Researchers at the University of Chicago created an algorithm that predicts where crime will happen. They trained it on historical data, and now it announces an area one week in advance, with 90% accuracy (Sparks, 2022). This novel algorithm works for crime prevention, more usually, Digital Forensics follows after a crime is committed. Digital forensics and cybercrime have evolved together.

What is Digital Forensics?
The most basic meaning of Forensics is ‘as applies to a court of law’. Forensic science uses the scientific method to find evidence. So, Digital Forensics investigates computers to secure and preserve evidence, needed by juries to judge whether a crime has been committed (Lutkevich, 2021). But, because of the widespread use of technology, the work includes any device on which data is stored digitally: computers, laptops, cameras, phones, & tablets (EC-Council, 2022).
Digital Forensics is the tools and methodology used to find evidence on technological devices. For the evidence to mean anything in court, there must be a common standard of practice for the recovery of digital evidence (ACPO, 2011).
Standards in Digital Forensics
In the USA, digital evidence must reach two criteria to be admissible in court: “ it must be (1) relevant, arguably a very weak requirement, and (2) it must be ‘derived by the scientific method’ and ‘supported by appropriate validation’”( Manes, 2007).
The Association of Police Chief Officers (ACPO) in the UK, argues that digital evidence is no different from any other evidence. It needs to be secured and have a full chain of evidence log. The difference between digital evidence and IRL evidence is that the device is secured or seized before searching for evidence (ACPO, 2011).
The integrity of their findings must be ensured to retain credibility in court. A log of all actions must be kept. The first action taken is to ‘image’ or copy the data. No work can be done on the original, in case manipulation creates an error in the data, invalidating the evidence in the eyes of the Court. The chief investigator has the responsibility of ensuring these standards are met (Gujar, 2018).
A Brief History of Digital Forensics
Of course, digital forensics is a relatively new field in forensic analysis, as is cyber or computer crime. Until recently, computers were mostly industrial or research tools, but in the shadows, people were finding ways to use them for criminal activity (Pollitt, 2010).
Donn Parker wrote the first book on computer crime in 1976. A review on Goodreads tells the story of a man who printed out extra checks and tried to cash them all at once, at the same bank (Ron, 2011). No wonder he was caught.

Credit: https://commons.wikimedia.org/wiki/File:Sunshine_state_plate.jpg
In 1978, the Florida Computer Crime Act recognized the use of computers for crimes (Williams, 2022). Initially, the investigators for computer crime were hobbyists. In 1984, the FBI in the US set up a Computer Analysis and Response Team. The Fraud Squad in the UK created a computer crime team in 1985 (Open University, 2022). It wasn’t until 2000 that the FBI set up a proper computer laboratory to deal with computer crime(Williams, 2022).
What is Cybercrime?
There are three main areas where digital forensics gets involved in a criminal investigation.
Computer Crime
We are all aware of Hackers who break into the mainframes of corporations or countries and steal information. Or they leave behind Malware and Ransomware, that only upon payment to the Hacker will the code be provided to return control of the computer to the owner. These are the most common sorts of crimes that we associate with computers (what-when-how). But there are others.
Case Study
A postal inspector in the US, before 1992, was asked to submit evidence from a computer. It caused a great deal of consternation, and eventually, it was submitted as a ‘Questioned Document’ (Defintion). A Postal Inspection Service Laboratory was created at Dulles, Virginia, in 1996-97 to cope with these cases. They defined “Digital Evidence is any information of probative value that is either stored or transmitted in a binary form.” They revised binary to digital in later documentation (Whitcomb, 2002).
Computer Assisted Crime
These crimes are more insidious. They do not need a computer but, with the advancing technology, criminals have migrated to the new medium. Haven’t we all had a ‘Nigerian prince’ wanting to send us a million dollars? You might think that these begging letters started with email, but the first recorded case of the ‘Advance-fee scam’ was back in the French Revolution (Brunton, 2013). Not only have the scams adapted to computers, but child pornography is also another crime that has crept into the darker parts of the internet (what-when-how).
Technology Used as Part of a Crime
The third main area where digital forensics investigates a crime is where the device was used incidentally by a criminal. For instance, a list of clients of a drug dealer could be stored on a computer hard drive.
Sometimes, even hitting someone over the head with a laptop can be considered a cybercrime when it damages digital data. All of these crimes, and more, such as Identity Theft, Denial of Service, Swatting, Phishing, and Salami Slicing, need a special type of investigative tool. And that tool is digital forensics.
Case Study
September 11 2001 is a dark day in US History. While computers were not used for the crime, evidence about the conspiracy was uncovered on computers all over the world. In the same way as everyone else, the criminals used computers to communicate and coordinate their activities. It was after this that money became properly invested in digital forensics (Pollitt, 2010).
Obstacles for the Forensic Analyst

credit: https://commons.wikimedia.org/wiki/File:Digital_Rhetoric.jpg
The case study above highlights a major challenge for digital forensics: the sheer volume of information available. Think about how many files there are on your computer. I don’t know about you, but I keep several drafts of any document so that I can return and recover information that I might have deleted in a later draft. Then there are all the photographs on the average phone. Text messages, emails, all these add up. From this, you can guess that digital forensics is not a rapid process (Williams, 2022).
And this is before having to look for hidden or deleted files. What if the file doesn’t show up in the directory? All this data must be found.
How do Forensic Analysts Work?
I mentioned earlier that Digital Forensics was a set of tools and methodology. We have an image from fiction, of a forensic analyst, head down, typing at a keyboard, hacking their way through passwords to find a vital clue for the police. While I’m not saying this doesn’t happen, there are several software tools available to any agency that works to recover evidence. Some work best with Windows, others work for Mac. There are even open-source tools available (Williams, 2022). The purpose of these tools is to find the data and organize it, making collection and analysis straightforward.
Finally
The major problem for digital forensics and cybercrime is the sheer quantity of material. The typical digital forensic analyst must be patient and thorough, to search through the mass of material. As cybercrime becomes more frequent, so the counter-measures against digital analysis are improved. The digital forensic analyst must find ways around all the obstacles, that a criminal puts in place in the never-ending battle against crime.
Images:
University of Chicago: https://commons.wikimedia.org/wiki/File:Campus_Spring.jpg
Florida https://commons.wikimedia.org/wiki/File:Sunshine_state_plate.jpg
Digital information: https://commons.wikimedia.org/wiki/File:Digital_Rhetoric.jpg
References
ACPO. (2011). ACPO Good Practice Guide For Digital Evidence. https://www.npcc.police.uk/documents/crime/2014/Revised%20Good%20Practice%20Guide%20for%20Digital%20Evidence_Vers%205_Oct%202011_Website.pdf
Brunton, F. (2013) The long, weird history of the Nigerian email scam. Boston Globe. (May 19). https://www.bostonglobe.com/ideas/2013/05/18/the-long-weird-history-nigerian-mail-scam/C8bIhwQSVoygYtrlxsJTlJ/story.html
EC-Council. (2022) How well do you know Digital Forensics? https://www.eccouncil.org/what-is-digital-forensics/
Gurjar, C. (2018). Computer forensics investigation – a case study. INFOSEC. (April 6) https://resources.infosecinstitute.com/topic/computer-forensics-investigation-case-study/
Lutkevich, B. (2021) computer forensics (cyber forensics). Tech Target. (May). https://www.techtarget.com/searchsecurity/definition/computer-forensics#:~:text=Computer%20forensics%20is%20the%20application,in%20a%20court%20of%20law
Manes, G W., Downing, E., Watson, L., and Thrutchley, C. (2007) New Federal Rules and Digital Evidence. Annual ADFSL Conference on Digital Forensics, Security and Law. 3. https://commons.erau.edu/adfsl/2007/session-6/3
Open University. (2022). A Brief History of Digital Forensics. https://www.open.edu/openlearn/science-maths-technology/digital-forensics/content-section-4.2
Pollitt, M. (2010) A History of Digital Forensics. 6th IFIP WG 11.9 International Conference on Digital Forensics (DF), (Jan) Hong Kong, China. pp.3-15, ff10.1007/978-3-642-15506-2_1ff. ffhal-01060606f
Ron. (2011) Crime by Computer by Donn Parker Ron’s Review. Goodreads. (April 19). https://www.goodreads.com/review/show/162225581?book_show_action=true&from_review_page=1
Sparks, M, (2022) AI Predicts Crime a Week in Advance with 90% Accuracy. New Scientist (June 30). https://www.newscientist.com/article/2326297-ai-predicts-crime-a-week-in-advance-with-90-per-cent-accuracy/
What-when-how. Computer Crimes (police). http://what-when-how.com/police-science/computer-crimes-police/
Whitcomb, C.M. (2002). A Historical Perspective of Digital Evidence: A Forensic Scientist’s View. International Journal of Digital Evidence. Spring vol1. Issue 1. https://www.utica.edu/academic/institutes/ecii/publications/articles/9C4E695B-0B78-1059-3432402909E27BB4.pdf
Williams, L. (2022). What is Digital Forensics? History, Process, Types, Challenges. GURU 99. (November 12). www.guru99.com/digital-forensics.html





