courses

E-Discovery and Evidence

CS593: Digital Forensics — D. Kevin McGrath

Overview

This lecture introduces e-discovery — the process of discovering electronic evidence in civil litigation — and then addresses the most important thing a digital forensics expert does: develop evidence that is admissible in court. Finding persuasive evidence is secondary; finding admissible evidence is the job. The ability to develop admissible evidence is what makes DF professionals valuable members of a legal team.


E-Discovery in Civil Litigation

Civil litigation is where most digital forensics work occurs today. The process:

  1. An incident is discovered (e.g., an employee downloaded 6 GB of company data before leaving).
  2. An internal or external DF investigator assesses what happened.
  3. If the findings warrant it, the company files a complaint in court.
  4. ~Two months later: a scheduling conference determines the preliminary schedule for resolving the dispute.
  5. The discovery process begins: both sides formally exchange evidence they believe will support their case.
  6. Discovery often involves e-discovery: exchanging electronically stored information (ESI). This can take 6–18 months.
  7. Either side may file pretrial motions arguing the case can be resolved without trial.
  8. If no resolution: trial.

DF experts hired by one party will be involved both in gathering their client’s digital evidence and in analyzing the digital evidence provided by the other side.

Avoiding Trial

Both parties are usually trying to avoid trial — it is expensive, slow, and unpredictable. The goal of discovery is often to show the other side what they would face at trial, inducing them to settle.

Example: In the antitrust case against Microsoft, the government obtained e-mails in which a Microsoft executive wrote that he wanted to “smother” Netscape and “cut off Netscape’s air supply.” Confronted with those e-mails in discovery, Microsoft had strong incentive to settle — those words would be devastating to read aloud in court.

Local Patent Rules for ESI

The 94 federal judicial districts have developed their own rules for ESI, largely independently. Local patent rules set standard procedures for patent cases, specifying what parties must preserve and produce.

The Northern District of Illinois, for example, recognizes that parties may request preservation and production of:

  1. “Deleted,” “slack,” “fragmented,” or “unallocated” data on hard drives.
  2. Random access memory (RAM) or other ephemeral data.
  3. On-line access data: temporary Internet files, history, cache, cookies, etc.
  4. Metadata fields updated automatically, such as last-opened dates.

These categories are not automatically discoverable, but parties must address them at a “meet and confer” early in the case.

2015 Changes to the Federal Rules of Civil Procedure

In December 2015, the FRCP introduced the concept of proportionality in e-discovery. E-discovery costs had grown out of control; the new rules require that requests for ESI be proportional to:

The goal is a uniform national framework encouraging parties to cooperate in developing reasonable discovery plans, reserving judicial intervention for disputes they cannot resolve themselves.


Introduction to Evidence

Evidence is what the case is about. As a DF investigator, you supply the evidence that empowers your legal team. In some criminal trials, the medical examiner’s evidence is the climax of the case — a DF expert can play the same role.

The key insight: your job is to produce evidence that is admissible. Admissibility drives the procedures for acquiring and processing evidence — which is why those procedures matter so much.


Federal Rules of Evidence

The Federal Rules of Evidence govern what evidence can be admitted in federal civil and criminal trials. Their purpose:


Admissibility

Evidence must satisfy three requirements to be admissible:

  1. Relevant — probative of some fact at issue.
  2. Not unduly prejudicial — probative value must outweigh prejudicial impact (probative value is the legal term).
  3. Not hearsay — or must fall within a recognized exception.

Relevance and Prejudice

Evidence must be relevant to the dispute. Evidence that is relevant but whose prejudicial impact outweighs its probative value is excluded. The concern is that jurors will draw improper inferences (e.g., “this person stole code at their last job, so they must be guilty of this unrelated charge”).

Hearsay

Hearsay has two defining characteristics:

  1. A statement made outside of court (oral, written, e-mail, or any other form).
  2. Offered to establish the truth of what the statement asserts.

Example: A 911 operator testifying that a bystander told her “the blue car ran the stop sign” is offering hearsay — the out-of-court statement is being used to prove the blue car ran the stop sign.

Why hearsay is banned:

  1. Doubles the possibility of error or lying — did the original speaker say it correctly? Did the testifying witness hear it correctly?
  2. The actual declarant cannot be cross-examined.
  3. The fact-finder cannot assess the declarant’s demeanor and credibility.
  4. The original statement was not made under oath.

What is not hearsay: Introducing an e-mail log to show that two people were in communication (not to assert the truth of the e-mail contents) is not hearsay. Photos and video are generally not hearsay because they do not involve human assertion.

Exceptions to the Hearsay Rule

Business records exception: The most important hearsay exception for digital forensics. Applies to records that are:

  1. Kept using a standard system (computer program, equipment, process).
  2. Entered in a standard way into that system as a routine matter of business.
  3. Known to a custodian who can testify about the procedures.

Business records do not mean only financial records — they mean any record collected routinely and automatically as part of normal operations: server logs, ATM withdrawal records, access logs, web server history. All of these are admissible as business records.

Automated records: Data captured by automated equipment without human intervention (e.g., GPS location data, sensor readings) is generally not considered a “statement” at all and does not implicate hearsay rules.

Multi-level hearsay: When a business record contains hearsay within hearsay, each layer must independently fall within a hearsay exception for the whole to be admissible.


Scientific Evidence (Rule 702)

When you present scientific evidence, you must satisfy Federal Rule of Evidence 702 — Testimony by Expert Witnesses. Rule 702 requires that expert testimony be grounded in:

A DF expert’s analysis has four components, each of which can independently become grounds for excluding the evidence:

choice of technique → fit → execution → conclusions
  1. Choice of technique: Use a standard technique accepted in the field. Establish that it constitutes scientific knowledge (“I used standard program X, which everyone in the field uses for this purpose”).
  2. Fit: Show that the technique was appropriate for this case. A valid technique that was the wrong tool for the problem is excludable.
  3. Quality of execution: Show that you actually performed the technique correctly and documented everything. Sloppy execution gets evidence excluded.
  4. Conclusions: Conclusions must be commensurate with the data — not broader than what the analysis supports.

Any of the first three elements can be used to exclude evidence; the fourth affects weight rather than admissibility, but a conclusion that overreaches will undermine your credibility.


Expert Reports

Everything — your choices, actions, and findings — must be laid out in an expert report. Assume every paragraph will be examined under oath in deposition by opposing counsel.

The NIJ guide “Forensic Examination of Digital Evidence” (2004) defines four standard report sections:

Assessment

Before touching any evidence, determine:

Assessment produces a list of what you are going to look for and why.

Example: A roofing company owner’s laptop was serviced at Mom & Pop’s Computer Repair. The repair shop discovered child pornography. Before drawing conclusions, an assessor must consider: who else had access to that laptop? The employee who brought it in? Mom & Pop’s staff? The story of the case depends on the answer.

Acquisition

Never touch the original. Acquire evidence in a way that protects and preserves it.

The acquisition will be described in detail in the expert report. If you can’t explain precisely what you did, the evidence may be excluded.

Examination and Analysis

Two modes of extraction:

Analysis maps the extracted data to the hypotheses being tested. Document every step; you may be working fifteen cases simultaneously, and memory is not reliable.

Conclusions

Draw conclusions from your analysis and document them in the report.

If the opposing attorney asks, “Did you notice there was an external hard drive connected to that computer?” you must be in a position to say with certainty whether there was or was not. That certainty comes only from thorough documentation taken in the moment — not from memory consulted months later.