 Distributed Processing Engines. This effectively shared the processing power over these multiple pieces of hardware, accelerating processing speed to unparalleled levels.

Going forward, this processing capability coupled with workflow processes that both protect and empower the police, promises to significantly reduce the data backlog, expedite case reviews and increase speed to justice, helping to safeguard citizens faster. And, as AI develops, the expectation is that this form of digital forensics will lead to virtual assistants that will make causal links, propose possible avenues for further investigation, and offer up actions for consideration.

Such advances are therefore not only empowering the police and making the process faster but will also make it more thorough by exhausting every line of enquiry.

Harsh Behl is Director of Product Management (Digital Forensics and Incident Response) at Exterro

You Might Also Read: 

Europol Is Told To Delete Its 'Big Data Ark':

 

« Ukraine Predicts A Massive Cyber Attack From Russia
October Is Cyber Security Awareness Month »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

Huawei

Huawei

Huawei is a leading global ICT solutions provider. with end-to-end capabilities across the carrier networks, enterprise, consumer, and cloud computing fields.

CERT.hr

CERT.hr

CERT.hr is the national authority competent for prevention and protection from computer threats to public information systems in the Republic of Croatia.

Menlo Security

Menlo Security

Menlo Security protects organizations from cyberattacks by eliminating the threat of malware from the web, documents, and email.

Logz.io

Logz.io

Logz.io is an AI-powered log analysis platform that offers the open source ELK Stack as a enterprise-grade cloud service with machine learning technology.

CyberSec.sk

CyberSec.sk

CyberSec.sk is the Slovak portal bringing the latest cyber security news, politics, tips and instructions on how to protect the internet.

Secude

Secude

SECUDE is an established global security solutions provider offering innovative data protection for SAP users.

Cyber NYC

Cyber NYC

Cyber NYC is a suite of strategic investments to grow New York City’s cybersecurity workforce, help companies drive innovation, and build networks and community spaces.

NETRIO

NETRIO

If you are looking for a highly mature, exceptionally competent Managed Service Provider, NETRIO has solutions to keep your business running at warp speed with zero disruptions.

Axio Global

Axio Global

Axio is a leading cyber risk management SaaS company. Our Axio360 platform gives companies visibility to their cyber risk, and enables them to prioritize investments to protect their business.

Romanian Tech Startup Association (ROTSA)

Romanian Tech Startup Association (ROTSA)

Romanian Tech Startups Association is an umbrella organization that aims to promote, support and represent the interests of tech startups in Romania.

Nuts Technologies

Nuts Technologies

Nuts Technologies are simplifying data privacy and encryption with our innovative and novel data containers we call nuts based on our Zero Trust Data framework.

GTT Communications

GTT Communications

GTT are a global network provider that serves thousands of multinational and national enterprise, government and carrier customers with a portfolio of advanced connectivity and security services.

Tidal Cyber

Tidal Cyber

We formed Tidal for one simple reason—we believe that defenders need and deserve tools and services that make achieving the benefits of threat-informed defense practical and sustainable.

Nokod Security

Nokod Security

Nokod Security delivers an application security platform for low-code / no-code custom applications and Robotic Process Automation (RPA).

Frontal

Frontal

Frontal is a specialized unit in Blockchain and Web3.0 cybersecurity. Securing Digital Assets, Cryptocurrency, DeFi, Blockchain and Web3.0 ecosystem.

Sequentur

Sequentur

Sequentur is an award-winning Managed IT Services company. We are SOC 2 certified and provide Managed IT Services and Cybersecurity services to businesses nationwide.