<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta>
      <journal-title-group>
        <journal-title>Catania, IT
" alessandro.simonetta@gmail.com (A. Simonetta);
lf@albertogiorgio.com (L. Fazio);
mariacristina.paoletti@gmail.com (M. C. Paoletti)
~ https://www.albertogiorgio.com/ (L. Fazio)</journal-title>
      </journal-title-group>
    </journal-meta>
    <article-meta>
      <title-group>
        <article-title>A Forensic Methodology for the Identification of Illicit Data Leakage</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Alessandro Simonetta</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Luciano Fazio</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Maria Cristina Paoletti</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Department of Enterprise Engineering, University of Rome “Tor Vergata”</institution>
          ,
          <addr-line>Via del Politecnico n.1, 00133, Rome</addr-line>
          ,
          <country country="IT">Italy</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Studio Giorgio ®</institution>
          ,
          <addr-line>via Gallarate n.112, 20155, Milan</addr-line>
          ,
          <country country="IT">Italy</country>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2021</year>
      </pub-date>
      <volume>000</volume>
      <fpage>0</fpage>
      <lpage>0003</lpage>
      <abstract>
        <p>The digital revolution had and is having profound impacts on modern society and, with it, we are witnessing the birth of new digital illicits, increasingly widespread both in Italy and in the USA. The most common case is the exfiltration of company data by unfaithful employees or former employees, who, for economic interests, act imprudently thinking that such activities are dificult to identify. This article deals with a methodology that allows you to find, in compliance with existing laws, such behaviors with the use of dedicated software tools. Furthermore, this innovation, which makes use of sophisticated data analysis techniques, must provide results that are immediately understandable and accessible even to a non-technical expert in the field such as a lawyer or a judge. For this reason, particular emphasis is given to the presentation of the found evidences through the formulation of a technical-legal report.</p>
      </abstract>
      <kwd-group>
        <kwd>eol&gt;computer forensics</kwd>
        <kwd>digital proof</kwd>
        <kwd>forensic tools</kwd>
        <kwd>forensic analysis</kwd>
        <kwd>civil illicit</kwd>
        <kwd>civil proceeding</kwd>
        <kwd>presentation of evidence</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>When we use any electronic device, such as a computer or
smartphone, our activities remain permanently recorded
in the device’s memory. These data are commonly called
"digital traces" [1] and they can be created depending on
the type of activity the user has carried out, such as:
• execution of a system program;
• read or copy a file;
• send or receive files via the Internet;
• print a file;
• access to a network resource;
• access to a remote or cloud system;
• execution of a query on a database.</p>
      <p>However, in order for a digital trace to be used in any
proceeding and, therefore, to take on probative value
(thus becoming a digital evidence) it must be:
• authentic, it is necessary to have absolute
certainty of the authenticity of the source from
which it comes;
• intact, it is necessary to have a series of
procedural precautions during its collection, in order not
to alter its form or content in any way;
• truthful, obtained through the correct
interpretation of the computer data;
• complete, through the certainty of having
analyzed all the aspects connected to it, avoiding to
leave out relevant information that could modify
its status;
• forensic, obtained by respecting the laws in
force [2].</p>
      <p>In the field of private law, digital evidence is comparable
to an IT document that is defined in the Italian
Digital Administration Code, Legislative Decree 07/03/2005
n.82. In it we find the prerequisites that a digital
document should have in order to be suitable for evidential
evaluation. Unfortunately, because of the continuous
technological evolution of the subject, the standards
often fail to guarantee a perfect synchrony between the
crystallization in legal terms and the change of technical
standards [3].</p>
      <p>Therefore, the lack of some key concepts such as the
criteria for the identification, collection, acquisition,
storage and transport of digital evidence has led to the use of
the international standard ISO1/IEC2 27037:2012 (Fig. 1).
For the management of digital evidence, the standard
identifies four fundamental characteristics:
• verifiability : it must be possible for any involved
party to evaluate the activities carried out in each
phase of the life of a digital evidence;
• repeatability: it must be possible for any involved
party to be able to reach the same results and,
therefore, digital evidence, starting from the same</p>
      <sec id="sec-1-1">
        <title>1https://www.iso.org/home.html 2https://www.iec.ch/homepage</title>
      </sec>
    </sec>
    <sec id="sec-2">
      <title>2. Data collection in the United States and in Italy</title>
      <p>The preliminary stage to a civil proceeding in Italian law
is the crystallization of the evidence in order to make
it legally usable. This crystallization operation can take
place through an acquisition by means of bailifs or with
the inclusion in deeds directly by the parties. In the
latter circumstance, the parties involved are not obliged
to present all the evidence (if these, for example, are not
in their favor) but they must ensure, in any case, that the
product complies with the regulations in force in terms
of admissibility of the evidence.</p>
      <p>In the United States procedural law, on the other hand,
there is a preliminary phase to a proceeding called
discovery (known in England as disclosure). During this phase,
the parties can both obtain evidence relating to their
own questions (evidence gathering), and investigate the
opposing field to seek new information with the hope
of obtaining further evidence admissible for the hearing
(evidence seeking) [6].</p>
      <p>Figure 1: Scheme for the treatment of a digital evidence In case of non-production of documents, and even
worse, of incorrect or inadequate conservation of
electronic documents, the consequences are serious and can
conditions and following the same actions per- compromise the subsequent procedural phase.
formed during the data analysis; In the Italian legal system there is a similar mechanism
• reproducibility: it must be possible for any in- (art. 210 cpc3) [7] but less efective, which is based on a
volved party to be able to reach the same results diametrically opposite principle: the investigating judge,
and, therefore, digital evidence, using diferent under certain limits (art. 118 cpc) and at the request of
tools than the original ones, in order to be able a party, can order the other party or a third party to
to demonstrate that under certain conditions the show in court a document or other thing which it deems
original result is achieved regardless of the instru- necessary for the trial. Both legislations, however, agree
ment used; on the methods for the material collection of digital data,
• justifiability : it must be possible for the operator the so-called acquisition and preservation from voluntary
who analyzed the data that led to digital evidence and involuntary alterations.
to justify every action and all the methods used In order for an acquisition to produce a digital data
to arrive at the result. that can be used in any type of judicial procedure, in
addition to being performed according to the standards
The use of the standard makes it possible to guarantee already described, it must be accompanied by a
docuthe integrity of the digital evidence from the acquisition ment that describes all the handovers that the support
phase and the subsequent analysis phase, and, at the object of acquisition undergoes between its identification,
same time, to obtain the admissibility characteristic of its possible seizure (where foreseen) and the
crystallizathe evidence in a proceeding. tion of the data within it. This document is known as</p>
      <p>We remind you that starting from 2016 the GDPR (Gen- “Chain of Custody”. It is the answer tested by practice
eral Data Protection Regulation) [4] was launched, which to satisfy a rule of the discipline of the acquisition of
came into force in Italy from May 2018. The introduction evidence: the party interested in the acquisition of an
of a strict regulation on personal data, however, had no object must present suficient elements to make it appear
impact on the issue of the processing of digital evidence, that it corresponds to what is claimed to be [8].
since art. 9 (c.2 letter f) of the Regulation provides that At this point it is necessary to identify the suitable
the processing of personal data is lawful if it is neces- tool to physically carry out the data acquisition from a
sary to ascertain, exercise or defend a right in court or variety of possible candidate tools [9]. Once the tool has
whenever the judicial authorities exercise their judicial been decided, we move on to the data extraction phase
functions [5]. from the digital source and to the creation of the so-called
forensic image, in one of the possible formats available in the new one (e.g. customer list, company secrets,
conand in relation to the goal we want to achieve [10]. ifdential information, source code or banks data).</p>
      <p>Before starting the analysis, it is necessary to confirm To the ex employee could be challenged various
ofthat what was collected and crystallized corresponds fenses, for example, for having violated the contractual
exactly to the original format. This is possible through rules that bind him to the old company, or the rules in
the generation of the hash code of the two objects, which force in the field of copyright protection, of company
obviously must provide the same result. The use of this jurisprudence or unfair competition (art. 2598 cc4).
coding technique makes it possible to verify the exact According to the data provided courtesy of Studio
Giorcorrespondence of the two objects in any process phase. gio®5 on over 100 cases handled in Italy, the exfiltration
techniques used by the former employee are the same
compared to those used in the US (Table 2): sending
3. Case study emails to personal mailboxes is the tool used for 50% of
cases, while external USB devices are used for over 30%
Between 2018 and 2020, into the United States inci- (much higher than 9% of the US statistic).
dents caused (or involving) by internal staf increased
by 47% [11]. The frequency of accidents varies
according to the type of company. The Verizon 2021 Breach Table 2
Investigation Report [12] provides an overview of the Typical unfaithful employee behavior in IT
diferent types of incidents in the various types of com- Behavior %
panies involved. Companies in the Health and Finance
sector recorded the largest number of incidents caused E-mail forwarding to personal e-mail account 51.75
by the incorrect use of their employees’ access privileges UDsaitnageuxfnialturathtioornizuesdi/nugneexntcerrynpatlesditUesSB devices 390..8850
and sufered the largest number of data thefts. The exfil- Others 7.60
tration of data by the unfaithful employee in the United
States, according to a 2020 statistic that involved 300
accidents in 8 diferent types of industrial sectors[ 13],
was perpetrated for as many as 43% of the cases through 3.1. Forensic analysis software platforms
forwarding to personal email accounts, while, for 16% of
cases through the incorrect use of cloud sharing
privileges. The remaining number of data exfiltration cases
involve using USB devices (9%) and more. See Table 1.</p>
      <p>To prove wrongdoing by a former employee the company
has the right, by virtue of the clauses normally required
for the use of company tools (PC, telephone, e-mail box,
storage disks, ...), to access the information contained
therein. On the market there are various [16] software
platforms that allow you to support the digital
forensic expert in all activities, starting from the creation of
forensic images [17]:</p>
      <p>It is interesting to note that the main reasons that
induce employees to make such a gesture [11, 14, 15] are
economic (64%), followed by espionage (17%),
entertainment (17%) and issues of resentment (14%). So, if the
economic leverage is so strong, it will be even higher for
a former employee who will feel free from constraints in
leaving the old company.</p>
      <p>For this reason we will analyze the case study of the
former employee who, after moving from one company
to another, uses documents owned by the old company
• AccessData FTK (Forensic ToolKit)6
• X-ways Forensic 7
• EnCase 8
• Magnet AXIOM9</p>
      <sec id="sec-2-1">
        <title>All data analysis platforms have peculiarities that dis</title>
        <p>tinguish them from each other and, therefore, pros and
cons, but all strive to provide a comprehensive solution
for the analysis of the most common hardware/software
environments.</p>
        <p>The aforementioned tools allow you to process a huge
amount of data but, before allowing full use of their
functions, they need to have the computer used for their
operation carry out a preliminary data processing phase.</p>
      </sec>
      <sec id="sec-2-2">
        <title>4Italian Civil Code</title>
        <p>5https://www.albertogiorgio.com/
6https://www.exterro.com/forensic-toolkit
7http://www.x-ways.net/forensics/
8https://security.opentext.com/encase-forensic
9https://www.magnetforensics.com/products/magnet-axiom/</p>
        <p>During the pre-processing phase, the entire content there are database access monitoring software that can
of the data extracted from the original finds is read (in detect "suspicious" activities that cannot be performed.
the form of a forensic image) and, by means of machine Finally, the expert will draw up a technical report
learning techniques [18][19][20], now increasingly used aimed at showing the evidence found.
in various scientific contexts [ 21][22][23][24][25][26],
the data and images are classified and indexed [ 27][28], 3.2. Presentation of the evidence
thus creating the most common artifacts from the source
system. This phase is typically onerous from a computa- The presentation of the results of a forensic analysis is
tional point of view and requires a fair amount of time, crucial to understand the behavior of the former
emwhich often clashes with the need for speed of an analysis. ployee.</p>
        <p>For this reason, new computing architectures are being The presentation takes place by means of the drafting
studied, such as quantum computing [29] or computing of a technical-legal report, that brings together what was
solutions based on multi-valued algebra (MVL) [30][31]. found with any specific violations identified.</p>
        <p>Once this phase has been completed, the analysis soft- Fig. 2 shows the structure of an expert report in its
funware allow access to the statistically most relevant be- damental sections. The aim is to highlight the evidence
haviors of the former employee, such as: found, using a language suitable for understanding even
for a non-technical reader such as a lawyer or a judge.
1. USB devices connected in the last working period</p>
        <p>of the former employee [32];
2. files accessed and possibly copied to an external</p>
        <p>device or remotely, in the last working period;
3. cloud storage services used without authorization</p>
        <p>from the company;
4. emails containing company information sent to</p>
        <p>personal email addresses;
5. printing of company documentation.</p>
      </sec>
      <sec id="sec-2-3">
        <title>Obtained this minimum set of information, it is pos</title>
        <p>sible to have suficient elements to have the legitimate
suspicion (if not proof) of the export of confidential and
protected company data. However, this approach is not
comprehensive because it considers the activities
performed by employees on corporate devices and tools.</p>
        <p>As the internal network can be a valid vehicle for
disseminating data that can also be used with non-company
workstations, the analysis can also be extended to this
potentially available class of activity.</p>
        <p>For example, the monitoring and logging tools of
network activities (if present) allow to detect, even
afterwards, the data read/copied by a specific user within
the company storage, such as QRadar Risk manager, CA
Spectrum and Netwrix Auditor [33].</p>
        <p>It is important to underline that, the initial phase of
crystallization of the entire amount of data, to which the
former employee had access during the employment rela- Figure 2: Scheme for the presentation of the evidence
tionship (forensic image), is fundamental both as a term
of comparison for the research of the exported data, and The premise shows who conferred the assignment, the
to demonstrate the origin of the data for which protection objective of the assignment and any other useful
eleis requested. ment to motivate the choices in the methodology adopted.</p>
        <p>All these analyzes are based on the employee using a Sometimes it is useful, already at this stage, to provide the
digital data transfer. There are also analog modes (which reader with an anticipation of the evidence subsequently
leave no trace) and are more dificult to detect, such as a found.
screen photograph. The following sections are all intended for an expert</p>
        <p>However, it should also be considered that enterprise- in the field, therefore they technically describe the
develevel companies should adopt solutions to protect data lopment of the various operations.
dynamically also based on the type of request. In fact,
[1] R. Brighi, Informatica forense, algoritmi e garanzie
processuali, Ars interpretandi, Rivista di
ermeneutica giuridica (2021). doi:10.7382/100798.
[2] V. G. Calabro, La fragilità delle tracce digitali,
Master breve in Diritto e Tecnologie Informatiche (2009).</p>
        <p>doi:10.13140/RG.2.2.27355.62240.
[3] C. Galli, A. Giorgio, Others, L’acquisizione forense
delle prove in materia di violazione dei segreti
aziendali, in: Il nuovo diritto del know how e dei segreti
commerciali, Wolters Kluver, 2018.
[4] European Union, Regulation 2016/679
(General Data Protection Regulation), 2016. URL:
https://eur-lex.europa.eu/legal-content/EN/TXT/</p>
        <p>PDF/?uri=CELEX:32016R0679.
[5] G. Barrera, Il trattamento ai fini di ricerca dei
dati personali relativi a condanne penali e reati.
a proposito di gdpr, Rivista di studi e ricerche
sulla criminalità organizzata (2019). doi:10.13130/
cross-11272.
[6] M. Gradi, L’obbligo di verità delle parti, ISBN</p>
        <p>9788892114036, G. Giappichelli Editore, 2018.
[7] L. Dittrich, L’esibizione delle prove, in: Diritto</p>
        <p>Processuale Civile, Utet Giuridica, 2019.
[8] L. Bartoli, La catena di custodia del materiale
infor4. Conclusions matico: soluzioni a confronto, Universidad de La
Laguna. Servicio de Publicaciones, España (2016).</p>
        <p>The Italian judicial system, in the civil field, does not URL: http://riull.ull.es/xmlui/handle/915/6247.
have a specific reference standard for the management [9] M. Faiz, W. Prabowo, Comparison of acquisition
of digital evidence, for this reason the methodologies ap- software for digital forensics purposes, 2018. doi:10.
plied by professionals in the sector refer to international 22219/KINETIK.V4I1.687.
standards, such as ISO/IEC 27037:2012. [10] E. Akbal, S. Dogan, Forensics image acquisition</p>
        <p>Furthermore, the methods of introducing digital data process of digital evidence, International Journal of
into civil proceedings in Italy difer considerably from Computer Network &amp; Information Security (2018).
what happens overseas, however the method of acquir- [11] Insider threat statistics you should know,
ing and analyzing the evidence remains valid in both 2021. URL: https://www.tessian.com/blog/
doctrines. insider-threat-statistics/.</p>
        <p>The statistics collected in the USA have shown an ever [12] Verizon 2021 breach investigations report, 2021.
greater growth in data exfiltration from companies, iden- URL: https://www.verizon.com/business/en-sg/
tifying the unfaithful employee as the cause of greater resources/reports/dbir/.
frequency. While, in Italy, we observed the same trend [13] Most common data exfiltration behaviors
for the former employee who fraudulently commits the during insider threats in the united states
same ofense using the same techniques. in 2020, https://www.statista.com/statistics/</p>
        <p>This article describes the methodology to be adopted
1155846/most-common-data-exfiltration-insiderto protect the company in the event of data exfiltration threat-types-usa/, 2020.
[14] R. Avanzato, F. Beritelli, M. Russo, S. Russo, M. Vac- [25] F. Bonanno, G. Capizzi, L. G. Sciuto, A neuro
caro, Yolov3-based mask and face recognition al- wavelet-based approach for short-term load
foregorithm for individual protection applications, in: casting in integrated generation systems, in: 2013
CEUR Workshop Proceedings, 2020, pp. 41–45. International Conference on Clean Electrical Power
[15] G. Capizzi, C. Napoli, S. Russo, M. Woźniak, Lessen- (ICCEP), 2013, pp. 772–776. doi:10.1109/ICCEP.
ing stress and anxiety-related behaviors by means 2013.6586946.
of ai-driven drones for aromatherapy, volume 2594, [26] F. Bonanno, G. Capizzi, G. Lo Sciuto, C. Napoli,
2020, pp. 7–12. Wavelet recurrent neural network with
semi[16] Popular computer forensics, 2021. URL: parametric input data preprocessing for micro-wind
https://resources.infosecinstitute.com/topic/ power forecasting in integrated generation
syscomputer-forensics-tools/. tems, 2015, pp. 602–609. doi:10.1109/ICCEP.
[17] K. Ghazinour, D. M. Vakharia, K. C. Kannaji, 2015.7177554.</p>
        <p>R. Satyakumar, A study on digital forensic [27] G. C. Cardarilli, L. D. Nunzio, R. Fazzolari, D.
Gitools, IEEE International Conference on Power, ardino, A. Nannarelli, M. Re, S. Spanò, A
pseudoControl, Signals and Instrumentation Engineering softmax function for hardware-based high speed
(ICPCSI) (2017) 3136–3142. doi:10.1109/ICPCSI. image classification, Scientific Reports 11 (2021).
2017.8392304. doi:10.1038/s41598-021-94691-7.
[18] R. M. A. Mohammad, M. Alqahtani, A com- [28] G. Capizzi, G. Lo Sciuto, C. Napoli, E. Tramontana,
parison of machine learning techniques for M. Woźniak, A novel neural networks-based
texifle system forensics analysis, Journal of ture image processing algorithm for orange defects
Information Security and Applications 46 classification, Int. J. Comput. Sci. Appl. 13 (2016)
(2019) 53–61. URL: https://www.sciencedirect. 45–60.
com/science/article/pii/S2214212618307579. [29] S. K. Sharma, M. Khaliq, The role of quantum
doi:10.1016/j.jisa.2019.02.009. computing in software forensics and digital
ev[19] C. Napoli, G. Pappalardo, E. Tramontana, A math- idence: Issues and challenges, in: Limitations
ematical model for file fragment difusion and a and Future Applications of Quantum
Cryptograneural predictor to manage priority queues over phy, IGI Global, 2021, pp. 169–185. doi:10.4018/
bittorrent, International Journal of Applied Mathe- 978-1-7998-6677-0.ch009.</p>
        <p>matics and Computer Science 26 (2016) 147–160. [30] A. Simonetta, M. C. Paoletti, M. Muratore, A new
[20] S. Spanò, G. C. Cardarilli, L. Di Nunzio, R. Fazzo- approach for designing of computer architectures
lari, D. Giardino, M. Matta, A. Nannarelli, M. Re, using multi-value logic, International Journal on
An eficient hardware implementation of rein- Advanced Science, Engineering and Information
forcement learning: The q-learning algorithm, Technology (in press).</p>
        <p>IEEE Access 7 (2019) 186340–186351. doi:10.1109/ [31] A. Simonetta, M. C. Paoletti, Designing digital
ACCESS.2019.2961174. circuits in multi-valued logic, International
[21] A. A. Jaber, R. Bicker, Fault diagnosis of industrial Journal on Advanced Science,
Engineerrobot gears based on discrete wavelet transform and ing and Information Technology 8 (2018)
artificial neural network, Insight 58 (2016) 179–186. 1166–1172. URL: http://ijaseit.insightsociety.
doi:10.1784/INSI.2016.58.4.179. org/index.php?option=com_content&amp;view=
[22] M. Wozniak, D. Polap, G. Borowik, C. Napoli, A article&amp;id=9&amp;Itemid=1&amp;article_id=5966.
ifrst attempt to cloud-based user verification in doi:10.18517/ijaseit.8.4.5966.
distributed system, in: 2015 Asia-Pacific Confer- [32] A. Neyaz, N. Shashidhar, Usb artifact analysis
ence on Computer Aided System Engineering, IEEE, using windows event viewer, registry and file
2015, pp. 226–231. system logs, Electronics (2019). doi:10.3390/
[23] A. A. Jaber, A. Saleh, H. F. M. Ali, Prediction of electronics8111322.</p>
        <p>hourly cooling energy consumption of educational [33] A. Khurat, P. Sangkhachantharanan, An
aubuildings using artificial neural network, Inter- tomatic networking device auditing tool based
national Journal on Advanced Science, Engineer- on cis benchmark, 18th International
Coning and Information Technology 9 (2019) 159–166. ference on Electrical Engineering/Electronics,
doi:10.18517/IJASEIT.9.1.7351. Computer, Telecommunications and Information
[24] A. A. Jaber, K. M. Ali, Artificial neural network Technology (ECTI-CON) (2021). doi:10.1109/
based fault diagnosis of a pulley-belt rotating sys- ECTI-CON51831.2021.9454830.
tem, International Journal on Advanced Science, [34] V. Calabrò, P. D. Checco, B. Fiammella, La
timeEngineering and Information Technology 9 (2019) line: aspetti tecnici e rilevanza processuale, IISFA
544–551. doi:10.18517/IJASEIT.9.2.7426. Memberbook (2011).</p>
      </sec>
    </sec>
  </body>
  <back>
    <ref-list />
  </back>
</article>