“Forensics and Privacy-enhancing Technologies — Logging and Collecting Evidence in Flocks”



M. S. Olivier. “Forensics and Privacy-enhancing Technologies — Logging and Collecting Evidence in Flocks”. In: Advances in Digital Forensics. Ed. by M. Pollitt and S. Shenoi. Springer, 2005, pp. 17–31


Flocks is a Privacy-enhancing Technology used to hide the Web usage patterns of employees in an organisation against profiling or mere inspection by administrators and other officials. However, Flocks is intended to support identification of senders of malicious requests by means of a legitimate forensics investigation.

The purpose of the paper is twofold. Firstly, it formalises what should be logged for an appropriate forensics investigation. Secondly, exactly what evidence should be explored once a malicious request has been noticed, is considered. It is argued that (i) evidence that would have been collected about a malicious request if the PET were not used, should still be collected, and (ii) evidence that becomes visible by some legitimate means because the PET is used, should be collected. However, information that has not become visible by such legitimate means, but is available because the PET is being used, should not be collected. In the latter case privacy concerns override the fact that a malicious request might be uncovered by investigating more logged information. These positions are defended and formalised using mathematical notation.

A pre- or postprint of the publication is available at http://mo.co.za/ask/flfor.pdf.
The definitive version of the paper is available from the publisher.
DOI: 10.1007/0-387-31163-7_2

AUTHOR={Martin S Olivier},
TITLE={Forensics and Privacy-enhancing Technologies --- Logging and Collecting Evidence in {F}locks},
BOOKTITLE={Advances in Digital Forensics},
EDITOR={Mark Pollitt and Sujeet Shenoi},
PUBLISHER={Springer} )

