By now, it's well known that the world of DVR forensics and computer forensics kind of looks the same, but really isn't quite the same. Answers to questions regarding DVR forensics often start with "it depends."
In the world of digital forensics, every item of evidence should / must be hashed upon receipt. And ... the same is true for DVR files in the world of forensic video analysis. You should hash all files upon receipt.
You receive a couple of .264 files from a crime scene, you hash them, then you make copies, and begin your work. If you're working a computer forensic style of workflow, then your copies are "true and exact copies of the originals." But, you're working a forensic video analysis type workflow. Your copies are not true and exact copies of the originals - they're proxy files. Proxy means substitute / stand-in. They're "converted." The process of creating the proxy - re-wrapping the data stream, carving out the time stamp ... all of those convenient things we do to make our lives easier ... means that the resulting proxy file will not have the same hash value as the original from the crime scene. And ... that's OK. That's normal.
Using a tool like FTK imager, one can hash a whole project folder. In the folder are the original files, the proxy files, any other derivative files, etc. A quick examination of the hash values clearly shows that the hash of the original .264 files (green) does not match the hash of the .avi proxy files (red). Again, that's OK. That's normal.
As forensic video analysts, we need to know that (a) this is happening and (b) it's normal. If you have to create a proxy file in order to work and respond to the request, this mismatch of the hash values will happen. Just hash the resulting files in the working folder to keep a record of them as they were created. Pull a still frame out as a separate file? Hash it. Carve out the time stamp as a separate file? Hash it.
As worlds converge, there will be a bit of sorting out of procedures and dialog. It's OK.
This blog is no longer active and is maintained for archival purposes. It served as a resource and platform for sharing insights into forensic multimedia and digital forensics. Whilst the content remains accessible for historical reference, please note that methods, tools, and perspectives may have evolved since publication. For my current thoughts, writings, and projects, visit AutSide.Substack.com. Thank you for visiting and exploring this archive.
Featured Post
Welcome to the Forensic Multimedia Analysis blog (formerly the Forensic Photoshop blog). With the latest developments in the analysis of m...
Wednesday, March 13, 2019
Saturday, March 9, 2019
Simple image and video processing
I'm back doing product reviews and comparisons. Yay!
In the blog post announcing my joining the Amped team a few years ago, its CEO noted "Jim is well known also for his direct, unfiltered and passionate style."
It's been a while, but the directness and passion are still here; and I have yet to find a filter. ;) ... and, in case you missed it, I'm no longer part of the Amped team. More on that in a future post.
Today's test - Input-Ace vs Amped FIVE for simple image / video processing. *
To facilitate the test, I've enlisted the help of an analyst from a private lab with Input-Ace and FIVE. I just needed a few stills and screen shots to work with. The test begins with a video extracted by me from a black box 2CIF DVR, the kind that are rather ubiquitous here in the US. It's one of my test/validate files, so I know the values that we are starting with.
The task: "I just need a still image of the vehicle for a BOLO." This should be a 2 minute process .. or less.
Now, the process and tools are a bit different when working in Input-Ace vs Amped FIVE. But, I devised a test of something I used to do several times per day at the LAPD - process 2 CIF video for a flyer. Resize / Aspect Ratio - problems of resolution can be fixed in either tool.
My experiment is two-fold.
The "workflow engine" way of working is not natural to me. But, my friend is rather proficient with the tool and noted that fixing the resolution issue was a two-step process - first restore the aspect ratio and then restore the size. Each step in Input-Ace utilized Nearest Neighbor interpolation. The time to configure the filters and output a still was less than 30 seconds.
Notes:
Nearest neighbor simply copies the value of the closest pixel in the position to be interpolated. (Anil. K. Jain, “Fundamentals of Digital Image Processing”, Prentice Hall, pp. 253–255, 320–322, 1989. ISBN: 0-13-336165-9.)
For FIVE, this solution is equally easy - the Line Doubling filter (Deinterlace > Line Doubling). Line Doubling utilized a Linear interpolation. As with Input-Ace, the time to configure the filters and output a still was less than 30 seconds.
Notes:
Linear interpolates two adjacent lines. (E. B. Bellers and G. de Haan, “Deinterlacing - An overview”, in Proceedings of the IEEE, Vol. 86, No. 9, pp. 1839–1857, Sep. 1998. http://dx.doi.org/10.1109/5.705528.)
In terms of speed and ease of use - it's a tie.
Remember, this task isn't an "analysis" as such. This process is one of those common requests - we just need an image, quickly, for a BOLO. But, you want to fix the problems with the file before giving the investigator their image. Sending out a 2 CIF image without correcting / restoring the resolution could lead to problems with recognition as the images appear "squashed."
Next, I wanted to know if there was a qualitative difference between the two resulting files. This is where FIVE excels - analysis. FIVE's implementation of Similarity Metrics (Link > Video Mixer) was used.
The results:
From a qualitative standpoint - it's a tie.
Thus, if the two pieces of software can deliver what is visually the same result, in the same amount of time, then what's the tie breaker? Features? Service? Price?
The tie breaker is for you to decide. What features are "must haves?" What are the terms of service? Are they acceptable to your agency? What's the better value for your agency, your caseload, and your workflow?
For features, does it matter if there are 130 filters / tools if you only use about a dozen of them on a regular basis? I'm in a different place in my casework now - more "analysis" than "processing." For me, the value proposition based on features still tilts towards Amped's tools. Besides, I've had my license for years now. I'm not coming at the tool for the first time. For many at the local police level, it's more processing than analysis - with analysis being done at the prosecutor's office. Input-Ace as a production tool is quite well positioned. As an analysis tool, you'll need something else for now. The testimony of Input-Ace's primary evangelist, Grant Fredericks, will confirm that it's major part of his tool-set, but not the only tool he uses.
For the terms of service, examine each product's End User License Agreement - otherwise known as "that thing you don't read as you install the software." The EULA is the company's promise to you - the terms of what you're getting. Are the terms acceptable? If you're in North America, can you get someone on the phone to help during business hours? Input-Ace vs Amped contact pages are linked here for your convenience. Are you OK with a web portal as your only option?
For price, it can only be published price vs. published price. I am told that the quoted price for an annual subscription of Input-Ace is US$3k. The generally quoted price of a perpetual license of FIVE is EUR 9000. The EUR / USD exchange has been quite volatile of late, so the dollar price has come down a bit under US$11k on the exchange. I believe that a perpetual license of Input-Ace is available, but I don't have information on that price ... nor do I know an agency that has gone that route.
Then there's the ordering component of price. Price doesn't matter if you can't order the product. Can your agency pre-pay for goods via an office shared in Brooklyn, NY, with 40+ other entities at any price? States like New Jersey and Illinois forbid such pre-payment explicitly. Counties and cities like Los Angeles forbid pre-payment practically. Did you check up on the business? Run a Bizapedia search on the business. Do you get a result? Do you recognize the names? Does anything look odd? FIVE's EULA indicates that support will be done via the web portal, not at their "NY office." Are those terms acceptable? Then check the provider of the competition. Do the same thing. Run a Bizapedia search. Recognize any names? It may not be your money that your agency is spending, but due diligence is necessary nonetheless.
I'm of the firm belief that any true comparison of products must include the total experience - comparing the features as well as the user / customer experience. Features are pretty straightforward. User / customer experiences vary from person to person. I've shared mine with you. Feel free to share yours with me.
*An important note: this was a simple case study. It's results were valid for what specifically was studied. It's not meant to validate either tool for use on a particular case, or your particular case. The opinions expressed herein are those of the author alone.
In the blog post announcing my joining the Amped team a few years ago, its CEO noted "Jim is well known also for his direct, unfiltered and passionate style."
Today's test - Input-Ace vs Amped FIVE for simple image / video processing. *
To facilitate the test, I've enlisted the help of an analyst from a private lab with Input-Ace and FIVE. I just needed a few stills and screen shots to work with. The test begins with a video extracted by me from a black box 2CIF DVR, the kind that are rather ubiquitous here in the US. It's one of my test/validate files, so I know the values that we are starting with.
The task: "I just need a still image of the vehicle for a BOLO." This should be a 2 minute process .. or less.
Now, the process and tools are a bit different when working in Input-Ace vs Amped FIVE. But, I devised a test of something I used to do several times per day at the LAPD - process 2 CIF video for a flyer. Resize / Aspect Ratio - problems of resolution can be fixed in either tool.
My experiment is two-fold.
- How fast / easy is it to load a video, fix the resolution issue (restore the missing information that happens when the DVR is set to ignore every other line of resolution - 2 CIF), and output a still for a BOLO.
- What's the difference in quality between the two processes? Is there a difference in the results? If so, what is it?
Notes:
Nearest neighbor simply copies the value of the closest pixel in the position to be interpolated. (Anil. K. Jain, “Fundamentals of Digital Image Processing”, Prentice Hall, pp. 253–255, 320–322, 1989. ISBN: 0-13-336165-9.)
For FIVE, this solution is equally easy - the Line Doubling filter (Deinterlace > Line Doubling). Line Doubling utilized a Linear interpolation. As with Input-Ace, the time to configure the filters and output a still was less than 30 seconds.
Notes:
Linear interpolates two adjacent lines. (E. B. Bellers and G. de Haan, “Deinterlacing - An overview”, in Proceedings of the IEEE, Vol. 86, No. 9, pp. 1839–1857, Sep. 1998. http://dx.doi.org/10.1109/5.705528.)
Next, I wanted to know if there was a qualitative difference between the two resulting files. This is where FIVE excels - analysis. FIVE's implementation of Similarity Metrics (Link > Video Mixer) was used.
- SAD (Sum of Absolute Differences - mean) (0 .. 255): 2.0677.
- PSNR (Peak Signal to Noise Ratio - dB): 28.7395.
- MSSIM (Mean Structural Similarity) (0 .. 1): 0.9335.
- Correlation (Correlation Coefficient.) (-1 .. 1): 0.9895.
From a qualitative standpoint - it's a tie.
Thus, if the two pieces of software can deliver what is visually the same result, in the same amount of time, then what's the tie breaker? Features? Service? Price?
The tie breaker is for you to decide. What features are "must haves?" What are the terms of service? Are they acceptable to your agency? What's the better value for your agency, your caseload, and your workflow?
For features, does it matter if there are 130 filters / tools if you only use about a dozen of them on a regular basis? I'm in a different place in my casework now - more "analysis" than "processing." For me, the value proposition based on features still tilts towards Amped's tools. Besides, I've had my license for years now. I'm not coming at the tool for the first time. For many at the local police level, it's more processing than analysis - with analysis being done at the prosecutor's office. Input-Ace as a production tool is quite well positioned. As an analysis tool, you'll need something else for now. The testimony of Input-Ace's primary evangelist, Grant Fredericks, will confirm that it's major part of his tool-set, but not the only tool he uses.
For the terms of service, examine each product's End User License Agreement - otherwise known as "that thing you don't read as you install the software." The EULA is the company's promise to you - the terms of what you're getting. Are the terms acceptable? If you're in North America, can you get someone on the phone to help during business hours? Input-Ace vs Amped contact pages are linked here for your convenience. Are you OK with a web portal as your only option?
For price, it can only be published price vs. published price. I am told that the quoted price for an annual subscription of Input-Ace is US$3k. The generally quoted price of a perpetual license of FIVE is EUR 9000. The EUR / USD exchange has been quite volatile of late, so the dollar price has come down a bit under US$11k on the exchange. I believe that a perpetual license of Input-Ace is available, but I don't have information on that price ... nor do I know an agency that has gone that route.
Then there's the ordering component of price. Price doesn't matter if you can't order the product. Can your agency pre-pay for goods via an office shared in Brooklyn, NY, with 40+ other entities at any price? States like New Jersey and Illinois forbid such pre-payment explicitly. Counties and cities like Los Angeles forbid pre-payment practically. Did you check up on the business? Run a Bizapedia search on the business. Do you get a result? Do you recognize the names? Does anything look odd? FIVE's EULA indicates that support will be done via the web portal, not at their "NY office." Are those terms acceptable? Then check the provider of the competition. Do the same thing. Run a Bizapedia search. Recognize any names? It may not be your money that your agency is spending, but due diligence is necessary nonetheless.
I'm of the firm belief that any true comparison of products must include the total experience - comparing the features as well as the user / customer experience. Features are pretty straightforward. User / customer experiences vary from person to person. I've shared mine with you. Feel free to share yours with me.
*An important note: this was a simple case study. It's results were valid for what specifically was studied. It's not meant to validate either tool for use on a particular case, or your particular case. The opinions expressed herein are those of the author alone.
Friday, March 8, 2019
The return of product reviews and comparisons
Some of the things that I haven't been able to do for some time are product reviews and comparisons. First, the blog was all but shut down by my LAPD CO. Then, in my LE retirement, I was able to do product features when I was employed at Amped Software, Inc., to be sure. But, I was never allowed to compare / contrast Amped SRL's tools with others available on the market. Now that I'm on my own, I can pick up where I left off. There's a lot of catching up to do. Well, it's time ...
First out of the gate: Input-ACE vs Amped FIVE.
I will examine some common workflows and file processing challenges. I won't hold anything back.
Stay tuned.
First out of the gate: Input-ACE vs Amped FIVE.
I will examine some common workflows and file processing challenges. I won't hold anything back.
Stay tuned.
Thursday, March 7, 2019
Calculating the cost of redacting police body worn video
There's been an interesting back and forth over the release of body camera video and the cost of redaction happening in Washington DC. As someone who teaches and performs redactions, I've been following it with some interest.
Here's the source document that I'll be referencing from DC Transparency Watch.
I first got wind of this from a tweet. Here's a copy:
It seems that an elected neighborhood representative wanted DC Metro to release "the video" of the incident. What's not in dispute is that 7 officers arrived to find 3 juveniles, resulting in 229 minutes of footage. The elected official's tweet certainly indicates her displeasure at being invoiced for services needed to fulfill her request.
Whilst not every state allows agencies to charge for the production of redacted copies of video / audio, it seems that the Federal City does.
To some, $5,387.00 dollars might seem a bit much. But, is it a fair charge? How did the MPD come up with this rather precise number? MPD's initial response to the request was an invoice indicating a charge for 229 minutes at $23 per minute. Again, where does this number come from? Is it fair?
There's some interesting back and forth on social media about this, like the email reply shown above. But, I was more concerned with the cost calculation.
As I teach redaction, I use a job costing formula that looks like this:
( ___ [total footage time per recording] x ____ [processing time per minute of recording]) x ___ [total subjects or objects to redact] = ___ minutes x ___ recorders = ___ minutes to complete the task. Total time x ___ $/hr (employee cost) = ____ total cost.
The total footage time, in this case, gets divided by the total number of officers on scene with BWCs. The processing time per minute of recording varies based upon what task is being performed. In the standards compliant workflow that I teach, these tasks are Triage, Redaction Task, and Redaction Quality Assurance. Each of these steps use the same formula, but the processing time per minute varies - Triage is the longest, then QA, then the actual redaction task. There's case management and supervisory review to factor in as well.
Note: (I do give the complete formula and all of the variables in class)
Based on the above formula, I calculated that it would take about 311 hours to complete the request. A police records clerk in DC earns between $38k and $45k per year (source). Many states also factor in the total employment cost of the employee, which includes pension and benefits. Also considering that the supervisor most likely earns more, I calculated the average hourly rate to be $26/hr. With this in mind, the cost to fulfill this request would be $8,089.38. Not far off from what the representative was invoiced.
Assuming that MPD is overworked and that likely some of the workflow was skipped, and assuming that the agency just billed the average employee cost at salary without benefits and pension, the numbers were adjusted. I eliminated the QA step and adjusted the hourly rate to $22/hr. The new totals look like this: 231.01 hours x $22/hr = $5,082.22 - right about where the MPD ended up with their invoice.
I don't intend to weigh in on the politics of one branch of the same government charging another branch. I mean only to illustrate the rational basis of setting costs for redaction of body camera video - or any video that is in police custody and subject to privacy restrictions before public release.
Cost estimation is a necessary step in the process.
Here's the source document that I'll be referencing from DC Transparency Watch.
I first got wind of this from a tweet. Here's a copy:
It seems that an elected neighborhood representative wanted DC Metro to release "the video" of the incident. What's not in dispute is that 7 officers arrived to find 3 juveniles, resulting in 229 minutes of footage. The elected official's tweet certainly indicates her displeasure at being invoiced for services needed to fulfill her request.
Whilst not every state allows agencies to charge for the production of redacted copies of video / audio, it seems that the Federal City does.
To some, $5,387.00 dollars might seem a bit much. But, is it a fair charge? How did the MPD come up with this rather precise number? MPD's initial response to the request was an invoice indicating a charge for 229 minutes at $23 per minute. Again, where does this number come from? Is it fair?
There's some interesting back and forth on social media about this, like the email reply shown above. But, I was more concerned with the cost calculation.
As I teach redaction, I use a job costing formula that looks like this:
( ___ [total footage time per recording] x ____ [processing time per minute of recording]) x ___ [total subjects or objects to redact] = ___ minutes x ___ recorders = ___ minutes to complete the task. Total time x ___ $/hr (employee cost) = ____ total cost.
The total footage time, in this case, gets divided by the total number of officers on scene with BWCs. The processing time per minute of recording varies based upon what task is being performed. In the standards compliant workflow that I teach, these tasks are Triage, Redaction Task, and Redaction Quality Assurance. Each of these steps use the same formula, but the processing time per minute varies - Triage is the longest, then QA, then the actual redaction task. There's case management and supervisory review to factor in as well.
Note: (I do give the complete formula and all of the variables in class)
Based on the above formula, I calculated that it would take about 311 hours to complete the request. A police records clerk in DC earns between $38k and $45k per year (source). Many states also factor in the total employment cost of the employee, which includes pension and benefits. Also considering that the supervisor most likely earns more, I calculated the average hourly rate to be $26/hr. With this in mind, the cost to fulfill this request would be $8,089.38. Not far off from what the representative was invoiced.
Assuming that MPD is overworked and that likely some of the workflow was skipped, and assuming that the agency just billed the average employee cost at salary without benefits and pension, the numbers were adjusted. I eliminated the QA step and adjusted the hourly rate to $22/hr. The new totals look like this: 231.01 hours x $22/hr = $5,082.22 - right about where the MPD ended up with their invoice.
I don't intend to weigh in on the politics of one branch of the same government charging another branch. I mean only to illustrate the rational basis of setting costs for redaction of body camera video - or any video that is in police custody and subject to privacy restrictions before public release.
Cost estimation is a necessary step in the process.
- Supervisors need to know how long it will take to perform each step in the process in order to know whom to assign the work.
- The process needs to know how long it will take such that the requestor can have an estimated completed date (most statutes require notification if the turn around will be longer than 7 days).
- Agencies need to know how long these requests take to fulfill such that appropriate staffing levels are maintained.
- When agencies evaluate technology for redaction, they need a baseline calculation in order to gauge the proposed cost/time numbers.
This exercise is just a peek at what is covered in our Redaction courses. We offer a course specific to California's new laws, a course that covers the issue in the generic (both legal and technical) and is thus applicable all over, as well as courses that cover the general legal environment combined with the specific technology used for the redaction tasks - Adobe, Amped (with Audacity), or Magix. We offer them either on-site (ours or yours) or on-line. Click here for more information. We'd love to see you in one soon.
Wednesday, March 6, 2019
Evaluating Research
As analysts, we rely upon research to form the basis of our work. If we're conducting a 3D measurement exercise utilizing Single View Metrology, as operationalized by the programmers at Amped SRL, we're relying not only upon the research of Antonio Criminisi and his team, but also the programmers who put his team's work into their tool. We trust that all those involved in the process are acting in good faith. More often than not, analysts don't dig around to check the research that forms the foundation of their work.
In my academic life, I've conducted original research, I've supervised the research of others, I teach research methods, I've acted as an anonymous peer-reviewer, and I participate in and supervise an Institutional Review Board (IRB). In my academic life, as well as in my professional life as an analyst, I use the model shown above to guide my research work.
For those that are members of the IAI, and receive the Journal of Forensic Identification, you may have noticed that the latest edition features two letters to the editor that I submitted last summer. For those that don't receive the JFI, you can follow along here but there's no link that I can provide to share the letters as the JFI does not allow the general public to view it's publications. Thus, I'm sharing a bit about my thought process in evaluating the particular article that prompted my letters here on the blog.
The article that prompted my letter dealt with measuring 3D subjects depicted in a 2D medium (Meline, K. A., & Bruehs, W. E. (2018). A comparison of reverse projection and laser scanning photogrammetry. Journal of Forensic Identification, 68(2), 281-292), otherwise known as photogrammetry.
When evaluating research, using the model shown above, one wants to think critically. As a professional, I have to acknowledge that I know both of the authors and have for some time. But, I have to set that aside, mitigating any "team player bias" and evaluate their work on it's own merits. Answers to questions about validity and value should not be influenced by my relationships but by the quality of the research alone.
The first stop on my review is a foundation question, is the work experimental or non-experimental? There is a huge difference between the two. In experimental research an independent variable is manipulated in some way to find out how it will affect the dependent variable. For example, what happens to recorded frame rate in a particular DVR when all camera inputs are under motion or alarm mode? "Let's put them all under load and see" tests the independent variables' (camera inputs) potential influence on the dependent variable (recorded file) to find out if / how one affects the other. In non-experimental research there is no such manipulation, it's largely observational. Experimental research can help to determine causes, as one is controlling the many factors involved. In general, non-experimental research can not help to determine causes. Experimental research is more time consuming to conduct, and thus more costly.
With this in mind, I read the paper looking for a description of the variables involved in the study - what was being studied and how potential influencing factors were being controlled. Finding none, I determined that the study was non-experimental - the researchers simply observed and reported.
The case study featured a single set of equipment and participants. The study did not examine the outputs from a range of randomly chosen DVRs paired with randomly chosen cameras. Nor did the study include a control group of participants. For the comparison of the methods studied, the study did not feature a range of laser scanners or a range of tools in which to create the reverse projection demonstratives. No discussion as to the specifics of the tool choices was given.
For the participants, those performing the measurement exam, no random assignment was used. Particularly troubling, the participants used in the study were co-workers of the researchers. Employees represent a vulnerable study population and problems can arise when these human subjects are not able to properly consent to participating in the research. As an IRB supervisor, this situation raises the issue of potential bias. As an IRB supervisor, I would expect to see a statement about how the bias would be mitigated in the research and that the researchers' IRB had acknowledged and approved of the research design. Unfortunately, no such statement exists in the study. Given that the study was essentially a non-experimental test of human subjects, and not an experimental test of a particular technology or technique, an IRB's approval is a must. One of the two letters that I submitted upbraided the editorial staff of the JFI for not enforcing it's own rules as regards their requirement for an IRB approval statement for tests of human subjects.
Given the lack of control for bias and extraneous variables, the lack of randomness of participant selection, and the basic non-experimental approach of the work, I decided that this paper could not inform my work or my choice in employing a specific tool or technique.
Digging a bit deeper, I looked at the authors' support for statements made - their references. I noticed that they chose to utilize some relatively obscure or largely unavailable sources. The chosen references would be unavailable to the average analyst without the analyst paying hundreds of dollars to check just one of the references. In my position, however, I have access to a world of research for free through my affiliations with various universities. So, I checked their references.
What I found, and thus reported to the Editor, was that many times the cited materials could not be applied to support the statements made in the research. In a few instances, the cited material actually refuted the authors' assertions.
In the majority of the cited materials, the authors noted that their work couldn't be used to inform a wider variety of research, that case-specific validity studies should be conducted by those engaged in the technique described, or that they were simply offering a "proof-of-concept" to the reader.
In evaluating this particular piece of research, I'm not looking to say - "don't do this technique" or "this technique can't be valid." I want to know if I can use the study to inform my own work in performing photogrammetry. Unfortunately, due to the problems noted in my letters, I can't.
If you're interested in engaging in the creation of mixed-methods demonstratives for display in court, Occam's Input-ACE has an overlay feature that allows one to mix the output from a laser scan into a project that contains CCTV footage. The overlay feature is comparable to a "reverse projection" - it's a demonstrative used to illustrate and reinforce testimony. A "reverse projection" demonstrative is not, in and of itself, a measurement exercise / photogrammetry. Though it is possible to set up the demonstrative, then use SVM to measure within the space. If one wants to measure within the space in such a way as a general rule (not case specific), proper validity studies need to be conducted. At the time of the writing of this post, no such validity studies exist for the calculation of measurements with such a mixed measures approach. If one is so inclined, the model above can be used to both design and evaluate such a study. Until then, I'll continue on with Single View Metrology as the only properly validated 3D measurement technique for 3D subjects / objects depicted within a 2D medium.
In my academic life, I've conducted original research, I've supervised the research of others, I teach research methods, I've acted as an anonymous peer-reviewer, and I participate in and supervise an Institutional Review Board (IRB). In my academic life, as well as in my professional life as an analyst, I use the model shown above to guide my research work.
For those that are members of the IAI, and receive the Journal of Forensic Identification, you may have noticed that the latest edition features two letters to the editor that I submitted last summer. For those that don't receive the JFI, you can follow along here but there's no link that I can provide to share the letters as the JFI does not allow the general public to view it's publications. Thus, I'm sharing a bit about my thought process in evaluating the particular article that prompted my letters here on the blog.
The article that prompted my letter dealt with measuring 3D subjects depicted in a 2D medium (Meline, K. A., & Bruehs, W. E. (2018). A comparison of reverse projection and laser scanning photogrammetry. Journal of Forensic Identification, 68(2), 281-292), otherwise known as photogrammetry.
When evaluating research, using the model shown above, one wants to think critically. As a professional, I have to acknowledge that I know both of the authors and have for some time. But, I have to set that aside, mitigating any "team player bias" and evaluate their work on it's own merits. Answers to questions about validity and value should not be influenced by my relationships but by the quality of the research alone.
The first stop on my review is a foundation question, is the work experimental or non-experimental? There is a huge difference between the two. In experimental research an independent variable is manipulated in some way to find out how it will affect the dependent variable. For example, what happens to recorded frame rate in a particular DVR when all camera inputs are under motion or alarm mode? "Let's put them all under load and see" tests the independent variables' (camera inputs) potential influence on the dependent variable (recorded file) to find out if / how one affects the other. In non-experimental research there is no such manipulation, it's largely observational. Experimental research can help to determine causes, as one is controlling the many factors involved. In general, non-experimental research can not help to determine causes. Experimental research is more time consuming to conduct, and thus more costly.
With this in mind, I read the paper looking for a description of the variables involved in the study - what was being studied and how potential influencing factors were being controlled. Finding none, I determined that the study was non-experimental - the researchers simply observed and reported.
The case study featured a single set of equipment and participants. The study did not examine the outputs from a range of randomly chosen DVRs paired with randomly chosen cameras. Nor did the study include a control group of participants. For the comparison of the methods studied, the study did not feature a range of laser scanners or a range of tools in which to create the reverse projection demonstratives. No discussion as to the specifics of the tool choices was given.
For the participants, those performing the measurement exam, no random assignment was used. Particularly troubling, the participants used in the study were co-workers of the researchers. Employees represent a vulnerable study population and problems can arise when these human subjects are not able to properly consent to participating in the research. As an IRB supervisor, this situation raises the issue of potential bias. As an IRB supervisor, I would expect to see a statement about how the bias would be mitigated in the research and that the researchers' IRB had acknowledged and approved of the research design. Unfortunately, no such statement exists in the study. Given that the study was essentially a non-experimental test of human subjects, and not an experimental test of a particular technology or technique, an IRB's approval is a must. One of the two letters that I submitted upbraided the editorial staff of the JFI for not enforcing it's own rules as regards their requirement for an IRB approval statement for tests of human subjects.
Given the lack of control for bias and extraneous variables, the lack of randomness of participant selection, and the basic non-experimental approach of the work, I decided that this paper could not inform my work or my choice in employing a specific tool or technique.
Digging a bit deeper, I looked at the authors' support for statements made - their references. I noticed that they chose to utilize some relatively obscure or largely unavailable sources. The chosen references would be unavailable to the average analyst without the analyst paying hundreds of dollars to check just one of the references. In my position, however, I have access to a world of research for free through my affiliations with various universities. So, I checked their references.
What I found, and thus reported to the Editor, was that many times the cited materials could not be applied to support the statements made in the research. In a few instances, the cited material actually refuted the authors' assertions.
In the majority of the cited materials, the authors noted that their work couldn't be used to inform a wider variety of research, that case-specific validity studies should be conducted by those engaged in the technique described, or that they were simply offering a "proof-of-concept" to the reader.
In evaluating this particular piece of research, I'm not looking to say - "don't do this technique" or "this technique can't be valid." I want to know if I can use the study to inform my own work in performing photogrammetry. Unfortunately, due to the problems noted in my letters, I can't.
If you're interested in engaging in the creation of mixed-methods demonstratives for display in court, Occam's Input-ACE has an overlay feature that allows one to mix the output from a laser scan into a project that contains CCTV footage. The overlay feature is comparable to a "reverse projection" - it's a demonstrative used to illustrate and reinforce testimony. A "reverse projection" demonstrative is not, in and of itself, a measurement exercise / photogrammetry. Though it is possible to set up the demonstrative, then use SVM to measure within the space. If one wants to measure within the space in such a way as a general rule (not case specific), proper validity studies need to be conducted. At the time of the writing of this post, no such validity studies exist for the calculation of measurements with such a mixed measures approach. If one is so inclined, the model above can be used to both design and evaluate such a study. Until then, I'll continue on with Single View Metrology as the only properly validated 3D measurement technique for 3D subjects / objects depicted within a 2D medium.
Monday, March 4, 2019
What is Analysis?
What is analysis?
a·nal·y·sis [əˈnalÉ™sÉ™s] - NOUN
analyses (plural noun)
synonyms: dissection · assay · testing · breaking down · separation · reduction · decomposition · fractionation
antonyms: synthesis
Forensic science is the systematic and coherent study of traces to address questions of authentication, identification, classification, reconstruction, and evaluation for a legal context. (Source: A Framework to Harmonize Forensic Science Practices and Digital/Multimedia Evidence. OSAC Task Group on Digital/Multimedia Science. 2017)
What is a trace? A trace is any modification, subsequently observable, resulting from an event. You walk within the view of a CCTV system, you leave a trace of your presence within that system.
Thus, forensic video analysis (or forensic multimedia analysis) can be seen as a systematic and coherent examination of video (multimedia) traces (elements) to address questions of authentication, identification, classification, reconstruction, and evaluation for a legal context.
In the former definition, we can see the quantitative nature of analysis. The latter definition reveals it's potential qualitative elements.
In a quantitative data analysis, things are stable, controlled - facts can be obtained (facts are measurable / objective). In a qualitative data analysis, things are dynamic. Your role as an observer may influence the analysis. What is "true" depends on the situation & setting (truths are things we "know" - subjective). A quantitative study is controlled. A qualitative study is observed.
A qualitative study's purpose is to describe or understand something. The purpose of a quantitative study is to test, resolve, or predict something (e.g. in order to use a DVR to determine speed of an object within it's derivative video files - results will be a range of values, one must resolve how the DVR creates files "typically" through a controlled series of tests).
The analyst's viewpoint during a quantitative study is logical, empirical, deductive (conclusion guaranteed). In a qualitative study, it's situational and inductive (conclusion merely likely) or abductive (taking one's best shot). Performing a comparative analysis with convenience samples is an example of taking one's best shot. A quantitative study would feature an appropriate sample size calculation and note any limitations that arose as a result of not being able to achieve the appropriate samples.
From a contextual standpoint, a quantitative's context is not taken into consideration but rather controlled via methodological procedures. In this way, potential bias is mitigated. In a qualitative study, context matters - values, feelings, opinions, individual participants matter.
In a quantitative study, the analyst seeks to solve, to conclude, or to verify a predetermined hypothesis. With a qualitative study, the orientation changes - seeking rather to discover or explore. This can occur often in investigations - new information developed leads to changes in the direction of the investigation as things / people are ruled-in / ruled-out.
In a quantitative analysis, the inputs and results are numerical - data is in the form of numbers / numerical info. A qualitative analysis is narrative in nature - data is in the form of words, sentences, paragraphs, notes, or pictures / graphics / etc.
After conducting a quantitive analysis, one's results / findings can be generalized to other populations or situations. The results of a qualitative analysis are case specific, particular, or specialized.
With all of this in mind, what is analysis? What type of analysis are you conducting? What type of analysis are you reporting? When analyzing the work of other analysts, what type of work are they conducting / reporting?
You can use this dialog to build a template / matrix. In reviewing work, examine the elements above to determine if the work is quantitative or qualitative. For example, you're reviewing an analyst's work in on a measurement request (photogrammetry). The results section features a picture that has been marked up with arrows and text. No methodology is discussed. These results would be considered qualitative. If the results section featured a conclusion, a range of values, error estimation, and a reference / methodology section, it could be considered quantitative. You could take the analyst's data and reproduce their study - which is not possible from an annotated picture.
The elements for a quantitative analysis described above, when reported back to the Trier of Fact, help ensure that you've maintained standards compliance (ASTM E2825-18). Rhetorical or narrative statements are fine for the introductory section of your report - a summary of the request - but are not sufficient for supporting a conclusion or describing one's processes.
If you'd like to know more, join me in an upcoming training session. For more information or to sign up, click here.
a·nal·y·sis [əˈnalÉ™sÉ™s] - NOUN
analyses (plural noun)
- detailed examination of the elements or structure of something. "statistical analysis" · "an analysis of popular culture"
- the process of separating something into its constituent elements. Often contrasted with synthesis. "the procedure is often more accurately described as one of synthesis rather than analysis"
synonyms: dissection · assay · testing · breaking down · separation · reduction · decomposition · fractionation
antonyms: synthesis
Forensic science is the systematic and coherent study of traces to address questions of authentication, identification, classification, reconstruction, and evaluation for a legal context. (Source: A Framework to Harmonize Forensic Science Practices and Digital/Multimedia Evidence. OSAC Task Group on Digital/Multimedia Science. 2017)
What is a trace? A trace is any modification, subsequently observable, resulting from an event. You walk within the view of a CCTV system, you leave a trace of your presence within that system.
In the former definition, we can see the quantitative nature of analysis. The latter definition reveals it's potential qualitative elements.
In a quantitative data analysis, things are stable, controlled - facts can be obtained (facts are measurable / objective). In a qualitative data analysis, things are dynamic. Your role as an observer may influence the analysis. What is "true" depends on the situation & setting (truths are things we "know" - subjective). A quantitative study is controlled. A qualitative study is observed.
A qualitative study's purpose is to describe or understand something. The purpose of a quantitative study is to test, resolve, or predict something (e.g. in order to use a DVR to determine speed of an object within it's derivative video files - results will be a range of values, one must resolve how the DVR creates files "typically" through a controlled series of tests).
The analyst's viewpoint during a quantitative study is logical, empirical, deductive (conclusion guaranteed). In a qualitative study, it's situational and inductive (conclusion merely likely) or abductive (taking one's best shot). Performing a comparative analysis with convenience samples is an example of taking one's best shot. A quantitative study would feature an appropriate sample size calculation and note any limitations that arose as a result of not being able to achieve the appropriate samples.
From a contextual standpoint, a quantitative's context is not taken into consideration but rather controlled via methodological procedures. In this way, potential bias is mitigated. In a qualitative study, context matters - values, feelings, opinions, individual participants matter.
In a quantitative study, the analyst seeks to solve, to conclude, or to verify a predetermined hypothesis. With a qualitative study, the orientation changes - seeking rather to discover or explore. This can occur often in investigations - new information developed leads to changes in the direction of the investigation as things / people are ruled-in / ruled-out.
In a quantitative analysis, the inputs and results are numerical - data is in the form of numbers / numerical info. A qualitative analysis is narrative in nature - data is in the form of words, sentences, paragraphs, notes, or pictures / graphics / etc.
After conducting a quantitive analysis, one's results / findings can be generalized to other populations or situations. The results of a qualitative analysis are case specific, particular, or specialized.
With all of this in mind, what is analysis? What type of analysis are you conducting? What type of analysis are you reporting? When analyzing the work of other analysts, what type of work are they conducting / reporting?
You can use this dialog to build a template / matrix. In reviewing work, examine the elements above to determine if the work is quantitative or qualitative. For example, you're reviewing an analyst's work in on a measurement request (photogrammetry). The results section features a picture that has been marked up with arrows and text. No methodology is discussed. These results would be considered qualitative. If the results section featured a conclusion, a range of values, error estimation, and a reference / methodology section, it could be considered quantitative. You could take the analyst's data and reproduce their study - which is not possible from an annotated picture.
The elements for a quantitative analysis described above, when reported back to the Trier of Fact, help ensure that you've maintained standards compliance (ASTM E2825-18). Rhetorical or narrative statements are fine for the introductory section of your report - a summary of the request - but are not sufficient for supporting a conclusion or describing one's processes.
If you'd like to know more, join me in an upcoming training session. For more information or to sign up, click here.
Thursday, February 28, 2019
The importance of audio
It's been about 4 years now since the body-worn camera really exploded on the scene. Citizens demanded accountability and transparency from their police and the market responded with cameras of all types. Cameras have been deployed on the officer, on the vehicle, and in the air (drones / helicopters). Citizens like the real-time view that theses cameras bring in reviewing officers' interactions with the public. BUT ... these cameras often come with a very sensitive microphone that can clearly capture not only the words of the officers but also every single sound within about 25' radius. This can be a problem in light of the various privacy laws that exist in the US.
This mind-blowing amount of data is sitting in servers at police stations and in the cloud via platforms like Evidence.com. The majority of the cloud vendors offer a solution to accommodate records act releases in light of the many privacy laws that require compliance. But, as users are finding out, pennies saved on features not purchased are costing them dollars when dealing with redaction and other requests for the video they store.
When an agency goes through an equipment purchasing process, they often expend all of their resources and are locked into the solution for years - sometimes a decade or longer. Thus, the test / validate process becomes vital. It's equally vital that all stakeholders participate.
Many agencies purchased camera and storage solutions, but skipped on a redaction plan to come under spending targets. Or, they had a legal structure that let them deny requests for data at the time - but that legal assurance no longer exists (California's new laws are an example of this). They're now faced with new challenges as laws have been enacted / changed to assure that disclosure of videos is the norm, not the exception. Given the guidance in SWGDE's Video and Audio Redaction Guidelines, that redaction must include the audio, video, and metadata, agencies are scrambling to cobble together solutions to fulfill records requests in a timely and cost effective manor.
Video redaction is rather straight forward. Many tools have offered the basic blur, mosaic, and/or solid shape redactions for video content for quite some time. The COTS tools from Adobe, Apple, Avid, Magic all offer some form of global or selective video redaction. There are purpose built redaction tools from Axon, Ikena, etc. that offer redaction as well. Tools like Amped's FIVE have the ability to redact video. BUT ... it's the audio / metadata redaction where many tools fall short.
Amped SRL's CEO promised audio redaction in FIVE in 2106 at the LEVA Training Symposium in Scottsdale in support of Amped's partnership with Axon (who were both present at the Symposium as vendors). To date, audio redaction still has not been implemented in FIVE. Sure, if audio is present in the file, FIVE will pass it through or strip it out. But FIVE isn't an audio editing / redacting tool. For redactions with FIVE, I suggest using FIVE to separate the audio and using a tool like Audacity to edit / redact the audio. At leas Audacity is free and easy to use. If an agency has multiple people working on redaction, it really does make sense to split up the redaction tasks anyway (audio / video / metadata), so I guess the lack of audio support in FIVE for the redaction task isn't that big of a deal.
Ikena's Spotlight suffers similarly. Though it supports audio redaction, it's lack of support for proprietary / secure video file types makes it a tough sell to agencies. In a comparison of FIVE vs Spotlight for redaction, it's a close call. FIVE gives you support for odd file types as well as a full suite of restoration / clarification filters. Spotlight gives you a dedicated redaction platform for audio and video. Both fall short on identifying / redacting specific elements of a file's metadata.
I've been quite the cheerleader for Amped's products over the years, and have noted their strengths for a while now. I've been teaching their product line for over 7 years now, creating and delivering a curriculum that's rather specific to forensic science. But, the lack of audio support has always been the elephant in the room. For example, with the older Video Mixer and new Multiview filters, audio is simply dropped. Users expect to mix video views to create compelling demonstratives - that include an audio source. But these filters do not allow the user to select an audio source for the resulting file. With this, they end up processing the file in a non-linear editor. This issue is where the lack of audio support becomes a big deal and brings us back to that "one tool to fix everything" discussion. It's quite obvious by now that Amped SRL wants to have the best video / image tool, and doesn't want to concern themselves with audio / metadata.
This brings us back to redaction, and the other parts of the multimedia container. If you're going to need an audio editor anyway, and if you're going to have to assemble the separately redacted parts as a final step, why not just do everything in a COTS tool and save the money?
For these reasons, and a few others, the decision was made to offer our redaction courses in many flavors. In standing up training and professional services as a separate organization this year, we can offer training in performing redactions with the relevant COTS platforms as well as a more generic redaction course for supervisory / quality control staff. The initial roll-out of our redaction classes will happen in March 2019 and feature the Adobe Creative Suite tools, Magix Software tools, and Amped SRL's FIVE paired with Audacity - each offered as a separate class. Also the generic course will highlight the different tools, focussing on the process without diving too deeply on the technology.
Recent court cases involving body-worn cameras have highlighted the importance of the devices' audio. Audio is a vital piece of the container. The audio track is often used to confirm / refute elements of complaints, uses of force, and other events that unfold before the device. Because it is present in the container, it must be redacted carefully and accurately. Because audio must be redacted, your redaction solution must include the ability to redact audio. Because it must be redacted, our training sessions feature a variety of options from the big vendors. Stay tuned ...
This mind-blowing amount of data is sitting in servers at police stations and in the cloud via platforms like Evidence.com. The majority of the cloud vendors offer a solution to accommodate records act releases in light of the many privacy laws that require compliance. But, as users are finding out, pennies saved on features not purchased are costing them dollars when dealing with redaction and other requests for the video they store.
When an agency goes through an equipment purchasing process, they often expend all of their resources and are locked into the solution for years - sometimes a decade or longer. Thus, the test / validate process becomes vital. It's equally vital that all stakeholders participate.
Many agencies purchased camera and storage solutions, but skipped on a redaction plan to come under spending targets. Or, they had a legal structure that let them deny requests for data at the time - but that legal assurance no longer exists (California's new laws are an example of this). They're now faced with new challenges as laws have been enacted / changed to assure that disclosure of videos is the norm, not the exception. Given the guidance in SWGDE's Video and Audio Redaction Guidelines, that redaction must include the audio, video, and metadata, agencies are scrambling to cobble together solutions to fulfill records requests in a timely and cost effective manor.
Video redaction is rather straight forward. Many tools have offered the basic blur, mosaic, and/or solid shape redactions for video content for quite some time. The COTS tools from Adobe, Apple, Avid, Magic all offer some form of global or selective video redaction. There are purpose built redaction tools from Axon, Ikena, etc. that offer redaction as well. Tools like Amped's FIVE have the ability to redact video. BUT ... it's the audio / metadata redaction where many tools fall short.
Amped SRL's CEO promised audio redaction in FIVE in 2106 at the LEVA Training Symposium in Scottsdale in support of Amped's partnership with Axon (who were both present at the Symposium as vendors). To date, audio redaction still has not been implemented in FIVE. Sure, if audio is present in the file, FIVE will pass it through or strip it out. But FIVE isn't an audio editing / redacting tool. For redactions with FIVE, I suggest using FIVE to separate the audio and using a tool like Audacity to edit / redact the audio. At leas Audacity is free and easy to use. If an agency has multiple people working on redaction, it really does make sense to split up the redaction tasks anyway (audio / video / metadata), so I guess the lack of audio support in FIVE for the redaction task isn't that big of a deal.
Ikena's Spotlight suffers similarly. Though it supports audio redaction, it's lack of support for proprietary / secure video file types makes it a tough sell to agencies. In a comparison of FIVE vs Spotlight for redaction, it's a close call. FIVE gives you support for odd file types as well as a full suite of restoration / clarification filters. Spotlight gives you a dedicated redaction platform for audio and video. Both fall short on identifying / redacting specific elements of a file's metadata.
I've been quite the cheerleader for Amped's products over the years, and have noted their strengths for a while now. I've been teaching their product line for over 7 years now, creating and delivering a curriculum that's rather specific to forensic science. But, the lack of audio support has always been the elephant in the room. For example, with the older Video Mixer and new Multiview filters, audio is simply dropped. Users expect to mix video views to create compelling demonstratives - that include an audio source. But these filters do not allow the user to select an audio source for the resulting file. With this, they end up processing the file in a non-linear editor. This issue is where the lack of audio support becomes a big deal and brings us back to that "one tool to fix everything" discussion. It's quite obvious by now that Amped SRL wants to have the best video / image tool, and doesn't want to concern themselves with audio / metadata.
This brings us back to redaction, and the other parts of the multimedia container. If you're going to need an audio editor anyway, and if you're going to have to assemble the separately redacted parts as a final step, why not just do everything in a COTS tool and save the money?
For these reasons, and a few others, the decision was made to offer our redaction courses in many flavors. In standing up training and professional services as a separate organization this year, we can offer training in performing redactions with the relevant COTS platforms as well as a more generic redaction course for supervisory / quality control staff. The initial roll-out of our redaction classes will happen in March 2019 and feature the Adobe Creative Suite tools, Magix Software tools, and Amped SRL's FIVE paired with Audacity - each offered as a separate class. Also the generic course will highlight the different tools, focussing on the process without diving too deeply on the technology.
Recent court cases involving body-worn cameras have highlighted the importance of the devices' audio. Audio is a vital piece of the container. The audio track is often used to confirm / refute elements of complaints, uses of force, and other events that unfold before the device. Because it is present in the container, it must be redacted carefully and accurately. Because audio must be redacted, your redaction solution must include the ability to redact audio. Because it must be redacted, our training sessions feature a variety of options from the big vendors. Stay tuned ...
Wednesday, February 27, 2019
One tool to fix everything?
When I first began working cases, there weren't many vendors offering gear and services in this space. There wasn't really a market, per se. Most of us used COTS tools like Photoshop, Premiere Pro, Media Composer, etc. Then, the purpose-built tools arrived and analysts' hopes were raised - will there be one tool that fixes everything and fills every need? So many years later, the answer is still no.
For example, if you like Input-Ace for processing proprietary files, you'll likely have an extra capture tool, Photoshop for optical correction (with various plug-ins), Acrobat for reporting, and so forth. Input-Ace has some capabilities for creating demonstratives, but not on the scale of PremierePro or Media Composer - so you'll likely have one or both of those tools as well. For audio, your preference of Audacity / Audition / Sound Forge / etc. will likely depend on when you started working with audio and what plug-in suites you own. But, you'll need an audio tools as Input-Ace isn't a tool for audio forensics ... which is fine. Remember, Sound Forge isn't a tool for converting proprietary video files.
Likewise for Amped's customers. Sure, FIVE is a feature packed tool. But, like Input-Ace, it lacks full support for audio, creating robust demonstratives, etc. So, you'll need the Adobe Creative Suite or the full package from Magix (Vegas, Sound Forge, and Spectral Layers).
Why is this so?
Outside of federal / national service, it's rare to find an agency with dedicated analysts and a dedicated trial support crew. Most analysts are also asked to create demonstratives for the investigation, the media, and the court. Sometimes, trial support employees are asked to perform analysis. Often multimedia analysts are tasked with computer forensics, mobile device forensics, and the entire "digital crime scene." In a few cases, the employee is responsible for the entire crime scene - latent prints, serology, photography... + the digital stuff (CCTV, computers, phones, etc.). Usually, the smaller the agency / company, the more the individual employee is tasked to do.
Thus, there will likely never be one tool to fix everything. You may think we're close. We're not. Encase is a nice tool for computer forensics, but it doesn't really handle a computer that happens to be a DVR. For that, you'll need a tool like DVR Examiner. But even DVR Examiner has limits, some of which are addressed by Salvation Data's Video Investigator Portable (VIP). SalvationData has tools for computer and mobile device forensics as well, DME Forensics does not. It's not a bad thing. It just is.
In future posts, I'll explore some essential workflows that show this blend of tools. I'll illustrate the various points that may complicate your validation and offer tips to solve this tricky problem. In each case, we'll follow the standards and show how to populate a standards-compliant report. I'll be building out my ScreenCast portal with some of these simple video tutorials. For full fledged training to competency, there are the options of micro-learning, in-person (in Henderson, NV), and in-person (at your location).
Whilst some may bemoan this lack of a singularity, I don't. I love the wondrous variety that has appeared in the marketplace. I welcome the challenge of showing / training / educating you about this complex topic. I'm already rolling out new training offerings, with more to come. Jump over to the training page for the up-to-date training calendar. Or, sign-up for my new newsletter.
The future of forensic multimedia analysis is wide open. I'm excited to be a part of it, and to be your guide. Join me in the fun.
For example, if you like Input-Ace for processing proprietary files, you'll likely have an extra capture tool, Photoshop for optical correction (with various plug-ins), Acrobat for reporting, and so forth. Input-Ace has some capabilities for creating demonstratives, but not on the scale of PremierePro or Media Composer - so you'll likely have one or both of those tools as well. For audio, your preference of Audacity / Audition / Sound Forge / etc. will likely depend on when you started working with audio and what plug-in suites you own. But, you'll need an audio tools as Input-Ace isn't a tool for audio forensics ... which is fine. Remember, Sound Forge isn't a tool for converting proprietary video files.
Likewise for Amped's customers. Sure, FIVE is a feature packed tool. But, like Input-Ace, it lacks full support for audio, creating robust demonstratives, etc. So, you'll need the Adobe Creative Suite or the full package from Magix (Vegas, Sound Forge, and Spectral Layers).
Why is this so?
Outside of federal / national service, it's rare to find an agency with dedicated analysts and a dedicated trial support crew. Most analysts are also asked to create demonstratives for the investigation, the media, and the court. Sometimes, trial support employees are asked to perform analysis. Often multimedia analysts are tasked with computer forensics, mobile device forensics, and the entire "digital crime scene." In a few cases, the employee is responsible for the entire crime scene - latent prints, serology, photography... + the digital stuff (CCTV, computers, phones, etc.). Usually, the smaller the agency / company, the more the individual employee is tasked to do.
Thus, there will likely never be one tool to fix everything. You may think we're close. We're not. Encase is a nice tool for computer forensics, but it doesn't really handle a computer that happens to be a DVR. For that, you'll need a tool like DVR Examiner. But even DVR Examiner has limits, some of which are addressed by Salvation Data's Video Investigator Portable (VIP). SalvationData has tools for computer and mobile device forensics as well, DME Forensics does not. It's not a bad thing. It just is.
In future posts, I'll explore some essential workflows that show this blend of tools. I'll illustrate the various points that may complicate your validation and offer tips to solve this tricky problem. In each case, we'll follow the standards and show how to populate a standards-compliant report. I'll be building out my ScreenCast portal with some of these simple video tutorials. For full fledged training to competency, there are the options of micro-learning, in-person (in Henderson, NV), and in-person (at your location).
Whilst some may bemoan this lack of a singularity, I don't. I love the wondrous variety that has appeared in the marketplace. I welcome the challenge of showing / training / educating you about this complex topic. I'm already rolling out new training offerings, with more to come. Jump over to the training page for the up-to-date training calendar. Or, sign-up for my new newsletter.
The future of forensic multimedia analysis is wide open. I'm excited to be a part of it, and to be your guide. Join me in the fun.
Friday, February 15, 2019
A decade later, still going strong
About a decade ago, Photoshop officially became a verb in Los Angeles and I began my quest for the tool or tools that would replace my old friend. I stumbled upon a small Italian company with an amazing product - Amped SRL and it's flagship product, FIVE. I was instantly a fan. Becoming a customer was a bit more problematic as I wasn't officially a "forensic analyst" yet. As a surveillance / counter-surveillance operator, I used the fact that FIVE could connect to a Milestone Client (my Axis pole cameras) and do all those wonderful "Photoshoppy" things to the live feed. Thus, I pitched my original purchase request noting that FIVE was an ISR tool needed to add capabilities to our night-time surveillance operations.
I finally received a license, getting quite creative in the acquisition process, and began to sort out training. There was no way that my agency would send me to Italy and it was too cost prohibitive to bring an Italian instructor to Los Angeles. Luckily, the North American reseller of Amped's products was about a half-day's drive from LA. I booked a "training session" and headed down the highway.
Upon arrival, I was greeted by a friendly face and an outstretched arm that was holding a rather tasty local brew. We discussed the filters, in no particular order. We discussed use cases, in no particular order. That I had existing expertise in photography and imaging helped me to make sense and contextualize the information. But, it wasn't "training" as I recognized it or as CA POST defined it.
I made my host an offer. I'm a trained and educated curriculum / instructional designer. I'm a CA POST certified instructor. I'll design / create / deliver a curriculum for multi-media analysis, based on Amped FIVE, and deliver it to your customers under contract. Given that I often earned about half-again my income as "comp time " (aka furloughed-in-place), and that I had to use that "comp time" rather frequently, I worked out that I could deliver a training session somewhere in North America about once per month. Agreement was reached and the relationship with Amped Software, Inc. began.
Fast forward to today. I've been all over the US as a contract instructor. I've been to Canada. I've trained agents of more than 50 countries who wanted to come to the US for their training. I've spent an amazing 3 weeks in South Africa working with their police service in modernizing their offerings. A little more than 3 years ago, I retired from the LAPD and joined the staff of Amped Software, Inc, as the Director of Support / Training.
The curriculum that was developed for the North American market is fit for purpose in this market. It's not necessarily applicable for other markets around the world, although there are many similarities. I have found that the modifications made, and the specific curriculum variant created for the US military courts easily accommodates countries with a Magistrate system of jurisprudence. When teaching courses with non-US students, I make every effort to contextualize the offerings to their context.
Whilst the rest of the world moves at a slower pace, the North American market changes quite a bit year-over-year. You might of heard that Amped decided to not continue with Axon as a reseller of it's products in this market last year. What you might not know is how the changes in the latest tax laws (federal and state) have caused significant impact to the market.
To respond to the changes in tax / business law, as well as in response to the economic / market demands, I've made the decision to expand training offerings to the on-line space via a micro-learning model as a separate business entity. Being the rights-holder of my curriculum's IP, I'm able to be flexible in where / how the curriculum is presented.
The Apex Learning portal was launched shortly after the first of this year on the LearnUpon LMS. You can find out more by clicking here. All of the training that I've presented live will eventually be offered on-line via a micro-learning model. The first course is already released - Statistics for Forensic Analysts.
If you're a long-time LEVA member, like me, you might recall my mentioning a "curriculum in a box concept." The "curriculum in box" is an "undergraduate education" in digital multimedia analysis. This will eventually be fully implemented in the Apex Learning portal. The first of these classes, the aforementioned Stats class, is already live. More courses will be released soon. Next up, however, will be a redaction class that is a response to the new laws in California - but applicable to any agency faced with redacting DME under tight budgetary and time constraints.
As budgets tighten, and travel becomes a problem, migrating training and education to the virtual space, facilitated by the micro-learning model, is the logical next step. The cost savings of not having to travel to you, or for you to travel to me, is passed along in significantly lower registration costs. As an example, an undergraduate Stats class offered at Texas A&M University would cost a Texas resident about $1200 (source). This is the base rate for the class. There are also admission fees, the fees to take the pre-requisite courses, and the travel to / from College Station over the semester. Apex is offering the course at $595.
The generic university course in statistics is geared to the academic, interested in the world of objective statistics. This world is entirely different than the statistics that underpin the forensic sciences - subjective statistics. That is why, after a solid introduction, Statistics for Forensic Analysts explores the two types of statistics separately and fairly. This class is for consumers and producers of statistics within the forensic sciences - not for the quants who inhabit the university halls.
Future offerings will be priced in a similar fashion. We're able to pass the savings on to you, and we do.
It's also worth noting that the courses on offer are not "in competition" with the other classes available to analysts. As an example, the Stats class is entirely complimentary to the LEVA Levels courses and serves to further inform these information-dense offerings. The Forensic Photographic Comparison course that will arrive on the portal later this year will similarly serve as an incredible scientific foundation to LEVA's Level 3. There's no way a single vendor can offer everything that you need. We're offering courses not currently present in the market in order to support the community - not to replace offerings from your current vendors.
Finally, I'll be updating the Forensic Photoshop book and the Forensic Photoshop course and offering them via the portal. A complete refresh of the tools and plug-ins will be featured for those who are still using Photoshop. Remember, courses like LEVA Level 3 still feature Photoshop as their platform. If a student is new to Photoshop, they must learn the meat of the course and the platform at the same time. Revamping the Forensic Photoshop course will allow the LEVA student to arrive at that course with competency in the tool, assuring that they can be all-in on the instruction. For those privateers who can't afford expensive tools from government-oriented vendors, tools from companies like Adobe are still popular. DME-specific courses are needed and will be presented in the portal.
It's an exciting time here. I'm thankful that you've been with me for this amazing journey. The next few years will bring so much change to the market. Will you join with me in embracing change and upgrading your knowledge?
I finally received a license, getting quite creative in the acquisition process, and began to sort out training. There was no way that my agency would send me to Italy and it was too cost prohibitive to bring an Italian instructor to Los Angeles. Luckily, the North American reseller of Amped's products was about a half-day's drive from LA. I booked a "training session" and headed down the highway.
Upon arrival, I was greeted by a friendly face and an outstretched arm that was holding a rather tasty local brew. We discussed the filters, in no particular order. We discussed use cases, in no particular order. That I had existing expertise in photography and imaging helped me to make sense and contextualize the information. But, it wasn't "training" as I recognized it or as CA POST defined it.
I made my host an offer. I'm a trained and educated curriculum / instructional designer. I'm a CA POST certified instructor. I'll design / create / deliver a curriculum for multi-media analysis, based on Amped FIVE, and deliver it to your customers under contract. Given that I often earned about half-again my income as "comp time " (aka furloughed-in-place), and that I had to use that "comp time" rather frequently, I worked out that I could deliver a training session somewhere in North America about once per month. Agreement was reached and the relationship with Amped Software, Inc. began.
Fast forward to today. I've been all over the US as a contract instructor. I've been to Canada. I've trained agents of more than 50 countries who wanted to come to the US for their training. I've spent an amazing 3 weeks in South Africa working with their police service in modernizing their offerings. A little more than 3 years ago, I retired from the LAPD and joined the staff of Amped Software, Inc, as the Director of Support / Training.
The curriculum that was developed for the North American market is fit for purpose in this market. It's not necessarily applicable for other markets around the world, although there are many similarities. I have found that the modifications made, and the specific curriculum variant created for the US military courts easily accommodates countries with a Magistrate system of jurisprudence. When teaching courses with non-US students, I make every effort to contextualize the offerings to their context.
Whilst the rest of the world moves at a slower pace, the North American market changes quite a bit year-over-year. You might of heard that Amped decided to not continue with Axon as a reseller of it's products in this market last year. What you might not know is how the changes in the latest tax laws (federal and state) have caused significant impact to the market.
To respond to the changes in tax / business law, as well as in response to the economic / market demands, I've made the decision to expand training offerings to the on-line space via a micro-learning model as a separate business entity. Being the rights-holder of my curriculum's IP, I'm able to be flexible in where / how the curriculum is presented.
The Apex Learning portal was launched shortly after the first of this year on the LearnUpon LMS. You can find out more by clicking here. All of the training that I've presented live will eventually be offered on-line via a micro-learning model. The first course is already released - Statistics for Forensic Analysts.
If you're a long-time LEVA member, like me, you might recall my mentioning a "curriculum in a box concept." The "curriculum in box" is an "undergraduate education" in digital multimedia analysis. This will eventually be fully implemented in the Apex Learning portal. The first of these classes, the aforementioned Stats class, is already live. More courses will be released soon. Next up, however, will be a redaction class that is a response to the new laws in California - but applicable to any agency faced with redacting DME under tight budgetary and time constraints.
As budgets tighten, and travel becomes a problem, migrating training and education to the virtual space, facilitated by the micro-learning model, is the logical next step. The cost savings of not having to travel to you, or for you to travel to me, is passed along in significantly lower registration costs. As an example, an undergraduate Stats class offered at Texas A&M University would cost a Texas resident about $1200 (source). This is the base rate for the class. There are also admission fees, the fees to take the pre-requisite courses, and the travel to / from College Station over the semester. Apex is offering the course at $595.
The generic university course in statistics is geared to the academic, interested in the world of objective statistics. This world is entirely different than the statistics that underpin the forensic sciences - subjective statistics. That is why, after a solid introduction, Statistics for Forensic Analysts explores the two types of statistics separately and fairly. This class is for consumers and producers of statistics within the forensic sciences - not for the quants who inhabit the university halls.
Future offerings will be priced in a similar fashion. We're able to pass the savings on to you, and we do.
It's also worth noting that the courses on offer are not "in competition" with the other classes available to analysts. As an example, the Stats class is entirely complimentary to the LEVA Levels courses and serves to further inform these information-dense offerings. The Forensic Photographic Comparison course that will arrive on the portal later this year will similarly serve as an incredible scientific foundation to LEVA's Level 3. There's no way a single vendor can offer everything that you need. We're offering courses not currently present in the market in order to support the community - not to replace offerings from your current vendors.
Finally, I'll be updating the Forensic Photoshop book and the Forensic Photoshop course and offering them via the portal. A complete refresh of the tools and plug-ins will be featured for those who are still using Photoshop. Remember, courses like LEVA Level 3 still feature Photoshop as their platform. If a student is new to Photoshop, they must learn the meat of the course and the platform at the same time. Revamping the Forensic Photoshop course will allow the LEVA student to arrive at that course with competency in the tool, assuring that they can be all-in on the instruction. For those privateers who can't afford expensive tools from government-oriented vendors, tools from companies like Adobe are still popular. DME-specific courses are needed and will be presented in the portal.
It's an exciting time here. I'm thankful that you've been with me for this amazing journey. The next few years will bring so much change to the market. Will you join with me in embracing change and upgrading your knowledge?
Thursday, February 14, 2019
Convert numbers to different number systems
Here's some helpful and time-saving advice on using MS Excel to convert numbers between different number systems (link).
Monday, February 11, 2019
Number Systems: An Introduction to Binary, Hexadecimal, and More
Here's an excellent tutorial on number systems (link) and their relationship to colour representation in computer systems.
Wednesday, February 6, 2019
Training, training, and more training
With the new year comes new tax laws, new regulations, and new rules that require businesses and individuals to modify their path as they navigate the world of governmental compliance. It's no different here in stormy southern Nevada.
But, with change comes opportunity. 2019 brings change for the better, and more training offerings than ever before.
I've already announced the release of Statistics for Forensic Analysts. This is offered as micro-learning, on-line and on-demand and comes in response to initiatives at the federal and state level. Given that statistics form the foundation of much of opinion based testimony in the digital forensic sciences, as well as the other disciplines that offer photographic comparison evidence (latent print, tool mark, firearms, questioned documents, etc), this class is designed to provide the necessary instruction in statistics - specifically tailored for forensic science practitioners.
With redaction begin the focus of much of the US, as well as being the focus of a new set of laws in California, I've announced a redaction class specific for California agencies to help not only with mastering the technology ... but also navigating complex a legal context. This class comes in four versions, if you will. If you're an Amped Software customer, the hands-on learning will be facilitated with Amped FIVE (video) and Audacity (audio). If you're an Adobe customer, the hands-on learning will be facilitated with the Adobe Creative Suite. If you're a Magix customer, the hands-on learning will be facilitated with Vegas and Sound Forge. And, if you haven't decided on a solution, our general class will provide an overview of all of these solutions, giving you a sense of what may work best for you, your agency, and your legal context. Even if you're not in California, their strict regime's rules help to illustrate the many compliance issues you may not realize apply to you and your agency.
All of these redaction classes will be offered via micro-learning, maximizing your training dollars and offering significant savings over traveling to training. Partnering with LearnUpon for the LMS, these micro-learning sessions are available world-wide with local currency payment options via Square, PayPal, or TransferWise. They will also be offered in Henderson, NV. If you've got a big group, and you'd like a training session at your location, that can be arranged as well. In fact, all of the offerings going forward will be available this way - on-line, in Henderson, or at your location.
It's going to be an exciting year. I'm excited that technology has evolved such that it's becoming easier and more cost effective to offer flexible training options. So stay tuned, it's going to be a fun ride. New offerings will be rolling out each month. In the meantime, head over and sign up for Statistics for Forensic Analysts ...
But, with change comes opportunity. 2019 brings change for the better, and more training offerings than ever before.
I've already announced the release of Statistics for Forensic Analysts. This is offered as micro-learning, on-line and on-demand and comes in response to initiatives at the federal and state level. Given that statistics form the foundation of much of opinion based testimony in the digital forensic sciences, as well as the other disciplines that offer photographic comparison evidence (latent print, tool mark, firearms, questioned documents, etc), this class is designed to provide the necessary instruction in statistics - specifically tailored for forensic science practitioners.
With redaction begin the focus of much of the US, as well as being the focus of a new set of laws in California, I've announced a redaction class specific for California agencies to help not only with mastering the technology ... but also navigating complex a legal context. This class comes in four versions, if you will. If you're an Amped Software customer, the hands-on learning will be facilitated with Amped FIVE (video) and Audacity (audio). If you're an Adobe customer, the hands-on learning will be facilitated with the Adobe Creative Suite. If you're a Magix customer, the hands-on learning will be facilitated with Vegas and Sound Forge. And, if you haven't decided on a solution, our general class will provide an overview of all of these solutions, giving you a sense of what may work best for you, your agency, and your legal context. Even if you're not in California, their strict regime's rules help to illustrate the many compliance issues you may not realize apply to you and your agency.
All of these redaction classes will be offered via micro-learning, maximizing your training dollars and offering significant savings over traveling to training. Partnering with LearnUpon for the LMS, these micro-learning sessions are available world-wide with local currency payment options via Square, PayPal, or TransferWise. They will also be offered in Henderson, NV. If you've got a big group, and you'd like a training session at your location, that can be arranged as well. In fact, all of the offerings going forward will be available this way - on-line, in Henderson, or at your location.
It's going to be an exciting year. I'm excited that technology has evolved such that it's becoming easier and more cost effective to offer flexible training options. So stay tuned, it's going to be a fun ride. New offerings will be rolling out each month. In the meantime, head over and sign up for Statistics for Forensic Analysts ...
Thursday, January 31, 2019
Reproducibility
One of the scenarios that multimedia analysts find themselves in when doing casework is reproducing the work of others. Sure, you've been trained on the tools that you use. But, have you been trained on the tools that others use? This is one of the many reasons I have always advocated analysts have a "one of each" mentality. Get all the available tools. Get all of the available training.
If opposing counsel's analyst has used Adobe products, for example, do you the training and experience with these tools? What if the analyst is using an older version of the tools?
As an example of this, I have an old laptop with Photoshop CS2 running the legacy scripts from Reindeer Graphics. Sure, Chris Russ has new tools available, like his new Forensic ID plug-in. I like Forensic ID. I like that I can visually adjust the deconvolution filter, not relying so much on specific numbers and targeting the results. But, there are still times when I'll need the old stuff (cold case work, appeals, etc.). That's why I keep everything.
If you're a Adobe Creative Cloud subscriber, you can access older versions of their tools via the web site. The "Other Downloads" page has a complete listing of the legacy versions, each coming with specific warnings about updates and security. I recommend installing these in Virtual Machines so as to not compromise your host OS' security.
Find the needed installer. Install it into a VM (I like VirtualBox). Take the opposing analyst's notes. Attempt to reproduce the work and results. Document your work. Done.
Over at the Amped Support Portal, similar functionality exists for users with current support contracts. You'll find the change log and installers for previous versions.
For other tools, like Doug Carner's Video Cleaner, only the current version is readily available on the company's web site. If you're using a tool from a company that only hosts the current release, you'll want to keep a copy of each version's installer. If you're working the other side of a case, and the analyst is using an older version of VideoCleaner, or similar tool, you'll likely have to reach out to the developer / company for the older version's installer. Whilst Doug is a nice man and will likely send you a download link rather quickly, other companies might not be so accommodating. It may take a request from the court, written to the software company, to get the older installer and a temporary license. Or, as has happened to me, the court may rule that you're not allowed to use your preferred tool as it's not available to the other side (licensing restrictions, cost, etc.).
This year, reproducing others' work in various tools will be the focus of a series of informational videos that I'll be creating and hosting over at Screencast.com. Stay tuned for that.
Enjoy.
If opposing counsel's analyst has used Adobe products, for example, do you the training and experience with these tools? What if the analyst is using an older version of the tools?
As an example of this, I have an old laptop with Photoshop CS2 running the legacy scripts from Reindeer Graphics. Sure, Chris Russ has new tools available, like his new Forensic ID plug-in. I like Forensic ID. I like that I can visually adjust the deconvolution filter, not relying so much on specific numbers and targeting the results. But, there are still times when I'll need the old stuff (cold case work, appeals, etc.). That's why I keep everything.
If you're a Adobe Creative Cloud subscriber, you can access older versions of their tools via the web site. The "Other Downloads" page has a complete listing of the legacy versions, each coming with specific warnings about updates and security. I recommend installing these in Virtual Machines so as to not compromise your host OS' security.
Find the needed installer. Install it into a VM (I like VirtualBox). Take the opposing analyst's notes. Attempt to reproduce the work and results. Document your work. Done.
Over at the Amped Support Portal, similar functionality exists for users with current support contracts. You'll find the change log and installers for previous versions.
For other tools, like Doug Carner's Video Cleaner, only the current version is readily available on the company's web site. If you're using a tool from a company that only hosts the current release, you'll want to keep a copy of each version's installer. If you're working the other side of a case, and the analyst is using an older version of VideoCleaner, or similar tool, you'll likely have to reach out to the developer / company for the older version's installer. Whilst Doug is a nice man and will likely send you a download link rather quickly, other companies might not be so accommodating. It may take a request from the court, written to the software company, to get the older installer and a temporary license. Or, as has happened to me, the court may rule that you're not allowed to use your preferred tool as it's not available to the other side (licensing restrictions, cost, etc.).
This year, reproducing others' work in various tools will be the focus of a series of informational videos that I'll be creating and hosting over at Screencast.com. Stay tuned for that.
Enjoy.
Monday, January 28, 2019
Training Notice: Statistics for Forensic Analysts
I'm pleased to announce that Apex Learning, our state-of-the-art learning portal, is officially launching today with our first offering - Statistics for Forensic Analysts.
Statistics play an important and expanding role in criminal investigations, prosecutions and trials, not least in relation to forensic scientific evidence produced by expert witnesses. The Royal Statistical Society (UK) began a process in 2010 to inform and educate stakeholders in the justice system in with their publication of Fundamentals of Probability and Statistical Evidence in Criminal Proceedings. From that original work product, a total of four publications have been produced from the Society’s Statistics and the Law Section. Simultaneously, the National Commission on Forensic Science (US) began to study the issue. Several of its subcommittees have informed the discussion on the use of statistics in forensic science, issuing various guidance documents to the US Department of Justice. In 2015, the US state of Texas passed SB-1287 creating a licensing program for forensic science practitioners and analysts. Within the Texas licensing program, analysts will be tested across a variety of foundational domains in order to obtain licensure, including statistics.
What's different about Apex Learning?
To accommodate learners around the world, we're packaging these courses as micro-learning and delivering them on-line. Upon sign-up, learners have up to 60 days to complete each course.
We're leveraging a state-of-the-art learning management system to deliver quality training and education offerings that can be accessed from anywhere in the world. This reduces the cost to train / educate each analyst dramatically. We're passing the savings on to the customer, as you'll see in our first offering's price.
With PayPal, we can accept payment in the majority of the world's currencies. For institutional orders (multiple students from the same agency), we can accept bank transfers in over 30 currencies from our European based TransferWise accounts.
Our courses aren't designed to compete with anyone's offerings. They're designed to complement them by adding depth and breadth, shoring up topics that the average analyst might not be exposed to.
Stay tuned as we roll out more offerings. It's going to be a great year.
Statistics play an important and expanding role in criminal investigations, prosecutions and trials, not least in relation to forensic scientific evidence produced by expert witnesses. The Royal Statistical Society (UK) began a process in 2010 to inform and educate stakeholders in the justice system in with their publication of Fundamentals of Probability and Statistical Evidence in Criminal Proceedings. From that original work product, a total of four publications have been produced from the Society’s Statistics and the Law Section. Simultaneously, the National Commission on Forensic Science (US) began to study the issue. Several of its subcommittees have informed the discussion on the use of statistics in forensic science, issuing various guidance documents to the US Department of Justice. In 2015, the US state of Texas passed SB-1287 creating a licensing program for forensic science practitioners and analysts. Within the Texas licensing program, analysts will be tested across a variety of foundational domains in order to obtain licensure, including statistics.
What's different about Apex Learning?
To accommodate learners around the world, we're packaging these courses as micro-learning and delivering them on-line. Upon sign-up, learners have up to 60 days to complete each course.
We're leveraging a state-of-the-art learning management system to deliver quality training and education offerings that can be accessed from anywhere in the world. This reduces the cost to train / educate each analyst dramatically. We're passing the savings on to the customer, as you'll see in our first offering's price.
With PayPal, we can accept payment in the majority of the world's currencies. For institutional orders (multiple students from the same agency), we can accept bank transfers in over 30 currencies from our European based TransferWise accounts.
Our courses aren't designed to compete with anyone's offerings. They're designed to complement them by adding depth and breadth, shoring up topics that the average analyst might not be exposed to.
Stay tuned as we roll out more offerings. It's going to be a great year.
Tuesday, January 22, 2019
Training Notice: Redaction for California SB1421 / AB748 Compliance
Training Notice
Recent legal changes in California have impacted the way in which agencies handle video / multimedia evidence requests from the public. Complying with the new laws, and maintaining compliance with state and federal privacy codes requires agencies to manage the processing of requests quite carefully. Requests for records around a critical event can quickly swamp an agency’s staff given the new statutory time frames for the release of data.
Senate Bill 1421, Skinner (D. Berkeley), opens public access to internal investigations of police shootings and other incidents where an officer killed or seriously injured someone, as well to sustained findings of sexual assault and lying on the job.
Assembly Bill 748, Ting (D. San Francisco), requires police departments to release within 45 days audio or video footage of shootings or other incidents involving serious use of force, unless it would interfere with an active investigation.
This in-person course will get the agency and their redaction staff up to speed on the issues and the technology necessary to bring the agency into compliance with the new laws.
Location: Apex Partners, Ltd., Henderson, NV USA
Date: April 2-3, 2019
Product Information: Adobe Creative Suite
Click here for more information and to sign-up for this course.
This course can be brought to the agency. Visit the web site to find out how.
Recent legal changes in California have impacted the way in which agencies handle video / multimedia evidence requests from the public. Complying with the new laws, and maintaining compliance with state and federal privacy codes requires agencies to manage the processing of requests quite carefully. Requests for records around a critical event can quickly swamp an agency’s staff given the new statutory time frames for the release of data.
Senate Bill 1421, Skinner (D. Berkeley), opens public access to internal investigations of police shootings and other incidents where an officer killed or seriously injured someone, as well to sustained findings of sexual assault and lying on the job.
Assembly Bill 748, Ting (D. San Francisco), requires police departments to release within 45 days audio or video footage of shootings or other incidents involving serious use of force, unless it would interfere with an active investigation.
This in-person course will get the agency and their redaction staff up to speed on the issues and the technology necessary to bring the agency into compliance with the new laws.
Location: Apex Partners, Ltd., Henderson, NV USA
Date: April 2-3, 2019
Product Information: Adobe Creative Suite
Click here for more information and to sign-up for this course.
This course can be brought to the agency. Visit the web site to find out how.
Monday, January 14, 2019
Test your report's readability
One of the concepts that I tend to repeat when training folks in the forensic sciences is that our work should target the last mechanical device that will display or project our work products as well as targeting the combined perceptual abilities of the Trier of Fact. Working in this way, there will be no surprises when it comes to presenting your work.
The same is true for your reports. Your reports will make sense to you. You wrote them. They'll make sense to your quality control staff (your reviewers) as they tend to exist in the same culture and climate as you. But, will they make sense to the Trier of Fact - without you having to explain it to them?
There is functionality within our toolset to help with this question - how readable is my report? If you're using MS Word to draft your reports, it's actually quite easy to set this up.
After you enable this feature, open a file that you want to check, and check the spelling by pressing F7 or going to Review > Spelling & Grammar. When Word finishes checking the spelling and grammar, it displays information about the reading level of the document.
Each readability test bases its rating on the average number of syllables per word and words per sentence. The following sections explain how each test scores your file's readability.
Flesch Reading Ease test (references)
Originally developed for the US Navy in 1975, this test rates text on a 100-point scale. The higher the score, the easier it is to understand the document. For most forensic science processing / analysis reports, you want the score to be between 55 and 70. Given that we'll have to use standard scientific terminology, it will be difficult to achieve readability scores higher than 70.
The formula for the Flesch Reading Ease score is:
206.835 – (1.015 x ASL) – (84.6 x ASW)
where:
ASL = average sentence length (the number of words divided by the number of sentences)
ASW = average number of syllables per word (the number of syllables divided by the number of words)
Flesch-Kincaid Grade Level test
This test rates text on a U.S. school grade level. For example, a score of 8.0 means that an eighth grader can understand the document. For your reports, aim for a score of approximately 7.0 to 10.0. It will prove difficult to bring these values down, as noted above, due to our use of scientific language which gets averaged into the total score.
The formula for the Flesch-Kincaid Grade Level score is:
(.39 x ASL) + (11.8 x ASW) – 15.59
where:
ASL = average sentence length (the number of words divided by the number of sentences)
ASW = average number of syllables per word (the number of syllables divided by the number of words)
The Readability Statistics shown above is from a raw authentication report - before editing and before the insertion of the plain English explanations for each of the processes.
Given that about 95% of cases plea and never see the inside of a court room, it's vitally important that your reports be readable. 95% of your reports will be read, interpreted, and acted upon without your being present to help the reader understand what you said / meant. With this simple tool that is built into many word processing applications, you can assure that your reports are readable, and at what grade level.
If you're using Google Docs, you'll need to run your report through another app or web site. Readability Statistics were removed some time ago.
Enjoy.
The same is true for your reports. Your reports will make sense to you. You wrote them. They'll make sense to your quality control staff (your reviewers) as they tend to exist in the same culture and climate as you. But, will they make sense to the Trier of Fact - without you having to explain it to them?
There is functionality within our toolset to help with this question - how readable is my report? If you're using MS Word to draft your reports, it's actually quite easy to set this up.
- Click the File tab, and then click Options.
- Click Proofing.
- Under When correcting spelling and grammar in Word, make sure the Check grammar with spelling check box is selected.
- Select Show readability statistics.
After you enable this feature, open a file that you want to check, and check the spelling by pressing F7 or going to Review > Spelling & Grammar. When Word finishes checking the spelling and grammar, it displays information about the reading level of the document.
Each readability test bases its rating on the average number of syllables per word and words per sentence. The following sections explain how each test scores your file's readability.
Flesch Reading Ease test (references)
Originally developed for the US Navy in 1975, this test rates text on a 100-point scale. The higher the score, the easier it is to understand the document. For most forensic science processing / analysis reports, you want the score to be between 55 and 70. Given that we'll have to use standard scientific terminology, it will be difficult to achieve readability scores higher than 70.
The formula for the Flesch Reading Ease score is:
206.835 – (1.015 x ASL) – (84.6 x ASW)
where:
ASL = average sentence length (the number of words divided by the number of sentences)
ASW = average number of syllables per word (the number of syllables divided by the number of words)
Flesch-Kincaid Grade Level test
This test rates text on a U.S. school grade level. For example, a score of 8.0 means that an eighth grader can understand the document. For your reports, aim for a score of approximately 7.0 to 10.0. It will prove difficult to bring these values down, as noted above, due to our use of scientific language which gets averaged into the total score.
The formula for the Flesch-Kincaid Grade Level score is:
(.39 x ASL) + (11.8 x ASW) – 15.59
where:
ASL = average sentence length (the number of words divided by the number of sentences)
ASW = average number of syllables per word (the number of syllables divided by the number of words)
The Readability Statistics shown above is from a raw authentication report - before editing and before the insertion of the plain English explanations for each of the processes.
Given that about 95% of cases plea and never see the inside of a court room, it's vitally important that your reports be readable. 95% of your reports will be read, interpreted, and acted upon without your being present to help the reader understand what you said / meant. With this simple tool that is built into many word processing applications, you can assure that your reports are readable, and at what grade level.
If you're using Google Docs, you'll need to run your report through another app or web site. Readability Statistics were removed some time ago.
Enjoy.
Tuesday, December 18, 2018
Sample Sizes and Speed Calculations, oh my!
There's been a lot of talk lately about using the footage from a DVR to determine the speed of an object depicted on the video. In my classes on the topic, I explain how to set up the experiment to validate the results of your tests. In this post, I want to present a few snapshots of the steps in the validation.
It's been well documented that DVRs are not Swiss chronographs, they're mostly a cheap box of random parts. The on-screen time stamps have been shown to be "estimates" and "approximations" of time - not entirely reliable. It's also well documented that the files' metadata contains hints about time. Let's take a look at a few scenarios.
Test 1: Geovision
The question in this case was, is the particular evidence item reliable in it's generation of frames such that the frame rate metadata could be used for speed calculation?
A sample size calculation was performed to see how many tests would need to be performed to build a model of the DVR's performance. In this way, we'd know if the evidence item was typical of the performance of the DVR or a one-time error.
It's been well documented that DVRs are not Swiss chronographs, they're mostly a cheap box of random parts. The on-screen time stamps have been shown to be "estimates" and "approximations" of time - not entirely reliable. It's also well documented that the files' metadata contains hints about time. Let's take a look at a few scenarios.
Test 1: Geovision
The question in this case was, is the particular evidence item reliable in it's generation of frames such that the frame rate metadata could be used for speed calculation?
A sample size calculation was performed to see how many tests would need to be performed to build a model of the DVR's performance. In this way, we'd know if the evidence item was typical of the performance of the DVR or a one-time error.
Analysis: A priori: Compute required sample size
Input: Tail(s) = One
Proportion p2 = 0.8
α err prob = 0.05
Power (1-β err prob) = 0.99
Proportion p1 = 0.5
Output: Lower critical N = 24.0000000
Upper critical N = 24.0000000
Total sample size = 37
Actual power = 0.9907227
Actual α = 0.0494359
The calculation determined that a total of 37 tests (sample size = 37) would yield the best results of our generic binomial test (works correctly / doesn't work correctly). On the other end of the graph, for a sample size less than 10, a coin flip would have been more accurate.
The Frame Analysis shown above, generated by Amped FIVE, seems to indicate that the I Frame generation is fairly regular and perhaps the P Frames are duplicates of the previous I Frame. You'd only get this information from an analysis of the metadata - plus a hash of each frame. Nothing viewed on-screen, watching the video play, would give you this specific information.
It's important to note that this one video represents one channel in a 16-channel DVR. The DVR features motion / alarm activation of it's recordings. It took a bit of digging to find out how many camera streams were active (motion / alarm) during the time the evidence item was being recorded.
With the information in hand, we created an experiment to reproduce the original recording conditions.
But first, a couple of important definitions are needed.
Observational Data: It's an observational study which they observe things in different circumstances over which the researcher has no control.
Experimental Data: It's data that is collected from an experimental study that involves taking measurements which can be controlled.
Our experiment in this case was "experimental." We were able to control which of the DVRs channels were actively recording - when and for how long.
With the 37 tests conducted and the data recorded, it was determined that the average recording rate within the DVR - for the channel that recorded the evidence item - was effectively seven seconds per frame. Essentially, the DVR was so overwhelmed with data that it could not process all of the incoming signal effectively. It did the best that it could, but in it's "error state," the I Frames were copied to fill the data container. Some I Frames were even duplicates of previous I Frames. This was likely due to a rule about the fps needed to create the piece of media - the system's native container format was .avi.
Test 2: Dahua
In a second test, a "generic" black box DVR was tested. The majority of the parts could be sourced to Dahua (China). The 16 camera system outputs a native file with a .264 extension.
The "forensic applications," FIVE included, are all based on FFMPEG for the "conversion" of these types of files. After conversion, the report of the processing indicated that the fps of the output video was 25fps. BUT, this was recorded in the US.
Is 25fps the correct rate?
Is 25fps an "error state?"
If 25fps isn't the "correct rate," what should it be?
In this case, the frame rate information in the original container was "non-standard." As such, FFMPEG had no way of identifying what "it should be" and thus defaulted to 25fps - the output container needs to know it's playback rate. Why 25fps? FFMPEG is French - where the playback rate (PAL) is 25fps.
In this case, we didn't have an on-screen timestamp to begin our work. Thus, we needed to conduct and experiment to attempt to calculate an effective frame rate for this particular DVR. This begins with a sample size calculation. How many tests do we need to build the model of the DVR's performance.
t tests - Linear multiple regression: Fixed model, single regression coefficient
Analysis: A priori: Compute required sample size
Input: Tail(s) = One
Effect size f² = 0.15
α err prob = 0.05
Power (1-β err prob) = 0.99
Number of predictors = 2
Output: Noncentrality parameter δ = 4.0062451
Critical t = 1.6596374
Df = 104
Total sample size = 107
Actual power = 0.9902320
In order to control for all of the points of data entry into the system (16 channels) as well as data choke points (chips and busses), our sample size has increased quite significantly. It's not a simple yes/no test as in Test 1 (above).
A multiple linear regression attempts to model the relationship between two or more explanatory variables and a response variable by fitting a linear equation to observed data. Essentially, how do the channels, busses, and chips (independent / control variables) influence the resulting data container (dependent variable)?
The tests were run and the data assembled. It was found that the effective frame rate of the channel that recorded our evidence was 1.3526fps. If you had just accepted the 25fps given to you by FFMPEG, the display of the video would have been inaccurate. Using the 25fps for the speed calculation would also yield inaccurate results. Having the effective frame rate, plus the validation of the results, helps the entire process trust your results.
It certainly helps that my tool of choice in working with the video data, Amped FIVE, contains the tools necessary to analyse the data. I can hash each frame (hash is now part of the Inspector Tools in FIVE). I can analyse the metadata (see above). Plus, I can adjust the playback rate precisely (Change Frame Rate filter).
These examples illustrate the distinct difference between what one "knows" and what one can "prove." We can "know" what the data stream tells us via the various frame analysis tools that are available. We can "prove" the validity of our results by conducting the appropriate tests, utilizing the appropriate number of tests (sample size).
If you are interested in knowing more about this topic, or if you need help on a case, or if you'd like to learn how to do these tests yourself, you can find out more by clicking here.
Subscribe to:
Posts (Atom)













