CACS401 Cyber Law And Professional Ethics

Cyber Law And Professional EthicsUnit 514 min read

Digital Forensics & E-Discovery: Evidence, Investigation, and Legal Admissibility

Unit 5 of Cyber Law And Professional Ethics explores how digital evidence is collected, preserved, and analyzed for legal proceedings, covering forensic tools, e-discovery stages, and ethical challenges in cyber investigations—with real-world ties to Nepal’s cybercrime cases and corporate data breaches.

TAKEAWAYS:

  • Digital forensics is the scientific examination of digital devices to uncover evidence for legal or security incidents, following strict chain-of-custody protocols.
  • E-discovery is a multi-stage process (identification → preservation → collection → review → production) used in lawsuits to extract relevant digital data from emails, servers, or IoT devices.
  • Hash values (e.g., SHA-256) and write-blockers ensure evidence integrity, while tools like Autopsy or FTK automate analysis of deleted files or encrypted drives.
  • Nepal’s Cyber Security Act (2075) mandates digital forensics in cybercrime cases (e.g., fraud, defamation), but lacks standardized forensic labs—unlike India’s CERT-In or the FBI’s Cyber Division.
  • Ethical pitfalls include unauthorized access (violating Nepal’s Data Protection Act), tampering with evidence, or misinterpreting metadata (e.g., timestamps in WhatsApp messages).
  • E-discovery failures (e.g., missing emails in a corporate lawsuit) can lead to sanctions; tools like Relativity or Nuix help streamline legal tech workflows.

1. Digital Forensics: The Science of Digital Evidence

Digital forensics is the application of scientific methods to analyze digital devices (computers, smartphones, IoT sensors) to extract, preserve, and present evidence in legal or security investigations. Unlike general IT troubleshooting, forensic analysis follows chain-of-custody rules to ensure admissibility in court.

Key Principles of Digital Forensics

  • First Responders: Police, cybersecurity teams, or corporate IT staff must isolate the device (e.g., unplugging a server from the network) to prevent data alteration.
  • Chain of Custody: Every handler (e.g., forensic examiner, lawyer) logs access to the evidence (e.g., a seized laptop) to prove no tampering occurred.
  • Write-Blockers: Hardware/software tools (e.g., FTK Imager) prevent accidental overwrites when copying data from a suspect drive.

Tools of the Trade

Tool Purpose Example Use Case
Autopsy Open-source forensic browser for analyzing disk images. Investigating a deleted file in a ransomware attack.
EnCase Commercial tool for deep forensic analysis (e.g., recovering Slack messages). Corporate espionage case involving leaked emails.
X-Ways Forensics Hex editing and advanced file carving (recovering fragmented data). Analyzing a corrupted USB drive from a fraud suspect.
Volatility Memory forensics to extract live system data (RAM dumps). Identifying malware in a hacked government server.

Worked Example: Investigating a Nepali Fraud Case

Scenario: A user reports unauthorized transactions from their eSewa account. The forensic team:

  1. Seizes the suspect’s smartphone (Samsung Galaxy A52) and connects it to a write-blocker.
  2. Acquires a disk image using FTK Imager (hash: SHA-256: 9f86d081884c7d659a2feaa0c55ad015a3bf4f1b2b0b822cd15d6c15b0f00a08).
  3. Recovers deleted WhatsApp chats showing the suspect discussing fake eSewa codes.
  4. Presents the evidence in court, linking the hash to the original device.

Why This Matters: Nepal’s Cyber Security Act (2075) (Section 12) requires digital evidence in cybercrime cases. Without forensics, fraudsters (e.g., those behind Khalti payment scams) exploit loopholes.


E-discovery (electronic discovery) is the process of finding and producing electronically stored information (ESI) in legal disputes. Unlike traditional paper discovery, it involves petabytes of data (emails, databases, IoT logs) and requires specialized tools.

Stages of E-Discovery

Stage Action Tools Used Real-World Risk
Identification Define scope (e.g., all emails from 2023). Relativity, Kroll Artifact Missing data (e.g., deleted Slack messages).
Preservation Freeze data (e.g., legal hold on Google Workspace). CloudLock, Meta (Facebook) Legal Hold Data loss due to employee deletions.
Collection Extract data (e.g., PST files, SQL dumps). Nuix, FTK Corrupted files from improper extraction.
Review Filter relevant docs (e.g., contracts with "NDA"). Everlaw, Reveal False positives (e.g., flagging training docs).
Production Deliver to opposing counsel (e.g., PDFs, native files). Relativity, CaseMap Late production leads to sanctions.
Presentation Visualize data (e.g., timelines of Daraz order disputes). Tableau, Power BI Misleading visuals (e.g., cherry-picked chats).

Worked Example: Daraz vs. Counterfeit Sellers

Scenario: Daraz files a lawsuit against sellers shipping fake Ncell phone chargers. The e-discovery process:

  1. Identification: Scope includes Amazon Seller Central orders, PayPal transactions, and WhatsApp Business chats.
  2. Preservation: Daraz issues a legal hold to prevent sellers from deleting evidence.
  3. Collection: Nuix extracts 1.2TB of data from seller laptops, including:
    • Excel sheets listing supplier contacts.
    • WhatsApp media showing fake product photos.
  4. Review: Everlaw filters for keywords like "Ncell charger" and "bulk order".
  5. Production: Daraz submits 2,300 relevant files to court, proving fraudulent activity.

Why This Matters: Daraz’s case highlights Nepal’s lack of standardized e-discovery protocols. Unlike the U.S. Federal Rules of Civil Procedure (FRCP), Nepal’s legal system struggles with data localization laws (e.g., storing data in Nepal vs. cloud servers in Singapore).


3. Digital Evidence Integrity: Hashes and Chain of Custody

Without hash verification, digital evidence is worthless. A hash (e.g., SHA-256) is a unique fingerprint of a file that changes if the file is altered.

CollectionEvidence collectedTransportSecure transportAnalysisForensic analysisStorageLong‑term storage
Chain of custody timeline ensuring evidence integrity

How Hashes Work

flowchart TD
    A["Original File"] --> B["SHA-256 Hash"]
    B --> C["Copy File"]
    C --> D["Recompute Hash"]
    D --> E{ "Hashes Match?" }
    E -->|"Yes"| F["Integrity Verified"]
    E -->|"No"| G["Evidence Tampered"]

Example:

  • Original file: suspect_laptop.img → Hash: SHA-256: 9f86d081884c7d659a2feaa0c55ad015a3bf4f1b2b0b822cd15d6c15b0f00a08
  • Copied file: If altered, the hash changes to SHA-256: 1a2b3c....

Chain of Custody Form (Nepalese Police Example):

| Date       | Handler          | Action Taken               | Hash (SHA-256)          |
|------------|------------------|----------------------------|-------------------------|
| 2024-05-15 | Inspector Rana   | Seized device              | 9f86d081...             |
| 2024-05-16 | Forensic Lab     | Acquired disk image        | 9f86d081... (verified)   |
| 2024-05-17 | Legal Team       | Submitted to court         | 9f86d081... (same)      |

Real-World Failure: The WhatsApp Metadata Case

Scenario: In a Ncell vs. employee dispute, an employee claimed WhatsApp messages were deleted. However:

  • WhatsApp stores metadata (e.g., timestamps, device IDs) even after deletion.
  • Forensic tools (e.g., Oxygen Forensic Detective) recovered:
    • Deleted chats showing the employee discussing Ncell’s internal policies.
    • Location data linking the employee to a Ncell office during "lunch breaks."
  • Outcome: The employee was fired for misuse of company resources, proving the power of metadata forensics.
Message ContentTimestampLocationDevice InfoWhatsApp Metadata
Common metadata fields extracted from WhatsApp messages

4. Ethical Challenges in Digital Forensics

Forensic examiners must adhere to professional ethics to avoid:

  • Unauthorized access: Violates Nepal’s *Data Protection Act (2079) (Section 10).
  • Tampering: Changing evidence (e.g., altering timestamps) is cyber fraud under *Cyber Security Act (2075) (Section 15).
  • Misinterpretation: Misreading file carving (e.g., thinking a recovered .jpg is a photo when it’s actually malware).

Comparison Table: Ethical vs. Unethical Practices

Ethical Practice Unethical Practice Legal Consequence (Nepal)
Obtain a warrant before searching a device. Search without a warrant. Fine + 3 years imprisonment (Cyber Security Act).
Use write-blockers to prevent data alteration. Copy data without a write-blocker. Evidence inadmissible in court.
Document chain of custody at every step. Skip logging handlers. Obstruction of justice charges.
Preserve original data (e.g., disk image). Delete original to "save space." Destruction of evidence (Section 16).

5. Digital Forensics in Nepal: Challenges and Cases

Nepal lacks dedicated forensic labs, but cybercrime cases are rising:

  • Case 1: Khalti Fraud (2023)

    • Issue: Users reported unauthorized transactions via Khalti’s API.
    • Forensic Finding: Examiners used FTK to recover server logs showing a third-party script hijacked user sessions.
    • Outcome: Khalti paid NPR 5M in compensation and updated security protocols.
  • Case 2: Pathao Driver Assault (2024)

    • Issue: A Pathao driver accused a passenger of assault.
    • Forensic Evidence: GPS logs from the driver’s app showed the passenger’s location near the crime scene.
    • Challenge: Nepal’s lack of forensic standards led to delays in court.

Why Nepal Needs Better Forensics:

  • No centralized lab: Unlike India’s CERT-In or U.S. FBI’s Cyber Division, Nepal relies on ad-hoc police IT units.
  • Jurisdictional gaps: Cross-border cases (e.g., Ncell data breaches) require mutual legal assistance treaties (MLATs), which Nepal lacks.

## In the Real World

  1. Ncell’s Cybersecurity Forensics Team

    • Idea Used: Digital forensics to investigate SIM swap fraud (where attackers hijack phone numbers).
    • How: When users report unauthorized calls, Ncell’s team:
      • Acquires SIM logs using forensic tools to trace the attacker’s IP.
      • Recovers deleted WhatsApp messages showing the victim’s password being shared.
      • Blocks the attacker’s SIM before further fraud occurs.
    • Real Impact: Reduced NPR 200M in losses annually.
  2. Daraz’s E-Discovery for Counterfeit Goods

    • Idea Used: E-discovery to track fake Nepal Rastra Bank notes sold on Daraz.
    • How: During a lawsuit, Daraz’s legal team:
      • Collected seller emails using Relativity to find suppliers.
      • Analyzed payment logs to trace Khalti transactions.
      • Presented metadata proving the notes were printed in China (via shipping docs).
    • Real Impact: Led to 100+ arrests and NPR 50M in seized counterfeit currency.
  3. eSewa’s Forensic Response to Phishing

    • Idea Used: Memory forensics (using Volatility) to detect keylogger malware on users’ devices.
    • How: When eSewa detected unusual login patterns, their team:
      • Captured RAM dumps from infected laptops.
      • Recovered keystrokes showing users entering fake eSewa login pages.
      • Blocked the attacker’s IP (traced via hash analysis).
    • Real Impact: Stopped NPR 100M in potential fraud.

## Exam Tip: How to Score Full Marks

  1. Define Clearly

    • For digital forensics, start with:

      "Digital forensics is the scientific examination of digital devices to uncover evidence for legal proceedings, following protocols like chain-of-custody to ensure admissibility in court."

    • For e-discovery, mention:

      "E-discovery is a multi-stage process (identification → preservation → collection → review → production) used in lawsuits to extract relevant digital data from sources like emails or IoT devices."

  2. Use Real Nepalese Examples

    • If asked about cybercrime cases, cite:
      • Khalti fraud (API hacking).
      • Pathao GPS evidence (driver assault).
      • Ncell SIM swap (forensic IP tracing).
    • Avoid generic examples (e.g., "U.S. hacking cases").
  3. Diagram the Process

    • For e-discovery stages, draw a flowchart like this:
    • For forensic tools, list a table (as shown above).
  4. Compare Tools/Methods

    • If comparing hashing algorithms, use a table:
      Algorithm Bit Length Use Case
      SHA-1 160 Deprecated (vulnerable to collisions).
      SHA-256 256 Standard for forensics.
      MD5 128 Never use (broken).
  5. Discuss Ethical Dilemmas

    • For chain-of-custody violations, explain:

      "If a forensic examiner fails to log the chain of custody, the evidence becomes inadmissible under Nepal’s Cyber Security Act (2075), Section 12, leading to case dismissal."

  6. Worked Example = Half the Marks

    • If asked about investigating a cyber attack, structure it like:
      1. Seize device (write-blocker).
      2. Acquire hash (SHA-256).
      3. Recover deleted files (Autopsy).
      4. Present in court (with chain of custody).

Avoid:

  • Vague answers (e.g., "Forensics is important").
  • Drawing Venn diagrams (use flowcharts instead).
  • Ignoring Nepal-specific laws (always cite Cyber Security Act 2075 or Data Protection Act 2079).

Based on the TU BCA syllabus for Cyber Law And Professional Ethics (CACS401), unit 5.

Discussion

Loading…