Short answer: no.
Long answer: everything old is indeed new again.
In 2016, I presented an information session on authentication at the LEVA Conference in Scottsdale, Az. Here's the session description:
Understanding Concepts of Image Authentication Workshop (2016)
This workshop is for those interested in the authentication of digital images. The workshop provides an overview of the techniques and skills necessary to perform basic authentication examinations using Amped Authenticate (Axon Detect) on digital images in a “forensic science” setting as well as to package, deliver, and present those findings in their local court room context.
At this year's LEVA Conference, it seems that the old topic is being dusted off, with one small addition. Can you spot the main difference between the 2016 session description (above) and this year's (below)?
Authenticate: The Beginners Guide to Image Authentication* (2019)
Image authentication techniques have multiplied over recent years. The simplicity of Image editing and the increase of bogus imagery, “Deep Fakes”, being identified in the media has, quite rightly, meant that methods to detect manipulation must be available to the legal system.
The difference: "Deep Fakes"
There's one big problem though. A "deep fake" is a video. Authenticate doesn't work on video, only images of a specific file type.
In my forensic multimedia analysis course (link), I feature a number of proposed techniques that address so-called "deep fake videos." All of the solutions work within a fusion-based methodology - requiring different tools and applications of those tools to identify the many components that make up fake videos.
But the wider question, why use the term "deep fakes" incorrectly to market an information session on an image authentication tool? Is this SEO gone wild? I don't know. At a minimum, it's confusing. At the maximum, it's deceptive. Hopefully, you weren't just going to learn about "deep fakes." If so, you're sure to be disappointed - again, Authenticate does not process or authenticate video.
Have a great day my friends.
keywords: audio forensics, video forensics, image forensics, audio analysis, video analysis, image analysis, forensic video, forensic audio, forensic image, digital forensics, forensic science, amped five, axon five, training, forensic audio analysis, forensic video analysis, forensic image analysis, amped software, amped software training, amped five training, axon five training, amped authenticate, amped authenticate training
This blog is no longer active and is maintained for archival purposes. It served as a resource and platform for sharing insights into forensic multimedia and digital forensics. Whilst the content remains accessible for historical reference, please note that methods, tools, and perspectives may have evolved since publication. For my current thoughts, writings, and projects, visit AutSide.Substack.com. Thank you for visiting and exploring this archive.
Featured Post
Welcome to the Forensic Multimedia Analysis blog (formerly the Forensic Photoshop blog). With the latest developments in the analysis of m...
Showing posts sorted by relevance for query authentication. Sort by date Show all posts
Showing posts sorted by relevance for query authentication. Sort by date Show all posts
Thursday, September 12, 2019
Friday, July 26, 2019
SWGDE Practical Considerations for Submission and Presentation of Multimedia Evidence in Court - initial draft for public comment
Today's post deals with SWGDE Practical Considerations for Submission and Presentation of Multimedia Evidence in Court, the initial draft for public comment. My comments on this guide deals more with foundation than specific technical details. Let's take a look.
In Section 4, you'll find this guidance, "This should also include documentation of any persons contacted in relation to the evidence." Wow!
Consider whom you may have contacted?
In Section 5.1, there are a number of points that need to be considered.
First,"Has the proffered evidence been properly authenticated? F.R.E. 901, 902."
Wow again. Remember, "authentication" is different than "hash." Authentication deals with accuracy in context, not integrity in transport.
Also remember that the majority of programs used these days do not actually interact with the evidence files but create a proxy file via FFmpeg. This is certainly true of the major players in this space, Input-Ace and Amped FIVE.
I remember, when working for Amped Software, Inc., that many customers would contact us because FIVE's "conversion" of files (the creation of a proxy file) would result in a different frame count vs. the original data file. Naturally, the resulting file would not hash the same. But, testing the contextual authenticity is what FRE 901 & 902 is all about. Was there a material change in context that resulted from the creation of the "working copy?"
You wouldn't know if you didn't conduct even a basic authenticity exam.
Remember, contextual authentication is not a feature of LEVA's CFVT / CFVA programs. Neither is it a feature of the IAI's CFVE program. It is, however, one of the tested domains in the AVFA certification (see this post on these programs).
There are precious few people trained in contextual authentication or enabled by a valid and reliable tool set. If you're interested, please come to one of our upcoming training sessions or take our on-line authentication course.
Included in the discussion of contextual authenticity is the next statement in the document, "Is the proffered evidence an original or an accurate reproduction of the original? F.R.E. 1002 and F.R.E. 1003."
Again, how would you know if you don't test? How do you test if you don't know how to conduct authenticity exams? What tools do you use? What does your experimental design look like?
The FRE, in 901(a) deals with "true and exact" or "bitstream" copies. These copies will hash the same - copy vs. original. But, when you create a proxy / working file, and there are errors in the process, the hash values will be different.
"Authentication testimony may include:
The retrieval method.
The condition of the original recording device and the accuracy of the resultant multimedia.
Time offsets and other observations noted during the retrieval.
Agency evidence and storage protocols.
Chain of custody documentation."
The retrieval method should be documented.
By placing the FRE notes in the document, but giving them a "drive-by" treatment, they're setting up the typical examiner for problems. Why? The audience for this document is not the examiner, per se. It's trial support technicians and attorneys. They're pointing out an obvious problem in the system - that contextual authentication must happen - without noting that so few examiners have the knowledge, skills, experience in this vital process.
Don't get me wrong, I'm not advocating for the elimination of authenticity exams. Quite the opposite, I'm one of the biggest proponents. What I'm saying here is that the document should do only one thing - render marginal technical advice on the "display" of evidence at trial. Leave the legal advice out completely. SWGDE is a loose collection of practitioners, not lawyers.
As always, if you have any issues with what you've read, please leave your (polite) comments below.
Have a good weekend my friends.
In Section 4, you'll find this guidance, "This should also include documentation of any persons contacted in relation to the evidence." Wow!
Consider whom you may have contacted?
- Your coworkers.
- Your supervisor.
- Others in your chain of command.
- Others outside of your chain of command.
- The FVA List.
If you sent a query to the FVA list, did you turn over a copy of your correspondence to the process in discovery? But more fundamentally, if you sent a query to the FVA list, did you have specific permission to do so. So many list members share copies of evidence on this relatively un-secure platform. If members of the FVA List shared opinions, did those opinions make it to discovery? Did you properly account for their opinions / their work if their opinions / work differs from yours?
In Section 5.1, there are a number of points that need to be considered.
First,"Has the proffered evidence been properly authenticated? F.R.E. 901, 902."
Wow again. Remember, "authentication" is different than "hash." Authentication deals with accuracy in context, not integrity in transport.
Also remember that the majority of programs used these days do not actually interact with the evidence files but create a proxy file via FFmpeg. This is certainly true of the major players in this space, Input-Ace and Amped FIVE.
I remember, when working for Amped Software, Inc., that many customers would contact us because FIVE's "conversion" of files (the creation of a proxy file) would result in a different frame count vs. the original data file. Naturally, the resulting file would not hash the same. But, testing the contextual authenticity is what FRE 901 & 902 is all about. Was there a material change in context that resulted from the creation of the "working copy?"
You wouldn't know if you didn't conduct even a basic authenticity exam.
Remember, contextual authentication is not a feature of LEVA's CFVT / CFVA programs. Neither is it a feature of the IAI's CFVE program. It is, however, one of the tested domains in the AVFA certification (see this post on these programs).
There are precious few people trained in contextual authentication or enabled by a valid and reliable tool set. If you're interested, please come to one of our upcoming training sessions or take our on-line authentication course.
Included in the discussion of contextual authenticity is the next statement in the document, "Is the proffered evidence an original or an accurate reproduction of the original? F.R.E. 1002 and F.R.E. 1003."
Again, how would you know if you don't test? How do you test if you don't know how to conduct authenticity exams? What tools do you use? What does your experimental design look like?
The FRE, in 901(a) deals with "true and exact" or "bitstream" copies. These copies will hash the same - copy vs. original. But, when you create a proxy / working file, and there are errors in the process, the hash values will be different.
"Authentication testimony may include:
The retrieval method.
The condition of the original recording device and the accuracy of the resultant multimedia.
Time offsets and other observations noted during the retrieval.
Agency evidence and storage protocols.
Chain of custody documentation."
The retrieval method should be documented.
- Did you retrieve it? If not, who did? Are they on the witness list?
- Are all of the device settings noted?
- Is the complete signal path - lens to hard drive - accounted for?
"The condition of the original recording device and the accuracy of the resultant multimedia" speaks to ground truth. How do you know that the resultant multimedia file is an accurate representation of events. How would you know? You test. Did you test? Did you disclose your test design / reports / results?
By placing the FRE notes in the document, but giving them a "drive-by" treatment, they're setting up the typical examiner for problems. Why? The audience for this document is not the examiner, per se. It's trial support technicians and attorneys. They're pointing out an obvious problem in the system - that contextual authentication must happen - without noting that so few examiners have the knowledge, skills, experience in this vital process.
Don't get me wrong, I'm not advocating for the elimination of authenticity exams. Quite the opposite, I'm one of the biggest proponents. What I'm saying here is that the document should do only one thing - render marginal technical advice on the "display" of evidence at trial. Leave the legal advice out completely. SWGDE is a loose collection of practitioners, not lawyers.
As always, if you have any issues with what you've read, please leave your (polite) comments below.
Have a good weekend my friends.
Wednesday, January 22, 2014
Image Authentication Assumptions
I recently received an e-mail from a reader with a single image attached. The question, has this image been altered? Simple question? Not really, it seems.
As a favor, I loaded it into Amped's Authenticate. Sure enough, the image has been through Photoshop as indicated by the various File Analysis filters. So, the image has been "altered."
It could be contextually accurate, even though it's been through Photoshop. Does a curves adjustment invalidate an image from use? The EXIF info shows a size change and a few other problems. But EXIF information can be spoofed. Other things about an image can be fabricated in an attempt to fool authentication software. So, if this was a trial, what would you do? How would you structure your enquiry?
Should I stake my name and reputation on a software's test against a single image without a reference? No way. Not a chance. Have you ever seen a Black Swan?
Thus, I would want a reference image. If the submission is purported to be a "camera original," then I should be able to test against a reference image from the same camera. In other words, I want your camera in my lab to conduct my authentication experiments.
Here's an example that I use in my Image Authentication classes. A person turns in a cell phone picture to the police as proof that a certain ticket and tow was unjustified. In my example, a person received a parking ticket for parking in front of a fire hydrant. The person is seeking not only to have the ticket voided, but is also seeking a refund on towing and impound fees. On the face of it, there is no hydrant in the image. Case closed? No.
To do a proper test, I need a reference image. I need the camera in my lab - in this case, the person's cell phone. I take the necessary reference pictures and find that the image submitted as evidence in traffic court to be a forgery. Oops! Submitting false evidence to the court is a big, big no-no.
The plot on the top is the DCT Plot of the evidence Image. If I have the phone, and I get the actual "original" image off the storage device, these plots should look the same. Obviously, they don't. There are other mismatches as I go through the process, but you get the idea.
The idea, and the point, is that it may be relatively easy to fool an authentication test without a valid reference. It is, however, very hard (Black Swan notwithstanding) to fool a test when you have a valid reference to test against.
The obvious message here is to not even try to submit forgeries into the court system.
But, the thing that scares me about as much as the above scenario is when law enforcement use their personal cell phones to document crime scenes. Here is one instance where "just trying to get something done" can get you into a bit of a bind. If there's a challenge to the authenticity of the images you've generated, we'll need your phone. Will you like what we find? Will you like us rooting around your phone's contents? Remember, if you receive a lawful order from your command to give up the phone to the investigation, it's a lawful order. Eliminate the potential problem and just use a separate point and shoot camera of decent quality, or engage your agency's official resources for photographing evidence.
Finally, and this one ties the whole thing together with the "screen capture rant" that I've been on. You use your personal cell phone to make a video of the monitor of a DVR at a crime scene. You use the video to make the images that lead to an arrest. All's well that ends well? No, hardly. If it turns out that the DVR had usable digital out options (like USB), and you didn't use it to secure the actual evidence, you've' just recorded yourself not properly securing the actual evidence. Oops. In that case, you may lose more than the use of your phone.
To wrap it all up, authentication is a powerful tool when done properly. It's a complex process that involves many moving pieces - the evidence file, the reference file, the reference source, procedures, chain of command, interviews, and so forth. If you're not able to account for the pieces of the puzzle, you may get an incomplete (wrong) picture.
As a favor, I loaded it into Amped's Authenticate. Sure enough, the image has been through Photoshop as indicated by the various File Analysis filters. So, the image has been "altered."
It could be contextually accurate, even though it's been through Photoshop. Does a curves adjustment invalidate an image from use? The EXIF info shows a size change and a few other problems. But EXIF information can be spoofed. Other things about an image can be fabricated in an attempt to fool authentication software. So, if this was a trial, what would you do? How would you structure your enquiry?
Should I stake my name and reputation on a software's test against a single image without a reference? No way. Not a chance. Have you ever seen a Black Swan?
Thus, I would want a reference image. If the submission is purported to be a "camera original," then I should be able to test against a reference image from the same camera. In other words, I want your camera in my lab to conduct my authentication experiments.
Here's an example that I use in my Image Authentication classes. A person turns in a cell phone picture to the police as proof that a certain ticket and tow was unjustified. In my example, a person received a parking ticket for parking in front of a fire hydrant. The person is seeking not only to have the ticket voided, but is also seeking a refund on towing and impound fees. On the face of it, there is no hydrant in the image. Case closed? No.
To do a proper test, I need a reference image. I need the camera in my lab - in this case, the person's cell phone. I take the necessary reference pictures and find that the image submitted as evidence in traffic court to be a forgery. Oops! Submitting false evidence to the court is a big, big no-no.
The plot on the top is the DCT Plot of the evidence Image. If I have the phone, and I get the actual "original" image off the storage device, these plots should look the same. Obviously, they don't. There are other mismatches as I go through the process, but you get the idea.
The idea, and the point, is that it may be relatively easy to fool an authentication test without a valid reference. It is, however, very hard (Black Swan notwithstanding) to fool a test when you have a valid reference to test against.
The obvious message here is to not even try to submit forgeries into the court system.
But, the thing that scares me about as much as the above scenario is when law enforcement use their personal cell phones to document crime scenes. Here is one instance where "just trying to get something done" can get you into a bit of a bind. If there's a challenge to the authenticity of the images you've generated, we'll need your phone. Will you like what we find? Will you like us rooting around your phone's contents? Remember, if you receive a lawful order from your command to give up the phone to the investigation, it's a lawful order. Eliminate the potential problem and just use a separate point and shoot camera of decent quality, or engage your agency's official resources for photographing evidence.
Finally, and this one ties the whole thing together with the "screen capture rant" that I've been on. You use your personal cell phone to make a video of the monitor of a DVR at a crime scene. You use the video to make the images that lead to an arrest. All's well that ends well? No, hardly. If it turns out that the DVR had usable digital out options (like USB), and you didn't use it to secure the actual evidence, you've' just recorded yourself not properly securing the actual evidence. Oops. In that case, you may lose more than the use of your phone.
To wrap it all up, authentication is a powerful tool when done properly. It's a complex process that involves many moving pieces - the evidence file, the reference file, the reference source, procedures, chain of command, interviews, and so forth. If you're not able to account for the pieces of the puzzle, you may get an incomplete (wrong) picture.
Friday, July 19, 2019
What is forensic science
As I prepare to head out to Orlando for next week's OSAC in-person meeting, I want to revisit one of the papers that the OSAC has issued since it's founding.
Consider that the OSAC is a group that includes all forensic science disciplines. Thus, in harmonizing the language used to describe what should be a simple term - forensic science - much work was done to arrive at a definition that works for all forensic science disciplines.
I've shared the highlights in several posts and papers. Here's the full discussion.
---
2. Forensic Science
A definition of forensic science should focus on the evidence scrutinized and the questions answered by the inquiry. After extensive research, surveys, and discussions, the TG formed the following understanding of the aim and purpose of forensic science:
Traces are the fundamental objects of study in forensic science. A trace is a vestige, left from a past event or activity, criminal or not. The principle that every contact leaves a trace was initially attributed to Edmond Locard, and has evolved into a new definition of the trace to include a lacuna in available evidence, as well as activities in virtual settings (Jaquet-Chiffelle, 2013):
A trace is any modification, subsequently observable, resulting from an event.
This is not to suggest that all forensic questions involve event reconstruction, merely that all traces involve some modification. Even immutable objects can be a trace when their occurrence in relation to a forensic inquiry is the consequence of an event (e.g., a mobile device identifier deposited at a crime scene, or DNA transferred onto a victim). The modification can affect an entity in an environment or the environment itself. Its nature can be physical or virtual, material or immaterial, analog or digital. It can reveal itself as a presence or as an absence.
Forensic science addresses questions, potentially across all forensic disciplines. These questions are addressed using a specific and finite number of core forensic processes. For the purpose of this document, these processes are labeled as: 1) authentication, 2) identification,
3) classification, 4) reconstruction, and 5) evaluation.
The following definition of forensic science emerged from this work:
The systematic and coherent study of traces to address questions of authentication, identification, classification, reconstruction, and evaluation for a legal context.
The term systematic in this definition encompasses empirically supported research, controlled experiments, and repeatable procedures applied to traces. The term coherent entails logical reasoning and methodology. This definition uses legal context in the broadest terms, including the typical criminal, civil, and regulatory functions of the legal system, as well as its extensions such as human rights, employment, natural disasters, security matters.
---
Continuing on ...
---
3. Digital/Multimedia Evidence
To understand the scientific foundations of digital/multimedia evidence and how this fits into forensic science, it is necessary to consider the specializations of digital/multimedia evidence. Digital/multimedia evidence encompasses the following sub-disciplines (ed. note: edited for brevity), which are organized according to the current OSAC structure:
Video/image technology and analysis: handling images and videos for forensic purposes. This includes classification and identification of items, such as comparing an item in an image or video with a known item (e.g., car, jacket). This also includes authentication of images and videos, metadata analysis, Photo Response Non-Uniformity (PRNU) analysis, image quality assessment, and detection of manipulation. Operational techniques include image and video enhancement and restoration.
Digital evidence: handling digital traces for forensic purposes, including classification and identification of items, activity reconstruction, detection of manipulation (e.g., authentication of digital document, concealment of evidence). Within the current OSAC structure, audio recordings are treated as a form of digital evidence for enhancement and authentication purposes.
The foundational sciences for the various sub-disciplines of digital/multimedia evidence are primarily biology, physics, and mathematics, but also include: computer science, computer engineering, image science, video and television engineering, acoustics, linguistics, anthropology, statistics, and data science. Principles of these, and other disciplines, are applied to the traces, data, and systems examined by forensic scientists. Study of foundational principles in digital/multimedia evidence is ongoing, with consideration for their suitability in forensic science applications.
Furthermore, many digital traces are changes to the state of a computer system resulting from user actions. In this context, the discovery of principles in how computer systems function, is a fundamental scientific aspect of digital/multimedia evidence. The systematic and coherent study of digital/multimedia evidence is made more complicated by the evolving nature of technology and its use. While the foundations of digital/multimedia evidence are largely in computer science, computer engineering, image science, video and television engineering, and data science, the underlying digital traces are, in large part, created by actions of operating systems, programs, and hardware that are under constant development. As a result, it will not always be possible to test in advance the performance of such systems under every possible combination of variables that may arise in casework. However, it may be possible, to test the performance of a particular system under a particular set of variables in order to address questions arising in a specific case. For instance, digital documents created using a new version of word processing software can exhibit digital traces that were not previously known. The observed traces can be understood by conducting experiments; studying the software under controlled conditions. In this manner, generalized knowledge of digital/multimedia evidence is established and can be used by any forensic scientists to obtain reproducible, widely accepted results.
---
It's this last paragraph that I'll finish with. Notice these statements:
Consider that the OSAC is a group that includes all forensic science disciplines. Thus, in harmonizing the language used to describe what should be a simple term - forensic science - much work was done to arrive at a definition that works for all forensic science disciplines.
I've shared the highlights in several posts and papers. Here's the full discussion.
---
2. Forensic Science
A definition of forensic science should focus on the evidence scrutinized and the questions answered by the inquiry. After extensive research, surveys, and discussions, the TG formed the following understanding of the aim and purpose of forensic science:
Traces are the fundamental objects of study in forensic science. A trace is a vestige, left from a past event or activity, criminal or not. The principle that every contact leaves a trace was initially attributed to Edmond Locard, and has evolved into a new definition of the trace to include a lacuna in available evidence, as well as activities in virtual settings (Jaquet-Chiffelle, 2013):
A trace is any modification, subsequently observable, resulting from an event.
This is not to suggest that all forensic questions involve event reconstruction, merely that all traces involve some modification. Even immutable objects can be a trace when their occurrence in relation to a forensic inquiry is the consequence of an event (e.g., a mobile device identifier deposited at a crime scene, or DNA transferred onto a victim). The modification can affect an entity in an environment or the environment itself. Its nature can be physical or virtual, material or immaterial, analog or digital. It can reveal itself as a presence or as an absence.
Forensic science addresses questions, potentially across all forensic disciplines. These questions are addressed using a specific and finite number of core forensic processes. For the purpose of this document, these processes are labeled as: 1) authentication, 2) identification,
3) classification, 4) reconstruction, and 5) evaluation.
The following definition of forensic science emerged from this work:
The systematic and coherent study of traces to address questions of authentication, identification, classification, reconstruction, and evaluation for a legal context.
The term systematic in this definition encompasses empirically supported research, controlled experiments, and repeatable procedures applied to traces. The term coherent entails logical reasoning and methodology. This definition uses legal context in the broadest terms, including the typical criminal, civil, and regulatory functions of the legal system, as well as its extensions such as human rights, employment, natural disasters, security matters.
---
Continuing on ...
---
3. Digital/Multimedia Evidence
To understand the scientific foundations of digital/multimedia evidence and how this fits into forensic science, it is necessary to consider the specializations of digital/multimedia evidence. Digital/multimedia evidence encompasses the following sub-disciplines (ed. note: edited for brevity), which are organized according to the current OSAC structure:
Video/image technology and analysis: handling images and videos for forensic purposes. This includes classification and identification of items, such as comparing an item in an image or video with a known item (e.g., car, jacket). This also includes authentication of images and videos, metadata analysis, Photo Response Non-Uniformity (PRNU) analysis, image quality assessment, and detection of manipulation. Operational techniques include image and video enhancement and restoration.
Digital evidence: handling digital traces for forensic purposes, including classification and identification of items, activity reconstruction, detection of manipulation (e.g., authentication of digital document, concealment of evidence). Within the current OSAC structure, audio recordings are treated as a form of digital evidence for enhancement and authentication purposes.
The foundational sciences for the various sub-disciplines of digital/multimedia evidence are primarily biology, physics, and mathematics, but also include: computer science, computer engineering, image science, video and television engineering, acoustics, linguistics, anthropology, statistics, and data science. Principles of these, and other disciplines, are applied to the traces, data, and systems examined by forensic scientists. Study of foundational principles in digital/multimedia evidence is ongoing, with consideration for their suitability in forensic science applications.
Furthermore, many digital traces are changes to the state of a computer system resulting from user actions. In this context, the discovery of principles in how computer systems function, is a fundamental scientific aspect of digital/multimedia evidence. The systematic and coherent study of digital/multimedia evidence is made more complicated by the evolving nature of technology and its use. While the foundations of digital/multimedia evidence are largely in computer science, computer engineering, image science, video and television engineering, and data science, the underlying digital traces are, in large part, created by actions of operating systems, programs, and hardware that are under constant development. As a result, it will not always be possible to test in advance the performance of such systems under every possible combination of variables that may arise in casework. However, it may be possible, to test the performance of a particular system under a particular set of variables in order to address questions arising in a specific case. For instance, digital documents created using a new version of word processing software can exhibit digital traces that were not previously known. The observed traces can be understood by conducting experiments; studying the software under controlled conditions. In this manner, generalized knowledge of digital/multimedia evidence is established and can be used by any forensic scientists to obtain reproducible, widely accepted results.
---
It's this last paragraph that I'll finish with. Notice these statements:
- "However, it may be possible, to test the performance of a particular system under a particular set of variables in order to address questions arising in a specific case."
- "The observed traces can be understood by conducting experiments; studying the software under controlled conditions. In this manner, generalized knowledge of digital/multimedia evidence is established and can be used by any forensic scientists to obtain reproducible, widely accepted results."
These statements have to do with validation and experimental design. Are you validating your tools? Are you conducting experiments, following the rules of experimental design?
If you'd like to explore these concepts, we've got classes that address most of the topics illustrated in this section of the document. Check out our calendar. If you find a date / class that works for your schedule, sign up. If you can't find a date that works, suggest one. We're here to help.
See you in Orlando.
Thursday, May 17, 2012
Where are we going?
California has essentially declared war on images (and reason) - requiring "blind" authentication of images that are used in trial. A simple "that's not me," and off we go down the winding hole. In essence, authentication is on everyone's mind these days.
The ruling caught everyone by surprise. The criminal justice system just wasn't ready to dive into this mess. There aren't enough "experts" to go around, there aren't enough commercially available choices to readily perform authentication tasks, and the results ... well, let's just say that people of good will can disagree.
Nevertheless, all is not lost. I've seen what's just around the corner and I like what I see. I've been privileged to kick the tyres of some new software, as well as some completely redesigned stuff from a name that you know. I'll break the news when I'm allowed to.
I just wanted to say that all is not lost. There's affordable software on the horizon that combines image and video processing, detailed reporting, "forensic" viability, and a good training schedule. All the things that we need to tackle this authentication mess.
For the most part, "blind authentication" is a mad man's game. Who can prove a negative? But, if an allegation of forgery is made ... a specific allegation ... then we can test for it. That's what I'm talking about with what's on the horizon.
Stay tuned.
The ruling caught everyone by surprise. The criminal justice system just wasn't ready to dive into this mess. There aren't enough "experts" to go around, there aren't enough commercially available choices to readily perform authentication tasks, and the results ... well, let's just say that people of good will can disagree.
Nevertheless, all is not lost. I've seen what's just around the corner and I like what I see. I've been privileged to kick the tyres of some new software, as well as some completely redesigned stuff from a name that you know. I'll break the news when I'm allowed to.
I just wanted to say that all is not lost. There's affordable software on the horizon that combines image and video processing, detailed reporting, "forensic" viability, and a good training schedule. All the things that we need to tackle this authentication mess.
For the most part, "blind authentication" is a mad man's game. Who can prove a negative? But, if an allegation of forgery is made ... a specific allegation ... then we can test for it. That's what I'm talking about with what's on the horizon.
Stay tuned.
Friday, February 15, 2013
NaTIA Pacific Chapter Meeting News
The dates have been set for the NaTIA Pacific Chapter's Spring Meeting. We'll be in Pasadena, at the historic Scottish Rite Cathedral, April 15-18.
Among other business, including the vendor showcase, I'll be presenting the following seminars:
1. FVA of native IP cam (Milestone) footage with AmpedFIVE (2 hours)
With the roll-out of IP cameras, it goes without saying that some of the footage will need to be enhanced or clarified. This session will illustrate how Amped FIVE can work with the native Milestone files that come from cameras like Axis (the most popular cameras in the law enforcement arsenal) as well as work with the live feed, dialing into the camera/server directly and performing enhancements to the live feed.
2. Authentication of digital images (2 hours)
Programs like JPEG Snoop and FourMatch are based on a database of camera signatures. Thus, they are not effective in authenticating images from social media, DVRs, or deleted images carved from cell phone data dumps. Contextual authentication - has the image been altered through cut/paste or delete - is at the heart of most requests for authentication of digital images in our courts. This session will illustrate the many domains of contextual authentication using Amped's Authenticate.
The meeting is open to dues current NaTIA members and is a LE only event. If you are an active LE employee involved in surveillance or digital forensics, consider joining the National Technical Investigators Association. The annual dues are still only $25.
Among other business, including the vendor showcase, I'll be presenting the following seminars:
1. FVA of native IP cam (Milestone) footage with AmpedFIVE (2 hours)
With the roll-out of IP cameras, it goes without saying that some of the footage will need to be enhanced or clarified. This session will illustrate how Amped FIVE can work with the native Milestone files that come from cameras like Axis (the most popular cameras in the law enforcement arsenal) as well as work with the live feed, dialing into the camera/server directly and performing enhancements to the live feed.
2. Authentication of digital images (2 hours)
Programs like JPEG Snoop and FourMatch are based on a database of camera signatures. Thus, they are not effective in authenticating images from social media, DVRs, or deleted images carved from cell phone data dumps. Contextual authentication - has the image been altered through cut/paste or delete - is at the heart of most requests for authentication of digital images in our courts. This session will illustrate the many domains of contextual authentication using Amped's Authenticate.
The meeting is open to dues current NaTIA members and is a LE only event. If you are an active LE employee involved in surveillance or digital forensics, consider joining the National Technical Investigators Association. The annual dues are still only $25.
Sunday, March 29, 2009
Preference for originals?
California has a unique exception to the "Best Evidence Rule." California Evidence Code Section 1521 states:
1521. (a) The content of a writing may be proved by otherwise admissible secondary evidence. The court shall exclude secondary evidence of the content of writing if the court determines either of the following:
(1) A genuine dispute exists concerning material terms of the writing and justice requires the exclusion.
(2) Admission of the secondary evidence would be unfair.
(b) Nothing in this section makes admissible oral testimony to prove the content of a writing if the testimony is inadmissible under Section 1523 (oral testimony of the content of a writing).
(c) Nothing in this section excuses compliance with Section 1401 (authentication).
(d) This section shall be known as the "Secondary Evidence Rule."
(1) A genuine dispute exists concerning material terms of the writing and justice requires the exclusion.
(2) Admission of the secondary evidence would be unfair.
(b) Nothing in this section makes admissible oral testimony to prove the content of a writing if the testimony is inadmissible under Section 1523 (oral testimony of the content of a writing).
(c) Nothing in this section excuses compliance with Section 1401 (authentication).
(d) This section shall be known as the "Secondary Evidence Rule."
Here's the reference to 1401:
1400. Authentication of a writing means (a) the introduction of evidence sufficient to sustain a finding that it is the writing that the proponent of the evidence claims it is or (b) the establishment of such facts by any other means provided by law.
1401. (a) Authentication of a writing is required before it may be received in evidence.
(b) Authentication of a writing is required before secondary evidence of its content may be received in evidence.
1402. The party producing a writing as genuine which has been altered, or appears to have been altered, after its execution, in a part material to the question in dispute, must account for the alteration or appearance thereof. He may show that the alteration was made by another, without his concurrence, or was made with the consent of the parties affected by it, or otherwise properly or innocently made, or that the alteration did not change the meaning or language of the instrument. If he does that, he may give the writing in evidence, but not otherwise.
1401. (a) Authentication of a writing is required before it may be received in evidence.
(b) Authentication of a writing is required before secondary evidence of its content may be received in evidence.
1402. The party producing a writing as genuine which has been altered, or appears to have been altered, after its execution, in a part material to the question in dispute, must account for the alteration or appearance thereof. He may show that the alteration was made by another, without his concurrence, or was made with the consent of the parties affected by it, or otherwise properly or innocently made, or that the alteration did not change the meaning or language of the instrument. If he does that, he may give the writing in evidence, but not otherwise.
The problem here lies in the fact that the success or failure of a challenge based on these areas of the evidence code depends entirely upon the judge. Also, finding evidence of success or failure in challenging based on these is really tough as these challenges don't often make the headlines or swing entire cases.
Wednesday, October 10, 2012
FourMatch in an Image Authentication Workflow
Four and Six recently posted the latest in a series of blog posts placing their new FourMatch authentication tool in context within the larger image authentication workflow.
" ... The biggest strength of FourMatch is its ability to provide compelling evidence that an image file has not been modified since it was first captured. However, FourMatch is not designed to tell you whether an image is untruthful. It merely tells you whether the photo remains in the pristine state it would be in coming direct from the camera. That means that many files that fail the FourMatch test may still be truthful images. Perhaps someone just cropped the image without altering the remaining photo content. Or perhaps someone just re-saved the photo using a higher degree of JPEG compression in order to make the file smaller to upload to the Internet. Both of these changes would cause the resulting file to fail the FourMatch test, even though the actual content of the file is still reliable ..."
" ... Let’s start with considering FourMatch as a standalone authentication measure. Particularly within a legal setting, there are many times when people may need assurance that an image can be trusted, particularly given the ease with which images can be manipulated with modern software ..." Two things come to mind, is it possible that an image is authentic, completely untouched by software, yet fail the test? Meet the black swan. Even though their database is quite robust, it still needs updating regularly. Thus, the software - given the tremendous head start - will play catch up as new phones and cameras come out. Not finding that black swan depends on keeping your subscription up to date, keeping your local database up to date, and Four and Six keeping their end up to date. Also, as it's software and it's database driven, can it be spoofed? Hmmm.
At this point, I think it's abundantly clear what FourMatch is and isn't. The question now is ... is it worth the initial price + on-going subscription (+ off-line surcharge for those folks who have an un-internet-connected lab) for what it provides? Given that a lot of folks haven't upgraded from Photoshop CS3, this cost also includes upgrading Photoshop as well.
" ... The biggest strength of FourMatch is its ability to provide compelling evidence that an image file has not been modified since it was first captured. However, FourMatch is not designed to tell you whether an image is untruthful. It merely tells you whether the photo remains in the pristine state it would be in coming direct from the camera. That means that many files that fail the FourMatch test may still be truthful images. Perhaps someone just cropped the image without altering the remaining photo content. Or perhaps someone just re-saved the photo using a higher degree of JPEG compression in order to make the file smaller to upload to the Internet. Both of these changes would cause the resulting file to fail the FourMatch test, even though the actual content of the file is still reliable ..."
" ... Let’s start with considering FourMatch as a standalone authentication measure. Particularly within a legal setting, there are many times when people may need assurance that an image can be trusted, particularly given the ease with which images can be manipulated with modern software ..." Two things come to mind, is it possible that an image is authentic, completely untouched by software, yet fail the test? Meet the black swan. Even though their database is quite robust, it still needs updating regularly. Thus, the software - given the tremendous head start - will play catch up as new phones and cameras come out. Not finding that black swan depends on keeping your subscription up to date, keeping your local database up to date, and Four and Six keeping their end up to date. Also, as it's software and it's database driven, can it be spoofed? Hmmm.
At this point, I think it's abundantly clear what FourMatch is and isn't. The question now is ... is it worth the initial price + on-going subscription (+ off-line surcharge for those folks who have an un-internet-connected lab) for what it provides? Given that a lot of folks haven't upgraded from Photoshop CS3, this cost also includes upgrading Photoshop as well.
Thursday, December 26, 2013
Academic sources for authentication of digital images
For folks needing references for their authentication work, here's a short list (in no particular order):
- E. Kee, M.K. Johnson and H. Farid, "Digital image authentication from JPEG headers", IEEE Transactions on Information Forensics and Security, vol. 6, pp. 1066-1075, 2011.
- J. Kornblum, "Using JPEG quantization tables to identify imagery processed by software", Digital Investigation, vol. 5, pp. S21–S25, 2008.
- CCITT Recommendation T.81, ISO/IEC 10918-1:1994, "Information technology - Digital compression and coding of continuous-tone still images: Requirements and guidelines ", 1992.
- Z. Lin, J. He, X. Tang, Chi K. Tang "Fast, automatic and fine-grained tampered JPEG image detection via DCT coefficient analysis", Journal Pattern Recognition, Vol. 42, pp. 2492-2501, 2009.
- Alin C. Popescu and H. Farid, "Statistical tools for digital forensics", Lecture Notes in Computer Science, vol. 3200, pp 128-147, 2005.
- H. Farid, "Exposing digital forgeries from JPEG ghosts", IEEE Transactions on Information Forensics and Security, vol. 4, pp. 154-160, 2009.
- M.C. Stamm and K.J.R. Liu, "Forensic Detection of Image Tampering Using Intrinsic Statistical Fingerprints in Histograms", IEEE Transactions on Information Forensics and Security, vol. 5, pp. 492-506, 2010.
- J. Lukas, J. Fridrich and M. Goljan, "Digital Camera Identification from Sensor Noise ", IEEE Transactions on Information Security and Forensics, pp. 205-214, 2006.
- Mo Chen, J. Fridrich and M. Goljan , "Digital Imaging Sensor Identification (Further Study)", Proceedings. of SPIE Electronic Imaging, Security, Steganography and Watermarking of Multimedia Contents, pp. 0P-0Q, 2007.
- W. Wang, J. Dong and T. Tan, "Tampered Region Localization of Digital Color Images Based on JPEG Compression Noise", Proceedings of the 9th International Conference on Digital watermarking, pp. 120-133, 2010.
- R. Gonzalez and R. Woods, "Digital Image Processing (3rd ed.)", Prentice Hall, pp. 165–168, 2008.
- M. Kirchner and T. Gloe, "On Resampling Detection in Re-compressed Images". IEEE Workshop on Information Forensics and Security, pp. 21-25, 2009.
Monday, August 26, 2019
Demonstrative exhibits and reconstruction of events
My last post generated a few responses that I want to address in a separate post, as opposed to editing the previous post. A few people got the impression that I was saying that what folks are doing with ACE's Camera Match Overlay isn't "forensic science" or "forensic video analysis." That's not at all what I was saying. Let's dive into that question to explain.
First, the definition of forensic science again: "Forensic science is the systematic and coherent study of traces to address questions of authentication, identification, classification, reconstruction, and evaluation for a legal context."
Forensic science thus includes:
The type of work performed in the examples on ACE's websit clearly indicate that the Camera Match Overlay is a tool for reconstruction. This is how the product is being positioned in the market. Camera Match Overlay is an addition to ACE, and not part of it's basic functionality. If you're not involved in reconstruction, you can skip the Overlay tool and save a few bucks.
What ACE's basic functionality excels at is "evaluation." What's in the container? How should it be handled? Those File Triage type questions. Once answered, it's a short trip to repackaging the data in a format that is playable for the end user. But remember, evaluation has it's own set of rules.
ACE is also really good at reconstruction - the syncing and linking separate video streams. Reconstruction has it's own rules, workflow, and toolset. Reconstruction attempts to illustrate a theory of the sequence of events in question. Reconstruction is not authentication, identification, or classification - which have their own rules, workflows, and toolsets.
With that in mind, the second set of questions deals with training and tools.
A 16 hour training session on Camera Match Overlay's operation and use is likely sufficient for a technician to be able know which buttons do what functions across a variety of use cases. What it is not is a comprehensive education on photogrammetry. Because the focus of tool-specific training is the tool, we've split off the foundational education side as separate, non-tool-specific deep dives so that you get an unbiased exploration of the discipline from a neutral third party. If you're giving technician level testimony (no opinion offered), tool-specific training is likely enough. But, if you're offering an opinion (even passively), then you need a foundational education in the discipline in which you're engaged.
The third set of questions deals with the legal aspects of evidence hearings.
Keeping in mind that I'm not an attorney, consider the evidence hearing's rules (Frye / Daubert). Both types of hearings have as a foundational element what is commonly known as the “general acceptance test.” Generally accepted scientific methods are admissible, and those that are not sufficiently established are inadmissible.
Can a tool or technique without a history of publication or validation be "sufficiently established?"
Camera Match Overlay technology is new. It's the "shiny new object" for reconstruction exercises. The resulting videos become an amazing demonstrative aid to one's testimony, using the power of stunning visuals to illustrate one's theory of a case. But, bear in mind that it's only a demonstrative illustration of a single theory. There may be other theories worthy of exploration. If you're engaged in science, Daubert requires that you explore those other theories. If you're just engaged in trial support, and thus have no opinion, then go right ahead and create those stunning visuals.
All of this requires a bit of honesty. When I've simply retrieved files, I'm engaged in technician level work. When I've clarified and enlarged a frame, I've engaged in technician level work. These activities can support an analysis, and thus help to illustrate one's opinion, but they're not "analysis" in and of themselves. From the Frye ruling, "while courts will go a long way in admitting expert testimony deduced from a well-recognized scientific principle of discovery, the thing from which the deduction is made must be sufficiently established to have gained general acceptance in the field in which it belongs." When I want to offer an opinion, I must use tools and techniques that have been sufficiently established in my field. If I want to use "reconstruction" tools to reinforce my opinion in an "identification" exam, those tools must be sufficiently established within the realm of "identification." At this time, there are no studies validating the use of the Camera Match Overlay technology and methods for "identification" or "classification."
There are no studies involving the product at all. It's brand new. I'm certainly open to participating in validation studies, if anyone want to engage in our services. But for now, Camera Match Overlay seems to belong to the world of reconstruction until validated otherwise.
Thanks for reading. Have a great day my friends.
First, the definition of forensic science again: "Forensic science is the systematic and coherent study of traces to address questions of authentication, identification, classification, reconstruction, and evaluation for a legal context."
Forensic science thus includes:
- authentication
- identification
- classification
- reconstruction
- evaluation
The type of work performed in the examples on ACE's websit clearly indicate that the Camera Match Overlay is a tool for reconstruction. This is how the product is being positioned in the market. Camera Match Overlay is an addition to ACE, and not part of it's basic functionality. If you're not involved in reconstruction, you can skip the Overlay tool and save a few bucks.
What ACE's basic functionality excels at is "evaluation." What's in the container? How should it be handled? Those File Triage type questions. Once answered, it's a short trip to repackaging the data in a format that is playable for the end user. But remember, evaluation has it's own set of rules.
ACE is also really good at reconstruction - the syncing and linking separate video streams. Reconstruction has it's own rules, workflow, and toolset. Reconstruction attempts to illustrate a theory of the sequence of events in question. Reconstruction is not authentication, identification, or classification - which have their own rules, workflows, and toolsets.
With that in mind, the second set of questions deals with training and tools.
A 16 hour training session on Camera Match Overlay's operation and use is likely sufficient for a technician to be able know which buttons do what functions across a variety of use cases. What it is not is a comprehensive education on photogrammetry. Because the focus of tool-specific training is the tool, we've split off the foundational education side as separate, non-tool-specific deep dives so that you get an unbiased exploration of the discipline from a neutral third party. If you're giving technician level testimony (no opinion offered), tool-specific training is likely enough. But, if you're offering an opinion (even passively), then you need a foundational education in the discipline in which you're engaged.
The third set of questions deals with the legal aspects of evidence hearings.
Keeping in mind that I'm not an attorney, consider the evidence hearing's rules (Frye / Daubert). Both types of hearings have as a foundational element what is commonly known as the “general acceptance test.” Generally accepted scientific methods are admissible, and those that are not sufficiently established are inadmissible.
Can a tool or technique without a history of publication or validation be "sufficiently established?"
Camera Match Overlay technology is new. It's the "shiny new object" for reconstruction exercises. The resulting videos become an amazing demonstrative aid to one's testimony, using the power of stunning visuals to illustrate one's theory of a case. But, bear in mind that it's only a demonstrative illustration of a single theory. There may be other theories worthy of exploration. If you're engaged in science, Daubert requires that you explore those other theories. If you're just engaged in trial support, and thus have no opinion, then go right ahead and create those stunning visuals.
All of this requires a bit of honesty. When I've simply retrieved files, I'm engaged in technician level work. When I've clarified and enlarged a frame, I've engaged in technician level work. These activities can support an analysis, and thus help to illustrate one's opinion, but they're not "analysis" in and of themselves. From the Frye ruling, "while courts will go a long way in admitting expert testimony deduced from a well-recognized scientific principle of discovery, the thing from which the deduction is made must be sufficiently established to have gained general acceptance in the field in which it belongs." When I want to offer an opinion, I must use tools and techniques that have been sufficiently established in my field. If I want to use "reconstruction" tools to reinforce my opinion in an "identification" exam, those tools must be sufficiently established within the realm of "identification." At this time, there are no studies validating the use of the Camera Match Overlay technology and methods for "identification" or "classification."
There are no studies involving the product at all. It's brand new. I'm certainly open to participating in validation studies, if anyone want to engage in our services. But for now, Camera Match Overlay seems to belong to the world of reconstruction until validated otherwise.
Thanks for reading. Have a great day my friends.
Monday, December 22, 2014
PhotoDetective - first look
A few weeks ago, I alerted you to a Kickstarter campaign around a new image authentication product called PhotoDetective. Well, I've put my copy through a few tests and it's time to share the results.
The program is quite simple to use. It has a very clean/lean interface - almost too lean. It has a few of the basic authentication algorithms that you've come to expect. But, nothing fancy. No reporting. What you see is what you get.
Your basic Exif tools are there. You can export the info to a text file.
It's all menu driven.
Some of the filters are self explanatory, some aren't (if you're unfamiliar with the science of authentication). There's no title to the results - if you want to screen capture your resulting images.
There's also no comparative function. Sure, it gives you a basic look at the QT - but you'll have to do the work to make sure it's right.
Now, the results:
The program is quite simple to use. It has a very clean/lean interface - almost too lean. It has a few of the basic authentication algorithms that you've come to expect. But, nothing fancy. No reporting. What you see is what you get.
Your basic Exif tools are there. You can export the info to a text file.
It's all menu driven.
Some of the filters are self explanatory, some aren't (if you're unfamiliar with the science of authentication). There's no title to the results - if you want to screen capture your resulting images.
There's also no comparative function. Sure, it gives you a basic look at the QT - but you'll have to do the work to make sure it's right.
Now, the results:
- For my cut/delete/paint over tests - it found the problems rather easily as long as they were blatant. For my more subtly changed images, I found what I was looking for only because I knew where I was looking. I could probably fool the average user into a false negative (a false conclusion of no evidence of tampering).
- For my cut/paste tests - again, it did well with the blatant examples and not so well with the subtle ones.
To be sure, there's nothing wrong (per se) with the program. It's very basic in its functionality. The problem will come when people buy this as their only tool. As I noted above, it could lead to a lot of false negatives when wielded by an untrained user.
In all, limited but not bad for $30 when used by a trained analyst. In untrained hands ... OMG.
Tuesday, August 20, 2019
Authentication education - now available on-line
I've been teaching authentication for many years. I've been all over the US and Canada presenting in classes big and small. Now, I've taken the big leap. My comprehensive educational course, Introduction to Forensic Multimedia Authentication, is available on-line as micro-learning.
This course lays the foundation for your work with your preferred tool. Current research, best practices, standards, and work flows are covered for audio, images, video, and the meta-data that are found in evidence files. If you'd like to see what is covered, here's the syllabus. This offering is the same as the in-person 40 hour course, which you can now do on-line. Because it's on-line, I can offer it to you for a much lower price than an in-person offering. Plus, you can take up to 60 days to complete it.
This course moves beyond the buttons of your preferred tool to lay the foundations for the work that you do. As such, it will assist you in explaining your work in your reports and in your testimony.
Click on the course link above. Check out the syllabus. Sign up today.
This course lays the foundation for your work with your preferred tool. Current research, best practices, standards, and work flows are covered for audio, images, video, and the meta-data that are found in evidence files. If you'd like to see what is covered, here's the syllabus. This offering is the same as the in-person 40 hour course, which you can now do on-line. Because it's on-line, I can offer it to you for a much lower price than an in-person offering. Plus, you can take up to 60 days to complete it.
This course moves beyond the buttons of your preferred tool to lay the foundations for the work that you do. As such, it will assist you in explaining your work in your reports and in your testimony.
Click on the course link above. Check out the syllabus. Sign up today.
Wednesday, October 17, 2012
Meet Amped Software at the LEVA Conference
This just in from Amped Software:
We are happy to announce that we’ll be present at the Law Enforcement & Emergency Services Video Association (LEVA) 2012 Annual Training Conference on October 22-26, 2012 at the BAHIA Hotel in San Diego, California.
We will be demonstrating and showcasing the new 2012 version of our popular Amped Five Professional forensic video enhancement software. VideoScanner, our new product for forensic video e-discovery, will be shown in action at our booth. This is a new tool that can save countless hours for investigators looking for video evidence on a suspect’s computer.
Training conferences like LEVA are very important for us: with respect to other kind of events, here we have the possibility to be in touch with our actual end users and meet with world class forensic video analysts. Here we can present our technology to experts who can fully understand its potential and give concrete feedback for its further improvement. For this reason we are presenting here not only our popular software for forensic video analysis, Amped Five, but also our latest projects.
In particular with VideoScanner we created a very simple tool which can save hours looking and inspecting video files in digital forensic cases. VideoScanner allows the investigator to quickly extract few representative frames to all the videos found on a device for a efficient inspection. As a bonus it add several forensic facilities, such as the possibility to calculate the hash code on all the analyzed files and the automatic creation of the analysis report.
We are using this conference to show a preview of Authenticate, our new project which for digital photo authentication. Authenticate will incorporate an innovative workflow concept into a ground-breaking software for image authentication within a feature-packed, but easy to use, user experience. We see this as a critical tool for prosecutors and investigators in states such as California in light of the recent Beckley court ruling on requirements for digital evidence authentication. Evidence is being challenged in courts on the basis of authenticity and Authenticate will provide several tools for evaluating the originality of an image. We are offering several types of tools in Authenticate and have combined several different techniques, from simple metadata and quantization table analysis to actual pixel value inspection and cutting edge techniques used to specifically match an image to a camera or device.
At LEVA, Amped Software will be in booth 122 in the main exhibit hall. We have donated a VideoScanner tool for the LEVA Door Prize Drawing. You have to be present to win, so we'll see you there!
We are happy to announce that we’ll be present at the Law Enforcement & Emergency Services Video Association (LEVA) 2012 Annual Training Conference on October 22-26, 2012 at the BAHIA Hotel in San Diego, California.
We will be demonstrating and showcasing the new 2012 version of our popular Amped Five Professional forensic video enhancement software. VideoScanner, our new product for forensic video e-discovery, will be shown in action at our booth. This is a new tool that can save countless hours for investigators looking for video evidence on a suspect’s computer.
Training conferences like LEVA are very important for us: with respect to other kind of events, here we have the possibility to be in touch with our actual end users and meet with world class forensic video analysts. Here we can present our technology to experts who can fully understand its potential and give concrete feedback for its further improvement. For this reason we are presenting here not only our popular software for forensic video analysis, Amped Five, but also our latest projects.
In particular with VideoScanner we created a very simple tool which can save hours looking and inspecting video files in digital forensic cases. VideoScanner allows the investigator to quickly extract few representative frames to all the videos found on a device for a efficient inspection. As a bonus it add several forensic facilities, such as the possibility to calculate the hash code on all the analyzed files and the automatic creation of the analysis report.
We are using this conference to show a preview of Authenticate, our new project which for digital photo authentication. Authenticate will incorporate an innovative workflow concept into a ground-breaking software for image authentication within a feature-packed, but easy to use, user experience. We see this as a critical tool for prosecutors and investigators in states such as California in light of the recent Beckley court ruling on requirements for digital evidence authentication. Evidence is being challenged in courts on the basis of authenticity and Authenticate will provide several tools for evaluating the originality of an image. We are offering several types of tools in Authenticate and have combined several different techniques, from simple metadata and quantization table analysis to actual pixel value inspection and cutting edge techniques used to specifically match an image to a camera or device.
At LEVA, Amped Software will be in booth 122 in the main exhibit hall. We have donated a VideoScanner tool for the LEVA Door Prize Drawing. You have to be present to win, so we'll see you there!
Sunday, January 24, 2010
Authentication fun
Authentication has become more interesting with the invention of the iPhone and its associated apps.
A friend sent this picture to me for authentication. He mentioned that a friend of his had shot this during a training session, and that there was a ghost in the tree line. He wanted to know what I thought about it, if there was indeed a ghost in the tree line.
The short answer is, yes, there is a ghost of a soldier in the tree line.
The image was sent from one friend to another via iPhones. There was no use of Photoshop ... is the image authentic?
Well ... not really. The iPhone has a free app called Ghost Capture. It can add any number of ghost images to photos shot with your iPhone ... including the "Gettysburg Soldier."
My friend was suspicious of the image from the beginning. His suspicions were warranted.
Enjoy.
A friend sent this picture to me for authentication. He mentioned that a friend of his had shot this during a training session, and that there was a ghost in the tree line. He wanted to know what I thought about it, if there was indeed a ghost in the tree line.
The short answer is, yes, there is a ghost of a soldier in the tree line.
The image was sent from one friend to another via iPhones. There was no use of Photoshop ... is the image authentic?
Well ... not really. The iPhone has a free app called Ghost Capture. It can add any number of ghost images to photos shot with your iPhone ... including the "Gettysburg Soldier."
My friend was suspicious of the image from the beginning. His suspicions were warranted.
Enjoy.
Wednesday, July 14, 2010
Authentication of on-line images
From People v Beckley, et all (B212529 - Ca. 2nd Appellate District): "In this opinion we hold that the prosecution‘s failure to authenticate a photograph and "gang roster" downloaded from internet web sites should have barred their admission but that the errors were harmless as to both defendants. We also conclude there was insufficient evidence to support the street gang enhancement of each defendant‘s sentence. We modify the judgments as to each defendant by striking the street gang enhancements. We further modify Finn‘s judgment by striking the gun use enhancements under Penal Code section 12022.53, subdivisions (b) through (d) and remand for resentencing."
"In rebuttal to Beckley‘s and Fulmore‘s testimony denying Beckley‘s gang involvement, Detective Schoonmaker testified regarding gang-related evidence he recovered from the MySpace.com internet accounts of Finn and Beckley"
"To rebut Fulmore‘s testimony that she did not associate with the Southside Compton Crips and that she insisted Beckley stop his association with the gang, the prosecution offered a photograph purportedly showing Fulmore flashing the Southside Compton Crips gang sign. Detective Schoonmaker testified that he downloaded the photograph from Beckley‘s home page on the internet website MySpace. The trial court admitted the photograph over both defendants‘ objections that it had not been authenticated. We agree with defendants that the court erred in admitting the photograph but we conclude that the error was harmless."
"A photograph is a "writing" and "[a]uthentication of a writing is required before it may be received in evidence." (Evid. Code, §§ 250, 1401, subd. (a).)"
"In People v. Bowley (1963) 59 Cal.2d 855, our Supreme Court established the two methods of authenticating a photograph. "It is well settled," the court stated, "that the testimony of a person who was present at the time a film was made that it accurately depicts what it purports to show is a legally sufficient foundation for its admission into evidence." (Id. at p. 859.) In addition, the court noted, authentication of a photograph "may be provided by the aid of expert testimony, as in the Doggett case, although there is no one qualified to authenticate it from personal observation." (Id. at p. 862.) In People v. Doggett (1948) 83 Cal.App.2d 405, the Court of Appeal upheld the admission of a photograph showing the defendants committing a crime. Because only the victim and the defendants, none of whom testified, were present when the crime took place and one of the defendants took the photograph, there was no one to testify that it accurately depicted what it purported to show. The People, however, produced evidence of when and where the picture was taken and that the defendants were the persons shown committing the crime. Furthermore, a photographic expert testified that the picture was not a composite and had not been faked. The court held this foundation sufficiently supported the photograph‘s admission as substantive evidence of the activity depicted. (Id. at p. 410.) Citing Doggett with approval, the Supreme Court held in Bowley that "a photograph may, in a proper case, be admitted into evidence not merely as illustrated testimony of a human witness but as probative evidence in itself of what it shows." (People v. Bowley, supra, 59 Cal.2d at p. 861.)
"Although defendants conceded that the face in the MySpace photograph was Fulmore‘s, neither method of authentication recognized in Bowley qualified the photo for admission as accurately depicting that Fulmore had assumed the pose shown in the photograph. Schoonmaker could not testify from his personal knowledge that the photograph truthfully portrayed Fulmore flashing the gang sign and, unlike Doggett, supra, 83 Cal.App.2d at p. 410, no expert testified that the picture was not a 'composite‘ or 'faked‘ photograph. Such expert testimony is even more critical today to prevent the admission of manipulated images than it was when Doggett and Bowley were decided. Recent experience shows that digital photographs can be changed to produce false images. (See e.g. U. S. v. Newsome (3d Cir. 2006) 439 F.3d 181, 183 [digital photographs used to make fake identification cards].) Indeed, with the advent of computer software programs such as Adobe Photoshop "it does not always take skill, experience, or even cognizance to alter a digital photo." (Parry, Digital Manipulation and Photographic Evidence: Defrauding The Courts One Thousand Words At A Time (2009) 2009 J. L. Tech. & Pol‘y 175, 183.) Even the Attorney General recognizes the untrustworthiness of images downloaded from the internet, quoting the court‘s warning in St. Clair v. Johnny’s Oyster & Shrimp, Inc. (S.D. Tex 1999) 76 F. Supp.2d 773, 775 that "[a]nyone can put anything on the Internet. No web-site is monitored for accuracy and nothing contained therein is under oath or even subject to independent verification absent underlying documentation. Moreover, the Court holds no illusions that hackers can adulterate the content of any web-site from any location at any time.‘"
... to be continued ...
Enjoy.
"In rebuttal to Beckley‘s and Fulmore‘s testimony denying Beckley‘s gang involvement, Detective Schoonmaker testified regarding gang-related evidence he recovered from the MySpace.com internet accounts of Finn and Beckley"
"To rebut Fulmore‘s testimony that she did not associate with the Southside Compton Crips and that she insisted Beckley stop his association with the gang, the prosecution offered a photograph purportedly showing Fulmore flashing the Southside Compton Crips gang sign. Detective Schoonmaker testified that he downloaded the photograph from Beckley‘s home page on the internet website MySpace. The trial court admitted the photograph over both defendants‘ objections that it had not been authenticated. We agree with defendants that the court erred in admitting the photograph but we conclude that the error was harmless."
"A photograph is a "writing" and "[a]uthentication of a writing is required before it may be received in evidence." (Evid. Code, §§ 250, 1401, subd. (a).)"
"In People v. Bowley (1963) 59 Cal.2d 855, our Supreme Court established the two methods of authenticating a photograph. "It is well settled," the court stated, "that the testimony of a person who was present at the time a film was made that it accurately depicts what it purports to show is a legally sufficient foundation for its admission into evidence." (Id. at p. 859.) In addition, the court noted, authentication of a photograph "may be provided by the aid of expert testimony, as in the Doggett case, although there is no one qualified to authenticate it from personal observation." (Id. at p. 862.) In People v. Doggett (1948) 83 Cal.App.2d 405, the Court of Appeal upheld the admission of a photograph showing the defendants committing a crime. Because only the victim and the defendants, none of whom testified, were present when the crime took place and one of the defendants took the photograph, there was no one to testify that it accurately depicted what it purported to show. The People, however, produced evidence of when and where the picture was taken and that the defendants were the persons shown committing the crime. Furthermore, a photographic expert testified that the picture was not a composite and had not been faked. The court held this foundation sufficiently supported the photograph‘s admission as substantive evidence of the activity depicted. (Id. at p. 410.) Citing Doggett with approval, the Supreme Court held in Bowley that "a photograph may, in a proper case, be admitted into evidence not merely as illustrated testimony of a human witness but as probative evidence in itself of what it shows." (People v. Bowley, supra, 59 Cal.2d at p. 861.)
"Although defendants conceded that the face in the MySpace photograph was Fulmore‘s, neither method of authentication recognized in Bowley qualified the photo for admission as accurately depicting that Fulmore had assumed the pose shown in the photograph. Schoonmaker could not testify from his personal knowledge that the photograph truthfully portrayed Fulmore flashing the gang sign and, unlike Doggett, supra, 83 Cal.App.2d at p. 410, no expert testified that the picture was not a 'composite‘ or 'faked‘ photograph. Such expert testimony is even more critical today to prevent the admission of manipulated images than it was when Doggett and Bowley were decided. Recent experience shows that digital photographs can be changed to produce false images. (See e.g. U. S. v. Newsome (3d Cir. 2006) 439 F.3d 181, 183 [digital photographs used to make fake identification cards].) Indeed, with the advent of computer software programs such as Adobe Photoshop "it does not always take skill, experience, or even cognizance to alter a digital photo." (Parry, Digital Manipulation and Photographic Evidence: Defrauding The Courts One Thousand Words At A Time (2009) 2009 J. L. Tech. & Pol‘y 175, 183.) Even the Attorney General recognizes the untrustworthiness of images downloaded from the internet, quoting the court‘s warning in St. Clair v. Johnny’s Oyster & Shrimp, Inc. (S.D. Tex 1999) 76 F. Supp.2d 773, 775 that "[a]nyone can put anything on the Internet. No web-site is monitored for accuracy and nothing contained therein is under oath or even subject to independent verification absent underlying documentation. Moreover, the Court holds no illusions that hackers can adulterate the content of any web-site from any location at any time.‘"
... to be continued ...
Enjoy.
Friday, May 11, 2018
Report writing in forensic multimedia analysis
You've analyzed evidence. You've made a few notes along the way. You've turned those notes over to the process. Your agency doesn't have a specific requirement about what should be in your notes or your report or how detailed they should be. In all the cases that you've worked, you've never been asked for specifics / details.
Now, your case has gone to trial. An attorney is seeking to qualify you to provide expert (opinion) testimony. They introduce you, your qualifications, and what you've been asked to do. The judge may or may not declare you to be an expert so that your opinion can be heard.
As a brief aside, your title or job description can vary widely. I've been an analyst, specialist, director, etc. FRE Rule 702, and the similar rule in your state's evidence code, governs your testimonial experience. Here's the bottom line: according to evidence code, you're not an "expert" unless the Judge says so, and then only for the duration of your testimony in that case. After you're dismissed, you go back to being an analyst, specialist, etc. You may have specific expertise, and that's great. But the assignment of the title of "expert" as relates to this work is generally done by the judge in a specific case, related to the type of testimony that will be offered.
A technician generally offers testimony about a procedure and the results of the procedure. No opinion is given. "I pushed the button and the DVR produced these files."
An expert generally offers opinion based testimony about the results of an experiment or test. "I've conducted a measurement experiment and in my opinion, the unknown subject in the video at the aforementioned date/time is 6’2” tall, with an error of ..."
Everything's OK ... until it's not. You've been qualified as an expert. Is your report ready for trial? What should be in a report anyway?
First off, there's two types of guidance in answering this question. The first type, people's experiences, might help. But, then again, it might not. Just because someone got away with it, doesn't make it a standard practice. Just because you've been through a few trials doesn't make your way "court qualified." These are marketing gimmicks, not standard practices. The second type, a Standard Practice, comes from a standards body like the ASTM. As opposed to the SWG's, who produce guidelines (it would be nice if you ...), standards producing bodies like the ASTM produce standards (you must/shall). For the discipline of Forensic Multimedia Analysis, there are quite a few standards which govern our work. Here's a few of the more important ones:
Did your retrieval follow E1188-11? Did your preparation of the evidence items follow E860-07? Did you assign a unique identifier to each evidence item and label it according to E1459-13? Does your workplace handle evidence according to E1492-11? Did your work on the evidence items follow E2825-12?
If you're not even aware of these standards, how will you answer the questions under direct / cross examination?
Taking a slight step back, and adding more complexity, you're engaged in a forensic science discipline. You're doing science. Science has rules and requirements as well. A scientist's report, in general, is structured in the same way. Go search scientific reports and papers in Google Scholar or ProQuest. The contents and structure of the reports you'll find are governed by the accredited institution. I've spent the last 8 years working in the world of experimental science, conducting experiments, testing data, forming conclusions, and writing reports. The structure for my work was found in the school's guidance documentation and enforced by the school's administrative staff.
How do we know we're doing science? Remember the NAS Report? The result of the NAS Report was the creation of the Organization of Scientific Area Committees for Forensic Science about 5 years ago. The OSAC has been hard at work refining guidelines and producing standards. Our discipline falls within the Video / Image Technology and Analysis (VITAL) Subcommittee. In terms of disclosure, I've been involved with the OSAC since it's founding and currently serve as the Video Task Group Chair within VITAL. But, this isn't an official statement by/for them. Of course, it's me (as me) trying to be helpful, as usual. :)
Last year, an OSAC group issued a new definition of forensic science that can be used for all forensic science disciplines. Here it is:
Forensic science is the systematic and coherent study of traces to address questions of authentication, identification, classification, reconstruction, and evaluation for a legal context. Source: A Framework to Harmonize Forensic Science Practices and Digital/Multimedia Evidence. OSAC Task Group on Digital/Multimedia Science. 2017
What is a trace? A trace is any modification, subsequently observable, resulting from an event. You walk within the view of a CCTV system, you leave a trace of your presence within that system.
Thus it is that we're engaged in science. Should we not structure our reports in the same way, using the available guidance as to how they should look? Of course. But what would that look like?
Let's assume that your report has a masthead / letterhead with your/your agency's name and contact information. Here's the structure of a report that (properly completed) will conform to the ASTM standards and the world of experimental science.
Administrative Information
Examiner Information
Requestor Information
Unique Evidence Control Number(s)
Chain of Custody Information
Summary of Request
Service Requested (e.g. photogrammetry, authentication, change of format, etc.)
Methodology
Equipment List
Experimental Design / Proposed Workflow
Limitations / Delimitations
Delimitations of the Experiment
Limitations in the Data
Personnel Delimitations / Limitations
Processing
Amped FIVE Processing Report can be inserted here as it conforms to ASTM 2825-12(17).
Results / Summary
Problems / Errors Encountered
Validation
Conclusions
List of Output File(s) / Derivatives / Demonstratives
Approval(s)
Examiner
Reviewer
Administrative Approval
It would generally conclude with a declaration and a signature. Something like this, perhaps:
I, __________, declare under penalty of perjury as provided in 28 U.S.C. §1746 that the foregoing is true and correct, that it is made based upon my own personal knowledge, and that I could testify to these facts if called as a witness.
Now, let's talk about the sections.
The Administrative section.
Methodology
Limitations / Delimitations
Now, your case has gone to trial. An attorney is seeking to qualify you to provide expert (opinion) testimony. They introduce you, your qualifications, and what you've been asked to do. The judge may or may not declare you to be an expert so that your opinion can be heard.
As a brief aside, your title or job description can vary widely. I've been an analyst, specialist, director, etc. FRE Rule 702, and the similar rule in your state's evidence code, governs your testimonial experience. Here's the bottom line: according to evidence code, you're not an "expert" unless the Judge says so, and then only for the duration of your testimony in that case. After you're dismissed, you go back to being an analyst, specialist, etc. You may have specific expertise, and that's great. But the assignment of the title of "expert" as relates to this work is generally done by the judge in a specific case, related to the type of testimony that will be offered.
A technician generally offers testimony about a procedure and the results of the procedure. No opinion is given. "I pushed the button and the DVR produced these files."
An expert generally offers opinion based testimony about the results of an experiment or test. "I've conducted a measurement experiment and in my opinion, the unknown subject in the video at the aforementioned date/time is 6’2” tall, with an error of ..."
First off, there's two types of guidance in answering this question. The first type, people's experiences, might help. But, then again, it might not. Just because someone got away with it, doesn't make it a standard practice. Just because you've been through a few trials doesn't make your way "court qualified." These are marketing gimmicks, not standard practices. The second type, a Standard Practice, comes from a standards body like the ASTM. As opposed to the SWG's, who produce guidelines (it would be nice if you ...), standards producing bodies like the ASTM produce standards (you must/shall). For the discipline of Forensic Multimedia Analysis, there are quite a few standards which govern our work. Here's a few of the more important ones:
- E860-07. Standard Practice for Examining And Preparing Items That Are Or May Become Involved In Criminal or Civil Litigation
- E1188-11. Standard Practice for Collection and Preservation of Information and Physical Items by a Technical Investigator
- E1459-13. Standard Guide for Physical Evidence Labeling and Related Documentation
- E1492-11. Standard Practice for Receiving, Documenting, Storing, and Retrieving Evidence in a Forensic Science Laboratory
- E2825-12(17). Standard Guide for Forensic Digital Image Processing
Did your retrieval follow E1188-11? Did your preparation of the evidence items follow E860-07? Did you assign a unique identifier to each evidence item and label it according to E1459-13? Does your workplace handle evidence according to E1492-11? Did your work on the evidence items follow E2825-12?
If you're not even aware of these standards, how will you answer the questions under direct / cross examination?
Taking a slight step back, and adding more complexity, you're engaged in a forensic science discipline. You're doing science. Science has rules and requirements as well. A scientist's report, in general, is structured in the same way. Go search scientific reports and papers in Google Scholar or ProQuest. The contents and structure of the reports you'll find are governed by the accredited institution. I've spent the last 8 years working in the world of experimental science, conducting experiments, testing data, forming conclusions, and writing reports. The structure for my work was found in the school's guidance documentation and enforced by the school's administrative staff.
How do we know we're doing science? Remember the NAS Report? The result of the NAS Report was the creation of the Organization of Scientific Area Committees for Forensic Science about 5 years ago. The OSAC has been hard at work refining guidelines and producing standards. Our discipline falls within the Video / Image Technology and Analysis (VITAL) Subcommittee. In terms of disclosure, I've been involved with the OSAC since it's founding and currently serve as the Video Task Group Chair within VITAL. But, this isn't an official statement by/for them. Of course, it's me (as me) trying to be helpful, as usual. :)
Last year, an OSAC group issued a new definition of forensic science that can be used for all forensic science disciplines. Here it is:
Forensic science is the systematic and coherent study of traces to address questions of authentication, identification, classification, reconstruction, and evaluation for a legal context. Source: A Framework to Harmonize Forensic Science Practices and Digital/Multimedia Evidence. OSAC Task Group on Digital/Multimedia Science. 2017
What is a trace? A trace is any modification, subsequently observable, resulting from an event. You walk within the view of a CCTV system, you leave a trace of your presence within that system.
Thus it is that we're engaged in science. Should we not structure our reports in the same way, using the available guidance as to how they should look? Of course. But what would that look like?
Let's assume that your report has a masthead / letterhead with your/your agency's name and contact information. Here's the structure of a report that (properly completed) will conform to the ASTM standards and the world of experimental science.
Administrative Information
Examiner Information
Requestor Information
Unique Evidence Control Number(s)
Chain of Custody Information
Summary of Request
Service Requested (e.g. photogrammetry, authentication, change of format, etc.)
Methodology
Equipment List
Experimental Design / Proposed Workflow
Limitations / Delimitations
Delimitations of the Experiment
Limitations in the Data
Personnel Delimitations / Limitations
Processing
Amped FIVE Processing Report can be inserted here as it conforms to ASTM 2825-12(17).
Results / Summary
Problems / Errors Encountered
Validation
Conclusions
List of Output File(s) / Derivatives / Demonstratives
Approval(s)
Examiner
Reviewer
Administrative Approval
It would generally conclude with a declaration and a signature. Something like this, perhaps:
I, __________, declare under penalty of perjury as provided in 28 U.S.C. §1746 that the foregoing is true and correct, that it is made based upon my own personal knowledge, and that I could testify to these facts if called as a witness.
Now, let's talk about the sections.
The Administrative section.
- You're the examiner. If you have help, or someone helped you in your work, they should be listed too. Co-workers, subcontractors, etc.
- The requestor is the case agent, investigator, or the client. The person who asked you to do the work.
- Every item of evidence must have a unique identifier.
- Every item received must be controlled and it's chain of custody tracked. If others accessed the item, their names would be in the evidence control report / list. DEMS and cloud storage solutions like Evidence.com can easily do this and produce a report.
Summary of Request
- What was it that you were asked to do, in plain terms. For example, "Given evidence item #XXX, for date/time/camera, I was asked to determine the vehicle's make/model/year" - comparative analysis / content analysis. Or, "Given evidence item #XXX, for date/time/camera, I was asked to estimate the unknown subject's height" - photogrammetry. Or, "Given image evidence item #XXY-X, retrieved from evidence item #XXY (see attached report), I was asked to determine if the image's contextual information had been altered" - authentication.
- Provide an abstract of the test and the results - a brief overview of what was done and what the results were (with references to appropriate page numbers).
Methodology
- What tools did you use - hardware / software? You may want to include a statement as to each and their purpose / fitness for that purpose. As an example, I use Amped Five. Amped Five is fit for the purpose of conducting image science experiments as it is operationalized from peer-reviewed / published image science. It's processing reports include the source documentation.
- Your proposed workflow. What will guide your work? Can you document it easily? Does your processing report follow this methodology? Hint, it should. Here's my workflow for Photogrammetry, Content Analysis, and Comparative Analysis. You can find it originally in my book, Forensic Photoshop. It's what I use when I work as an analyst. It's what I teach.
Limitations / Delimitations
- Delimitations are the bounds within which your work will be conducted. I will test the image. I won't test the device that created the image.
- With DME, there are a ton of limitations in the data. If the tested question is, what is license plate, and a macro block analysis determines that there is no original data in the area of the license plate, then that is a limitation. If the tested question is, what is the speed of the vehicle, and you don't have access to the DVR, then that is a huge limitation. Limitations must be stated.
- Personnel issues should also be listed. Did someone else start the work that you completed? Was another person employed on the case for a specific reason? Did something limit their involvement? If the question involves the need to measure camera height at a scene, and you can't climb a ladder so you mitigated that in some way, list it.
Remember, on cross examination, attorneys rarely ask questions of people blindly. They likely already know the answer and are walking your down a very specific path to a very specific desired conclusion. Whilst an attorney might not subpoena Verint's tech support staff / communications, as an example, they may have access to the FVA list and may be aware of your communications about the case there. You may not have listed that you received help from that source, but the opposing counsel might. You won't know who's watching what source. They may ask if you've received help on the case. How would you answer if you didn't list the help and disclose the communications, all of the communications? If your agency's policy prohibits the release of case related info, and you shared case related info on the FVA list, your answer to the question now involves specific jeopardy for your career. I've been assigned to Internal Affairs, I've been an employee rep, I know how the system works when one has been accused of misconduct. How do you avoid the jeopardy? Follow your agency's policies and keep good records of your case activity.
Processing
Results / Summary
Approval(s)
Processing
- These are the steps performed and the settings used. This section should read like a recipe so that some other person with similar training / equipment can reproduce your work. This is the essence of Section 4 of ASTM 2825. Amped FIVE Processing Report can be inserted here as it conforms to ASTM 2825-12(17).
Results / Summary
- Did you encounter any problems or errors. List them.
- How did you validate your results? Did anyone peer review your work? This can include test/retest or other such validity exams.
- Conclusions - your opinion goes here. This is the result of your test / experiment / analysis.
- List of Output File(s) / Derivatives / Demonstratives
Approval(s)
- Examiner (your name here), along with anyone else who's work is included in the report.
- Reviewer(s) - was your completed work reviewed? Their name(s).
- Administrative Approval - did a supervisor approve of the completed exam?
Do your reports look like this? Does the opposing counsel analyst's report look like this? If not, why not? It may be an avenue to explore on cross examination. It's best to be prepared.
I know that this is a rather long post. But, I wanted to be rather comprehensive in presenting the topic and list the sources for the information listed. Hopefully, this proves helpful.
Enjoy.
Monday, August 19, 2019
Welcome
Welcome to the Forensic Multimedia Analysis blog (formerly the Forensic Photoshop blog).
With the latest developments in the analysis of multimedia (video, audio, images, and metadata), we move the discussion beyond a single piece of software to include (in no particular order) processing and analysis fundamentals, court cases, upcoming training offerings, product reviews, current research, standards and practices, industry events and trends, and much more.
Digital / multimedia forensic analysis covers the domains of:
With the latest developments in the analysis of multimedia (video, audio, images, and metadata), we move the discussion beyond a single piece of software to include (in no particular order) processing and analysis fundamentals, court cases, upcoming training offerings, product reviews, current research, standards and practices, industry events and trends, and much more.
Digital / multimedia forensic analysis covers the domains of:
- Authentication
- Photogrammetry
- Photographic Comparison
- Photographic Content Analysis
Clarification, enhancement, and restoration are processes that can occur within the domains, but aren't domains in and of themselves.
We use the term digital / multimedia forensic analysis, as opposed to forensic video analysis or forensic audio analysis as we acknowledge that modern multimedia evidence potentially contains audio, images, video, as well as metadata. Thus, we need to be able to process and analyze everything that's found in the evidence files that we receive.
It's also important to define "forensic science." For this, I'll refer to "A Framework to Harmonize Forensic Science Practices and Digital/Multimedia Evidence." OSAC Task Group on Digital/Multimedia Science. 2017 (link): "Forensic science is the systematic and coherent study of traces to address questions of authentication, identification, classification, reconstruction, and evaluation for a legal context."
What is a trace? "A trace is any modification, subsequently observable, resulting from an event." You walk within the view of a CCTV system, you leave a trace of your presence within that system. You send a text, you leave a trace on your phone.
Within this framework, and wherever possible, we'll frame our discussion around standards and science. Validity, reliability, and reproducibility will be our goals ... not to present something unique and proprietary that only we can do here, but to illustrate the science behind the tools and techniques so that you can do it too.
I hope you enjoy your time here.
Jaime
It's also important to define "forensic science." For this, I'll refer to "A Framework to Harmonize Forensic Science Practices and Digital/Multimedia Evidence." OSAC Task Group on Digital/Multimedia Science. 2017 (link): "Forensic science is the systematic and coherent study of traces to address questions of authentication, identification, classification, reconstruction, and evaluation for a legal context."
What is a trace? "A trace is any modification, subsequently observable, resulting from an event." You walk within the view of a CCTV system, you leave a trace of your presence within that system. You send a text, you leave a trace on your phone.
Within this framework, and wherever possible, we'll frame our discussion around standards and science. Validity, reliability, and reproducibility will be our goals ... not to present something unique and proprietary that only we can do here, but to illustrate the science behind the tools and techniques so that you can do it too.
I hope you enjoy your time here.
Jaime
Monday, April 30, 2012
Hex Searching
One of the interesting aspects of having a blog is that some people will write to you asking about something related that they read elsewhere on the web. While I am generally friendly and prompt in my replies to questions that come from this blog, I'm often left wondering ... why didn't you just ask them?
Here's an example.
California is going nuts with image authentication issues related to law enforcement's use of images from Facebook. Last year, Scott Anderson wrote an outstanding overview of image authentication techniques as his Masters thesis at UC Denver's National Center for Media Forensics.
The reader wants to know about "practical applications" of Scott's thesis as regards law enforcement. My response: he couldn't be more clear. The question had to do with searching hex data for signs that an image had been "Photoshopped."
First, I reminded the reader of Scott's admonition that there is no one "right way" to authenticate images. There are many right ways, some will work better than others. Also, there should be a specific allegation of forgery that can be tested against.
I asked the reader to perform a simple test. Take a picture with your camera phone. Upload it directly to your Facebook account. Log in to Facebook and click on the picture. On the Options tab, click download. You will now have two versions of the picture - the one on your phone and the one downloaded from Facebook. Examine both with a hex editor. Use the find feature and search for terms like Photoshop, Picasa, and so forth. (Scott offers sample search terms in the back of his paper)
Now, open one of the pictures in Photoshop. Do something to it and save it. Open the hex editor again and search for the word Photoshop. What did you find?
In my test, I found multiple instances of the word ... usually following whatever was done by Photoshop.
If you're not familiar with Scott Anderson's thesis, take a minute and read it (well, more than a minute ...). It's a great example of the wonderful work being done in Denver.
Enjoy.
Here's an example.
California is going nuts with image authentication issues related to law enforcement's use of images from Facebook. Last year, Scott Anderson wrote an outstanding overview of image authentication techniques as his Masters thesis at UC Denver's National Center for Media Forensics.
The reader wants to know about "practical applications" of Scott's thesis as regards law enforcement. My response: he couldn't be more clear. The question had to do with searching hex data for signs that an image had been "Photoshopped."
First, I reminded the reader of Scott's admonition that there is no one "right way" to authenticate images. There are many right ways, some will work better than others. Also, there should be a specific allegation of forgery that can be tested against.
I asked the reader to perform a simple test. Take a picture with your camera phone. Upload it directly to your Facebook account. Log in to Facebook and click on the picture. On the Options tab, click download. You will now have two versions of the picture - the one on your phone and the one downloaded from Facebook. Examine both with a hex editor. Use the find feature and search for terms like Photoshop, Picasa, and so forth. (Scott offers sample search terms in the back of his paper)
Now, open one of the pictures in Photoshop. Do something to it and save it. Open the hex editor again and search for the word Photoshop. What did you find?
In my test, I found multiple instances of the word ... usually following whatever was done by Photoshop.
If you're not familiar with Scott Anderson's thesis, take a minute and read it (well, more than a minute ...). It's a great example of the wonderful work being done in Denver.
Enjoy.
Monday, March 4, 2019
What is Analysis?
What is analysis?
a·nal·y·sis [əˈnalÉ™sÉ™s] - NOUN
analyses (plural noun)
synonyms: dissection · assay · testing · breaking down · separation · reduction · decomposition · fractionation
antonyms: synthesis
Forensic science is the systematic and coherent study of traces to address questions of authentication, identification, classification, reconstruction, and evaluation for a legal context. (Source: A Framework to Harmonize Forensic Science Practices and Digital/Multimedia Evidence. OSAC Task Group on Digital/Multimedia Science. 2017)
What is a trace? A trace is any modification, subsequently observable, resulting from an event. You walk within the view of a CCTV system, you leave a trace of your presence within that system.
Thus, forensic video analysis (or forensic multimedia analysis) can be seen as a systematic and coherent examination of video (multimedia) traces (elements) to address questions of authentication, identification, classification, reconstruction, and evaluation for a legal context.
In the former definition, we can see the quantitative nature of analysis. The latter definition reveals it's potential qualitative elements.
In a quantitative data analysis, things are stable, controlled - facts can be obtained (facts are measurable / objective). In a qualitative data analysis, things are dynamic. Your role as an observer may influence the analysis. What is "true" depends on the situation & setting (truths are things we "know" - subjective). A quantitative study is controlled. A qualitative study is observed.
A qualitative study's purpose is to describe or understand something. The purpose of a quantitative study is to test, resolve, or predict something (e.g. in order to use a DVR to determine speed of an object within it's derivative video files - results will be a range of values, one must resolve how the DVR creates files "typically" through a controlled series of tests).
The analyst's viewpoint during a quantitative study is logical, empirical, deductive (conclusion guaranteed). In a qualitative study, it's situational and inductive (conclusion merely likely) or abductive (taking one's best shot). Performing a comparative analysis with convenience samples is an example of taking one's best shot. A quantitative study would feature an appropriate sample size calculation and note any limitations that arose as a result of not being able to achieve the appropriate samples.
From a contextual standpoint, a quantitative's context is not taken into consideration but rather controlled via methodological procedures. In this way, potential bias is mitigated. In a qualitative study, context matters - values, feelings, opinions, individual participants matter.
In a quantitative study, the analyst seeks to solve, to conclude, or to verify a predetermined hypothesis. With a qualitative study, the orientation changes - seeking rather to discover or explore. This can occur often in investigations - new information developed leads to changes in the direction of the investigation as things / people are ruled-in / ruled-out.
In a quantitative analysis, the inputs and results are numerical - data is in the form of numbers / numerical info. A qualitative analysis is narrative in nature - data is in the form of words, sentences, paragraphs, notes, or pictures / graphics / etc.
After conducting a quantitive analysis, one's results / findings can be generalized to other populations or situations. The results of a qualitative analysis are case specific, particular, or specialized.
With all of this in mind, what is analysis? What type of analysis are you conducting? What type of analysis are you reporting? When analyzing the work of other analysts, what type of work are they conducting / reporting?
You can use this dialog to build a template / matrix. In reviewing work, examine the elements above to determine if the work is quantitative or qualitative. For example, you're reviewing an analyst's work in on a measurement request (photogrammetry). The results section features a picture that has been marked up with arrows and text. No methodology is discussed. These results would be considered qualitative. If the results section featured a conclusion, a range of values, error estimation, and a reference / methodology section, it could be considered quantitative. You could take the analyst's data and reproduce their study - which is not possible from an annotated picture.
The elements for a quantitative analysis described above, when reported back to the Trier of Fact, help ensure that you've maintained standards compliance (ASTM E2825-18). Rhetorical or narrative statements are fine for the introductory section of your report - a summary of the request - but are not sufficient for supporting a conclusion or describing one's processes.
If you'd like to know more, join me in an upcoming training session. For more information or to sign up, click here.
a·nal·y·sis [əˈnalÉ™sÉ™s] - NOUN
analyses (plural noun)
- detailed examination of the elements or structure of something. "statistical analysis" · "an analysis of popular culture"
- the process of separating something into its constituent elements. Often contrasted with synthesis. "the procedure is often more accurately described as one of synthesis rather than analysis"
synonyms: dissection · assay · testing · breaking down · separation · reduction · decomposition · fractionation
antonyms: synthesis
Forensic science is the systematic and coherent study of traces to address questions of authentication, identification, classification, reconstruction, and evaluation for a legal context. (Source: A Framework to Harmonize Forensic Science Practices and Digital/Multimedia Evidence. OSAC Task Group on Digital/Multimedia Science. 2017)
What is a trace? A trace is any modification, subsequently observable, resulting from an event. You walk within the view of a CCTV system, you leave a trace of your presence within that system.
In the former definition, we can see the quantitative nature of analysis. The latter definition reveals it's potential qualitative elements.
In a quantitative data analysis, things are stable, controlled - facts can be obtained (facts are measurable / objective). In a qualitative data analysis, things are dynamic. Your role as an observer may influence the analysis. What is "true" depends on the situation & setting (truths are things we "know" - subjective). A quantitative study is controlled. A qualitative study is observed.
A qualitative study's purpose is to describe or understand something. The purpose of a quantitative study is to test, resolve, or predict something (e.g. in order to use a DVR to determine speed of an object within it's derivative video files - results will be a range of values, one must resolve how the DVR creates files "typically" through a controlled series of tests).
The analyst's viewpoint during a quantitative study is logical, empirical, deductive (conclusion guaranteed). In a qualitative study, it's situational and inductive (conclusion merely likely) or abductive (taking one's best shot). Performing a comparative analysis with convenience samples is an example of taking one's best shot. A quantitative study would feature an appropriate sample size calculation and note any limitations that arose as a result of not being able to achieve the appropriate samples.
From a contextual standpoint, a quantitative's context is not taken into consideration but rather controlled via methodological procedures. In this way, potential bias is mitigated. In a qualitative study, context matters - values, feelings, opinions, individual participants matter.
In a quantitative study, the analyst seeks to solve, to conclude, or to verify a predetermined hypothesis. With a qualitative study, the orientation changes - seeking rather to discover or explore. This can occur often in investigations - new information developed leads to changes in the direction of the investigation as things / people are ruled-in / ruled-out.
In a quantitative analysis, the inputs and results are numerical - data is in the form of numbers / numerical info. A qualitative analysis is narrative in nature - data is in the form of words, sentences, paragraphs, notes, or pictures / graphics / etc.
After conducting a quantitive analysis, one's results / findings can be generalized to other populations or situations. The results of a qualitative analysis are case specific, particular, or specialized.
With all of this in mind, what is analysis? What type of analysis are you conducting? What type of analysis are you reporting? When analyzing the work of other analysts, what type of work are they conducting / reporting?
You can use this dialog to build a template / matrix. In reviewing work, examine the elements above to determine if the work is quantitative or qualitative. For example, you're reviewing an analyst's work in on a measurement request (photogrammetry). The results section features a picture that has been marked up with arrows and text. No methodology is discussed. These results would be considered qualitative. If the results section featured a conclusion, a range of values, error estimation, and a reference / methodology section, it could be considered quantitative. You could take the analyst's data and reproduce their study - which is not possible from an annotated picture.
The elements for a quantitative analysis described above, when reported back to the Trier of Fact, help ensure that you've maintained standards compliance (ASTM E2825-18). Rhetorical or narrative statements are fine for the introductory section of your report - a summary of the request - but are not sufficient for supporting a conclusion or describing one's processes.
If you'd like to know more, join me in an upcoming training session. For more information or to sign up, click here.
Tuesday, April 16, 2013
NaTIA Pacific Chapter wrap-up
It was nice to get to a NaTIA chapter event again. It's been quite a while.
The FVA of native (recorded) and live Milestone feeds was an intense class. I don't think that I've seen a room packed full like that in a long time. It's actually quite refreshing to see this level of interest in forensic video analysis. Milestone is the new big dog on the block and we've figured out their file structure as well as their server side for the live work.
Image authentication was also intense. There's nothing like mathematics to get the blood flowing early in the morning. Folks realized that there's so much more than the visual domains of authentication. If you're not into the math - into the algorithms of the image - you're missing so much.
Hopefully everyone walked away with a nice set of tools that will help solve some of their most troubling problems.
The FVA of native (recorded) and live Milestone feeds was an intense class. I don't think that I've seen a room packed full like that in a long time. It's actually quite refreshing to see this level of interest in forensic video analysis. Milestone is the new big dog on the block and we've figured out their file structure as well as their server side for the live work.
Image authentication was also intense. There's nothing like mathematics to get the blood flowing early in the morning. Folks realized that there's so much more than the visual domains of authentication. If you're not into the math - into the algorithms of the image - you're missing so much.
Hopefully everyone walked away with a nice set of tools that will help solve some of their most troubling problems.
Subscribe to:
Posts (Atom)










