|
|
Network Intrusions Responder Program (NITRO)
Instructor Guide
NITRO
Product names appearing in this document are for identification purposes only and do not
constitute product approval or endorsement by NCFI or any other entity of the U.S.
Government. Trademark and product names or brand names appearing within these pages
are the property of their respective owners.
The information contained in this document is intended solely for training purposes and
is subject to change without notice. NCFI assumes no liability or responsibility for any
errors that may appear in this document.
NITRO
Table of Contents
Network Intrusions Responder Program (NITRO) ____________________________ 1
Table of Contents _______________________________________________________ 3
Introduction to the NITRO Course _________________________________________ 5
Module 1 - Understanding Computer Hardware __________________________ 8
Lesson 1 - Safety Overview ________________________________________________________ 9
Lesson 2 - Overview to Computers__________________________________________________ 10
Lesson 3 - Motherboards and Components____________________________________________ 11
Lesson 4 - CPU and Memory ______________________________________________________ 13
Module 2 - Data Storage Components _____________________________________ 15
Lesson 1 - Hard Disk Drives_______________________________________________________ 16
Lesson 2 - Floppy Drives and Removable Media _______________________________________ 18
Module 3 - Input/Output Components _____________________________________ 20
Lesson 1 - Input/Output Devices and Ports____________________________________________ 21
Lesson 2 - BIOS and System Initialization ____________________________________________ 23
Module 4 - Operating Systems and Installation ______________________________ 26
Lesson 1 - File System / Operating System Basics ______________________________________ 27
Module 5 - Introduction to Networks ______________________________________ 29
Lesson 1 - Network Basics ________________________________________________________ 30
Lesson 2 - Network Technologies___________________________________________________ 31
Lesson 3 - Network Topologies ____________________________________________________ 32
Lesson 4 - Network Architecture ___________________________________________________ 33
Lesson 5 - The OSI Model ________________________________________________________ 35
Module 6 - Network Connectivity and Protocols _____________________________ 37
Lesson 1 - Network Connectivity ___________________________________________________ 38
Lesson 2 - Network Configuration Models____________________________________________ 40
Lesson 3 - Network Protocols ______________________________________________________ 41
Lesson 4 - Wireless Networks______________________________________________________ 43
Module 7 - IP Addresses and Subnets______________________________________ 46
Lesson 1 - IP Addresses __________________________________________________________ 47
Lesson 2 - Ports _________________________________________________________________ 49
Lesson 3 - Subnets_______________________________________________________________ 50
Lesson 4 - Network Security_______________________________________________________ 52
Module 8 - Common Network Crimes______________________________________ 56
Lesson 1 - E-Mail Scams _________________________________________________________ 57
Lesson 2 - On-line Fraud__________________________________________________________ 59
Lesson 3 - Identity Theft __________________________________________________________ 60
Lesson 4 - Social Threats _________________________________________________________ 62
Lesson 5 - Internal Threats ________________________________________________________ 64
Lesson 6 - Malicious Code ________________________________________________________ 65
Lesson 7 - Denial of Service Attacks ________________________________________________ 66
Lesson 8 - Extortion______________________________________________________________ 68
Lesson 9 - Network Attacks _______________________________________________________ 69
Lesson 10 - Terrorism ____________________________________________________________ 70
Module 9 - Phases of an Intrusion ________________________________________ 71
5-2008
For Official Use Only - Law Enforcement Sensitive
3
NITRO
Lesson
1 - Defining an Intrusion____________________________________________________ 72
Lesson
2 - Reconnaissance ________________________________________________________ 73
Lesson
3 - Network Attacks _______________________________________________________ 76
Lesson
4 - Entrenchment __________________________________________________________ 78
Lesson
5 - Infiltration and Extraction ________________________________________________ 80
Module 10 - Report Writing______________________________________________ 82
Lesson
1 - General Report Writing Techniques ________________________________________ 83
Lesson
2 - Cyber Case Interviewing Techniques _______________________________________ 89
Module 11 - Legal Issues ________________________________________________ 92
Lesson
1 - Search Warrants________________________________________________________ 93
Lesson
2 - Internet Service Providers ________________________________________________ 95
Module 12 - Fundamentals of Log Analysis_________________________________ 98
Lesson
1 - The Scientific Method and Intrusion Analysis ________________________________ 99
Lesson
2 - Observing Intrusion Activity and Forming a Hypothesis _______________________ 100
Lesson
3 - Predicting the Nature & Location of Intrusion Artifacts ________________________ 103
Lesson
4 - Using Log Analysis to Evaluate and Intrusion Hypothesis ______________________ 105
Module 13 - Log Sources _______________________________________________ 109
Lesson
1 - Windows Log Sources__________________________________________________ 110
Lesson
2 - Linux Log Sources _____________________________________________________ 113
Lesson
3 - Solaris Log Sources ____________________________________________________ 115
Lesson
4 - Log Searching ________________________________________________________ 117
Lesson
5 - IDS Logs ____________________________________________________________ 119
Module 14 - Log Analysis ______________________________________________ 121
Lesson
1 - Binary Traffic Analysis _________________________________________________ 122
Lesson
2 - Manual Log Analysis___________________________________________________ 126
Lesson
3 - Automated Log Analysis Tools___________________________________________ 128
Module 15 - Live Data Collection and Analysis _____________________________ 131
Lesson
1 - Data Collection _______________________________________________________ 133
Lesson
2 - Introduction to LiveWire________________________________________________ 135
Lesson
3 - LiveDiscover _________________________________________________________ 137
Lesson
4 - Volatile Data Analysis__________________________________________________ 138
Lesson
5 - Evidence Collection____________________________________________________ 141
Lesson
6 - Malicious Code Analysis________________________________________________ 144
Lesson
7 - Alternate Data Collection Tools __________________________________________ 146
4
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Introduction to the NITRO Course
Instructor Guide
The Instructor Guide is a resource for instructors to use to teach
Overview
the Network Intrusions Responder Program (NITRO) Course in a
consistent manner. This Guide provides:
• Overview of each module in the course
• Outline of topics to be taught in each module
• Timeline for presentation of topics
• List of all Practical Exercises
• List of tests
• Notes section for each topic where you can add your own class
notes for your presentations
How to Use this
Use this Guide as a roadmap to all of the topics covered in
Guide
NITRO. You can personalize this Guide by adding individual
notes to lesson topics to enhance your class presentations.
Introduction to
NITRO is a course designed to train first responders to
NITRO
successfully respond to and process a computer crime scene in a
home or business environment involving either a Windows or
Unix operating system. Instruction is dynamic, flexible, and
focuses on hands-on training.
NITRO training familiarizes students with:
• Legal aspects of incident response procedures
• Techniques for search and seizures
• Methods and tools necessary to successfully gather volatile
information
• Evidence processing and handling
• Media imaging
5-2008
For Official Use Only - Law Enforcement Sensitive
5
NITRO
NITRO Practical All exercises in NITRO are hands-on activities directed by
Exercises
instructors.
In this Guide
The following table shows the contents of this Guide.
Topic
See Page
Module 1 - Understanding Computer Hardware
8
Module 2 - Data Storage Components
15
Module 3 - Input/Output Components
20
Module 4 - Operating Systems and Installation
26
Module 5 - Introduction to Networks
29
Module 6 - Network Connectivity and Protocols
37
Module 7 - IP Addresses and Subnets
46
Module 8 - Common Network Crimes
56
Module 9 - Phases of an Intrusion
71
Module 10 - Report Writing
82
Module 11 - Legal Issues
92
Module 12 - Fundamentals of Log Analysis
98
Module 13 - Log Sources
109
Module 14 - Log Analysis
121
Module 15 - Live Data Collection and Analysis
131
6
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
NITRO testing
Before graduation from courses at NCFI, each student must show
Policy
an acceptable level of achievement on all course objectives as
demonstrated by written and performance-based tests. The
minimum passing score on all comprehensive written tests is
70%. The minimum passing score of 70% is also required on all
performance-based tests.
To measure a student’s progress throughout a course, NCFI uses
several testing methods:
• Practical Exercises (non-graded) - Performance-based
exercise to test the student’s ability to perform required tasks.
During this exercise, students work with peers and are guided
by and can seek assistance from instructors.
• Written Tests - Multiple choice and short answer questions.
Required minimum passing score is 70%.
• Graded Practical Exercise - Performance-based exercise to
test the student’s ability to perform required tasks. During this
exercise, students work with peers and are guided by and can
seek assistance from instructors. This exercise is graded and
reviewed with the students to assist them in measuring their
performance. The grades are not reflected in their overall
course completion.
• Performance-based Test - An exam in which the student must
work independently to perform required tasks. This exam is
graded and a passing grade of 70% is required.
• For the NITRO, the student’s progress will be monitored
through practical exercises, written tests, and graded
performance-based tests. Tests are given at the conclusion of
the course.
Students who fail a written or performance-based test are given
remedial training and tested again. Students will not be given a
retest within eight hours after notification of a test failure.
However, students will be retested no later than 24 academic
hours after notification of a test failure.
5-2008
For Official Use Only - Law Enforcement Sensitive
7
NITRO
Module 1 - Understanding Computer Hardware
Module 1:
This module explains the procedures necessary for safe handling
Overview
of computers. Students will learn the primary hardware
components that power the data processing and storage functions
of every computer. An understanding of MBs, CPUs, memory, and
bus is essential to knowing how a computer system works.
Module 1
Students disassemble and rebuild PCs.
Exercises
Module 1 Testing There is no testing for the content of this module.
Module 1
• Practice safety procedures when handling computer equipment
Objectives
• Identify major computer components
• Identify and explain MB types
• Recognize individual MB components including chipsets,
jumpers and switches, power supply and connections
• Define Basic Input/Output System (BIOS)
• Recall CPU functions and memory
In this Module
Here are the lessons in this module:
Lesson
See Page
Lesson 1 - Safety Briefing
9
Lesson 2 - Overview of Computers
10
Lesson 3 - Motherboards and Components
11
Lesson 4 - CPU and Memory
13
8
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 1 - Safety Overview
Lesson 1: Safety
Explains the procedures necessary for safe handling of computers.
Briefing
Lesson 1 Learning
• Identify the steps to take to protect yourself from injury when
Objectives
using a computer
• Explain how to protect computer components and stored data
Lesson 1 Topics
Here are the topics to present.
Topic
Key Points
Need for Safety
• Mention jewelry, IDs and any other items
Procedures
that may become hooked or tangled in
equipment.
My Notes:
Step-by-Step
• Reinforce wearing the wrist strap.
Safety
• Stress pulling the plug before working on
Procedures
PC.
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
9
NITRO
Lesson 2 - Overview to Computers
Lesson 2:
Presents the key components of the computer, history of
Overview of
computing, and basic terminology. Computer components are
Computers
identified and their roles are reviewed in relation to the computer
system as a whole.
Lesson 2
• Define basic computer terminology
Objectives
• Explain the history of the modern computer
• Identify the basic computer components
Lesson 2 Topics
Here are the topics to present.
Topic
Key Points
Introduction to
• Binary - used in many forms of data transfer:
Computers
Memory, CDs, fiber optic
• Portable computers: PDAs can be used to
transfer movies and pictures without the use
of a typical PC or laptop. There will be no
forensic evidence on a PC if transfers
occurred from PDA to PDA.
My Notes:
History of
• Switches, gears, etc. We are still using the
Computers
binary system today.
• Systems are getting smaller, cooler, and
faster.
My Notes:
Basic System
• Quick introduction, all of these parts will be
Components
covered more in-depth in class later.
My Notes:
10
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 3 - Motherboards and Components
Lesson 3:
This lesson explains the main functions of the motherboard (MB).
Motherboards and
It also introduces the Basic Input/Output System (BIOS) as the
Components
instruction set that controls the main functions of the computer.
Lesson 3
• Define the role of the motherboard
Objectives
• Identify types of motherboards
• Identify main motherboard components
• Explain BIOS and the concept of Plug and Play
• Basic functions of buses
• Identify various bus types
• Recognize various bus connectors
Lesson 3 Topics
Here are the topics to present.
Topic
Key Points
Motherboard
• While talking about the cases, show the mod
Overview
systems (ET, Falcon, toaster). These images
can be found at http://mini-itx.com.
• Slide shows various sections of the MB
• Again, each will be covered more in-depth
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
11
NITRO
Lesson 3 Topics, continued
Topic
Key Points
Motherboard
• Ask how many still use a floppy drive. Point
Components
out that they are becoming less popular and
in many cases have to be ordered as an
optional device. Dell charges $12 for a 3.5
inch floppy drive. Questions that could be
asked:
• Why are floppy drives becoming obsolete?
What types of devices are replacing them?
• Define non-volatile and volatile storage
• Start disassembly before getting to
motherboard and BIOS section
• Stress the differences between BIOS and
CMOS
• Perhaps go to motherboard.org to lookup
some of the new MB information
My Notes:
Bus Overview
• Several types of buses; all used to transfer
information from one stop to another
• May get a few questions about north bridge
and south bridge
• This is a good opportunity to diagram the
buses and their relationship to CPU, RAM,
PCI, etc. on the whiteboard
My Notes:
Bus Types
• This would be a good time to stress the idea
of backward compatibility
My Notes:
12
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 4 - CPU and Memory
Lesson 4:
The computer’s processor, also called the central processing unit
CPU and Memory
(CPU), works in concert with memory to process software and
user commands. This lesson explains the significance and
functions of both CPU and memory.
Lesson 4
• Explain the basic functions of the CPU
Objectives
• Identify the CPU in a computer
• Recognize various types of memory
Lesson 4 Topics
Here are the topics to present.
Topic
Notes
CPU Functions
• Highlight the difference between the slot and
socket chips
• The main brain of the computer
My Notes:
Memory
• Compare and contrast: RAM, ROM and
cache.
• Review the older types of RAM (SIMM, 30-
72 pin)
• Compare the DDR and RAMBUS. Students
(gamers) seem to be interested in the
differences.
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
13
NITRO
This page intentionally left blank.
14
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Module 2 - Data Storage Components
Module 2
Understanding the vast array of data storage components is vital
Overview
knowledge for processing an electronic crime scene investigation.
This module introduces disk drives and various types of removable
storage media.
Module 2
N/A
Exercises
Module 2 Testing Module content will be tested at the end of Module 3.
Module 2
• Explain how data is stored on a hard drive
Objectives
• Identify components of the hard drive
• Understand the workings of a floppy drive
• Recognize various removable media
In this Module
Here are the lessons in this module:
Lesson
See Page
Lesson 1 - Hard Disk Drives
16
Lesson 2 - Floppy Drives and Removable Media
18
NITRO
Lesson 1 - Hard Disk Drives
Lesson 1: Hard
Hard drives are the main storage of the computer. Drives use
Disk Drives
highly sophisticated technology to write data on platters. This
lesson examines the main components of hard drives and their
functions. Understanding how disk drives store information is
important to knowing how to safeguard data during a crime
investigation.
Lesson 1
• Identify the main components of a hard drive
Objectives
• Explain the process by which data is stored on and retrieved
from a hard drive
• Describe the basic formatting procedures for hard drives
• Explain hard drive geometry
Lesson 1 Topics
Here are the topics to present.
Topic
Notes
Hard Drive
• Hard drive diagram slide is useful because it
Components
shows an exploded view. A good time to
pass around various hard drives.
My Notes:
Hard Drive
• IDE and EIDE controllers are a part of the
Controllers/Int
drive. This has not always been the case.
erface
• Stress: ATAPI - CD-ROM drives; ATA5/6 -
(IDE,SATA,
40 pin / 80 wire
SCSI)
My Notes:
Hard Drive
• You may want to toggle between the slide
Geometry
describing the components (track, sector and
cylinder). Define one and then show it on
the diagram.
• Stress the difference between a sector and a
cluster.
My Notes:
16
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 1 Topics, continued
Drive
• Emphasize that low-level formatting is done
Preparation -
at the manufacturing site because it sets up
Wiping
the physical geometry.
• For partitioning, use a real-world example
such as dividing up the room into two groups
by placing a wall down the center row. One
side of the room uses Windows and the other
uses Linux.
• Remind them that the primary partitions take
precedence when assigning drive letters.
• High-level formatting prepares the drive for
the particular file system: (FAT16, FAT32,
NTFS)
My Notes:
RAID
• Try using a “devils advocate” approach to
Configuration
this section. Start with RAID 0 and imaging
Overview
and ask “OK, but what if … happens?” Then,
use this statement to highlight the next
version of RAID, stressing the benefits.
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
17
NITRO
Lesson 2 - Floppy Drives and Removable Media
Lesson 2: Floppy
This lesson examines types of floppy disk drives and a variety of
Drives and
removable media storage components. Understanding data storage
Removable Media
components of a computer system is important to knowing how to
safeguard information that is seized during a crime investigation.
Lesson 2
• Identify the characteristics of floppy disk drive components
Objectives
• Explain the characteristics of a magnetic drive
• Recognize common removable media
• Explain the characteristics of a magneto-optical drive
• Name the differences between magnetic and digital audio tapes
(DAT)
Lesson 2 Topics
Here are the topics to present.
Topic
Notes
Floppy Disk
• Ask students where the floppy drive
Drives
controller is located - Super IO Chip
My Notes:
Removable
• If you are running behind, this is where you
Media
can catch up. Material can be covered briefly,
as most students should be familiar with high
level information.
My Notes:
18
For Official Use Only - Law Enforcement Sensitive
5-2008
This page intentionally left blank.
5-2008
For Official Use Only - Law Enforcement Sensitive
19
NITRO
Module 3 - Input/Output Components
Module 3
This module examines the various components involved in the
Overview
transfer of data into and out of a computer system.
Module 3 Testing
Module 3
• Recognize basic input devices such as the keyboard, mouse,
Objectives
scanner, and modem
• Explain how monitors and video display adapters work
• Identify the various input/output ports found on a PC
• Define interrupts, IRQs, direct memory access, and device
drivers
• Recognize SCSI devices and connectors
In this Module
Here are the lessons in this module:
Lesson
See Page
Lesson 1 - Input/Output Devices and Ports
21
Lesson 2 - BIOS and System Initialization
23
20
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 1 - Input/Output Devices and Ports
Lesson 1:
This lesson introduces the basic input/output devices, including the
Input/Output
keyboard, mouse, scanner, monitor, printer, and modem. Students
Devices and Ports
will gain a broader understanding of common input/output
components and how they work.
Lesson 1
• Recognize input devices such as the keyboard, mouse, scanner,
Objectives
and modem
• Explain how monitors work and be familiar with video display
adapters
• Identify the various input/output ports
Lesson 1 Topics
Here are the topics to present.
Topic
Notes
Overview
• Going over this basic stuff is necessary to
help identify computers.
• If you haven’t shown the images of mod
PCs, show them now. If they have been
shown, refer back to them.
My Notes:
Input Devices
• The PS/2 ports are technically not keyboard
and mouse ports.
• FireWire ports have either 4 or 6 connectors.
Six connectors supply power; four
connectors do not.
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
21
NITRO
Lesson 1 Topics, continued
Topic
Notes
Output
• Review the basics
Devices
My Notes:
Input/Output
• Reiterate specifics:
Ports
• It’s a serial port, not a com port
• It’s a parallel port, not a printer port
• They are PS/2 ports, not keyboard and
mouse ports
My Notes:
Modems
• PC works in digital, phone lines work in
analog
• Cable modem is not a true modem; it’s a
basic type of router.
My Notes:
PC Cards
• Three main categories: Type 1 - memory,
Type 2 - communication, Type 3 - storage
devices
• Finding a PC card means they probably have
a notebook or a laptop
My Notes:
22
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 2 - BIOS and System Initialization
Lesson 2: BIOS
This lesson explains the main functions of the Basic Input/Output
and System
System (BIOS) as the instruction set that controls the main
Initialization
functions of the computer. It will delve into how the BIOS
initializes hardware and starts the operating system.
Lesson 2
• Define the role of the BIOS
Objectives
• Understand what POST codes are
• Explain BIOS and the concept of Plug and Play
• Explain how a system boots
Lesson 2 Topics
Here are the topics to present.
Topic
Notes
Motherboard
• Define non-volatile and volatile storage
Components
• Start disassembly before getting to
motherboard and BIOS section
• Stress the differences between BIOS and
CMOS
• Perhaps go to motherboard.org to lookup
some of the new MB information
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
23
NITRO
Lesson 2 Topics, continued
Topic
Notes
BIOS
• Discuss the basics of the BIOS and how the
Information
function of the setup program
• Make sure you note that each different
motherboard chipset may have a unique
keystroke required to enter the setup, and
many don’t even notify the user what to press
• Note that passwords could be implemented to
block investigators out of the BIOS and the
ways around the password - refer to websites
such as:
labmice.techtarget.com/articles/BIOS_hack.h
tm
• Note what information to gather while in
BIOS
My Notes:
The Boot
• Discuss IO.SYS and MSDOS.SYS
Process
• Stress which of the files are necessary to boot
a system
My Notes:
The Master
• Briefly cover the MBR and how the BIOS
Boot Record
points to this to load the operating system
My Notes:
24
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
This page intentionally left blank.
5-2008
For Official Use Only - Law Enforcement Sensitive
25
NITRO
Module 4 - Operating Systems and Installation
Module 4:
Windows XP Professional is one of the most popular and widely
Overview
used Operating System on the market today. This lesson explains
how to select a file system and install an Operating System
Module 4:
Students will configure their forensic workstations and install
Exercises
additional applications
Module 4 Testing
Module 4
• Installing Windows XP Professional
Objectives
• Compare and Contrast the FAT and NTFS File System
• Install updates on Windows XP
In this Module
Here are the lessons in this module:
Lesson
See Page
Lesson 1 - File System / Operating System Basics
27
26
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 1 - File System / Operating System Basics
Lesson 1: File
This lesson provides an overview of File System / Operating
Systems
System Basics, including selecting a file system.
Lesson 1 Learning
• Give a brief overview of file systems
Objectives
• Explain how to install Windows XP Professional
• Identify how Updates are installed on Windows XP
Lesson 1 Topics
Here are the topics to present.
Topic
Key Points
File Systems
• Show advantages and disadvantages of
NTFS vs. FAT
• Touch on how FAT can be converted to
NTFS through “convert.exe”
• Show in what operating systems each file
system can be found, where will
investigators run across certain ones in the
field
My Notes:
Operating
• Installing Windows may not be required
System
for this course, but showcase the steps in
Installation
case a student needs help on other
computers.
My Notes:
Operating
• Show how to enable or disable automatic
System Updates
patching, and how to use Windows Update
online and application.
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
27
NITRO
This page intentionally left blank.
28
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Module 5 - Introduction to Networks
Module 5
Most computers today are connected in some way to a network. To
Overview
understand network components and functions, students need to
recognize the common network architectures and know various
access methods. This module presents basic networking concepts,
architectures, and common network topologies.
Module 5
Exercises
Module 5 Testing
Objectives
• Explain network technologies
• Identify different network configurations including LAN,
WAN, and the Internet
• Explain the OSI model and how it standardizes network
communications
• Name the differences between TCP/IP and the OSI model
• Explain common ports and their uses
• Identify the six main network models
• Describe different network topologies
In this Module
The following table shows the contents of this module.
Topic
See Page
Lesson 1 - Networks Basics
30
Lesson 2 - Network Technologies
31
Lesson 3 - Network Topologies
32
Lesson 4 - Network Architecture
33
Lesson 5 - The OSI Model
35
5-2008
For Official Use Only - Law Enforcement Sensitive
29
NITRO
Lesson 1 - Network Basics
Lesson 1:
Networks are the pathways of communication that link individual
Networks Basics
computers and network devices. This lesson explores the types of
networks used today and the two primary methods of transmitting
network data.
Lesson 1 Learning
• Define what a network is and the components that comprise
Objectives
one
• Identify the various types of networks
• Explain the difference between circuit-switched and packet-
switched networks
Lesson 1 Topics
Here are the topics to present.
Topic
Key Points
Introduction to
• Purpose of: share resources
Networks
• IEEE 802.X, why have standards?
Interoperability
My Notes:
Network Types
• LAN & WAN = size and equipment
• Internet = interconnected networks
ISP (function)
• Differences and importance of Intranet /
Extranets
My Notes:
Network
• Circuit switched = like a telephone call or
Categories
train
• Packet switched = like the Post Office or
UPS
• Connection vs. Connectionless
My Notes:
30
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 2 - Network Technologies
Lesson 2: Network Networks send data from a sending device through network
Technologies
interfaces, across cables or other transmission media, to a
receiving device. In this lesson, you will describe the two most
common technologies used to facilitate this data transfer. Students
will gain an understanding of the technological framework upon
which networks are built.
Lesson 2 Learning
• Describe the difference between broadcast and point-to-point
Objectives
technologies
Lesson 2 Topics
Here are the topics to present.
Topic
Key Points
Introducing
• Broadcast - CSMA/CD - Collisions -
Network
Multipoint
Technologies
• Sniffing on Broadcast Networks
All systems can see the packets
• Point-to-Point - Token
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
31
NITRO
Lesson 3 - Network Topologies
Lesson 3:
In networking, the term topology refers to the layout identifying
Networks
the location of all network components and the way data flows
Topologies
through the network. This lesson presents the most common
network topologies: bus, ring, star, tree, and mesh.
Lesson 3 Learning
• Identify the main network topologies
Objectives
• Explain the difference between a physical topology and the
logical topology of a network
Lesson 3 Topics
Here are the topics to present.
Topic
Key Points
Topologies
• Physical - how the network is setup
Defined
• Logical - how the data flows around the
network
• Outline on the board for clarity:
Stress Bus, Star, Star-wired Ring, Mesh
• Bus versus Star = amount of cable used
• Review Topology diagrams in Student
Book
My Notes:
32
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 4 - Network Architecture
Lesson 4: Network A network’s architecture refers broadly to the overall
Architecture
configuration of the network and includes the type, topology,
hardware, speed, and specific cabling used in a given
implementation. It is important for students to know the
characteristics of the various network architectures. This
information will be necessary in assessing a crime scene and the
capabilities and properties of the target network.
Lesson 4 Learning
• Identify the most common network architectures
Objectives
Lesson 4 Topics
Here are the topics to present.
Topic
Key Points
Introduction to
• State basic architecture of:
Network
Ethernet - Token Ring
Architecture
FDDI - ATM
My Notes:
Ethernet
• Explain codes: 10baseT - 100baseT, etc.
• Describe cable types: coax and UTP
My Notes:
Token Ring
• Star-wired Ring = MAU
• Must have token to communicate
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
33
NITRO
Lesson 4 Topics, Continued
Topic
Key Points
Fiber Distributed
• Duel rings made of fiber
Data Interface
• Built-in failure recovery
(FDDI)
My Notes:
Asynchronous
• Data, sound, and video
Transfer Mode
• Fixed length cells
My Notes:
Broadband
• Refers to telecommunication methods
where wide ranges of frequencies are
available. Multiple frequencies can be
divided up into multiple channels, which
can be used to send more information
within a given amount of time.
My Notes:
34
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 5 - The OSI Model
Lesson 5: The OSI This lesson describes each step in the process of transmitting
Model
information from one computer to another across the network
through the Open Systems Interconnect (OSI) model. The OSI
model is a conceptual model or framework of how communication
is to take place and promote open networking environments.
Lesson 5 Learning
• Explain the main objectives of the OSI model
Objectives
• Name the seven OSI layers
• Identify the functions of each OSI layer
Lesson 5 Topics
Here are the topics to present.
Topic
Key Points
OSI Model
•
“Conceptual” or software
Overview
•
To-do list for communicating on a network
My Notes:
OSI Model
• Acronyms:
Layers
All People Seem To Need Data Processing
Please Do Not Throw Sausage Pizza Away
• Explain in general what happens at each
layer starting with the Application level
• The more “intelligent” a device is, the
higher it is on the OSI model.
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
35
NITRO
Page Intentionally Left Blank
36
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Module 6 - Network Connectivity and Protocols
Module 6
Networks come in many configurations, or topologies. Students
Overview
need to be able to recognize common network topologies and
understand how they function. This module introduces the various
network topologies and explains how networks interconnect.
Module 6
• Build a Local Area Network
Exercises
• Configure protocol stacks
• Compare/contrast protocols
Module 6 Testing
Objectives
• Identify network connection configurations
• Name network connection devices and their functions
• Recognize connection hardware and describe their
characteristics
• Describe different network topologies
In this Module
The following table shows the contents of this module:
Topic
See Page
Lesson 1 - Network Connectivity
38
Lesson 2 - Network Configuration Models
40
Lesson 3 - Network Protocols
41
Lesson 4 - Wireless Networks
43
5-2008
For Official Use Only - Law Enforcement Sensitive
37
NITRO
Lesson 1 - Network Connectivity
Lesson 1: Network This lesson identifies the various physical components used to
Connectivity
connect computers and devices within a network environment.
Students will learn how computers and stand-alone devices
interconnect to form a network. They will also discover how to
connect clients and servers on a LAN to other networks. An
introduction to wireless networks is also included.
Lesson 1 Learning
• Name the various types of transmission cabling used to wire a
Objectives
network
• Identify network interface cards and adapters
• Explain how modems work to provide remote access
• Identify the various types of wireless media
Lesson 1 Topics
Here are the topics to present.
Topic
Key Points
Network
• Explain what a NIC is
Connectivity
• Card can be ISA/PCI/USB and wireless
My Notes:
Network
• Characteristics - UTP is mostly used today
Transmission
• Categories of UTP
Media
• Types of fiber cables and connectors
My Notes:
38
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 1 Topics, continued
Network Devices
• Explain the NIC to MAC relationship
• Show coffer.com
• Explain where each of the following is
listed on the OSI model and why:
• Hubs, repeaters, bridges, switches, routers,
gateways.
• Explain the difference between active and
passive hubs, digital and analog repeaters.
My Notes:
Wireless Media
• Compare fixed versus mobile technologies
• Range of signals
• New wireless PC card will work in older
laptops
• Types of transmissions (3)
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
39
NITRO
Lesson 2 - Network Configuration Models
Lesson 2: Network
The network configuration models presented in this lesson include
Configuration
client/server network, server/server network, peer-to-peer network,
Models
server-centric network, enterprise network, and remote access
service (RAS) network. Students will learn to recognize common
network configurations. This information will be helpful for
computer crime investigations involving networks.
Lesson 2 Learning
• Identify the six main network configurations
Objectives
• Describe the key characteristics of each network configuration
• Explain how remote access service networks function
Lesson 2 Topics
Here are the topics to present.
Topic
Key Points
Introduction to
• What’s in it for me as an investigator?
Network Models
Knowing the model that a network is
associated with will help determine the
scope of a network. For instance, a server-
centric or enterprise environment will have
more nodes than a peer-to-peer
environment.
My Notes:
40
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 3 - Network Protocols
Lesson 3: Network Network protocols are guidelines that define how computers
Protocols
transmit and receive data. These rules for transmission follow the
guidelines established by the OSI model. Protocols ensure that all
devices attempting to communicate on a network are following the
same rules. In this lesson, students will explore commonly used
protocols.
Lesson 3
• Define network protocol
Objectives
• Describe the characteristics of TCP/IP, IPX/SPX, NetBEUI,
PPP, and PPTP
Lesson 3 Topics
Here are the topics to present.
Topic
Key Points
Protocols
• Explain the definition of the word protocol.
A code or a set of processes used in
accomplishing a task, for example: an SOP.
• Relate this to networking protocols - a set
of standards used to transmit information.
My Notes:
TCP/IP
• The protocol of the Internet
• Not associated with any company -
considered an open source protocol
• Is routable
• Is associated with: IP addresses, subnets,
gateways, DNS, etc.
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
41
NITRO
Lesson 3 Topics, continued
Topic
Key Points
Other Protocols
• NetBEUI/NetBIOS - Created by Microsoft
• IPX/SPX - Created by Novell
• PPP - Creates a connection between an
analog modem and an ISP. Once
connected, TCP/IP packets can travel to
and from a modem.
• PPTP - Non-routable packets are
encapsulated into routable packets. This
allows protocols like IPX/SPX to be sent
over the Internet.
My Notes:
42
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 4 - Wireless Networks
Lesson 4: Wireless
This lesson presents basic information about wireless networks,
Networks
including how they work, the different types of wireless networks,
the components that makeup a wireless network, and security
concerns. Students will gain insight on wireless networks and how
these networks can be used with good and bad intentions.
Lesson 4
• Explain what a wireless network is and how it works
Objectives
• Explain the 802.11 standard
• Explain the difference between infrastructure and ad-hoc
modes
• Discuss security concerns of implementing wireless networks
Lesson 4 Topics
Here are the topics to present.
Topic
Key Points
What is a
• Explain that 802.11b and g are compatible,
Wireless
but “a” devices will not communicate with
Network?
either of the other classifications. Explain
why (frequency).
• Address the security risks related to
Hotspots
• Explain the significance of the WiFi and
Centrino symbols
My Notes:
Types of
• Adhoc - used for temporarily swapping
Wireless
files
Networks
• Infrastructure - typical wireless
environment where a WAP is used to
connect wireless devices to a wired
network
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
43
NITRO
Lesson 4 Topics, continued
Topic
Key Points
Hardware
• Stress that the wireless-NIC could be
Components
integrated into the motherboard
My Notes:
Security
• Compare WEP and WPA
Concerns
• SSID and MAC filtering - easy to
implement, but rarely turned on. Routers
are “wide open” when they are initially
turned on. This is by design (IEEE specs).
My Notes:
Vulnerabilities
• Overlapping signals and Accidental
Association are related - one can cause the
other.
• Bluejacking - from a social aspect
• Man-in-the-Middle - Starbucks example
• War driving video is about 20 minutes long
My Notes:
44
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
This page intentionally left blank.
5-2008
For Official Use Only - Law Enforcement Sensitive
45
NITRO
Module 7 - IP Addresses and Subnets
Module 7:
This module explains Internet Protocol (IP) addresses and how
Overview
they are constructed. Students will learn about IP addressing and
the classes of networks in IP addressing schemes. They will also
learn about subnets and the IP addressing schemes for subnet
masks.
Module 7
Subnetting exercise in Lesson 3
Exercises
Module 7 Testing
Module 7
• Explain IP addresses and how they are constructed
Objectives
• Name the classes of IP addresses and their characteristics
• Describe Domain Name Service functions
• Define subnetting
• Explain how subnet masking is used
• Name the types of firewalls used today and their characteristics
In this Module
The following table shows the contents of this module:
Topic
See Page
Lesson 1 - IP Addresses
47
Lesson 2 - Ports
49
Lesson 3 - Subnets
50
Lesson 4 - Network Security
52
46
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 1 - IP Addresses
Lesson 1: IP
In a TCP/IP network, IP addressing is essential to the physical
Addresses
routing of network communications. Every device on a LAN must
have a unique IP address. Each address is essential for
internetworking over WANs. Students will learn the importance of
IP addressing and know the three classes of IP addresses. They
will also explore the concepts of domain name service (DNS).
Lesson 1 Learning
• Define IP addresses
Objectives
• Identify the various classes of IP addresses
• Explain the functions of DNS and Classless Inter-Domain
Routing (CIDR)
Lesson 1 Topics
Here are the topics to present.
Topic
Key Points
IP Address Basics
• Show them their IP, subnets, and MAC
addresses with ipconfig /all
• Demonstrate converting from binary to
decimal on the board. Stress that they
will not have to perform this on the test.
My Notes:
IP Address Classes
• Another way to identify the class - the
first two bits:
Class A - the 1st 2 bits - 00
Class B - the 1st 2 bits - 10
Class C - the 1st 2 bits - 11
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
47
NITRO
Lesson 1 Topics, continued
Topic
Key Points
More about IP
• Stress the benefits of:
Addresses
CIDR - better use of IP addresses
DNS - web versus IP address
DHCP - easier to manage IP addresses,
better use of IP addresses
My Notes:
48
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 2 - Ports
Lesson 2: Ports
This lesson presents information about network ports, what they
are, and how they are used, misused, and managed.
Lesson 2
• Discuss the definition of a port
Objectives
• Discuss how ports are used in network administration
• Discuss how hackers can identify open ports and what this
means to network security
Lesson 2 Topics
Here are the topics to present.
Topic
Key Points
Overview of
• Use an analogy to describe ports as a
Ports
tunnel or a private phone line. If it’s closed,
the packet cannot get through.
My Notes:
How Ports are
• Used for communication, monitoring
Used
traffic flow and security/control.
My Notes:
Configuring
• Use steps in book to manually break up
TCP/IP
class into different IP address segments.
• Based on class structure and setup, IP
addresses may be changed for the course.
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
49
NITRO
Lesson 3 - Subnets
Lesson 3: Subnets Networks can be logically divided into sub-networks (subnets) to
enhance efficiency and security. This lesson introduces subnetting
and the use of subnet masks.
Lesson 3
• Define subnetting and explain its benefits
Objectives
• Explain the value of subnet masks
• Identify the components of a subnet mask
Lesson 3 Topics
Here are the topics to present.
Topic
Key Points
Subnet Overview
• Stress that this is not on the test
• Identify the benefits
My Notes:
Subnet Masks
• Demonstrate with a ipconfig command
• Walk through the process, but going too
deep could cause confusion
• Exercise: Practice Subnetting
• Have each student ensure they can see
everyone else in their Network
Neighborhood
• Logically assign each team into a
different subnet - reboot if necessary
• Have students check again to see which
computers they can see in Network
Neighborhood
• To mix things up, try pinging
before/after subnetting.
My Notes:
50
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 3 Topics, continued
Topic
Key Points
Virtual LAN
• Another way of subnetting a network
• Based on the port on the switch
• Easy to look at the GUI setup and make
changes
• Can be done via MAC address and via
switch software - needs to be updated if
the NIC changes. Easy to move one
computer from one office to another.
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
51
NITRO
Lesson 4 - Network Security
Lesson 4: Network Network security, an essential component for network
Security
management, strives to protect network resources through layered
defenses. These defenses generally contain encryption, anti-virus
software, firewalls, and Intrusion Detection System (IDS) devices.
This lesson focuses on the network security methods available
today.
Lesson 4
• Explain the various firewall architectures
Objectives
• Name the types of firewalls used today and their characteristics
• Explain data encryption
• Define the security methods of IDS
• Identify various types of network logs
Lesson 4 Topics
Here are the topics to present.
Topic
Key Points
Data Encryption
• Use whiteboard to demonstrate that
Asymmetric and Symmetric Public key is
given out to anyone, Private key is not
My Notes:
Anti-virus
• Signatures have to be updated
Software
My Notes:
52
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 4 Topics, continued
Firewalls
• Compare to firewall in car
• Can be hardware and software
• Stress that they typically log only failed
attempts
• Stateful Inspection: looks into the packet
• Packet-Filtering: Is it incoming and is it
part of a requested traffic flow?
• Block command
• Circuit-Level: much more complex
• Three node connection:
You ----- Firewall ----- Website
• Attackers connect to firewall versus you
• Client Software needs to be reprogrammed:
Proprietary software may need to be
changed to work with this type of firewall.
Could be very expensive.
• Application Gateway - usually run as
software on client:
Slower than others, vulnerable to OS bugs
Hole in XP = hole in firewall
My Notes:
IDS
• SNORT - open source - downloadable
• Host-based vs. Network-based.
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
53
NITRO
Lesson 4 Topics, Continued
Topic
Key Points
Logs
• Always a potential source of evidence
My Notes:
Network
• Explain how IDS, firewalls, etc., can work
Security
in partnership
Summary
•
My Notes:
54
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
This page intentionally left blank.
5-2008
For Official Use Only - Law Enforcement Sensitive
55
NITRO
Module 8 - Common Network Crimes
Overview
Like physical crimes, network based crimes can be placed into
categories. In this module we will look at some of the most
commonly perpetrated crimes involving use of network
communications and discuss characteristics of each.
Objectives
• Describe each of the crimes
• Be able to discuss the methodologies of each crime
• Describe the traditional responses to these crimes.
In this Module
Here are the lessons in this module:
Lesson
See Page
Lesson 1 - E-Mail Scams
57
Lesson 2 - On-line Fraud
59
Lesson 3 - Identity Theft
60
Lesson 4 - Social Threats
62
Lesson 5 - Internal Threats
64
Lesson 6 - Malicious Code
65
Lesson 7 - Denial of Service Attacks
66
Lesson 8 - Extortion
68
Lesson 9 - Network Attacks
69
Lesson 10 - Terrorism
70
56
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 1 - E-Mail Scams
Lesson 1: E-Mail
Today’s criminals use the Internet and know a majority of victims
Scams
do not look closely at E-mail. As a result E-mail scams are quite
prevalent.
Lesson 1 Learning
• Describe E-mail Scams
Objectives
• Explain how E-Mail Scams are perpetrated
• Describe how investigators typically respond to these attacks
Lesson 1 Topics
Here are the topics to present.
Topic
Key Points
Overview
• Define Scam - a dishonest act or fraud
• Simple leap for scammers from surface-
•
mail to e-mail
• Works because people do not closely
•
inspect mail
• Logos and other items to give impression
•
of respectability
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
57
NITRO
Lesson 1 Topics, continued
Topic
Key Points
Attack
•
The Nigerian, or 419 Scam
Methodologies
•
Foreign Nation
•
Government connected source
•
Large sums of money
•
Money Access
•
Advance Fee
•
Where 419 comes from
•
Phishing
•
Legitimate looking E-mail in an attempt to
•
gain financial or personal information
•
E-Bay/PayPal
•
Banks
•
Cross Site Scripting
•
Spam
•
Unsolicited advertisement or bulk E-mail
•
My Notes:
Investigative
• Capture
Response
• Preservation
• Warrants
• Reporting
• Education
My Notes:
58
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 2 - On-line Fraud
Lesson 2: On-line The Internet is a busy place for business. Because of this there are
Fraud
numerous ways in which a victim can be defrauded in the world of
E-Commerce
Lesson 2 Learning
• Describe some of the common online fraud techniques
Objectives
• Discuss the methodologies used in these cases
• Describe some of the responses to these attacks
Lesson 2 Topics
Here are the topics to present.
Topic
Key Points
Overview
• Online Fraud is any form of trickery or
deceptive gain that is practiced on the
Internet
• Common attack vectors include:
• Price to good to be true
• Short time to decide
• Fine print
• Hijacked sites
• Box-of-rocks
• Stall tactics
My Notes:
Attack
• Bogus web sites
Methodologies
• Auctions
• Bogus Charities
My Notes:
Investigative
• Capture
Response
• Preservation
• Warrants
• Reporting
• Education
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
59
NITRO
Lesson 3 - Identity Theft
Lesson 3: Identity In 2007 there were an estimated 8.4 million reported cases of
Theft
identity theft in the U.S. That number is down from the reported
10.1 million in 2003. Even with the decline the identity theft
problem is ever present in society today
Lesson 3 Learning
• Describe some of the common online identity theft techniques
Objectives
• Discuss the methodologies used in these cases
• Describe some of the responses to these attacks
Lesson 3 Topics
Here are the topics to present.
Topic
Key Points
Overview
• Numerous ways in which a criminal or
• attacker can gain enough information to
assume some else’s identity
• Search Engines
• Public information sites
• Group sites
• Commercial sites
• Membership sites
My Notes:
Attack
• Name
Methodologies
• Phone
• Social Security Number
• Address
• License Plate
My Notes:
60
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 3 Topics, continued
Topic
Key Points
Investigative
• Capture
Response
• Preservation
• Warrants
• Reporting
• Education
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
61
NITRO
Lesson 4 - Social Threats
Lesson 4: Social
The Internet has created a layer of perceived anonymity for
Threats
criminals. This has led to an increase in social threats perpetrated
on the Internet.
Lesson 4 Learning
• Describe some of the common online social threats
Objectives
• Discuss the methodologies used in these cases
• Describe some of the responses to these attacks
Lesson 4 Topics
Here are the topics to present.
Topic
Key Points
Predators
• Communicate with other people on the
Internet without them being able to know
the “real person”
• Ability to lead victims to thinking predator
is different than what victim thinks
My Notes:
Stalkers
• Will look for those who meet their victim
criteria online and then begin the stalking
process
• Use available information to choose
victims
• May not be known to victim
My Notes:
Cyberbullying
• Usually always in reference to children
• When children use the Internet to bully,
harass, embarrass, or demean another child
it is considered cyberbullying
• Cyberbullying has led to murder and
suicide.
My Notes:
62
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 4 Topics, Continued
Topic
Key Points
Attack
• E-mail
Methodologies
• Chat
• Texting
• Impersonation
My Notes:
Investigative
• Capture
Response
• Preservation
• Warrants
• Reporting
• Education
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
63
NITRO
Lesson 5 - Internal Threats
Lesson 5: Internal Without a doubt, the greatest network threat is the internal threat.
Threats
Persons with knowledge of the internal workings of a system or
company have the greatest capability for potential damage.
Lesson 5 Learning
• Describe some of the common internal threats
Objectives
• Discuss the methodologies used in these cases
• Describe some of the responses to these attacks
Lesson 5 Topics
Here are the topics to present.
Topic
Key Points
Overview
• Greatest threat to network
• Insider has working knowledge of network
• Has access
• Greatest ability for potential damage
My Notes:
Attack
• Inappropriate Usage
Methodologies
• Embezzlement
• Extortion
• Espionage
• Sabotage
My Notes:
Investigative
• Capture
Response
• Preservation
• Warrants
• Reporting
• Education
My Notes:
64
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 6 - Malicious Code
Lesson 6:
Malicious Code is the generic term for a collection of attacks that
Malicious Code
use any type of script or program designed to exploit security
vulnerabilities. Worms, Trojans, Viruses, Backdoors are all
examples of malicious code.
Lesson 6 Learning
• Describe some of the common malicious code threats
Objectives
• Discuss the methodologies used in these cases
• Describe some of the responses to these attacks
Lesson 6 Topics
Here are the topics to present.
Topic
Key Points
Malicious Code
• Viruses
Attacks
• Trojans
• Worms
• Spyware
• Adware
• Rootkits
My Notes:
Investigative
• Capture
Responses
• Preservation
• Warrants
• Reporting
• Education
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
65
NITRO
Lesson 7 - Denial of Service Attacks
Lesson 7: Denial of For some attackers, simply making a resource un-available is the
Service Attacks
satisfaction of the attack. The Denial of Service attack is the goal
of these criminals.
Lesson 7 Learning
• Describe some of the common Denial of Service threats
Objectives
• Discuss the methodologies used in these cases
• Describe some of the responses to these attacks
Lesson 7 Topics
Here are the topics to present.
Topic
Key Points
DOS Attack
• Flooding target computer with more
information than it can handle, causing a
system crash or reset.
• Interfering with communications channel
in a way that others can’t access system.
• Starting a number of processes on target
system in a way that all available resources
are used and system can no longer respond
to requests.
• Changing access codes so that normal users
of the system can no longer access the
system.
My Notes:
DDOS Attack
• When multiple systems attack a target
system.
• Multiple systems are usually other
compromised systems over which attacker
has control.
My Notes:
66
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 7 Topics, Continued
Topic
Key Points
Investigative
• Capture
Response
• Preservation
• Warrants
• Reporting
• Education
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
67
NITRO
Lesson 8 - Extortion
Lesson 8:
Creating a sense of fear in a victim and then asking for money to
Extortion
make the fear stop is the goal of an extortionist. The Internet has
allowed this old-school criminal activity to continue in a modern
mode.
Lesson 8 Learning
• Describe some of the common extortion threats
Objectives
• Discuss the methodologies used in these cases
• Describe some of the responses to these attacks
Lesson 8 Topics
Here are the topics to present.
Topic
Key Points
Extortion on the
• Usually e-mail threat against person,
Internet
relative or property
• Direct threats
• Threats against tangible or non-tangible
data
• Threats against a web entity
• Protection
My Notes:
Investigative
• Capture
Response
• Preservation
• Warrants
• Reporting
• Education
My Notes:
68
For Official Use Only - Law Enforcement Sensitive
5-2008
NITRO
Lesson 9 - Network Attacks
Lesson 9: Network These types of attacks involve targeting the equipment and
Attacks
systems that comprise an entire network.
Lesson 9 Learning
• Describe some of the common Network Attacks
Objectives
• Discuss the methodologies used in these cases
• Describe some of the responses to these attacks
Lesson 9 Topics
Here are the topics to present.
Topic
Key Points
Network vs.
• Routers.
System Level
• Domain Name Servers
Attacks
• Firewalls
• Intrusion Detection Systems.
• Wireless networking equipment
• Access control systems
My Notes:
Investigative
• Capture
Responses
• Preservation
• Warrants
• Reporting
• Education
My Notes:
5-2008
For Official Use Only - Law Enforcement Sensitive
69
////////////////////////// |
||
|
|
|