Incident Response: Live Forensics and Investigations
|
|
|
- Kathlyn Sanders
- 10 years ago
- Views:
Transcription
1 Chapter 5 Incident Response: Live Forensics and Investigations Solutions in this chapter: Postmortem versus Live Forensics Today s Live Methods Case Study: Live versus Postmortem Computer Analysis for the Hacker Defender Program Network Analysis Summary Solutions Fast Track Frequently Asked Questions 89
2 90 Chapter 5 Incident Response: Live Forensics and Investigations Introduction To pull or not to pull the plug, that is the question.today, cyber crime investigators are faced with the grueling task of deciding whether shutting down a computer system is the most efficient and effective method to gather potential electronic evidence.traditionally, computer forensics experts agreed that shutting the computer system down in order to preserve evidence and eliminate the potential changing of information is best practice prior to examination. I remember having the phrases shut it down, and don t change anything beaten into my brain during the numerous trainings I ve attended throughout the years. However, one of the fundamental misconceptions with this philosophy is that computer forensics is the same as physical forensics. I would argue that they are not the same, given that computer forensics technology changes faster than traditional forensics disciplines like ballistics, serology, and fingerprint analysis.the second misconception is that we always collect everything at a physical crime scene. In a physical forensics environment, we commonly photograph the physical crime scene and take reasonable precautions to ensure the evidence is not disturbed.the truth is, in many cases, we only collect samples from a physical crime scene. Nevertheless, we have accepted this methodology as best practice, and have backed ourselves into a litigation corner.the evolution of technology has put us face to face with the harsh reality that it is sometimes more advantageous to perform Live analysis than a Postmortem one.the problem is that live analysis often changes evidence by writing to the hard drive. File time stamps, Registry keys, swap files, and memory are just some of the items that can be affected when conducting analysis on a live computer system. Often, once the live analyst is done, the resulting MD5 hash will not match the hash collected prior to the live collection. Postmortmem versus Live Forensics Why should we even consider conducting live investigations as a valid forensic methodology? The reason is we have to! In the pages that follow, I will discuss the need to move away from traditional methods of computer forensics and toward a live forensics model.
3 Incident Response: Live Forensics and Investigations Chapter 5 91 TIPVS. LIVE FORENSICS Postmortem and live forensics are both great evidence gathering techniques. However, in cases where you can only conduct a postmortem forensics, the need to look at other systems within the environment is strengthened. This expansion of your scope to include other systems on the network will give you a better understanding of how the target system acted within its native environment. Evolution of the Enterprise Technology has evolved in such a way that conducting live investigations is really the only option you have under certain circumstances. In the days of old, computer networks were simple. In today s world, the evolution of the enterprise network work makes it difficult for system administrators, IT security personal, and the like to be at more than one location. Managing IT resources at a single site can be a daunting task. Now think of the larger corporate network schema. Many companies have multiple computers at a single location. Additionally, those corporations may also have several locations in a city, country, or continent. What would happen to our resources if we had to respond to every site and pull the computer off the network to conduct a forensic analysis for every suspected compliance issue, security breach, or compromised host? This would be even worse if after all the effort, time, and resources, we conclude that none of the aforementioned even occurred. Sound familiar? It should, because it happens every day in the cyber world. Triage is a common practice when diagnosing problems within a network. It is our first reaction, and we don t necessarily assume we are under attack, or that our systems have been compromised. In a live forensic environment, IT security personnel could log on remotely, view running processes, dump physical memory, and make an educated guess as to whether or not the computer should be imaged remotely, or be physically removed from the network for further analysis. In this scenario, the investigator, using live forensics techniques, doesn t have to physically respond to the location to address the issue until they are satisfied with their initial inquiry.this methodology will help conserve resources.
4 92 Chapter 5 Incident Response: Live Forensics and Investigations Evolution of Storage Now back to pulling the pull. Once upon a time there was a server.this server was about 630 terabytes (TB) in size. It was responsible for handling the day-to-day operations of Company X, which traded stocks for its clients 24 hours a day.this server was believed to be compromised because of some unusual traffic detected within the log files of the firewall.this scenario presents us with the following issues. Problem 1: How are we going to fit this 630TB image into our 250GB USB2 external drive? Problem 2: How long would it take to image a drive that size? Problem 3:The machine cannot be shut down because the company would suffer a financial loss. In addition to all these issues, we must remember to make a bit-stream image, which was discussed earlier in Chapter 1. Let s discuss the preceding problems one at a time. Problem 1: It s not possible.you will need a bigger drive. Problem 2: The data resides on a substantially large server (630TB). Imaging the entire server is not practical, even though best practices dictate we should. Here is one of the reasons why: 630TB is equal to 6,926,923,254,988,880 bytes. 630 x 1,099,511,627,776 (1 Terabyte) = 6,926,923,254,988,880 bytes. See Table 5.1 to determine the byte sizes used in this scenario. Table 5.1 Byte Conversion Chart Drive Size Numerical Representation 2 to the Following Power 1 kilobyte 1, megabyte 1,048, gigabyte 1,073,741, terabyte 1,099,511,627, petabyte 1,125,899,906,842, exabyte 1,152,921,504,606,840, Let s assume you use the ICS Image MASSter Solo-3 IT, which states it can duplicate hard drives at a rate of 3 GB a minute.
5 Incident Response: Live Forensics and Investigations Chapter 5 93 Divide / (3 gigabytes) = total minutes Divide minutes /60 minutes (1 hour) = total hours Divide total hours / 24 hours (1 day) = 1493 total days Divide 1493 days / 365 day (1 year) = over 4 years to image the entire drive. As you can see from the preceding bullets, imaging the entire one-to-one drive is not practical. Even if you imaged the data, by utilizing additional resources, the analysis of such a large volume could prove just as prohibitive. The difference in conducting an analysis on such a large volume, as compared to specific data objects and/or smaller storage systems, (using a detective s analogy) would be equivalent to interviewing every person who lives on a block where a homicide has occurred (reasonable), versus interviewing everyone who lives in the city of the homicide victim (not reasonable). Notes from the Underground Using Compression If you re thinking that the use of compression could solve the preceding problems, you would be mistaken. Compression increases the time it takes to image the server s hard drive because the compression algorithm needs to examine and remove the redundant items prior to compressing them. Additionally, it would still be impossible to compress the larger hard drive into the smaller USB external drive. Problem 3: Shutting down the server is also not an option since the most obvious side effect would be the economic harm Company X would experience as a result. Many systems in existence today are mission critical, such as those supporting health care, transportation, and so on, and they couldn t be shut down without causing detrimental effects.
6 94 Chapter 5 Incident Response: Live Forensics and Investigations Encrypted File Systems The use of encryption has increased during the last few years. Its increased use presents a unique problem to investigators when conducting postmortem analysis. When encryption is applied to a data object, the contents of that object are illegible. Encryption, by default, is designed to obfuscate, and sometimes compress, the contents of the data object it encrypts. Once encrypted, the object s contents are hidden and are pretty much impossible to interpret. Encryption is applied to these data objects in one of three ways.the first implementation is file level encryption, in which individual files are encrypted. Figure 5.1 shows the contents of an encrypted file. Figure 5.1 File Contents When the File Is Encrypted Using AccessData s FTK Imager In order for an examiner to perform a postmortem analysis, he must first decrypt the file. Figure 5.2 shows a decrypted file.this could prove extremely difficult if the investigator does not have access to the encrypted file s password. No password may result in having to use a password cracking program. This decrypting process may prove useless if the password is too large, or the file is encrypted with a strong encryption algorithm and implementation.
7 Incident Response: Live Forensics and Investigations Chapter 5 95 Figure 5.2 File Contents When the File Is Not Encrypted Using AccessData s FTK Imager The second method used when applying encryption is volume level encryption. In this case, a volume within the hard disk is encrypted. Figure 5.3 shows an encrypted volume. Figure 5.3 A BestCrypt Encrypted Volume The third method used when encrypting a data object is whole disk encryption.this is when the entire hard drive is in encrypted. Figure 5.4 offers a forensic image of a fully encrypted disk. As you can see, its contents are illegible, and are of little value to a forensic examiner.
8 96 Chapter 5 Incident Response: Live Forensics and Investigations Figure 5.4 A Forensic Image of an Encrypted Hard Drive Using AccessData s FTK Imager When conducting postmortem forensic analysis against the first two methods, investigators often hope to find artifacts of an encrypted file in its decrypted state that may be left in allocated or unallocated space.these artifacts are sometimes created once the document has been opened, or when the plug has been pulled while the file is still displayed on the screen. While this is a valid premise, recovery of these artifacts may not always be successful. Moreover, performing a proper shutdown may further decrease your chances of finding such evidence. In Figure 5.5, you will notice that the program BestCrypt offers to open the file in a temporary folder, and then securely delete the file when the program is closed. When you use live forensics, the chances are significantly greater to view the contents of the encrypted file. If the document is open, it will most likely be loaded into physical memory. In a live forensic environment, the investigator could image the physical memory of the computer system and glean useful information about what files and programs the suspect may be currently using. So, before pulling the plug, it may be worth our while to examine the contents of the physical memory. Figure 5.6 shows one example of how we could image physical memory by using a network forensics tool.
9 Incident Response: Live Forensics and Investigations Chapter 5 97 Figure 5.5 A File-Cleaning Operation Offered by BestCrypt Figure 5.6 The Technologies Pathways ProDiscover IR Imaging Screen Once the image has been created, we can examine its contents. In Figure 5.7, you will notice the contents of the encrypted file are displayed in a readable format in the lower right-hand pane. Recovery of this information is because the file has been unencrypted by the user who is currently working with the document. Additionally, in Figure 5.8 you can see the BestCrypt program is running in physical memory.this information is also displayed in the lower right-hand pane.
10 98 Chapter 5 Incident Response: Live Forensics and Investigations Figure 5.7 An Unencrypted Document in Memory Using Technologies Pathways ProDiscover IR Figure 5.8 A View of Physical Memory Contents Using Technologies Pathways ProDiscover IR. Note that the BestCrypt Process Is Running.
11 Incident Response: Live Forensics and Investigations Chapter 5 99 In the case of whole disk encryption, a forensic examiner using live forensics techniques would be able to view the content of the drive when it is mounted by the suspect. Simply put, because the drive is presently being used, it is unencrypted. Figure 5.9 demonstrates our ability to view the mounted drive s contents in its unencrypted state. Figure 5.9 An Encrypted Hard Drive s Contents When Mounted Live with a Forensics Tool Like Technologies Pathways ProDiscover As you can see from the preceding examples, encryption presents a variety of problems for the traditional forensics examiner. With live investigative techniques, however, we can overcome these problems and obstacles. Today s Live Methods Several software companies presently manufacture network forensic and investigative software. Guidance Software,Technologies Pathways, Wetstone Technologies, ASR Data, E-fense, and E Trust by CA are just some of the
12 100 Chapter 5 Incident Response: Live Forensics and Investigations companies that produce this forensic and incident response software.these manufacturers use a variety of methods to conduct live investigations.the first method employed is the Pre-Deployed Agent model, where special software is pre-installed on a computer system prior to an incident. It is usually hidden from the end user and is invoked once it is connected to remotely. The second method currently in use is the Direct Connect model. In this model, the target computer is directly connected to by a remote machine and the software is pushed into memory.the connection remains active until the remote machine is disconnected. A third method is the On Demand Connection model, where the computer connects to the target machine and pushes the software into memory for a specific task. Once the task issued by the remote machine is completed, the connection is immediately torn down. Finally, some software developers use a boot disk or an investigative CD- ROM. During a live analysis, a disk is loaded to the live machine and a virtual session is initiated with a set of examination tools. Figure 5.10 shows a boot disk that allows you to conduct live forensics, as well as investigations. Figure 5.10 The E-fense s HELIX Incident Response, Electronic Discovery, and Computer Forensics Boot Disk
13 Incident Response: Live Forensics and Investigations Chapter Case Study: Live versus Postmortem Live investigations allow investigators to capture volatile information that would not normally be present in a postmortem investigation.this information can consist of running processes, event logs, network information, registered drivers, and registered services. Why is this important to us, you ask? Let s take a look at the case of running services and how this could be extremely important us. Running services tell us the types of services that may be running on a computer.these services run at a much higher priority than processes, and many users are unaware that these services actually exist. Given their high priority and lack of attention by the typical end user, they are a common target for hackers. By conducting a live investigation, we are able to see the state of these services, which could prove crucial to our investigation. For example, a hacker could turn off the service for McShield, which is a McAfee Antivirus service, and then later come back and infest the machine with malicious software. You might argue in the case of registered drivers that you could get a list of the drivers in a postmortem investigation.this is true; however, if you are at a crime scene and you conduct a live investigation, you might be able to see a driver for a digital camera. So you know to look for that camera in your surrounding area. But if you left the location, and then returned later to find that camera driver, you could only hope that the camera is still there when you make it back. As shown in the previous example, seeing registered drivers gives investigators knowledge of the peripherals of a suspect machine. Figure 5.11 illustrates some of the volatile information you can obtain about a systems state. Viewing running processes with the associated open network ports is one of the most important features of analyzing the system state.to peek into a system and correctly assess what processes are running and what ports they may be using is critical when trying to perform an investigative triage. Figure 5.12 offers a detailed look at the running processes of a target machine under investigation.
14 102 Chapter 5 Incident Response: Live Forensics and Investigations Figure 5.11 An Example of Live System Information You Can Obtain Using Wetstone s LiveWire Figure 5.12 A View of Running Processes Using Wetstone s LiveWire
15 Incident Response: Live Forensics and Investigations Chapter Notice how we can see not only the process s name in Figure 5.12 but also the priority, the number of threads, number of handles, memory usage, and uptime. Again, you might ask why all of this is important. Well, if you are trying to assess what someone is currently doing, or even what they have done in the past, this information is critical. In addition, in the world of memory resident executables, analyzing the current process list is vital. In a postmortem investigation, physical memory (RAM) is potentially the most important piece of evidence that is lost. However, this crucial piece of evidence is easily captured using live forensic and investigative tools, allowing the entire contents of RAM to be captured locally and even remotely. In Figure 5.13, we can see the contents of a memory dump and can conduct a search for the word keylogger in memory. Figure 5.13 A Keyword Search for the Term Keylogger in a Memory Dump Using Wetstone s LiveWire
16 104 Chapter 5 Incident Response: Live Forensics and Investigations The raw data contents of the memory provide a vast amount of information that could have been lost if the machine was powered down for a postmortem investigation. Memory contains evidence ranging from user accounts, passwords, unsaved document content, and malicious software. Terminology Alert Malicious Software Malicious software is a term describing a broad range of tools. However, memory-resident malicious software generally is seen with rootkits, Trojan horses, worms, and keyloggers. The following example contains a detailed explanation on how some memory-resident malicious software work. Computer Analysis for the Hacker Defender Program Hacker Defender is a popular rootkit that is capable of hiding processes, files, and even open ports. By default, when Hacker Defender is executed, it hides every file containing the prefix hxdef. As a result, the file hxdef100.ini, which is part of Hacker Defender, is hidden as soon as Hacker Defender executes.this file is then hidden from all users and even Windows Explorer itself. However, the file still exists in physical memory. Using live investigation techniques, you can take a memory snapshot and identify the file hxdef100.ini stored in RAM (see Figure 5.14).This same method can be used to reveal any file or process that Hacker Defender hides (see Figure 5.15). During a postmortem investigation, any files or processes hidden by Hacker Defender may not be accessible to the investigator. Figures 5.14 and 5.15 show evidence of the Hacker Defender program in the physical memory of a computer.
17 Incident Response: Live Forensics and Investigations Chapter Figure 5.14 Hacker Defender in Psychical Memory Using Wetstone s LiveWire Figure 5.15 Another View of Hacker Defender in Psychical Memory Using Wetstone s LiveWire As stated earlier, investigating a computer s system state is an important part of any investigation. It could help glean valuable information in a case and reduce the risk of missing data that could prove critical to your investigation. Network Analysis Often overlooked in live investigations is the environment in which the target computer resides. Data obtained from firewall laws, routers, intrusion detection systems, and so on are equally important to an examiner in obtaining the big picture. In the Hacker Defender case presented earlier, a defense attorney may argue that his client s machine was compromised and could not have committed the crime. A review of the firewall logs may show that the Hacker Defender activity from this computer was blocked, making this argument about the rootkit a moot point. As a live investigator, you should try to gain as much information about the network activity as possible.you might want to install a packet sniffer with the appropriate permission, of course and conduct a packet analysis of the traffic. Using this technique, you could determine if someone is connected to the box before conducting an analysis on the target machine. So remember, you may find additional evidence beyond the computer you are examining. Look for it.
18 106 Chapter 5 Incident Response: Live Forensics and Investigations Summary As we move forward, computer forensics as we now know it will change dramatically.the release of Microsoft s Vista will enable users to fully encrypt their hard drives.the use of virtual machines and virtual server farms are becoming more commonplace. Internet-based application servers will be harder for forensic examiners to physically collect. Additionally, Internet-based applications may generate diskless workstations, leaving the only evidence in physical memory. Finally, software vendors are starting to deploy a larger amount of software that securely deletes data because of identity-theft concerns. Because of these changes, and as I have pointed out in the examples in this chapter, I surmise that traditional forensics will become more impractical, and live investigations will become a necessity rather than a luxury.traditional methodologies are becoming somewhat obsolete.the need to adopt a new way of conducting these types of investigations is essential. While we have shied away from touching the computer in order to prevent any changes, it is now obvious that there are times when an examiner must interact with a live computer in order to retrieve vital data. Under the circumstances described earlier, you should be able to provide a reasonable explanation to any judge or jury as to why live forensics was used in place of traditional methods. However, should none of these circumstances exist, it may be best just to pull the plug. Special Thanks I would like to give thanks to my colleagues Christopher L.T. Brown and Chet Hosmer for their help with this chapter.their wisdom and insight into incident response and network forensic issues were invaluable. References Brown, Christopher L.T. Computer Evidence Collection & Preservation. Massachusetts: Charles River Media, Inc., Chirillo, John. Hack Attacks Revealed. New York, John Wiley & Sons, Inc., 2001.
19 Mandia, Kevin et al. Incident Response: Investigating Computer Crime. California: Osborne/McGraw-Hill, McClure, Stuart et al. Hacking Exposed: Network Security Secrets & Solutions. California: Osborne/McGraw-Hill, Szor, Peter. The Art of Computer Virus Research and Defense. New Jersey: Addison-Wesley, Solutions Fast Track Incident Response: Live Forensics and Investigations Chapter Postmortem versus Live Forensics In a live investigation, a system administrator can conduct an analysis remotely. Imaging large volumes can be a daunting task. Live forensics can be used to obtain data when encryption is in use. Capturing the contents of memory may provide you with the missing link. Today s Live Methods A Pre-Deployed Agent is software that is installed onto the computer prior to an incident. A boot disk can be used to contact live investigations. Case Study: Live versus Postmortem Live investigations allow investigators to capture volatile information that would not normally be present in a postmortem investigation. This information can consist of running processes, event logs, network information, registered drivers, and registered services. Running services tell us the types of services that may be running on a computer.these services run at a much higher priority than
20 108 Chapter 5 Incident Response: Live Forensics and Investigations processes, and many users are unaware that these services actually exist. Viewing running processes with the associated open network ports is one of the most important features of analyzing the system state.to peek into a system and correctly assess what processes are running and what ports they may be using is critical when trying to perform an investigative triage. Computer Analysis for the Hacker Defender Program Hacker Defender hides files from the user. Rootkit artifacts can sometimes be found in physical memory. Network Analysis You should look for evidence beyond the target computer. Understanding the network where the system resides can help you when conducting a live investigation.
21 Incident Response: Live Forensics and Investigations Chapter Frequently Asked Questions The following Frequently Asked Questions, answered by the authors of this book, are designed to both measure your understanding of the concepts presented in this chapter and to assist you with real-life implementation of these concepts. To have your questions about this chapter answered by the author, browse to /solutions and click on the Ask the Author form. Q: Can I view encrypted data in a live environment without having the password? A: The answer is yes, provided that the drive or file is unencrypted on the suspect s machine. Q: Can I view hidden processes like rootkits on a live computer? A: Using special software, you can view hidden processes and files on a live computer. Q: If I cannot image the entire drive, can I just copy the files I need? A: Yes, you can copy the files you need using live forensic software to ensure you have the entire copy. Also, take notes when doing this since you may have to testify later about why you chose this method and what, if anything, you changed.
Incident Response. Six Best Practices for Managing Cyber Breaches. www.encase.com
Incident Response Six Best Practices for Managing Cyber Breaches www.encase.com What We ll Cover Your Challenges in Incident Response Six Best Practices for Managing a Cyber Breach In Depth: Best Practices
ScoMIS Encryption Service
Introduction This guide explains how to install the ScoMIS Encryption Service Software onto a laptop computer. There are three stages to the installation which should be completed in order. The installation
EC-Council Ethical Hacking and Countermeasures
EC-Council Ethical Hacking and Countermeasures Description This class will immerse the students into an interactive environment where they will be shown how to scan, test, hack and secure their own systems.
MSc Computer Security and Forensics. Examinations for 2009-2010 / Semester 1
MSc Computer Security and Forensics Cohort: MCSF/09B/PT Examinations for 2009-2010 / Semester 1 MODULE: COMPUTER FORENSICS & CYBERCRIME MODULE CODE: SECU5101 Duration: 2 Hours Instructions to Candidates:
Digital Forensics Tutorials Acquiring an Image with FTK Imager
Digital Forensics Tutorials Acquiring an Image with FTK Imager Explanation Section Digital Forensics Definition The use of scientifically derived and proven methods toward the preservation, collection,
Network Incident Report
To submit copies of this form via facsimile, please FAX to 202-406-9233. Network Incident Report United States Secret Service Financial Crimes Division Electronic Crimes Branch Telephone: 202-406-5850
White Paper - Crypto Virus. A guide to protecting your IT
White Paper - Crypto Virus A guide to protecting your IT Contents What is Crypto Virus?... 3 How to protect yourself from Crypto Virus?... 3 Antivirus or Managed Agents... 3 Enhanced Email Services & Extra
ScoMIS Encryption Service
Introduction This guide explains how to implement the ScoMIS Encryption Service for a secondary school. We recommend that the software should be installed onto the laptop by ICT staff; they will then spend
Digital Forensics. Tom Pigg Executive Director Tennessee CSEC
Digital Forensics Tom Pigg Executive Director Tennessee CSEC Definitions Digital forensics Involves obtaining and analyzing digital information as evidence in civil, criminal, or administrative cases Analyze
2. From a control perspective, the PRIMARY objective of classifying information assets is to:
MIS5206 Week 13 Your Name Date 1. When conducting a penetration test of an organization's internal network, which of the following approaches would BEST enable the conductor of the test to remain undetected
Information Technology Audit & Forensic Techniques. CMA Amit Kumar
Information Technology Audit & Forensic Techniques CMA Amit Kumar 1 Amit Kumar & Co. (Cost Accountants) A perfect blend of Tax, Audit & Advisory services Information Technology Audit & Forensic Techniques
Cyber Security in Taiwan's Government Institutions: From APT To. Investigation Policies
Cyber Security in Taiwan's Government Institutions: From APT To Investigation Policies Ching-Yu, Hung Investigation Bureau, Ministry of Justice, Taiwan, R.O.C. Abstract In this article, we introduce some
What Do You Mean My Cloud Data Isn t Secure?
Kaseya White Paper What Do You Mean My Cloud Data Isn t Secure? Understanding Your Level of Data Protection www.kaseya.com As today s businesses transition more critical applications to the cloud, there
Digital Forensics. Larry Daniel
Digital Forensics Larry Daniel Introduction A recent research report from The Yankee Group found that 67.6 percent of US households in 2002 contained at least one PC The investigators foresee three-quarters
Fall. Forensic Examination of Encrypted Systems Matthew Postinger COSC 374
Fall 2011 Forensic Examination of Encrypted Systems Matthew Postinger COSC 374 Table of Contents Abstract... 3 File System Encryption... 3 Windows EFS... 3 Apple FileVault... 4 Full Disk Encryption...
Live View. A New View On Forensic Imaging. Matthiew Morin Champlain College
Live View A New View On Forensic Imaging Matthiew Morin Champlain College Morin 1 Executive Summary The main purpose of this paper is to provide an analysis of the forensic imaging tool known as Live View.
Forensically Determining the Presence and Use of Virtual Machines in Windows 7
Forensically Determining the Presence and Use of Virtual Machines in Windows 7 Introduction Dustin Hurlbut Windows 7 has the ability to create and mount virtual machines based upon launching a single file.
Windows Operating Systems. Basic Security
Windows Operating Systems Basic Security Objectives Explain Windows Operating System (OS) common configurations Recognize OS related threats Apply major steps in securing the OS Windows Operating System
Overview of Computer Forensics
Overview of Computer Forensics Don Mason, Associate Director National Center for Justice and the Rule of Law University of Mississippi School of Law [These materials are based on 4.3.1-4.3.3 in the National
How to build and use a Honeypot. Ralph Edward Sutton, Jr. DTEC 6873 Section 01
How to build and use a Honeypot By Ralph Edward Sutton, Jr DTEC 6873 Section 01 Abstract Everybody has gotten hacked one way or another when dealing with computers. When I ran across the idea of a honeypot
The Value of Physical Memory for Incident Response
The Value of Physical Memory for Incident Response MCSI 3604 Fair Oaks Blvd Suite 250 Sacramento, CA 95864 www.mcsi.mantech.com 2003-2015 ManTech Cyber Solutions International, All Rights Reserved. Physical
Incident Response and Computer Forensics
Incident Response and Computer Forensics James L. Antonakos WhiteHat Forensics Incident Response Topics Why does an organization need a CSIRT? Who s on the team? Initial Steps Detailed Project Plan Incident
The Proper Acquisition, Preservation, & Analysis of Computer Evidence: Guidelines & Best-Practices
The Proper Acquisition, Preservation, & Analysis of Computer Evidence: Guidelines & Best-Practices Introduction As organizations rely more heavily on technology-based methods of communication, many corporations
Data Security Incident Response Plan. [Insert Organization Name]
Data Security Incident Response Plan Dated: [Month] & [Year] [Insert Organization Name] 1 Introduction Purpose This data security incident response plan provides the framework to respond to a security
Determining VHD s in Windows 7 Dustin Hurlbut
Introduction Windows 7 has the ability to create and mount virtual machines based upon launching a single file. The Virtual Hard Disk (VHD) format permits creation of virtual drives that can be used for
MCTS Guide to Microsoft Windows 7. Chapter 7 Windows 7 Security Features
MCTS Guide to Microsoft Windows 7 Chapter 7 Windows 7 Security Features Objectives Describe Windows 7 Security Improvements Use the local security policy to secure Windows 7 Enable auditing to record security
NEW JERSEY STATE POLICE EXAMPLES OF CRIMINAL INTENT
Appendix A to 11-02-P1-NJOIT NJ OFFICE OF INFORMATION TECHNOLOGY P.O. Box 212 www.nj.gov/it/ps/ 300 Riverview Plaza Trenton, NJ 08625-0212 NEW JERSEY STATE POLICE EXAMPLES OF CRIMINAL INTENT The Intent
Getting Physical with the Digital Investigation Process
Getting Physical with the Digital Investigation Process Brian Carrier Eugene H. Spafford Center for Education and Research in Information Assurance and Security CERIAS Purdue University Abstract In this
IT Checklist. for Small Business INFORMATION TECHNOLOGY & MANAGEMENT INTRODUCTION CHECKLIST
INFORMATION TECHNOLOGY & MANAGEMENT IT Checklist INTRODUCTION A small business is unlikely to have a dedicated IT Department or Help Desk. But all the tasks that a large organization requires of its IT
Things To Do After You ve Been Hacked
Problem: You ve been hacked! Now what? Solution: Proactive, automated incident response from inside the network Things To Do After You ve Been Hacked Tube web share It only takes one click to compromise
NCS 330. Information Assurance Policies, Ethics and Disaster Recovery. NYC University Polices and Standards 4/15/15.
NCS 330 Information Assurance Policies, Ethics and Disaster Recovery NYC University Polices and Standards 4/15/15 Jess Yanarella Table of Contents: Introduction: Part One: Risk Analysis Threats Vulnerabilities
Digital Forensics & e-discovery Services
Digital Forensics & e-discovery Services U.S. Security Associates Digital Forensics & e-discovery Services 21st century fraud investigations require expert digital forensics skills to deal with the complexities
Lecture outline. Computer Forensics and Digital Investigation. Defining the word forensic. Defining Computer forensics. The Digital Investigation
Computer Forensics and Digital Investigation Computer Security EDA263, lecture 14 Ulf Larson Lecture outline! Introduction to Computer Forensics! Digital investigation! Conducting a Digital Crime Scene
Computer Hacking Forensic Investigator v8
CÔNG TY CỔ PHẦN TRƯỜNG CNTT TÂN ĐỨC TAN DUC INFORMATION TECHNOLOGY SCHOOL JSC LEARN MORE WITH LESS! Computer Hacking Forensic Investigator v8 Course Description: EC-Council releases the most advanced Computer
for Networks Installation Guide for the application on the server July 2014 (GUIDE 2) Lucid Rapid Version 6.05-N and later
for Networks Installation Guide for the application on the server July 2014 (GUIDE 2) Lucid Rapid Version 6.05-N and later Copyright 2014, Lucid Innovations Limited. All Rights Reserved Lucid Research
Cyber Security In High-Performance Computing Environment Prakashan Korambath Institute for Digital Research and Education, UCLA July 17, 2014
Cyber Security In High-Performance Computing Environment Prakashan Korambath Institute for Digital Research and Education, UCLA July 17, 2014 Introduction: Cyber attack is an unauthorized access to a computer
Digital Forensics: The aftermath of hacking attacks. AHK Committee Meeting April 19 th, 2015 Eng. Jamal Abdulhaq Logos Networking FZ LLC
Digital Forensics: The aftermath of hacking attacks AHK Committee Meeting April 19 th, 2015 Eng. Jamal Abdulhaq Logos Networking FZ LLC Topics Digital Forensics: Brief introduction Case Studies Case I:
DriveLock and Windows 7
Why alone is not enough CenterTools Software GmbH 2011 Copyright Information in this document, including URL and other Internet Web site references, is subject to change without notice. Unless otherwise
Automating Linux Malware Analysis Using Limon Sandbox Monnappa K A [email protected]
Automating Linux Malware Analysis Using Limon Sandbox Monnappa K A [email protected] A number of devices are running Linux due to its flexibility and open source nature. This has made Linux platform
CERIAS Tech Report 2003-29 GETTING PHYSICAL WITH THE DIGITAL INVESTIGATION PROCESS. Brian Carrier & Eugene H. Spafford
CERIAS Tech Report 2003-29 GETTING PHYSICAL WITH THE DIGITAL INVESTIGATION PROCESS Brian Carrier & Eugene H. Spafford Center for Education and Research in Information Assurance and Security, Purdue University,
Course Title: Computer Forensic Specialist: Data and Image Files
Course Title: Computer Forensic Specialist: Data and Image Files Page 1 of 9 Course Description The Computer Forensic Series by EC-Council provides the knowledge and skills to identify, track, and prosecute
Forensic Acquisition and Analysis of VMware Virtual Hard Disks
Forensic Acquisition and Analysis of VMware Virtual Hard Disks Manish Hirwani, Yin Pan, Bill Stackpole and Daryl Johnson Networking, Security and Systems Administration Rochester Institute of Technology
Developing Computer Forensics Solutions for Terabyte Investigations
Developing Computer Forensics Solutions for Terabyte Investigations Eric Thompson Corporation Orem, Utah USA www.accessdata.com Overview Computer Forensic Definition, Objectives and Policies History of
Network Security. Chapter 12. Learning Objectives. Chapter Outline. After reading this chapter, you should be able to:
Network Security Chapter 12 Learning Objectives After reading this chapter, you should be able to: Recognize the basic forms of system attacks Recognize the concepts underlying physical protection measures
10 Ways to Not Get Caught Hacking On Your Mac
10 Ways to Not Get Caught Hacking On Your Mac Three18 is a Comprehensive Technology Solutions Provider Apple Certified Partner Microsoft Gold Partner Symantec Security Solutions Partner Novell and RedHat
Description: Objective: Attending students will learn:
Course: Introduction to Cyber Security Duration: 5 Day Hands-On Lab & Lecture Course Price: $ 3,495.00 Description: In 2014 the world has continued to watch as breach after breach results in millions of
Scene of the Cybercrime Second Edition. Michael Cross
Scene of the Cybercrime Second Edition Michael Cross Chapter 1 Facing the Cybercrime Problem Head-On 1 Introduction 2 Defining Cybercrime 2 Understanding the Importance of Jurisdictional Issues 3 Quantifying
Cyber Security Best Practices
Cyber Security Best Practices 1. Set strong passwords; Do not share them with anyone: They should contain at least three of the five following character classes: o Lower case letters o Upper case letters
Network Instruments white paper
Network Instruments white paper USING A NETWORK ANALYZER AS A SECURITY TOOL Network Analyzers are designed to watch the network, identify issues and alert administrators of problem scenarios. These features
THE ROLE OF IDS & ADS IN NETWORK SECURITY
THE ROLE OF IDS & ADS IN NETWORK SECURITY The Role of IDS & ADS in Network Security When it comes to security, most networks today are like an egg: hard on the outside, gooey in the middle. Once a hacker
Computer Viruses: How to Avoid Infection
Viruses From viruses to worms to Trojan Horses, the catchall term virus describes a threat that's been around almost as long as computers. These rogue programs exist for the simple reason to cause you
10- Assume you open your credit card bill and see several large unauthorized charges unfortunately you may have been the victim of (identity theft)
1- A (firewall) is a computer program that permits a user on the internal network to access the internet but severely restricts transmissions from the outside 2- A (system failure) is the prolonged malfunction
Applications of Data Recovery Tools to Digital Forensics: Analyzing the Host Protected Area with the PC-3000
Applications of Data Recovery Tools to Digital Forensics: Analyzing the Host Protected Area with the PC-3000 Richard Leickly and David Angell Circle Hook Data Recovery { Richard, David}@CircleHookDR.com
Computer Forensics and What Is, and Is Not, There on Your Client s Computer. Rick Lavaty, Computer Systems Administrator, District of Arizona
Computer Forensics and What Is, and Is Not, There on Your Client s Computer Rick Lavaty, Computer Systems Administrator, District of Arizona Eddy Archibeque, Computer Systems Administrator, District of
SecureAge SecureDs Data Breach Prevention Solution
SecureAge SecureDs Data Breach Prevention Solution In recent years, major cases of data loss and data leaks are reported almost every week. These include high profile cases like US government losing personal
Whitepaper Enhancing BitLocker Deployment and Management with SimplySecure. Addressing the Concerns of the IT Professional Rob Weber February 2015
Whitepaper Enhancing BitLocker Deployment and Management with SimplySecure Addressing the Concerns of the IT Professional Rob Weber February 2015 Page 2 Table of Contents What is BitLocker?... 3 What is
FORBIDDEN - Ethical Hacking Workshop Duration
Workshop Course Module FORBIDDEN - Ethical Hacking Workshop Duration Lecture and Demonstration : 15 Hours Security Challenge : 01 Hours Introduction Security can't be guaranteed. As Clint Eastwood once
Live System Forensics
Live System Forensics By: Tim Fernalld & Colby Lahaie Patrick Leahy Center for Digital Investigation Champlain College 2/22/12 Contents Contents... 1 1 Introduction... 2 1.1 Research Statement... 2 1.2
for Networks Installation Guide for the application on the server August 2014 (GUIDE 2) Lucid Exact Version 1.7-N and later
for Networks Installation Guide for the application on the server August 2014 (GUIDE 2) Lucid Exact Version 1.7-N and later Copyright 2014, Lucid Innovations Limited. All Rights Reserved Lucid Research
Chapter 8: Security Measures Test your knowledge
Security Equipment Chapter 8: Security Measures Test your knowledge 1. How does biometric security differ from using password security? Biometric security is the use of human physical characteristics (such
10 steps to better secure your Mac laptop from physical data theft
10 steps to better secure your Mac laptop from physical data theft Executive summary: This paper describes changes Mac users can make to improve the physical security of their laptops, discussing the context
DEFENSE THROUGHOUT THE VULNERABILITY LIFE CYCLE WITH ALERT LOGIC THREAT AND LOG MANAGER
DEFENSE THROUGHOUT THE VULNERABILITY LIFE CYCLE WITH ALERT LOGIC THREAT AND Introduction > New security threats are emerging all the time, from new forms of malware and web application exploits that target
Incident Response. Six Best Practices for Managing Cyber Breaches. Nick Pollard, Senior Director Professional Services EMEA / APAC, Guidance Software
Incident Response Six Best Practices for Managing Cyber Breaches Nick Pollard, Senior Director Professional Services EMEA / APAC, Guidance Software www.encase.com 2014 Guidance Software Inc., All Rights
Loophole+ with Ethical Hacking and Penetration Testing
Loophole+ with Ethical Hacking and Penetration Testing Duration Lecture and Demonstration: 15 Hours Security Challenge: 01 Hours Introduction Security can't be guaranteed. As Clint Eastwood once said,
The Impact of U3 Devices on Forensic Analysis
The Impact of U3 Devices on Forensic Analysis R. Tank and P.A.H Williams School of Computer and Information Science Edith Cowan University Perth, Western Australia Abstract Flash and USB portable drives
THE CHALLENGES OF DATA SECURITY IN THE MODERN OFFICE
THE CHALLENGES OF DATA SECURITY IN THE MODERN OFFICE February 2008 The Government of the Hong Kong Special Administrative Region The contents of this document remain the property of, and may not be reproduced
Cyber Security Response to Physical Security Breaches
Cyber Security Response to Physical Security Breaches INTRODUCTION Physical break-ins and other unauthorized entries into critical infrastructure locations, such as electrical power substations, have historically
Driving Company Security is Challenging. Centralized Management Makes it Simple.
Driving Company Security is Challenging. Centralized Management Makes it Simple. Overview - P3 Security Threats, Downtime and High Costs - P3 Threats to Company Security and Profitability - P4 A Revolutionary
Hacking Database for Owning your Data
Hacking Database for Owning your Data 1 Introduction By Abdulaziz Alrasheed & Xiuwei Yi Stealing data is becoming a major threat. In 2012 alone, 500 fortune companies were compromised causing lots of money
Cloud Forensics. 175 Lakeside Ave, Room 300A Phone: 802/865-5744 Fax: 802/865-6446 http://www.lcdi.champlin.edu
Cloud Forensics Written & Researched by: Maegan Katz & Ryan Montelbano 175 Lakeside Ave, Room 300A Phone: 802/865-5744 Fax: 802/865-6446 http://www.lcdi.champlin.edu November 4, 2013 Disclaimer: This document
IRC Forensic Basics. by: James Guess. Internet Relay Chat (IRC) first met the world in the late 1980 s. It was the first
IRC Forensic Basics by: James Guess Origins of IRC Internet Relay Chat (IRC) first met the world in the late 1980 s. It was the first globally accessible chat network. The designers originally intended
Where is computer forensics used?
What is computer forensics? The preservation, recovery, analysis and reporting of digital artifacts including information stored on computers, storage media (such as a hard disk or CD-ROM), an electronic
31 Ways To Make Your Computer System More Secure
31 Ways To Make Your Computer System More Secure Copyright 2001 Denver Tax Software, Inc. 1. Move to more secure Microsoft Windows systems. Windows NT, 2000 and XP can be made more secure than Windows
Security Consultant Scenario INFO 517-900 Term Project. Brad S. Brady. Drexel University
Security Consultant Scenario INFO 517-900 Term Project Drexel University Author Note This paper was prepared for INFO-517-900 taught by Dr. Scott White. Table of Contents ABSTRACT.1 THE INTERVIEW...2 THE
Digital Forensics, ediscovery and Electronic Evidence
Digital Forensics, ediscovery and Electronic Evidence By Digital Forensics What Is It? Forensics is the use of science and technology to investigate and establish facts in a court of law. Digital forensics
This guide will go through the common ways that a user can make their computer more secure.
A beginners guide in how to make a Laptop/PC more secure. This guide will go through the common ways that a user can make their computer more secure. Here are the key points covered: 1) Device Password
information security and its Describe what drives the need for information security.
Computer Information Systems (Forensics Classes) Objectives for Course Challenges CIS 200 Intro to Info Security: Includes managerial and Describe information security and its critical role in business.
2014 Entry Form (Complete one for each entry.) Fill out the entry name exactly as you want it listed in the program.
2014 Entry Form (Complete one for each entry.) Fill out the entry name exactly as you want it listed in the program. Entry Name HFA Submission Contact Phone Email Qualified Entries must be received by
ITSC Training Courses Student IT Competence Programme SIIS1 Information Security
ITSC Training Courses Student IT Competence Programme SI1 2012 2013 Prof. Chan Yuen Yan, Rosanna Department of Engineering The Chinese University of Hong Kong SI1-1 Course Outline What you should know
An overview of IT Security Forensics
An overview of IT Security Forensics Manu Malek, Ph.D. Stevens Institute of Technology [email protected] www.cs.stevens.edu/~mmalek April 2008 IEEE Calif. 1 Outline Growing Threats/Attacks Need for Security
McAfee.com Personal Firewall
McAfee.com Personal Firewall 1 Table of Contents Table of Contents...2 Installing Personal Firewall...3 Configuring Personal Firewall and Completing the Installation...3 Configuring Personal Firewall...
Digital Forensic. A newsletter for IT Professionals. I. Background of Digital Forensic. Definition of Digital Forensic
I Digital Forensic A newsletter for IT Professionals Education Sector Updates Issue 10 I. Background of Digital Forensic Definition of Digital Forensic Digital forensic involves the collection and analysis
Best Practices for Building a Security Operations Center
OPERATIONS SECURITY Best Practices for Building a Security Operations Center Diana Kelley and Ron Moritz If one cannot effectively manage the growing volume of security events flooding the enterprise,
Computing forensics: a live analysis
April 18th, 2005 1 2 3 Objectives Evidence acquisition Recovery and examination of suspect digital evidence (think Warrick Brown on CSI) Hardware: servers, workstations, laptops, PDAs, mobiles, cameras
TIME TO LIVE ON THE NETWORK
TIME TO LIVE ON THE NETWORK Executive Summary This experiment tests to see how well commonly used computer platforms withstand Internet attacks in the wild. The experiment quantifies the amount of time
Lifecycle Solutions & Services. Managed Industrial Cyber Security Services
Lifecycle Solutions & Services Managed Industrial Cyber Security Services Around the world, industrial firms and critical infrastructure operators partner with Honeywell to address the unique requirements
The Hidden Dangers of Public WiFi
WHITEPAPER: OCTOBER 2014 The Hidden Dangers of Public WiFi 2 EXECUTIVE SUMMARY 4 MARKET DYNAMICS 4 The Promise of Public WiFi 5 The Problem with Public WiFi 6 MARKET BEHAVIOR 6 Most People Do Not Protect
ASSUMING A STATE OF COMPROMISE: EFFECTIVE DETECTION OF SECURITY BREACHES
ASSUMING A STATE OF COMPROMISE: EFFECTIVE DETECTION OF SECURITY BREACHES Leonard Levy PricewaterhouseCoopers LLP Session ID: SEC-W03 Session Classification: Intermediate Agenda The opportunity Assuming
GFI White Paper PCI-DSS compliance and GFI Software products
White Paper PCI-DSS compliance and Software products The Payment Card Industry Data Standard () compliance is a set of specific security standards developed by the payment brands* to help promote the adoption
Contact details For contacting ENISA or for general enquiries on information security awareness matters, please use the following details:
Malicious software About ENISA The European Network and Information Security Agency (ENISA) is an EU agency created to advance the functioning of the internal market. ENISA is a centre of excellence for
