How Police Officers Are Tackling The Data Backlog With Digital Forensics

Police forces across the globe are struggling with unprecedented volumes of data. In the UK, 90 percent of crimes now feature some digital element and officers across England and Wales claim cybercrime data is doubling every 18 months. Yet the way in which this data is collected, processed and reviewed is time consuming and resource intensive, with an overdependency on hardware and bottlenecks caused by the need to physically get the data to Digital Forensics Units (DFUs). 

Those forces that do have the capability to process data digitally are now finding themselves hampered by the speed with which this can occur. Some cases produce such massive amounts of data that they overwhelm existing equipment.

For instance, one European federal police agency needed to process seven terabytes of data from a Mac image, including a back-up folder and several PST email files – a process that would have taken days, if not weeks, particularly with respect to then indexing the data. Being able to divide and conquer this data has therefore become paramount.

Increasingly, police forces are seeking to empower their officers on the ground through remote collection. Digital kiosks, for instance, allow them to quickly extract and process evidence. However, any subsequent data that then comes to light has to be submitted directly to the DFU which may mean evidence is not analysed side by side, leading to connections being missed, pointing to the need for a collaborative environment.

But, putting police officers in the role of the investigator requires significant adjustments to be made to ensure that the process if defensible, the chain of custody is maintained, and that the officer is also protected. Controls would therefore need to be built-in to ensure certain aspects were automated, that officers weren’t subjected to graphic material unnecessarily, and that connections were made between seemingly unrelated pieces of evidence.

Cloud-based Digital Forensics

There’s long been an awareness that the digital forensics process needed modernising. The Digital Forensic Science Strategy makes the case for a cloud-based solution to centralise data management, enable collaboration between officers and digital forensics investigators, automate and streamline processes and rationalise data storage. This would make it possible for digital evidence to be collected remotely from anywhere but was seen as unachievable until 2025 at the earliest.

Despite the challenges involved, however, West Midlands Police became one of the first forces worldwide to deploy a cloud-based digital forensics service earlier this year.

Using Exterro’s FTK Central platform housed in Microsoft Azure, the force is now collecting, processing and reviewing extremely large volumes of data at speed, whilst also centralising access allowing officers and digital forensic investigators to work on evidential data simultaneously.

Forensic and legal review workflows delivered via a single collaborative, web-based tool gives users a real-time view into their assigned cases. As the solution requires minimal training, front line officers can work with forensic reviewers, examiners, and investigators to collect, process, and review key case-evidence. 

Protecting The Police

Built-in controls help protect the user, such as Explicit Image Detection which incorporates a mental health shield for investigators by guarding against unnecessary exposure to graphic material during forensic review. The AI-powered Video Recognition and Explicit Image Detection also interfaces with CAID and Project Vic, a comprehensive unified missing/exploited children database to identify victims while cross-case analytics also helps to identify possible connections, helping to safeguard children sooner. 

Other forces stand to gain the same benefits with officers and investigators able to work flexibly and collaboratively, freeing up resource and eliminating the delays that have allowed case load data to accumulate. Forces will also be much better placed to deal with future change, with the ability to access data over a variety of endpoints and help maintain accreditation with the ISO17025 quality standard for their forensic science activities which is now a mandatory requirement. 

On the continent, the European federal police agency referred to earlier, has also been able to use the same technology to tackle its data mountain. It processed the seven terabytes of data in just an hour and 40 minutes and indexed that data in under 12 hours by configuring one Distributed Processing Manager to manage 11 Distributed Processing Engines. This effectively shared the processing power over these multiple pieces of hardware, accelerating processing speed to unparalleled levels.

Going forward, this processing capability coupled with workflow processes that both protect and empower the police, promises to significantly reduce the data backlog, expedite case reviews and increase speed to justice, helping to safeguard citizens faster. And, as AI develops, the expectation is that this form of digital forensics will lead to virtual assistants that will make causal links, propose possible avenues for further investigation, and offer up actions for consideration.

Such advances are therefore not only empowering the police and making the process faster but will also make it more thorough by exhausting every line of enquiry.

Harsh Behl is Director of Product Management (Digital Forensics and Incident Response) at Exterro

You Might Also Read: 

Europol Is Told To Delete Its 'Big Data Ark':

 

« Ukraine Predicts A Massive Cyber Attack From Russia
October Is Cyber Security Awareness Month »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

Cyber Security Supplier Directory

Cyber Security Supplier Directory

Our Supplier Directory lists 6,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

ZenGRC

ZenGRC

ZenGRC - the first, easy-to-use, enterprise-grade information security solution for compliance and risk management - offers businesses efficient control tracking, testing, and enforcement.

Biscom

Biscom

Biscom offers solutions for secure file transfer, synchronization, file translation, and mobile devices, designed to deliver mission-critical reliability, streamline workflows and reduce costs.

Galvanize

Galvanize

Galvanize is a leading provider of award-winning, cloud-based security, risk management, compliance, and audit software for some of the world’s largest organizations.

Sentropi

Sentropi

Sentropi is an online protection solution against charge backs, account takeovers, identity thefts and online scams.

RISE

RISE

RISE is an independent, State-owned research institute, which offers unique expertise and over 100 testbeds and demonstration environments for future-proof technologies, products and services.

spiderSilk

spiderSilk

spiderSilk is a Dubai-based cybersecurity firm, specializing in simulating the most advanced cyber offenses on your technology so you can build your best security defenses.

River Loop Security

River Loop Security

River Loop Security specialize in solving complex cybersecurity challenges in the IoT and embedded devices space.

Secure Ideas

Secure Ideas

Secure Ideas is focused on penetration testing and application security including web applications, web services and mobile applications.

Future Technology Systems Company (FutureTEC)

Future Technology Systems Company (FutureTEC)

FutureTEC is a leading Information Technology Solutions Provider, delivering world-class Information Security, Information Management, and Business Solutions.

Prescient Solutions

Prescient Solutions

Prescient Solutions is a managed services provider, using a cloud-based model to provide IT solutions to small, mid-sized, global organizations and government entities.

PointWire

PointWire

PointWire offers a range of cybersecurity solutions and services including Penetration Testing on various levels, as well as Intrusion Detection and Prevention Systems.

Threatsys Technologies

Threatsys Technologies

Threatsys’s Integrated cyber security process helps your organizations to ensure that it’s secure from any fraudulent attacks.

Vertek

Vertek

Vertek is a leading provider of operations consulting, end-to-end business process outsourcing, business intelligence, software applications and managed cybersecurity solutions.

Silent Circle

Silent Circle

Silent Circle is the leader in end-to-end enterprise solutions for secure mobile communications.

Indevtech

Indevtech

Indevtech has been serving Hawaii since 2001, providing end-to-end managed IT services to small- and medium-businesses.

SecureLake

SecureLake

SecureLake (formerly Managni) is one of the most trusted US-based IT security and infrastructure companies.

Access Talent Today

Access Talent Today

Access Talent Today is an AI/ML and cyber security talent provider.