Hong Kong police gets Cofee boost

 

Summary

By tapping on Microsoft's Computer Online Forensic Evidence Extractor, Hong Kong police deploy fewer technical experts when gathering PC evidence at crime scenes.

Events

IBM Technology Conference & Expo 2012
May 23, 2012

Convention Centre B2 Room at 22nd Floor, Centara Grand @ Central World, 999/99 Rama I Road, Pathumwan, Bangkok 10330

Echelon 2012
June 11 and 12, 2012

University Cultural Centre, National University of Singapore

Startup Asia Jakarta 2012
June 7 and 8, 2012

12th Floor, Annex Building, Wisma Nusantara Complex, Jl. M.H. Thamrin No. 59 Jakarta 10350, Indonesia

MMA Forum Singapore
April 23-25, 2012

Grand Hyatt Singapore

A police officer arrives at the scene of a murder, plugs a thumbdrive into a computer that is still running, and executes some 150 evidence-gathering commands within 15 minutes. A scene from CSI? Not necessarily.

The Hong Kong Police Force's technology crime division is one of many law enforcement departments around the world involved in the testing of Computer Online Forensic Evidence Extractor (Cofee), a free tool from Microsoft which can be loaded onto a portable device such as a USB drive.

Cofee, a program that automates some 150 evidence-gathering commands for computers, was released earlier this year in beta version. Available only to law enforcement agencies, the tool was the brainchild of Anthony Fung, Microsoft's senior regional manager for Internet safety and anti-counterfeiting in the Asia-Pacific region.

Paul Jackson, chief inspector, computer forensics and training, Technology Crime Division, Hong Kong Police Force, told ZDNet Asia Thursday that Cofee is "one of many tools" the force uses to investigate a variety of online crimes and to recover digital evidence.

Data recovered from "live", or running, systems at the scene of a crime have proven to be invaluable in analyzing cases, he said in an e-mail interview.

"Before Cofee was available, similar evidence-gathering functions needed to be carried out using a wider variety of tools," noted Jackson. "Cofee neatly packages these capabilities into one tool which can be swiftly and efficiently deployed--even by non-expert investigators."

According to Jackson, 44 officers in the technology crime division, which falls under the Hong Kong Police's Commercial Crime Bureau, use the tool. Initial usage of the beta software has been in "incidence response" situations, he added, but declined to provide further detail on the nature of the cases.

Cofee, however, is designed to extract information from Windows-based systems. For Linux machines, the Hong Kong Police uses several tools or scripts to collect similar data, which have to be executed by a specialist, said Jackson.

And as the application is still in beta, the investigators do not depend solely on Cofee but also use other tools for validation, noted Jackson.

In an interview with ZDNet Asia last week in Singapore, Microsoft's Fung said law enforcement agencies typically faced challenges in handling computers at the crime scenes, largely due to expensive equipment and lack of trained or expert resources. Hong Kong-based Fung was in the island-state to attend the 13th Annual Conference and General Meeting of the International Association of Prosecutors.

With Cofee, an officer with "no or basic training" can preserve the data in about 15 minutes, and maintain its integrity such that it can be brought back to the forensic labs for analysis, said Fung. In the past, it would take a forensic scientist about three hours to manually execute the commands.

Cofee is based on existing extraction tools, he added. Some of the automated commands include recording the login credentials, providing details of the applications and processes executed at that time, and logging system-to-server communication.

Fung, a former police officer specializing in solving computer-related crimes--having spent 13 years with the Hong Kong Police prior to Microsoft--developed the tool based on his experience in law enforcement and in consultation with police officers in the field. The tool was created by both in-house and external coders.

The software, however, is meant to complement existing tools and is not a silver bullet, stressed Fung. "In fact, in the computer forensics industry, there is no one single tool--[whether available] commercially or through open source code--that can solve all the problems."

According to Fung, the beta phase has closed and Microsoft will issue the release edition "once the legal logistics are complete". The official release does not include support for Windows Vista, but a second version that will come shortly would.

Talkback

RAPIER

For those people not lucky enough to be on MSFT's special list to actually get their hands on COFEE, let me suggest you check out RAPIER - you can find it in googlecode.
Open source - does the same things as COFEE.

Sharkey September 30, 2008
Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

ZDNet Asia Live

Better biz models needed for sustainability http://t.co/B5DebtKB http://t.co/erFSwAUB #arcavir

http://t.co/VNaUVSe1 Better biz models needed for sustainability: Companies now see sustaina... http://t.co/i0P8D1Fw http://t.co/wiqTBKkj

Pacnet CEO departs; acquisition rumors gain #steam http://t.co/QSCFfCcy

5 SaaS adoption speed bumps to avoid http://t.co/AJQYAkOh via @zdnetasia

RT @SecMash: #InfoSec Malaysia organizations don't realize severity of cyberattacks - ZDNet Asia http://t.co/vFzACdwm #CyberSecurity

Experience trumps content in apps monetization http://t.co/MVPlf9gR

Better biz models needed for sustainability. http://t.co/tXuq7174

Sudden departure of Pacnet CEO, no explanation - ZDNet Asia: Sudden departure of Pacnet CEO, no explanationZDNet... http://t.co/UVG3OKCG

@ChemarieMonica : Malaysia organizations don't realize severity of cyberattacks - ZDN... http://t.co/iO8wdbz8 http://t.co/1QrdIsaV #tech

Malaysia organizations don't realize severity of cyberattacks. http://t.co/QK7PKdaP

RT @daryllau: Malaysia offers some manufacturing benefits over China http://t.co/mH23Uumr

Malaysia organizations don't realize severity of cyberattacks - ZDNet Asia http://t.co/HniF8J72 #news

#InfoSec Malaysia organizations don't realize severity of cyberattacks - ZDNet Asia http://t.co/vFzACdwm #CyberSecurity

http://t.co/bTDnDh7J Malaysia organizations don't realize severity of cyberattacks - ZDNet Asi... http://t.co/CzsMF2zn #infosec #security

Malaysia organizations don't realize severity of cyberattacks - ZDNet Asia: Malaysia organizat... http://t.co/iUpDhbeU #cloud #fail #TCN

So much as we know , MTK6575 extremely integrated frequency1GHz ARM Cortex-A9 processor, the superiority of 3G / HSPA Modem, and help the...

1 day ago by y15822137359 on 5 SaaS adoption speed bumps to avoid

I reckon your view: "CRM is strategy, not software", if a company replicating the approach uses in ERP implementation into CRM, what they...

2 days ago by wykoong on Gartner: Mobile CRM gives better ROI than social

This video will teach you about the Excel fill handle but also provide you with a workook to download... http://www.youtube.com/watch?v=...

2 days ago by TradeBrother on A quick fill handle trick for Microsoft Excel

waiting...

4 days ago by eapete on What should count in a company's market value?

Boy, you've opened a can of worms now.

Wait for the rants & raves.

4 days ago by eapete on What should count in a company's market value?

I was puzzling before this whether to replicate the success formula we executed for a financial institute, and come out with a standard s...

5 days ago by wykoong on Drop the egos, copy ideas, then innovate