E-Discovery and Evidence
CS593: Digital Forensics — D. Kevin McGrath
- E-Discovery and Evidence
Overview
This lecture introduces e-discovery — the process of discovering electronic evidence in civil litigation — and then addresses the most important thing a digital forensics expert does: develop evidence that is admissible in court. Finding persuasive evidence is secondary; finding admissible evidence is the job. The ability to develop admissible evidence is what makes DF professionals valuable members of a legal team.
E-Discovery in Civil Litigation
Civil litigation is where most digital forensics work occurs today. The process:
- An incident is discovered (e.g., an employee downloaded 6 GB of company data before leaving).
- An internal or external DF investigator assesses what happened.
- If the findings warrant it, the company files a complaint in court.
- ~Two months later: a scheduling conference determines the preliminary schedule for resolving the dispute.
- The discovery process begins: both sides formally exchange evidence they believe will support their case.
- Discovery often involves e-discovery: exchanging electronically stored information (ESI). This can take 6–18 months.
- Either side may file pretrial motions arguing the case can be resolved without trial.
- If no resolution: trial.
DF experts hired by one party will be involved both in gathering their client’s digital evidence and in analyzing the digital evidence provided by the other side.
Avoiding Trial
Both parties are usually trying to avoid trial — it is expensive, slow, and unpredictable. The goal of discovery is often to show the other side what they would face at trial, inducing them to settle.
Example: In the antitrust case against Microsoft, the government obtained e-mails in which a Microsoft executive wrote that he wanted to “smother” Netscape and “cut off Netscape’s air supply.” Confronted with those e-mails in discovery, Microsoft had strong incentive to settle — those words would be devastating to read aloud in court.
Local Patent Rules for ESI
The 94 federal judicial districts have developed their own rules for ESI, largely independently. Local patent rules set standard procedures for patent cases, specifying what parties must preserve and produce.
The Northern District of Illinois, for example, recognizes that parties may request preservation and production of:
- “Deleted,” “slack,” “fragmented,” or “unallocated” data on hard drives.
- Random access memory (RAM) or other ephemeral data.
- On-line access data: temporary Internet files, history, cache, cookies, etc.
- Metadata fields updated automatically, such as last-opened dates.
These categories are not automatically discoverable, but parties must address them at a “meet and confer” early in the case.
2015 Changes to the Federal Rules of Civil Procedure
In December 2015, the FRCP introduced the concept of proportionality in e-discovery. E-discovery costs had grown out of control; the new rules require that requests for ESI be proportional to:
- The importance of the issues at stake.
- The amount in controversy.
- The burden and expense of providing the requested information.
The goal is a uniform national framework encouraging parties to cooperate in developing reasonable discovery plans, reserving judicial intervention for disputes they cannot resolve themselves.
Introduction to Evidence
Evidence is what the case is about. As a DF investigator, you supply the evidence that empowers your legal team. In some criminal trials, the medical examiner’s evidence is the climax of the case — a DF expert can play the same role.
The key insight: your job is to produce evidence that is admissible. Admissibility drives the procedures for acquiring and processing evidence — which is why those procedures matter so much.
Federal Rules of Evidence
The Federal Rules of Evidence govern what evidence can be admitted in federal civil and criminal trials. Their purpose:
- Ensure the evidence system is seen as reliable and fair.
- Regulate what facts go to the jury by filtering out inflammatory, irrelevant, or untrustworthy material.
- Allow jurors to draw justifiable inferences from presented facts.
Admissibility
Evidence must satisfy three requirements to be admissible:
- Relevant — probative of some fact at issue.
- Not unduly prejudicial — probative value must outweigh prejudicial impact (probative value is the legal term).
- Not hearsay — or must fall within a recognized exception.
Relevance and Prejudice
Evidence must be relevant to the dispute. Evidence that is relevant but whose prejudicial impact outweighs its probative value is excluded. The concern is that jurors will draw improper inferences (e.g., “this person stole code at their last job, so they must be guilty of this unrelated charge”).
Hearsay
Hearsay has two defining characteristics:
- A statement made outside of court (oral, written, e-mail, or any other form).
- Offered to establish the truth of what the statement asserts.
Example: A 911 operator testifying that a bystander told her “the blue car ran the stop sign” is offering hearsay — the out-of-court statement is being used to prove the blue car ran the stop sign.
Why hearsay is banned:
- Doubles the possibility of error or lying — did the original speaker say it correctly? Did the testifying witness hear it correctly?
- The actual declarant cannot be cross-examined.
- The fact-finder cannot assess the declarant’s demeanor and credibility.
- The original statement was not made under oath.
What is not hearsay: Introducing an e-mail log to show that two people were in communication (not to assert the truth of the e-mail contents) is not hearsay. Photos and video are generally not hearsay because they do not involve human assertion.
Exceptions to the Hearsay Rule
Business records exception: The most important hearsay exception for digital forensics. Applies to records that are:
- Kept using a standard system (computer program, equipment, process).
- Entered in a standard way into that system as a routine matter of business.
- Known to a custodian who can testify about the procedures.
Business records do not mean only financial records — they mean any record collected routinely and automatically as part of normal operations: server logs, ATM withdrawal records, access logs, web server history. All of these are admissible as business records.
Automated records: Data captured by automated equipment without human intervention (e.g., GPS location data, sensor readings) is generally not considered a “statement” at all and does not implicate hearsay rules.
Multi-level hearsay: When a business record contains hearsay within hearsay, each layer must independently fall within a hearsay exception for the whole to be admissible.
Scientific Evidence (Rule 702)
When you present scientific evidence, you must satisfy Federal Rule of Evidence 702 — Testimony by Expert Witnesses. Rule 702 requires that expert testimony be grounded in:
- An empirical basis and validation in testing.
- Demonstrable error rates.
- Acceptability to the scientific community.
- Exposure to peer review.
A DF expert’s analysis has four components, each of which can independently become grounds for excluding the evidence:
choice of technique → fit → execution → conclusions
- Choice of technique: Use a standard technique accepted in the field. Establish that it constitutes scientific knowledge (“I used standard program X, which everyone in the field uses for this purpose”).
- Fit: Show that the technique was appropriate for this case. A valid technique that was the wrong tool for the problem is excludable.
- Quality of execution: Show that you actually performed the technique correctly and documented everything. Sloppy execution gets evidence excluded.
- Conclusions: Conclusions must be commensurate with the data — not broader than what the analysis supports.
Any of the first three elements can be used to exclude evidence; the fourth affects weight rather than admissibility, but a conclusion that overreaches will undermine your credibility.
Expert Reports
Everything — your choices, actions, and findings — must be laid out in an expert report. Assume every paragraph will be examined under oath in deposition by opposing counsel.
The NIJ guide “Forensic Examination of Digital Evidence” (2004) defines four standard report sections:
Assessment
Before touching any evidence, determine:
- What kind of digital evidence are you looking for?
- What devices (computers, servers, mobile phones, BlackBerries) are likely to be relevant?
- What peripheral evidence (passwords, e-mail IDs, system logs, encryption keys, financial spreadsheets) may be involved?
- Who has had access to the devices, and what is the chain of custody situation?
Assessment produces a list of what you are going to look for and why.
Example: A roofing company owner’s laptop was serviced at Mom & Pop’s Computer Repair. The repair shop discovered child pornography. Before drawing conclusions, an assessor must consider: who else had access to that laptop? The employee who brought it in? Mom & Pop’s staff? The story of the case depends on the answer.
Acquisition
Never touch the original. Acquire evidence in a way that protects and preserves it.
- Document everything: Where you went, what you saw, how devices were configured, what they were connected to, whether they had Internet access.
- Work on a forensically clean destination system (wiped and verified clean before use).
- Create a forensic copy — a bit-for-bit image — and do all analysis on the copy.
- Hash the original immediately and verify the hash of the copy. All future work must be done on the copy.
- Detailed acquisition forms (see NIJ 2004, p. 33) must be filled out.
The acquisition will be described in detail in the expert report. If you can’t explain precisely what you did, the evidence may be excluded.
Examination and Analysis
Two modes of extraction:
- Physical extraction: Identifies and recovers data across the entire physical drive without regard to the file system. Methods include keyword search, file carving, and extraction of partition and unallocated space. Recovers more data, including deleted files.
- Logical extraction: Extracts data through the file system on the drive. Includes data from deleted files, file slack, and unallocated space as recognized by the file system.
Analysis maps the extracted data to the hypotheses being tested. Document every step; you may be working fifteen cases simultaneously, and memory is not reliable.
Conclusions
Draw conclusions from your analysis and document them in the report.
- Conclusions must be commensurate with the evidence — do not overstate findings.
- The report must be comprehensive enough to withstand detailed deposition questioning.
- Include the forms from Appendix C of NIJ 2004 documenting every step of the process.
- Proper documentation is not optional. If you cannot document it, it did not happen in a legally useful sense.
If the opposing attorney asks, “Did you notice there was an external hard drive connected to that computer?” you must be in a position to say with certainty whether there was or was not. That certainty comes only from thorough documentation taken in the moment — not from memory consulted months later.