4. MARCO TEÓRICO
4.1 BREVE RESEÑA HISTÓRICA DEL OCIO Y EL TIEMPO LIBRE
4.1.4 Educación para el Tiempo Libre La educación para el tiempo libre es un fenómeno relativamente nuevo que se ha venido desarrollando a partir de la evolución
The investigation of networked systems, perhaps in the laboratory or more likely at the site of an investigation and possibly involving seizure of components, is not surprisingly more complicated by far than the investigation of an individual computer. In addressing this issue, Sommer points out inDigital Footprints: Assessing Computer Evidence[105]:
There are two principal situations to be considered: where the offence is concentrated on an individual’s use of the Internet and where a remote site holds evidence of an offence.
It is unlikely that all the networked information is necessarily available from the scene of an on-site investigation, in many situations there will be evidence not only on the host computer but also on network servers, ISPs and the like. In the case of an ISP there will be both legal and practical considerations that will require direct contact with the ISP, and possibly a warrant, and even with local network servers the required information is likely to be available only via a privileged account on the server itself and may require a separate warrant. In such a situation the investigator needs to have regard for the following considerations:
1. Possession of the appropriate authorization.
2. Investigating the network on site or seizing (parts of) the network must not compromise the rights of the organization or business running the network (seeBest Practices for Seizing Electronic Evidence by the U.S. Secret Service and the International Association of Chief of Police [44]).
3. All relevant evidence from sites presently or previously connected to the computer in question is gathered.
4. All relevant evidence from the computer in question is gathered. Gathering the network-related information referred to in the penulti- mate point will rely upon a person experienced in computer networking and in the particular platforms and software in use on that network, and possibly upon assistance from nontargeted personnel on-site, such as a reliable employee not implicated in the investigation. In the latter case, it is necessary that the employee be carefully instructed so that no compromise of the evidentiary reliability of the information may occur.
We return to these and some related topics in Chapter 6.
References
[1] Council of Europe, ‘‘Convention on Cybercrime,’’ http://conventions.coe. int/Treaty/en/Treaties/Html/185.htm, signed Nov. 23, 2001, visited July 2002.
[2] Di Gregory, K., ‘‘Carnivore and the Fourth Amendment,’’ delivered to a sub- committee of U.S. Congress on July 24, 2000, http://www.usdoj.gov/ criminal/cybercrime/carnivore.htm, visited July 2002.
[3] The Home Office U.K., ‘‘Regulation of Investigatory Powers Act 2000,’’ http://www.homeoffice.gov.uk/ripa/ripact.htm, 2000, visited July 2002. [4] Plesser, R. L., J. J. Halpert, and E. W. Cividanes, ‘‘USA Patriot Act for Internet
and Communications Companies,’’Computer and Internet Lawyer, March 2002,
http://eon.law.harvard.edu/privacy/Presser%20article–redacted.htm, visited July 2002.
[5] Her Majesty’s Stationary Office U.K., ‘‘Explanatory Notes to Anti-Terrorism, Crime and Security Act 2001,’’ http://www.legislation.hmso.gov.uk/acts/en/ 2001en24.htm, visited July 2002.
[6] Grossman, W., ‘‘A New Blow to Our Privacy,’’ http://www.guardian.co.uk/ online/story/0,3605,727644,00.html, visited July 2002.
[7] Sommer, P., ‘‘Intrusion Detection Systems As Evidence.’’ InRAID 98, Belgium:
University of Louvain-la-Neuve, Sept. 1998; ‘‘Intrusion Detection and Legal Proceedings,’’ http://www.raid-symposium.org/raid98/Prog_RAID98/ Talks.html#Sommer_09, visited July 2002.
[8] Johnson, T., ‘‘Storage Trends Disk, Optical, Tape,’’ http://www.dcs.napier.
ac.uk/~vldb99/IndustrialSpeakerSlides/johnson.pdf, 1999, visited March
[9] van der Knijff, R., ‘‘Embedded Systems Analysis.’’ In Handbook of Computer Crime Investigation, Chapter 11, E. Casey (ed.), London: Academic Press, 2002. [10] NIST, ‘‘Hard Disk Write Block Tool Specification,’’ http://www.cftt.nist.gov/
WB-spec-jan-07-1.pdf, visited July 2002.
[11] Digital Intelligence Inc., ‘‘Software and Hardware Solutions for the Computer Forensics Community,’’ http://www.digitalintel.com, visited July 2002. [12] Guidance Software, ‘‘FastBloc,’’ http://www.encase.com/products/hardware/
fastbloc.shtm, visited July 2002.
[13] Holley, J., ‘‘Computer Forensics,’’ SC Magazine, Sept. 2000, http://www.
scmagazine.com/scmagazine/2000_09/, visited May 2002.
[14] Farmer, D., and W. Venema, ‘‘Bring Out Your Dead,’’Dr. Dobb’s Journal, Jan.
2001.
[15] ForensiX, Fred Cohen & Associates, http://www.all.net/ForensiX/, visited June 2002.
[16] White Glove, http://www.all.net/WG/PLAC/tools.html, visited July 2002. [17] Dittrich, D., ‘‘Basic Steps in Forensic Analysis of Unix Systems,’’ http://
staff.washington.edu/dittrich/misc/forensics/, University of Washington, vis- ited June 2002.
[18] Seglem, K., M. Luque, and S. Murphy, ‘‘Unix Systems Analysis.’’ In Handbook of Computer Crime Investigation, E. Casey (ed.), London: Academic Press, 2002.
[19] Sammes, T., and B. Jenkinson, Forensic Computing—A Practitioner’s Guide,
Berlin: Springer-Verlag, 2000.
[20] Holley, J., ‘‘Meeting Computer Forensic Analysis Requirements,’’ SC
Magazine, March 2001, http://www.scmagazine.com/scmagazine/sc-online/ 2001/article/016/article.html, visited March 2002.
[21] Computer Forensics Tool Testing (CFTT) Project Web Site, ‘‘Disk Imaging Tool Specification Version 3.1.6,’’ http://www.cftt.nist.gov/DI-spec-3-1-6. doc, Oct. 12, 2001, visited March 2002.
[22] Schneier, B.,Applied Cryptography, New York: Wiley, 1994.
[23] NIST, ‘‘Announcing the Standard for SECURE HASH STANDARD SHA-1,’’ Federal Information Processing Standards Publication180-1, http://www.itl.nist. gov/fipspubs/fip180-1.htm, 1995, April 17, visited March 2002.
[24] Tripwire Inc., http://www.tripwire.com, visited July 2002.
[25] WetStone Technologies Inc., ‘‘SMART Watch,’’ http://www.wetstonetech. com, visited March 2002.
[26] Power Quest Corporation, ‘‘PartitionMagic 7,’’ http://www.powerquest. com/partitionmagic/, visited March 2002.
[27] Sanderson, P., http://online.securityfocus.com/archive/104/254394, 04 Feb. 2002, visited Jan. 2003.
[28] National Committee on Information Technology Standards, ‘‘Technical Committee T13 AT Attachment,’’ http://www.t13.org/, March 8, 2002, visited March 2002.
[29] McDonald, A., and M. Kuhn, ‘‘StegFS: A Steganographic File System for
Linux’’,Lecture Notes in Computer Science, Vol 1768, 2000, pp. 463–477.
[30] Johnson, A., ‘‘Steganography for DOS Programmers,’’ Dr. Dobb’s Journal,
Jan. 1997.
[31] DIBS USA Inc., ‘‘DIBS Mobile Forensic Workstation,’’ http://www.dibsusa. com/, visited July 2002.
[32] Guidance Software Inc., ‘‘EnCase,’’ http://www.guidancesoftware.com/, visited March 2002.
[33] New Technologies Inc. (NTI), ‘‘Law Enforcement Computer Evidence Suite,’’ http://www.forensics-intl.com/, visited March 2002.
[34] AcessData Inc., ‘‘The Forensic Toolkit,’’ http://www.accessdata.com/, visited March 2002.
[35] Ontrack Data International Inc., ‘‘DataTrail FacTracker,’’ http://www.ontrack. com/factracker/, visited July 2002.
[36] Vogon International Ltd., ‘‘GenX,’’ http://www.vogon-international.com/, visited March 2002.
[37] Bryson, C., and M. R. Anderson, ‘‘Shadow Data the Fifth Dimension of Data Security Risk,’’ NTI, http://www.forensics-intl.com/art15.html, visited March 2002.
[38] Guttmann, P., ‘‘Secure Deletion of Data from Magnetic and Solid-State Mem-
ory,’’ Proc.6th USENIX Security Symposium, San Jose, CA, July 22–25, 1996.
[39] Gross, A., ‘‘Analysing Computer Intrusions,’’ Ph.D. Thesis, San Diego Supercomputer Center, University of California, San Diego, 1997.
[40] The Houston Chronicle, ‘‘Computer Sleuths Sniffing Out Deleted Enron E-mail,’’ Jan. 16, 2002.
[41] Computerworld New Zealand, ‘‘Handhelds Give up Secrets,’’ http://www.idg. net.nz/webhome.nsf/nl/63E5E17F5D96FBFACC256B0500727855, Monday, Nov. 19, 2001, visited March 2002.
[42] Paraben Inc., ‘‘PDA Seizure,’’ http://www.paraben-forensics.com/, visited March 2002.
[43] Gibbs, K. E., and D. F. Clark, ‘‘Wireless Network Analysis.’’ InHandbook of
Computer Crime Investigation, Chapter 10, E. Casey (ed.), London: Academic Press, 2002.
[44] The U.S. Secret Service and the International Association of Chief of Police, ‘‘Best Practices for Seizing Electronic Evidence,’’ http://www.infowar.com/ law/00/e-evidence/e-evidence.shtml, visited July 2002.
[45] Jensen, D., ‘‘Prospective Assessment of AI Technologies for Fraud Detection:
A Case Study.’’ In AI Approaches to Fraud Detection and Risk Management,
Collected Papers from the 1997 Workshop, Technical Report WS-97-07, Menlo
Park, CA: AAAI Press, http://eksl-www.cs.umass.edu/~jensen/papers/
aaaiws97a.html, 1995, visited March 2002.
[46] Jensen, D., ‘‘Link Analysis,’’ http://eksl-www.cs.umass.edu/aila/link-analy- sis.html, visited Jan. 2002.
[47] i2 Inc., ‘‘Analyst’s Notebook,’’ http://www.i2.co.uk/home.html, visited July 2002.
[48] Operational Information Security, Information Networks Division, Defence
Science and Technology Division,CFIT1User Manual, 2001.
[49] i2 Inc., ‘‘Case Studies, Analyst’s Notebook,’’ http://www.i2.co.uk/applications/ casestudies/, visited March 2002.
[50] NetMap Analytics LLC, ‘‘NetMap,’’ http://www.netmapsolutions.com/, vis- ited Feb. 2002.
[51] Xanalys, ‘‘Watson,’’ http://www.xanalys.com/watson.html, visited July 2002.
[52] SPSS Inc., ‘‘Clementine,’’ http://www.spss.com/products/, Feb. 2002. [53] IBM, ‘‘Intelligent Miner for Data/Text,’’ http://www-3.ibm.com/software/
data/iminer/, visited March 2002.
[54] Socho, G. J., Fios Inc., ‘‘Once You Have the Evidence—Then What?’’ In IP
Litigator, Vol. 5, No. 2, http://www.fiosinc.com/wp-once.html, March/April 1999, Aspen Law Business, visited March 2002.
[55] Holley, J., ‘‘Getting the Hard Facts,’’ SC Magazine, April 2001, http://
www.scmagazine.com/scmagazine/2001_04/, visited May 2002.
[56] ACES, Statement of Janet Reno Attorney General of the United States Before the United States Senate Committee on Appropriations, http://www.senate. gov/~appropriations/commerce/testimony/reno229.htm, Feb. 29, 2000, vis- ited March 2002.
[57] ILook Investigator, http://www.ilook-forensics.org/, visited July 2002. [58] U.S. DOJ National Drug Intelligence Center, ‘‘Hashkeeper Database,’’ http://
www.hashkeeper.org/, visited July 2002.
[59] Vais, M., ‘‘Law Enforcement Tools and Technologies for Investigating Cyber
Attacks: A National Needs Assessment Report,’’Institute for Security Technology
Studies,Dartmouth College, NH, June 2002.
[60] Fisher, G., ‘‘Computer Forensics Guidance,’’NSRL ITL Bulletin, Nov. 2001, http://www.nsrl.nist.gov/itlbulletin.html, visited March 2002.
[61] Patzakis J., ‘‘The EnCase Process,’’ InHandbook of Computer Crime, Chapter 3,
E. Casey (ed.), London: Academic Press, 2002. [62] Guidance Software, Encase3 distribution, June 2001.
[63] Bahl, L., F. Jelinek, and R. Mercer, ‘‘A Maximum Likelihood Approach to
Continuous Speech Recognition,’’IEEE Trans. on Pattern Analysis and Machine
Intelligence, Vol. 5, No. 2, 1983, pp. 179–190.
[64] Church K., and P. Hanks, ‘‘Word Association Norms, Mutual Information and
Lexicography,’’Computational Linguistics, Vol. 16, No. 1, 1990, pp. 22–29.
[65] Huang X., et al., ‘‘The SPHINX-II Speech Recognition System: An Overview,’’ Computer, Speech and Language, Vol. 2, 1993, pp. 137–148.
[66] http://rr.sans.org/incident/IRCF.php, visited July 2002.
[67] Guidance Software,EnCase Legal Journal,2nd ed., 2001.
[68] Law Foundation of NSW, Database of ‘‘Federal Court of Australia Cases,’’ http:// www.austlii.edu.au/au/cases/cth/federal_ct/index.html, visited July 2002.
[69] Farmer, D., ‘‘What are MACtimes?’’Dr Dobbs Journal,Oct. 2000.
[70] Department of Defense, U.S., ‘‘Department of Defense Trusted Computer System Evaluation Criteria,’’ (The Orange Book), August 15, 1983.
[71] Hosmer, C., WetStone Technologies Inc., ‘‘Time-Lining Computer Evidence,’’ www.wetstonetech.com/timpaper.htm, visited March 2002.
[72] Noblett, M. G., M. M. Pollitt, and L. A. Presley, ‘‘Recovering and Examining
Computer Forensic Evidence,’’Forensic Science Communications, Vol. 2, No. 4,
Oct. 2000.
[73] Computer Crime and Intellectual Property Section (CCIPS), Department of Justice, ‘‘Federal Guidelines for Searching and Seizing Computers,’’ http:// www.usdoj.gov/criminal/cybercrime/search_docs/toc.htm, 1994, visited June 2002.
[74] Computer Crime and Intellectual Property Section (CCIPS), Criminal Division, United States Department of Justice, ‘‘Searching and Seizing Computers and Obtaining Electronic Evidence in Criminal Investigations,’’ http://www.usdoj.gov/criminal/cybercrime/searchmanual.htm, Jan. 2001, visited June 2002.
[75] Galil, Y., ‘‘New Federal Guidelines for Searching and Seizing Computers—
From Servers to PDAs,’’ Internet Law Journal, Feb. 5, 2001, http://
www.tilj.com/content/litigationheadline02050102.htm, visited July 2002. [76] Jones, N., ‘‘Law for Systems Administrators Conference—Working with the
Police,’’ http://www.ja.net/conferences/security/january01/N.Jones.pdf, Jan. 30, 2001, visited July 2002.
[77] NIJ (U.S. National Institute of Justice) Guide, ‘‘Electronic Crime Scene Investigation: A Guide for First Responders,’’ http://www.ncjrs.org/txtfiles1/ nij/187736.txt, visited March 2002.
[78] U.S. Department of Justice Federal Bureau of Investigation, ‘‘Digital
Evidence: Standards and Principles,’’Forensic Science Communications, Vol. 2,
No. 2, April 2000.
[79] International Organization on Computer Evidence, International Conference
on Digital Evidence,http://www.ioce2002.com/index.cfm, visited March 2002. [80] Council of Europe, ‘‘Convention on Cybercrime (ETS No. 185), Summary,’’ http://conventions.coe.int/treaty/en/Summaries/Html/185.htm, visited July 2002.
[81] Council of Europe, ‘‘Council of Europe,’’ http://www.coe.int/, visited July 2002. [82] Council of Europe, ‘‘About Conventions and Agreements in the European
Treaty Series (ETS),’’ http://conventions.coe.int/, visited March 2002. [83] G8, ‘‘G8 Meeting of Justice and Interior Ministers in Washington, DC in
1997,’’ http://www.g8summit.gov.uk/prebham/washington.1297.shtml, vis- ited Match 2002.
[84] Sussmann, M., ‘‘The Critical Challenges from International High-Tech and
Computer-Related Crime at the Millennium,’’Duke Journal of Comparative &
International Law, Vol. 9, No. 2, Spring 1999, p. 451.
[85] Parliament of the Commonwealth of Australia, Parliamentary Joint Com- mittee on the National Crime Authority, ‘‘The Law Enforcement Implications of New Technology,’’ Aug. 2001.
[86] Council of Europe, ‘‘Convention on Cybercrime First Protocol,’’ http:// www.legal.coe.int/economiccrime/cybercrime/AvProjetProt2002E.pdf, visi- ted March 2002.
[87] Council of Europe, Convention on Cybercrime ‘‘Second Protocol,’’ http:// conventions.coe.int/Treaty/en/Treaties/Html/182.htm, visited March 2002.
[88] McConnell International, ‘‘Cyber Crime . . .and Punishment? Archaic Laws
Threaten Global Information,’’ Dec. 2000, http://www.mcConnellinterna- tional.com, visited Feb. 2002.
[89] Armstrong, I., ‘‘Legislators Turn up the Heat on Cybercrime,’’SC Magazine,
April 2001, http://www.scmagazine.com/scmagazine/2001_04/feature.html, visited Feb. 2002.
[90] Schjolberg, S., ‘‘The Legal Framework—Unauthorised Access to Computer Systems. Penal Legislation in 43 Countries,’’ http://www.mossbyrett.of.no/ info/legal.html, visited Feb. 2002.
[91] Select Committee on European Union, Minutes of Evidence, ‘‘Examination of Witnesses (Questions 404–419),’’ http://www.parliament.the-stationery-office.
co.uk/pa/ld199900/ldselect/ldeucom/95/0031503.htm, Wednesday March 15, 2000, visited July 2002.
[92] United Nations Economic and Social Council, ‘‘Conclusions of the Study on Effective Measures To Prevent and Control High-Technology and Computer- Related Crime, Report of the Secretary-General,’’ http://www.odccp.org/ adhoc/crime/10_commission/4e.pdf, visited July 2002.
[93] European Commission, ‘‘Creating a Safer Information Society by Improving the Security of Information Infrastructures and Combating Computer- Related Crime,’’ Brussels, Belgium 2001.
[94] U.S. Department of Justice, ‘‘Independent Technical Review of the Carnivore System Draft Report,’’ http://www.usdoj.gov/jmd/publications/ carnivore_draft_1.pdf, visited March 2002.
[95] IIT Research Institute, ‘‘Independent Technical Review of the Carnivore System Final Report,’’ http://www.epic.org/privacy/carnivore/carniv_final. pdf, visited March 2002.
[96] Federal Bureau of Investigation, ‘‘Carnivore Diagnostic Tool,’’ http://www. fbi.gov/hq/lab/carnivore/carnivore2.htm, visited July 2002.
[97] The Electronic Privacy Information Center (EPIC), Information Regarding Carnivore Obtained Through FOIA, http://www.epic.org/privacy/carnivore/ foia_documents.html, visited March 2002.
[98] The Home Office U.K., ‘‘Accessing Communications Data Draft Code of Practice,’’ http://www.homeoffice.gov.uk/ripa/pcdcpc.htm, October 25, 2001, visited March 2002.
[99] The Home Office U.K., ‘‘Explanatory Notes to Regulation of Investigatory Powers Act 2000, chapter 23,’’ http://www.hmso.gov.uk/acts/en/2000en23. htm, Aug. 15, 2000, visited July 2002.
[100] The Home Office U.K., ‘‘Mass Surveillance?’’ http://www.homeoffice.gov. uk/ripa/mass.htm, Aug. 1, 2000, visited March 2002.
[101] Brown, I., S. Davies, and G. Hosein (eds.), ‘‘The Economic Impact of the Regulation of Investigatory Powers Bill,’’ http://www.britishchambers. org.uk/newsandpolicy/downloads/lsereport.pdf, June 12, 2000, visited July 2002.
[102] Privacy Digest, ‘‘Home Office Backs Seven-year Retention Laws,’’ http://www. privacy.digest.com/2001/10/03, Oct. 3, 2001, visited March 2002.
[103] Computer Crime and Intellectual Property Section (CCIPS), Department of Justice U.S., ‘‘Field Guidance on New Authorities that Relate to Computer Crime and Electronic Evidence Enacted in the U.S. Patriot Act of 2001,’’ http://www.usdoj.gov/criminal/cybercrime/PatriotAct.htm, visited July 2002.
[104] G8 Justice and Interior Ministers, ‘‘Principles on the Availability of Data Essential to Protecting Public Safety,’’ http://www.g8j-i.ca/english/doc3. html, visited July 2002.
[105] Sommer, P., ‘‘Digital Footprints: Assessing Computer Evidence,’’ Criminal
Law Review, Special Edition, Dec. 1998, pp. 61–78, http://www.giustizia.it/ cassazione/convegni/dic2000/sommer_6.pdf, visited July 2002.