|
|
Lesson 8 - Extortion
Overview
Attack Methodologies
Investigative Responses
U.S. Department of
Homeland Security
United States
Secret Service
Extortion on the Internet
Direct threats
Threats against tangible or non-tangible data
Threats against a web entity
Protection
U.S. Department of
Homeland Security
United States
Secret Service
Investigative Responses
Capture
Preservation
Warrants
Reporting
Education
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 9 - Network Attacks
Overview
Attack Methodologies
Investigative Responses
U.S. Department of
Homeland Security
United States
Secret Service
Attacking a Network
Network routers
Domain Name Servers
Firewalls
Intrusion Detection Systems
Wireless networking equipment
Access control systems
U.S. Department of
Homeland Security
United States
Secret Service
Investigative Responses
Capture
Preservation
Warrants
Reporting
Education
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 10 - Terrorism
Overview
Attack Methodologies
Investigative Responses
U.S. Department of
Homeland Security
United States
Secret Service
Terrorism
Systematic creation of fear in group of people rather than
individual
Intimidation
U.S. Department of
Homeland Security
United States
Secret Service
Internet Use
Psychological warfare
Propaganda
Fund-raising
Message center for coordinating activities
Launch network attacks
Data mining
U.S. Department of
Homeland Security
United States
Secret Service
Internet Use
Denial of Service attacks against enemies
Site defacements of web sites counter to their cause
Spam e-mail attacks against enemies
Phishing attacks for banking information to help fund activities
U.S. Department of
Homeland Security
United States
Secret Service
Investigative Responses
Capture
Preservation
Warrants
Reporting
Education
U.S. Department of
Homeland Security
United States
Secret Service
Module 9 - Phases of an Intrusion
U.S. Department of
Homeland Security
United States
Secret Service
You Will Learn . . .
Defining and Intrusion
Reconnaissance
Network Attacks
Entrenchment
Infiltration and Extraction
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 1 - Defining and Intrusion
Definition of an Intrusion
Goals of an Intrusion
Attacker Profiles
Phases of an Intrusion
U.S. Department of
Homeland Security
United States
Secret Service
Intrusion
Act of executing unauthorized actions against an information
system and/or its resources
Generally, considered to have taken place when someone
gains unauthorized access to a computer
When successful intrusion of single device occurs device is
considered compromised
Network intrusion is broader and includes compromise of
multiple devices on single or multiple networks
U.S. Department of
Homeland Security
United States
Secret Service
Vulnerability
A weakness in information system that could allow
unauthorized actions to be taken against system
U.S. Department of
Homeland Security
United States
Secret Service
Exploit
Tool used by an attacker to perform malicious attacks through
vulnerabilities in system
For example, error in an operating system that allows arbitrary
code execution
Program that attacker writes to perform attack against
operating system error is exploit
U.S. Department of
Homeland Security
United States
Secret Service
Threats and Threat Agents
Threats - Insider
Disgruntled employee
Uninformed employee
Threat Agents
Contractors
Recruited or placed agent
U.S. Department of
Homeland Security
United States
Secret Service
Threats and Threat Agents
Outsider
Hackers
Political activist “Hacktivist”
Information “brokers”
Foreign Governments or Corporations
Natural disasters
U.S. Department of
Homeland Security
United States
Secret Service
Goals of an Intrusion
Denial-of-Server (DoS) - Attack that makes computer resource
unavailable
Unauthorized Access - Act of gaining access to any computer
resource without express permission of owner of resource
Inappropriate Usage - Act of using computer resource in
manner deemed inappropriate for resource
U.S. Department of
Homeland Security
United States
Secret Service
Goals of an Intrusion
Other - Broad goals that may be difficult to categorize
Suspicious Activity - Any activity that does not conform to
the normal prescribed activity
Malware - Software designed to infiltrate, monitor, or
possibly damage a computer without the owner’s consent
U.S. Department of
Homeland Security
United States
Secret Service
Intruder Types
Many types of attackers and many reasons why networks and
systems attacked
Most intruders fit loosely into one of a few categories
differentiated by skill, resources, and motivation
Understanding basic intruder profiles and motivations may help
identify other compromised systems
U.S. Department of
Homeland Security
United States
Secret Service
Intruder Types
Advanced
Intermediate
Beginner
U.S. Department of
Homeland Security
United States
Secret Service
Advanced Attackers
Skilled and motivated
Generally exercise highest levels of caution and care
Slow and precise
Attempt to evade intrusion detection
Attempt to hide signs of presence
Attempt to mask source of attack
U.S. Department of
Homeland Security
United States
Secret Service
Advanced Attackers
Piggy back on another attackers data stream
Attempt to misdirect investigators by pointing to another source
Program in one or more languages and will modify or create
new exploit code/methods to support objective
Working knowledge of common system network architectures
Greatest ability to cause damage throughout network
U.S. Department of
Homeland Security
United States
Secret Service
Advanced Attackers
Can be found in organized crime, terrorist organizations,
foreign governments or next door
Motivation varies, tends to match motivations of organization if
associated
Intellectual challenge is common motivation
Sometimes categorized as Professional, State Sponsored, or
Elite
U.S. Department of
Homeland Security
United States
Secret Service
Intermediate Attacker
Attempt to follow same methodology as advanced group but
do not possess necessary skills, knowledge or experience
Moderate speed and precision
May attempt to evade intrusion detection
Attempt to remove signs of presence, but likely to miss
something
Attempt to mask source of attack
U.S. Department of
Homeland Security
United States
Secret Service
Intermediate Attacker
May have programming skills and ability to perform minor
modifications of exploit code to suit objectives
Working knowledge of common system and network
architectures
Example, could be system administrator attempting to further
his or her knowledge and abilities
Other terms for intermediate attacker, Amateur and Enthusiast
U.S. Department of
Homeland Security
United States
Secret Service
Beginner Attacker
User just getting into arena
Learning, relies on success and failures of others to teach
them basics
Tendency to rely on other’s code and scripts to do their work
Do not have basic understanding of intrusion phases
Usually fast and imprecise
Does not usually attempt to evade intrusion detection, unless a
function of tool they are using
U.S. Department of
Homeland Security
United States
Secret Service
Beginner Attacker
No attempt to hide signs of presence, unless a function of tool
May attempt to mask source of attack
Normally cannot program well, if at all, no ability to modify
exploit code to support objectives
Motivations tend to be game-oriented, attacks for as little as
bragging rights
Other terms for beginner attacker are script kiddy, kiddiot, and
packet monkey
U.S. Department of
Homeland Security
United States
Secret Service
Insiders
Person authorized to use network or system due to
membership in organization
Often underestimated or overlooked as source because
security focuses on protecting network perimeter from outside
Virtually any disgruntled employee using valid account could
take unauthorized actions against network
Level of skill is highly varied, employee’s motivations often
include some form of sabotage or retribution
U.S. Department of
Homeland Security
United States
Secret Service
Phases of an Intrusion
Not every intrusion will include all phases, specific actions will
depend on objectives and abilities
Reconnaissance - Gathering information about target
Attack - Gathering, compiling, and launching exploits
Entrenchment - Ensuring continued access to target system
and hiding traces of access
Extraction - Data theft or enabling channels for outbound
attackers to new targets
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 2 - Reconnaissance
Goals
Strategies
Techniques - General Web Browsing and Search
Techniques - Public Records and Archives Search
Techniques - Target Web Site Examination
Techniques - Identifying Physical Attack Vectors
Techniques - Live Host Identification
Techniques - Identifying Available Ports/Protocols
Techniques - Type and Version Identification
Techniques - Vulnerability Scans
U.S. Department of
Homeland Security
United States
Secret Service
Reconnaissance Goals
Target organization, including its main functions, staff
members, assets, partner organizations, etc
Target individuals, including names, functions, contact
information, credentials, etc
Target computers and networks, including addresses,
functions, installed applications, operating systems, etc
Any other information that may be beneficial
U.S. Department of
Homeland Security
United States
Secret Service
Direct versus Indirect
Reconnaissance strategies can be defined as “direct” or
“indirect”
Direct techniques involve taking actions on or against
information systems owned and/or operated by targeted
individual or organization
Actions may be observed and logged by target
Indirect strategies do not involve actions on or against target
information systems, will not be observed and logged by target
U.S. Department of
Homeland Security
United States
Secret Service
Reconnaissance Strategies
General Web browsing and searching
Public records searches
Target Web site examination
Identify physical attack vectors
Live host identification
Identification of open communication channels
Operating system and application identification
Operating system and application vulnerability scans
U.S. Department of
Homeland Security
United States
Secret Service
General Web Browsing and Search
Valuable tool during information gathering phase, especially if
used with information obtained by other means
For example, Googling an employee’s name produces home
page with personal data or postings on newsgroups and
discussion forums that yield sensitive company data
Searches of online discussion forums, such as Usenet, may
also reveal information about an organization’s security
weaknesses
U.S. Department of
Homeland Security
United States
Secret Service
Possible Artifacts
Searching and browsing 3rd party Web sites typically do not
generate any artifacts on information systems belonging to
target organization or individual
Will leave artifacts on network that hosts sites being browsed,
most notably a record of URLs accessed during attacker’s
research
U.S. Department of
Homeland Security
United States
Secret Service
Public Records
Domain Name Service (DNS)
Whois
Web site content archives
Web site defacement archives
Web server OS and Uptime
Government business registration sites
U.S. Department of
Homeland Security
United States
Secret Service
DNS
Used to maintain public record of domain names and
corresponding IP addresses
If you browse Microsoft.com, computer first asks DNS server
how to find that domain name
DNS will respond with IP addresses linked to Microsoft.com
U.S. Department of
Homeland Security
United States
Secret Service
DNS Records
IP address of the Web server(s) that hosts the Web site for a
particular domain name
IP address of the e-mail server(s) that hosts e-mail for a
particular domain name
IP addresses of the DNS servers that are authoritative for a
domain name
Host/domain names associated with an IP address
U.S. Department of
Homeland Security
United States
Secret Service
Whois Records
Several Regional Internet Registries (RIRs) responsible for
leasing IP addresses to ISPs and other large organizations
“Whois” is Internet utility that queries RIR database for public
information
Range of IP addresses assigned to an organization
Geographical address used when organization registered
domain
Names or handles, phone numbers, and e-mail addresses of
points of contact (POCs) for an organization
U.S. Department of
Homeland Security
United States
Secret Service
Web site Content Archives
Wayback Machine (http://www.archive.org) provides archival
storage for Web pages no longer available through original
provider
Wayback Machine offers ability to check for previous, less
security-conscious versions of organization’s site
U.S. Department of
Homeland Security
United States
Secret Service
Defacement Archives
Defacement archival sites provide information, archives, and
statistics regarding Web defacements
Example is Zone-H (http://www.zone-h.com)
Attackers can use Zone-h to learn if target has been defaced
previously
Record of defacement and listing of operating system and Web
server in use at time of compromise may be available
U.S. Department of
Homeland Security
United States
Secret Service
Web Server OS and Uptime Archives
Netcraft (http://news.netcraft.com) site provides network and
server-specific search functionality
Enter domain name, Netcraft will determine operating system
and uptime of server to which domain name points
Netcraft attempts to discover type of Web server application
running and will provide record of results for previous attempts
to gather information
U.S. Department of
Homeland Security
United States
Secret Service
Government Business Registration
Sites
For tax and liability purposes, federal and most state
governments require businesses submit several forms
Forms often public record and searchable on Internet for
information about potential targets
For example, the U.S. Securities and Exchange Commission’s
EDGAR (Electronic Data Gathering, Analysis, and Retrieval)
system
U.S. Department of
Homeland Security
United States
Secret Service
Possible Artifacts
Searching third-party archive and public record sites typically
will not generate artifacts on systems belonging to target
organization or individual
Will leave artifacts on network that hosts sites being browsed,
most notably record of URLs accessed during attacker’s
research
Possible that queries made against third-party DNS server will
be forwarded to DNS server owned or operated by target
organization
U.S. Department of
Homeland Security
United States
Secret Service
Target Web Site Examination
Target organization Web sites can serve an attacker as either
source of general information or as point of entry into network
During recon, the following tactics may be used when
reviewing a site:
Manual browsing
Automated crawling
URI prediction/guessing
Source code review
U.S. Department of
Homeland Security
United States
Secret Service
Manual Browsing
Manually browsing target Web site is legitimate method for
gathering intelligence about site and organization running site
Disadvantage, it is a direct technique, will leave traces on
target system and network
Can pattern can mimic legitimate user or be obfuscated by use
of various proxies or routing techniques
Browsing could also be routed through another previously
compromised box
U.S. Department of
Homeland Security
United States
Secret Service
Automated Crawling
Web crawlers (AKA Robots or Spiders) can be used to
automatically browse site and follow all available links
Results of Web page download from each link, saved for later
review.
Technique very obvious to anyone that reads logs of target
Web server or any associated reverse proxies
U.S. Department of
Homeland Security
United States
Secret Service
URI Prediction
Not all pages at Web site accessible via link
Pages not directly advertised on site or linked sometimes
found by guessing at naming convention used by site designer
Guessing naming conventions can lead to discovery of
additional pages containing valuable data
Guessing resources can lead to error logs on server
Can be generic errors or in the case of a restricted folder,
security-related errors
U.S. Department of
Homeland Security
United States
Secret Service
Source Code Review
Other than server side scripts, all HTML/XML markup
language and client-side scripts, sent to Web browser that
requests associated page
Code can be reviewed for information disclosure (in
programmer comments for example), as well as for
weaknesses in code itself
U.S. Department of
Homeland Security
United States
Secret Service
Possible Artifacts
Any record of URL requests from suspicious IP addresses or
IP ranges in logs of Web server or associated Web proxies
Logs that show broad, systematic pattern of URL requests,
characteristic of site being crawled
Logs that show failed URL access attempts that list non-
existent files close in name to actual existing files
IDS alerts referencing Web crawling or other abnormal URL
access patterns
U.S. Department of
Homeland Security
United States
Secret Service
Attack Vectors
A pathway through which an attack may be launched
Most common attack vector is via Internet, a mixture of
physical mediums
There are times when specific vectors will be useful or even
required, such as when target cannot be reached via Internet
U.S. Department of
Homeland Security
United States
Secret Service
Attack Vectors
POTS (Plain Old Telephone System)
Wireless
Direct physical access to the device
Mixed (any route across the Internet)
U.S. Department of
Homeland Security
United States
Secret Service
Identifying POTS Vectors
War-dialing is identifying computers listening for remote
connections on a POTS line, if response received, computer is
listening, further attack actions may be taken
Growing less viable as more systems use dedicated Internet
connections rather than dial-up modems
U.S. Department of
Homeland Security
United States
Secret Service
Identifying Wireless Vectors
Attackers can use computer with 802.11 network interface to
listen for frames transmitted from 802.11 compliant wireless
networks
Different 802.11 specifications, attacker would have to ensure
that attack wireless NIC(s) supported all necessary versions
Other wireless specifications not typically viable vector, but
cellular access to information systems becoming more
prevalent and Bluetooth can be used in close range situations
U.S. Department of
Homeland Security
United States
Secret Service
Identifying Physical Vectors
An attacker could obtain direct physical access to a target
device through unauthorized access to building/room
If target device is owned by organization to which attacker is
employed, physical access may already be available
U.S. Department of
Homeland Security
United States
Secret Service
Possible Artifacts
Call records that show incoming calls to phone number with
modem attached
Standard physical security violations or suspicious activity (e.g.
unknown persons in building, tripped alarms, broken locks,
etc.)
Console logins recorded in system logs during times when
building empty, or when owner of user account not present
802.11 frames from an unknown source
Presence of physical wiretap devices on a cable or device
U.S. Department of
Homeland Security
United States
Secret Service
Live Host Identification
The process of finding target hosts and verifying they are
online responding to communication requests
Can be done through several methods:
ICMP probes/sweeps
TCP/UDP probes/sweeps
Network monitoring
U.S. Department of
Homeland Security
United States
Secret Service
ICMP Probes/Sweeps
ICMP protocol used primarily for network troubleshooting, and
commonly to test hosts to see if they are online
ICMP “Echo Request” packet used to sweep multiple IP
addresses to elicit “echo response” packet from available hosts
Also called “ping sweep”
To pass through firewalls that block ICMP Echo Requests,
other ICMP packet types may be used to elicit response from
target host
U.S. Department of
Homeland Security
United States
Secret Service
TCP/UDP Sweeps
Modern networks sometimes block ICMP at external perimeter
defenses (firewalls and routers)
TCP and UDP packets can be sent instead in attempt to
circumvent this barrier
U.S. Department of
Homeland Security
United States
Secret Service
Network Monitoring
Passively monitoring network from compromised system can
identify other hosts instead network
Amount of traffic collected and number of hosts identified will
depend greatly upon sniffer placement within logical network
architecture
U.S. Department of
Homeland Security
United States
Secret Service
Possible Artifacts
IDS alerts referencing broad scans or sweeps
Firewall logs that show blocked packets attempting to reach a
large number of hosts in a short period of time
Firewall logs that show traffic blocked based upon abnormal
protocol options (unusual ICMP types, TCP ACK packets
existing outside of a session, etc.)
U.S. Department of
Homeland Security
United States
Secret Service
Ports/Protocols
Once physical vector identified, and target verified as being
online, attacker may choose to enumerate methods by which
target computer is willing to communicate
Communication methods include:
Accepted network and transport protocols (ICMP, TCP,
UDP)
Accepted application protocols (HTTP, FTP, SMTP, etc.)
Accepted TCP/UDP port numbers
U.S. Department of
Homeland Security
United States
Secret Service
Identifying TCP/UDP Port Numbers
Also called “Port Scanning,” connection attempts can be sent
to TCP and UDP ports to determine if application is listening
Scanner may attempt to initiate TCP session to multiple ports
Response to request with a TCP syn/ack packet, indicates
there is application or OS service listening on port
U.S. Department of
Homeland Security
United States
Secret Service
Identifying TCP/UDP Port Numbers
Scanner sends packets to UDP ports to test if ports are open
Since UDP is connectionless, packets either empty, or contain
data that not valid for protocol normally used with port
If port is open, the application listening on port will respond,
If port not open, ICMP Destination Unreachable message sent
U.S. Department of
Homeland Security
United States
Secret Service
Possible Artifacts
IDS alerts referencing port/protocol scans.
Firewall logs showing blocked attempts to access large
number of ports, in close sequence, on single host, in short
time
TCP session initiated to IP address, immediately terminated,
not followed by additional communication, observable in sniffer
log
TCP session only half set up then abandoned, potentially
observable in sniffer log
U.S. Department of
Homeland Security
United States
Secret Service
Type and Version Identification
Once open communication channel to device established,
attacker may need to know type and version of listening
application and/or operating system
Attack methods are highly dependant upon target versions and
patch levels
Common methods for identifying this information include:
Banner grabbing
Packet printing
U.S. Department of
Homeland Security
United States
Secret Service
Banner Grabbing
Process of connecting to commonly available services that
provide type and version information in greeting messages
U.S. Department of
Homeland Security
United States
Secret Service
Packet Printing
TCP/IP stack is part of operating system that controls TCP/IP
network communication
Implementation of stack differs on every operating system,
produces minor variances in operating system’s response to
certain requests
Scanning tools that perform packet printing (or fingerprinting)
check for variances on target host to identify operating system
U.S. Department of
Homeland Security
United States
Secret Service
Attributes Used for Packet Printing
ICMP Error Messages
TCP Sequence Numbers
TCP Options
TCP Timestamps
TCP Retransmissions Timeouts
Fragmentation Handling
IPID Values
U.S. Department of
Homeland Security
United States
Secret Service
Possible Artifacts
IDS alerts referencing scans
Errors in logs of scanned application or service referencing
communication problems or incomplete connection attempts
U.S. Department of
Homeland Security
United States
Secret Service
Targets for Vulnerability Scans
Web servers and FTP servers
E-mail servers
File and database servers
Directory service servers
RPC
Print services
Simple services
U.S. Department of
Homeland Security
United States
Secret Service
Vulnerability Scan Techniques
Presence of known vulnerable application component files
Ability to traverse into normally non-accessible directories on
host operating system
Ability to access unauthorized files
Ability to execute unauthorized code
U.S. Department of
Homeland Security
United States
Secret Service
Vulnerability Scan Techniques
Ability to make unauthorized calls to backend application or
database servers
Ability to route unauthorized data, such as spam or another
probe, through the server
Ability to trigger backchannel communication, a communication
session originating from target to hacker
U.S. Department of
Homeland Security
United States
Secret Service
Possible Artifacts
IDS alerts referencing a possible vulnerability scan
IDS alerts referencing any attack (Some vulnerability scans
launch partial attacks to determine if they’re possible, this may
trigger an IDS)
Any extremely large volume of traffic that is widely varied,
characteristic of comprehensive (multi-protocol), blatant
vulnerability scan
Any other activity characteristic of any attack
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 3 - Network Attacks
Goals
Strategic Categories
Strategies - Authentication Attacks
Techniques - Factor Guessing/Cracking
Techniques - Credential Recover/Reset
Techniques - Credential Injection
Techniques - Credential Theft
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 3 - Network Attacks
, continued
Strategies - Unexpected Input
Techniques - Excessive Input
Techniques - Excessive Input / Buffer Overflows
Techniques - Unexpected Input Content / XSS Attacks
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 3 - Network Attacks
, continued
Techniques - Unexpected Input Content / XSS Attacks
Techniques - Unexpected Input Content / Command Injection
Techniques - Unexpected Input Timing
Techniques - Unexpected Input Timing / Temp File Attacks
Techniques - Unexpected Input Timing / Request-Response
Latency Attacks
Techniques - Unexpected Input Timing / Boot Process Attacks
U.S. Department of
Homeland Security
United States
Secret Service
Entrenchment Goals
Unauthorized Access: Obtaining access to resource (system,
network, data, etc.) that is illegal, against policy, or otherwise
unauthorized by organization/individual owning resource
Access Privilege: Obtaining ability to manipulate resource
(change, delete, deactivate, etc.) to extent not authorized by
organization/individual owning resource
Denial of Service: Preventing resource from being available to
fulfill purpose either temporarily or permanently
U.S. Department of
Homeland Security
United States
Secret Service
Entrenchment Strategic Categories
Authentication Attacks: Attacks against authentication
mechanism for purpose of obtaining credentials to system or
network
Unexpected Input: Supplying input in way that will cause
application or operating system to behave in unauthorized
fashion, either to gain unauthorized access or disrupt
functionality of target system
U.S. Department of
Homeland Security
United States
Secret Service
Authentication Attack Strategies
Factor guessing/cracking: Attempting to determine factors
(passwords for example) to allow authentication to system
Credential recovery/reset: Taking actions to cause system or
administrator to send set of credentials to attacker
Credential injection: Creation of new credentials that will allow
authentication into target system
Credential theft: Theft of credentials either through inadvertent
disclosure or methods such as sniffing network traffic
U.S. Department of
Homeland Security
United States
Secret Service
Authentication and Authorization
Authentication attacks focus on obtaining credentials for
specific individual or account, or being authenticated as person
or account without credentials
What attacker can accomplish will depend on what
compromised/unauthorized account is allowed
If attacker requires more authority on system or network,
he/she will use another authentication attack, or different
attack strategy
U.S. Department of
Homeland Security
United States
Secret Service
Authentication Factors
“Something you know”: Usernames, passwords, pass-phrases,
answers to secret questions, etc
“Something you have”: USB tokens, smart cards, RFID tokens,
cookies, encryption keys, etc
“Something you are”: Retinal patterns, thumbprints, DNA, etc
U.S. Department of
Homeland Security
United States
Secret Service
Guessing/Cracking
Attacker generate set of values that represent possible
legitimate authentication factors
Attacker tests values against authentication system or stolen
set of password hashes to determine which ones are correct, if
any
U.S. Department of
Homeland Security
United States
Secret Service
Value Generation
Brute Force: Guessing every possible value for credential
using any combination of acceptable characters
Dictionary: Using only words from a dictionary to generate a
list of potential values, some attacks allow for small variances
such as common misspellings in the list of potential values
Hybrid: Using any combination of brute force and dictionary
mehtods
U.S. Department of
Homeland Security
United States
Secret Service
Value Generation
Pattern Recognition: For server/administrator assigned factors
that follow a pattern, an attacker could use the pattern to guess
the values of other valid factors
Pre-generated Hashes: When authentication factor is a hash
value of another piece of data, such as hash of password, list
of all possible hashes for a set of values can be pre-calculated,
term “rainbow table” is used to refer to some types of pre-
generated hash sets
U.S. Department of
Homeland Security
United States
Secret Service
Value Testing
Manually typing values in one at a time
Using an automated tool such as THC Hydra to pass test
values to authentication system
Using hashes calculated against values in set of data and
comparing to hashes stolen from authentication system or
used by authentication system
U.S. Department of
Homeland Security
United States
Secret Service
Value Testing and Session Length
When a session is underway and individual or application is
authenticated, that session will sometimes last for specific
amount of time
If credentials successfully guessed/cracked, may only be good
for length of session in progress
Likely the case when factor is temporary token, such as a
cookie
U.S. Department of
Homeland Security
United States
Secret Service
Possible Artifacts
Large numbers of failed authentication attempts for single
account seen in logs of authentication system
Failed authentication attempts for one or more non-existent
user account names
Failed authentication attempts that show series of passwords
that match pattern indicative of attack
IDS logs referencing password or authentication attack
U.S. Department of
Homeland Security
United States
Secret Service
Possible Artifacts
User accounts locked out due to high number of failures
List of passwords or password hashes found in text file in
abnormal location
The presence of password/hash dumping utilities such as
pwdump (pwdump.dll)
Authentication attempts (successful or failed) at abnormal
times, or for which authorized user of account does not recall
U.S. Department of
Homeland Security
United States
Secret Service
Credential Recovery and Reset
Users lose credentials (authentication factors), forget
password, lose tokens and sometimes can’t remember their
user names
Most authentication systems include mechanism for resetting a
user’s credentials to a new value, or recovering copy of lost
credentials
U.S. Department of
Homeland Security
United States
Secret Service
Recovery/Reset Mechanisms
Password reset links on Web sites
Help desk staff (available by phone or in person) that reset or
unlock an account
Operating system and directory user account management
interfaces that allow account with sufficient privilege to reset
credentials to other accounts
U.S. Department of
Homeland Security
United States
Secret Service
Credential Recovery/Reset Attack
Techniques
Requesting a password reset, and capturing password from
network
Registering a domain name previously belonging to another
person, recreating a previously existing e-mail address at
domain name, and using e-mail address as an authentication
factor and recipient for reset credentials transmissions
Directly requesting an individual’s credentials, while using
personal information about that individual
U.S. Department of
Homeland Security
United States
Secret Service
Possible Artifacts
Successful authentication attempts for account believed to be
no longer in use
Password resets for an account that was believed to be no
longer in use
Password resets for which the legitimate user of the account
claims to not be responsible
U.S. Department of
Homeland Security
United States
Secret Service
Credential Injection
Calling a help desk and requesting creation of an account
Using an online mechanism to request an account
Can be done to gain initial access to information on Web
sites that provide information
Some Web sites might require user validate identify for
registration, using some type of personal information
Others allow input of whatever information user chooses to
provide
Directly creating user accounts using administrative utility
U.S. Department of
Homeland Security
United States
Secret Service
Possible Artifacts
Existence of user account in account repository for which there
is no legitimate authorized user
Existence of user account in account repository that does not
match account naming convention for organization
Recorded logins of account for which there is no legitimate
authorized user
Log entries referencing account creation
U.S. Department of
Homeland Security
United States
Secret Service
Credential Theft
Capturing credentials as transmitted across network
Requires attacker have control or be present on one of
network mediums through which credentials sent
Tricking an individual into revealing credentials
Social Engineering
Stolen physical tokens such as ID cards and USB tokens
U.S. Department of
Homeland Security
United States
Secret Service
Possible Artifacts
Reports of theft of physical credentials or of disclosure of
credentials to someone believed authorized to make request
Successful authentication requests at abnormal times, or for
which authorized user of account does not recall
Existence of e-mails in e-mail repository or logged by proxy
that include requests for credentials, or links to Web pages
where such requests are made
U.S. Department of
Homeland Security
United States
Secret Service
Unexpected Input Strategies
Excessive Input: Sending more input than system or
application was expecting, or is able to handle
Unexpected Input Content: Sending input content that system
or application will process incorrectly due to inability to
recognize and/or properly control input type
Unexpected Input Timing: Sending input at times that system,
application or communication session is temporarily vulnerable
to interference
U.S. Department of
Homeland Security
United States
Secret Service
Excessive Input
Take advantage of a lack of input validation
Basic attack method to supply an excessive amount of input to
an application, operating system, or network
Effect could be to crash target or break a control system and
allow attacker to perform additional unauthorized actions
Buffer Overflow Attacks
Flooding
U.S. Department of
Homeland Security
United States
Secret Service
Input Size Validation
Properly coded applications should verify user-supplied input is
of proper size, If not, truncate input or produce error message
and/or stop the process
Network devices should terminate or block all communication
from hosts supplying excessive number of packets or service
requests
U.S. Department of
Homeland Security
United States
Secret Service
Excessive Input/Buffer Overflow
Buffer is temporary storage area, usually in RAM, allocated for
manipulation of data within a process
For instance, when logging into e-mail server, 32-character
space for username
Limitation is established in code of e-mail server application
and controls how much input will be accepted from user
U.S. Department of
Homeland Security
United States
Secret Service
Buffer Overflow Attack
Purposely sends entry too large for buffer
Sends in such a way that portion of entry is written to target
computer where program instruction code stored
Attacker uses method to intentionally cause execution of code
Result of code execution could be anything, but will often be
denial-of-service, command terminal session sent back to
attacker’s computer or injection of DLL or other program code
U.S. Department of
Homeland Security
United States
Secret Service
Possible Artifacts
Unexplained errors in the log files for application or service
attacked
Intrusion detection system alerts indicating a buffer overflow
Sniffer logs show large blocks of repetitive data, such as 0x90
or other hex values
Sniffer logs show blocks of data that do not conform to normal
rules for network protocol used
IDS alerts or sniffer logs showing common post-attack events
such as reverse shells, DLL transfer, OS commands, etc.
U.S. Department of
Homeland Security
United States
Secret Service
Cross-Site Scripting (XSS)
Cross-site scripting occurs when attacker supplies script
executed by another system’s Web browser or in another
browser window accessing a different site
U.S. Department of
Homeland Security
United States
Secret Service
Cross-Site Scripting (XSS)
Attacker posts script to website that permanently stores script
Serves it to other systems when they request the web page to
which it was posted
Allows attacker to run code in another person’s browser,
“persistent” or “stored” XSS attacks
U.S. Department of
Homeland Security
United States
Secret Service
Cross-Site Scripting (XSS)
Attacker will embed script in URL
If loaded by another user, will cause Web server to supply
malicious code to requesting browser to be executed in context
of requested page
Called “non-persistent” or “reflected” XSS attacks, rely on user
or browser to load the URL
U.S. Department of
Homeland Security
United States
Secret Service
Possible Artifacts of XSS
IDS alerts referencing an XSS attack
URLs containing scripting as seen in Web server and proxy
server logs, or in Web browser history
Web pages containing embedded scripting, as seen in proxy
server logs where proxy records full page
Unusual character encodings in URLs as seen in Web server
or proxy server logs, or in Web browser histories
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 4 - Entrenchment
Goals
StrategiesTechniques - Log
CleaningTechniques - Automatic
ExecutionTechniques - Hooking
Techniques - File Type Manipulation
Techniques - Naming Conventions and Placement
Techniques - Remote Connectivity
Techniques - File System Date/Time Stamp Manipulation
U.S. Department of
Homeland Security
United States
Secret Service
Entrenchment Goals
Attack Pivot Point: Attacker requires continued control of
system to use as pivot point from which to attack other
systems and networks
Data Theft: Attacker requires continued control of system to
perform data mining operations on system and any local
storage media.
General Control: Attacker wants to maintain control of system
as asset for various other uses
U.S. Department of
Homeland Security
United States
Secret Service
Entrenchment Goal Attributes
Entrenchment requires attacker retain some ability to remotely
control or manipulate target,
Method of control must remain undetected
U.S. Department of
Homeland Security
United States
Secret Service
Entrenchment Strategies
Log Cleaning: Removing records of unauthorized activities to
hide presence
Automatic Execution: Adding configuration changes that will
cause unauthorized programs to be started when host OS
boots, or restarts
Naming Conventions and Placement: Naming unauthorized
files, processes and configuration changes in way that they
appear legitimate or otherwise benign
U.S. Department of
Homeland Security
United States
Secret Service
Entrenchment Strategies
File Type Manipulation: Changing attributes which identify a
file’s type, such as signature and extension
Hooking: Intercepting calls to operating system so as to
interfere with data returned
Remote Connectivity: Maintaining one or more channels
through which compromised system can be remotely
controlled
U.S. Department of
Homeland Security
United States
Secret Service
Entrenchment Unauthorized Code
Entrenchment activities typically involve installation of
unauthorized code
This code will serve to perform one or more of functions
identified on previous slides
Common types include backdoors, rootkits and trojans
U.S. Department of
Homeland Security
United States
Secret Service
Log Cleaning
Attacker must remove records of unauthorized activity
Common record of unauthorized activity is a log entry
Log cleaning is process of deleting individual log entries, or
clearing entire log files to achieve goal
Can be done manually, with specific log cleaner malware, or
with a general-purpose rootkit
U.S. Department of
Homeland Security
United States
Secret Service
Log Cleaning - Record Deletion
Removing individual records easy with text logs
Attacker opens log in a text editor, deletes associated lines
and saves file
Proprietary log formats are much more difficult to handle
Attacker (or tools) must understand format of log, and be able
to identify beginning and end of each entry
Log viewers that correspond to proprietary logs do not typically
include function for removing individual entry
U.S. Department of
Homeland Security
United States
Secret Service
Log Cleaning - Log Clearing
Alternative to deleting individual records, clear an entire log
Done in situations where attacker is in hurry or does not have
mechanism for deleting individual records
Downside of log clearing is that it is quite noticeable
Attacker may clear log when not concerned with hiding
intrusion but more with removing information used to trace
attack back to source (not characteristic of entrenchment)
U.S. Department of
Homeland Security
United States
Secret Service
Log Cleaning - File Deletion
Attacker may choose to delete entire log file In lieu of record
deletion or log clearing
Least desirable of log cleaning methods as deletion of log file
is most noticeable and may cause system errors or crashes
More likely when dealing with more obscure log files not as
likely to be noticed
U.S. Department of
Homeland Security
United States
Secret Service
Log Cleaning - Possible Artifacts
File system date/time stamps changed during log cleaning
Log files that have had specific entries removed may have
abnormal time gaps between remaining entries
Empty or completely missing log files
Log entry indicating log was cleared
Existence of malicious code on system that includes log
cleaning as one of its functions
U.S. Department of
Homeland Security
United States
Secret Service
Automatically Starting Malware
Common for malicious code to be installed such that it will start
automatically when Windows boots
Main mechanism for accomplishing this is by adding Registry
key that will start executable file as new process or load library
into another process
Common methods include creating “Run” keys for executables,
installing new service, or trojanize legitimate service by
changing ServiceDLL key to load malicious DLL
U.S. Department of
Homeland Security
United States
Secret Service
Automatic Execution Directories
C:\Documents and Settings\All Users\Start
Menu\Programs\Startup
C:\Documents and Settings\<username>\Start
Menu\Programs\Startup
C:\Windows\Tasks
U.S. Department of
Homeland Security
United States
Secret Service
Job Scheduling
Most operating systems include mechanism for scheduling
executions to occur with various triggers, usually date/time
For Microsoft operating systems the Windows Task Scheduler
For Linux/Unix derivatives the “cron” daemon
U.S. Department of
Homeland Security
United States
Secret Service
Possible Artifacts
Existence of Registry entries that load unauthorized
executables or libraries
Unauthorized executables in auto-start directories
Unauthorized executables specified in an INI file
Existence of “.job” files on Windows
Entries in “crontab” file in Linux/Unix derivatives
Malicious code found on system which adds automatic start
configurations when executed
U.S. Department of
Homeland Security
United States
Secret Service
Hooking
Process of intercepting calls from one program to another so
as to interfere with any data exchanged
Can be used to hide data such as processes, files and specific
file contents
U.S. Department of
Homeland Security
United States
Secret Service
The OS API
API (Application Programming Interface) defined so programs
can be written that will run on and interface with OS
Functions that use API:
Directory listings
File copy and move operations
File editing operations
Network sending and receiving
Process and thread starting, stopping and enumeration
U.S. Department of
Homeland Security
United States
Secret Service
The OS API
For instance, when Windows Explorer used to view contents of
a directory, it is done via a standard API call from explorer.exe
to Windows OS DLL file
Operations are common during every day usage of OS
During entrenchment, same API calls used to find malicious
code
Important to attacker to prevent calls from revealing signs of
malware presence
U.S. Department of
Homeland Security
United States
Secret Service
OS API Hooking
Rootkits can be used to hook API calls, intercepting them at
various points
Sensitive values can be edited out of any returned values
U.S. Department of
Homeland Security
United States
Secret Service
Possible Artifacts of API Hooking
Hash values of OS files that have been hooked through direct
modification will be modified
Modified hash values for files indicates potential presence of
API hooks in memory
Technique is used by some rootkit detection programs such as
Rootkit Revealer
Discovery of API hooks during analysis of malicious code files
found on compromised system
U.S. Department of
Homeland Security
United States
Secret Service
File Type Manipulation
Attributes that define a file’s type can be manipulated to hide
file from general searches and from some specific forensic
analysis
Changing file extension to make file appear a different file type
Changing file signature to make file appear as a different file
U.S. Department of
Homeland Security
United States
Secret Service
Possible Artifacts
File signatures that do not match extension, or vice versa
Files that have a matching signature and extension, but which
cannot be read by appropriate application
U.S. Department of
Homeland Security
United States
Secret Service
Naming Conventions Strategies
Giving files/processes the same name as a legitimate file or
process
Giving files/processes a name that is slightly modified from
name of a legitimate file or process
Assigning a name that appears similar to the names of other
files
Use of special characters within names that will cause name to
blend in with other files, or will cause name to not be rendered
in certain interfaces
U.S. Department of
Homeland Security
United States
Secret Service
Placement Strategies
Placing unauthorized files in a directory where average user
unlikely to look
Placing unauthorized files named a certain way into a directory
with other files with similar names
Using normal directory names, but in wrong location, temp
directory often used
Storing files or file fragments in disk space not currently in use
Fragmenting file and inserting it into another file in small
amounts
U.S. Department of
Homeland Security
United States
Secret Service
Possible Artifacts
Files, Registry keys and processes misspelled or in wrong
location
Files that do not have appropriate hash value or file signature
Process running in more than one instance when not typical, or
when process is child of itself
Presence of programs on system used for file hiding
File names and directory locations discovered during analysis
of malicious code
U.S. Department of
Homeland Security
United States
Secret Service
Remote Connectivity
For extended operations intruder will require dependable
access to compromised systems
Could be legitimate channel that attacker accesses with stolen
credentials, or new channel created by attacker
U.S. Department of
Homeland Security
United States
Secret Service
Subverting Legitimate
Communication Channels
SMB/CIFS & DCE/RPC
Windows file sharing and remote procedure protocols
used to move data to and from, or even configure a remote
system
Requires attacker has credentials to system
most useful for manipulating a system from another device
within same network
U.S. Department of
Homeland Security
United States
Secret Service
Subverting Legitimate
Communication Channels
Remote administration applications
Terminal Services, VNC and Remote Desktop
Allow someone to open a graphical interface to another
system
Attacker can authenticate to these pre-existing applications
with stolen credentials
Other applications such as SSH and telnet used to
administer a system through a command line interface
U.S. Department of
Homeland Security
United States
Secret Service
Subverting Legitimate
Communication Channels
VPN tunnels:
Attacker can utilize tunnels that already exist to or from
compromised system to jump to other devices and/or
networks
U.S. Department of
Homeland Security
United States
Secret Service
Remote Backdoors
A non-legitimate method for listening for remote connections
from attacker to compromised system
Typically accomplished by starting process that listens for
remote connection attempts
Might be normal TCP connection attempt, or may involve
series of packets sent to specific ports in specific order which
will cause full listening socket to open (called “port knocking”)
U.S. Department of
Homeland Security
United States
Secret Service
Outbound Initiated Channels
Compromised system may sit behind firewall, prevents
inbound remote connection attempts
Alternative to process listening for inbound connection
attempts, malicious code package configured to initiate
outbound communication
Connections, called “Reverse Channels,” frequently successful
due to fact that firewall egress rules are typically less stringent
than ingress rules
U.S. Department of
Homeland Security
United States
Secret Service
Possible Artifacts: Legitimate
Channel Usage
Unusual login times for otherwise authorized account.
Logins for authorized account that user of account did not
initiate
Authentication or subsequent activity that occurs to fast for
human to be manually directing activity
Existence of malicious code on compromised system that
includes functions for connecting to remote administration
applications such as SSH or VNC
U.S. Department of
Homeland Security
United States
Secret Service
Possible Artifacts: Backdoors
Abnormal ports open on a system
Suspicious processes attached to a listening port
Inbound connection attempts to workstations
Abnormal patterns of inbound packets or connection attempts
Existence of malicious code on compromised system found to
start listening service when executed
U.S. Department of
Homeland Security
United States
Secret Service
Possible Artifacts: Outbound
Channels
DNS queries for known-bad domain names or DNS hosts
Outbound connection attempts to known-bad or suspicious IP
addresses or IP ranges
Outbound connection attempts occurring over abnormal ports
Outbound connection attempts which exhibit abnormal content
Existence of malicious code on compromised system found to
beacon to domain name or IP address when executed
U.S. Department of
Homeland Security
United States
Secret Service
File System Date/Time Stamp
Manipulation
Attacker may attempt to hide unauthorized activity by changing
associated date/time stamps
Attempt to make it appear as if activity is unrelated
U.S. Department of
Homeland Security
United States
Secret Service
Possible Artifacts
Date/time stamps for malicious code executables or DLLs that
match date/time stamps on files created much earlier than
other related activity
Date/time stamps for suspicious Registry keys that are set
much earlier than other related activity
Existence of malicious code on system found to modify
date/time stamps on files or Registry keys when executed
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 5 - Infiltration and Extraction
Sniffers
Trust Relationships
Data Extraction
U.S. Department of
Homeland Security
United States
Secret Service
Sniffers
A program used to monitor or capture network traffic
Collected data usually stored on compromised system in
hidden file
Often run as disguised processes on systems as:
Trojanzed device drives
Renamed programs configured to start at boot
Trojanized applications
U.S. Department of
Homeland Security
United States
Secret Service
Trust Relationships
Mechanism whereby users logged on and authenticated to one
server can access resources on another without need to re-
authenticate
If server A trusts users logged into server B, server A has
established a one-way trust
If server A trusts server B, and server B trusts server A, they
have established a two-way or absolute trust
If A and B have a two-way trust and B also trusts C, C can
access A through a pass through or transitive trust
U.S. Department of
Homeland Security
United States
Secret Service
Trust Relationships
Server A ¯ ------- Server B (One way trust)
Server A ¯ -------˘ Server B (Two-way or absolute trust)
Server A ¯ -------˘ Server B ¯ -----Server C (Transitive trust)
U.S. Department of
Homeland Security
United States
Secret Service
Trust Relationship Exploitation
Compromising a trusted system, domain or server
Using or exploiting the LDAP service
Forging or spoofing authentication credentials
Spoofing source information
Piggybacking off an already trusted system
Hijacking a session from a trusted system
U.S. Department of
Homeland Security
United States
Secret Service
Data Extraction
Process of obtaining data off compromised system
To avoid detection, desired data is filtered for relevancy and
sent in way that will not overload system or trigger IDS
Embedding data deep into packets often allows extraction of
data without detection
Hacker may schedule job to send data during time when
network traffic is heavy in attempt to avoid detection by using
network traffic volume
U.S. Department of
Homeland Security
United States
Secret Service
Data Extraction Methods
E-mail
Masked as services like HTTP, DNS or ARP
Backdoor connections
Services run on a regular basis
Ftp or telnet login by attacker
A print job run to a remote location or file
U.S. Department of
Homeland Security
United States
Secret Service
U.S. Department of
Homeland Security
United States
Secret Service
Module 10 - Report Writing
U.S. Department of
Homeland Security
United States
Secret Service
You Will Learn . . .
General Report Writing Techniques
Specific Report Templates
Interviewing Techniques
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 1 - General Report Writing
Techniques
Examiner Notes
Forensic Reporting
Title Page
Items Analyzed
Relevant Software
Glossary
Details of Findings
Items Provided
Hyperlinking
U.S. Department of
Homeland Security
United States
Secret Service
Forensic Report
Culmination of time intensive, painstaking work
Should reflect time, effort, professionalism put forth to acquire
information presented
Should be organized, clear, concise, free of grammatical and
punctuation errors
Consider report reflection of yourself, your skills, attention to
detail, experience and work ethic
U.S. Department of
Homeland Security
United States
Secret Service
Examiner Notes
Documentation created during investigative and analysis
processes, provides basis for examiner to report results of
case
Written notes and documentation created during investigation
should be preserved and may be discoverable
Examiner notes taken during execution of forensic
examination, along with final report of findings are foundation
on which many digital media-related cases are built
U.S. Department of
Homeland Security
United States
Secret Service
Note Taking
Essential part of a forensic examination
Assists in creation of document that will provide record of
procedures and processes performed
Examination notes should present clear timeline of actions
taken and results of actions
Properly recorded notes provide repeatable roadmap of
examination
Another examiner should be able follow notes to reproduce
same results obtained in original exam
U.S. Department of
Homeland Security
United States
Secret Service
Note Taking
Number, date, and initial all note pages using [page #] of [total
# of pages] numbering schema to account for all pages
Not uncommon for extensive periods of time to pass between
time of examination and prosecutorial action
Thorough note taking helps ensure accurate testimony as to
actions taken during examination
Follow rule, “If it wasn’t documented, it didn’t happen”
U.S. Department of
Homeland Security
United States
Secret Service
Forensic Report
Provide details about purpose for forensic analysis
Describe physical and/or logical evidence analyzed
Define related programs, terms and their relevance
U.S. Department of
Homeland Security
United States
Secret Service
Forensic Report
Clearly identify persons related to examination including
yourself, requestor, suspects, other pertinent individuals
Address relevant evidence found during examination
Clearly, concisely explain items of evidentiary value found on
suspect media during analysis
Identify location and relevance of items of evidentiary value as
relating to reason for analysis and/or investigation
U.S. Department of
Homeland Security
United States
Secret Service
Forensic Report
Should define all technical terms using common language that
non-technical investigators and prosecutors can understand
Should always contain information listed on following slide,
headings may vary from organization to organization
U.S. Department of
Homeland Security
United States
Secret Service
Report Contents
Report heading
Support requested, reason or purpose for analysis
Summary of findings
Digital media analyzed
Analysis/Suspect software listings
Glossary of technical terms
Details of findings
Items provided
U.S. Department of
Homeland Security
United States
Secret Service
Title Page
Report Header
Support Requested
Current Case Status
Summary of Findings
See Title Page example in student book
U.S. Department of
Homeland Security
United States
Secret Service
Title Page
Item
Description
Title (To:)
Indicates report’s recipient and date. This
information is usually directly related to charging
document or request for service.
From
Identifies report’s author, including name,
organization, and contact information.
Subject
Indicates type of work performed, as well as
any suspect and/or local case reference
information.
U.S. Department of
Homeland Security
United States
Secret Service
Title Page
Item
Description
Support
Concisely states what charges or allegations
Requested or
were addressed by the analysis, charging
Purpose for
jurisdiction or entity, with regard to a specific
Analysis
investigation.
Status
Indicates the current case status, usually Open
or Closed. This may change nature from a
report to a status update.
U.S. Department of
Homeland Security
United States
Secret Service
Title Page
Item
Description
Summary of
A short narrative describing type and nature
Findings
of any evidentiary items located during analysis
with respect to specific allegations or
charges. Failure to locate items that support
allegations should also be indicated here, as
well as items that may exonerate.
U.S. Department of
Homeland Security
United States
Secret Service
Title Page
Item
Description
Footer
Includes author’s name, title/rank, and a
“Released” field for approval signature. Footer
may include a legal disclaimer. All pages of the
report should be numbered in the Page X of X
format.
U.S. Department of
Homeland Security
United States
Secret Service
Items Analyzed
Items Analyzed section of report describes in detail physical
and/or logical evidence analyzed
Always include original and verified hash values of all evidence
items
U.S. Department of
Homeland Security
United States
Secret Service
Physical Items Analyzed
Manufacturer
Model, serial, and part number (when possible)
Item description
Any specific markings
U.S. Department of
Homeland Security
United States
Secret Service
Logical Items Analyzed
Items Analyzed section of report details images sent for
analysis as well as any “original” evidence items
List image files in addition to physical containers
Identify by original file name and include hash or other
validation mechanism
See Items Analyzed example in student book
U.S. Department of
Homeland Security
United States
Secret Service
Relevant Software (Analysis)
List all software applications used during forensic examination
to process or analyze suspect media
Ensure to include primary analysis tool
Identify software version and brief description of software’s
functionality or use
U.S. Department of
Homeland Security
United States
Secret Service
Relevant Software (Suspect)
Identifying software on suspect’s machine necessary
component of case
Include any software that may have created and/or interacted
with data of evidentiary value
Include any software identified as having been deleted
Pay particular attention to software commonly used to hide
data or securely erase data
U.S. Department of
Homeland Security
United States
Secret Service
Relevant Software (Suspect)
Software name and version
Full path to where application was located on suspect media
Brief description of program functionality and how it relates to
Request for Analysis and/or investigation
Be prepared to further explain items in this listing during
prosecution
See Relevant Software example in student book
U.S. Department of
Homeland Security
United States
Secret Service
Glossary
Defines technical terms, document formats, and procedure
details referenced in report that may not be readily understood
by average non-technical reader
Define only terms integral to understanding of examination
findings as presented in report
See Glossary example in student book
U.S. Department of
Homeland Security
United States
Secret Service
Details of Findings
Provides detailed information about items of evidentiary value
found on suspect media
Information should be thorough, yet concise, and only contain
details relevant to request for analysis and/or investigation
Should not contain detailed information about processes
executed that did not produce relevant information, unless
negative result is relevant
Information about non-productive processes should be in notes
U.S. Department of
Homeland Security
United States
Secret Service
Organization of Report
Several different ways to organize report
May use different organizational strategies for different
investigations
Might, for example, organize report on case that contains
many pieces of media by listing all items found on each piece
of media as one section
In other cases, may be more effective to organize data by date
and time in chronological order, e.g., cases involving email,
chat and downloads
U.S. Department of
Homeland Security
United States
Secret Service
Organization of Report
Another method, organize evidence by its relationship to a
particular criminal charge and subject
Approach works well for criminal prosecution
Allows prosecutor to quickly see evidence relevant to a
particular charge and subject
U.S. Department of
Homeland Security
United States
Secret Service
Organization of Report
Evidence can be ordered or segregated by device
Good organizational choice for case that has many pieces of
media such as a large quantity of CD’s or DVD’s
Strategy is not normally best choice when all evidence is
located on one device
U.S. Department of
Homeland Security
United States
Secret Service
Organization of Report
If evidence has multiple partitions, could further subdivide
results by individual partition
Detail partition’s file format and size
To further clarify evidence, could divide findings by each user
account or profile
Detail important files, structure, data, and discrepancies
Explain techniques, methodology, and relevance of information
in brief narrative statements whenever possible
U.S. Department of
Homeland Security
United States
Secret Service
Organization of Report
If analysis did not result in discovery of items of evidentiary
value, a simple statement should be included stating negative
results
Ensures reader does not misinterpret an omission as failure to
conduct full and competent analysis of evidence
U.S. Department of
Homeland Security
United States
Secret Service
Organization of Report
Include techniques used to locate or extract evidence
Can refer to report if asked in court how a specific piece of
evidence was located
Example, if file found by manual inspection of drive, state this,
not every search has to be done with an automated tool
Take time to develop organized structure before writing
See Details of Findings example in student book
U.S. Department of
Homeland Security
United States
Secret Service
Items Provided
Details all physical items included with report when submitted
Should include all items specified in Items Analyzed section
Include items that were generated as a result of analysis, such
as a zip disk, floppy disk, or any CD-Rs of findings, as well as
any extracted, hard copy documents
See Items Provided example in student book
U.S. Department of
Homeland Security
United States
Secret Service
Use of Hyperlinks
Hyperlinking is a way to direct readers to items referred to in
report on electronic media
Often not practical to display certain items in actual report
Example, report may reference offensive, graphic image of
child pornography
Some readers may not have need to view image
Others may be required to do so in order to confirm existence
Hyperlink allows those with need to inspect file, while sparing
others from having to view it
U.S. Department of
Homeland Security
United States
Secret Service
Use of Hyperlinks
May be so many items of interest, it would be too cumbersome
to include all actual images in written report
In this situation, hyperlink could lead to entire directory that
contains multiple files
If report is included on CD or other large media, use hyperlinks
where possible to illustrate items of evidentiary value
If not familiar with how to hyperlink, see procedure in student
book
U.S. Department of
Homeland Security
United States
Secret Service
Procedure: Create a Hyperlink in
Microsoft Word
Step/Action in student book.
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 2 - Interviewing Techniques
Cyber Crime Interviews
Interview Process
U.S. Department of
Homeland Security
United States
Secret Service
Cyber Crime Interviews
Develop leads, confirm events, and obtain a complete picture
of crime
Can help direct investigation
Assist in understanding nature of the crime, locating more
evidence, identifying suspects
May assist in revealing true scope of investigation
Can provide information needed to ensure conviction
U.S. Department of
Homeland Security
United States
Secret Service
Accusatory versus Non-Accusatory
Difference between an interview and interrogation
Purpose of interview:
Gather information that will confirm events
Develop suspects and leads
Identify facts that lead to root causes of incident
Not focused on getting an individual to confess
U.S. Department of
Homeland Security
United States
Secret Service
Interviews
Often first and best opportunity to determine what has
happened and clarify confusion or misconceptions
To develop information
To obtain information
Develop rapport with subjects
Conducted in non-confrontational manner
U.S. Department of
Homeland Security
United States
Secret Service
Interrogations
Focus on presenting facts of case and eliciting statements that
confirm suspect’s involvement
U.S. Department of
Homeland Security
United States
Secret Service
Accusatory versus Non-Accusatory
Accusatory approach may inhibit effective communication
Take into account perceptions of interviewees
Many people you will encounter during initial interviews have
little to no exposure to law enforcement outside of television
People may view interaction with government agents through
lens of personal attitudes, experiences, and beliefs about law
enforcement
Law enforcement often cast in negative light and government
agents seen as dimwitted and overbearing
U.S. Department of
Homeland Security
United States
Secret Service
Interview Process
Planning/Research
Opening/Rapport
General Questioning
Detailed Questioning
Interview Termination
U.S. Department of
Homeland Security
United States
Secret Service
Planning and Research
Conduct preliminary research on interviewee and organization
Helps to draft appropriate questions and an interviewing
approach that will be successful
knowledge and comprehension of technical subject’s area of
expertise presents professional and approachable image
Knowledge gained through planning and research enables
interviewer to ask more intelligent questions
U.S. Department of
Homeland Security
United States
Secret Service
Opening/Rapport
The initial contact is critical to obtaining cooperation
Showing respect for individual and organization and explaining
importance of questions, vital steps in obtaining cooperation
Explain to interview subjects that you need assistance in
determining facts of case and understanding issues involved
U.S. Department of
Homeland Security
United States
Secret Service
General Questioning
Start with open-ended questions that allow subject to explain
his/her knowledge of events
Questions should develop a general framework of incident
derived from subject’s personal knowledge of factual events
Important to obtain general outline of events that transpired to
document information relevant to case
U.S. Department of
Homeland Security
United States
Secret Service
General Questions Address
Key incidents that brought situation to light
Hardware involved (routers, firewalls, IDS)
Specific individuals involved in incident and actions they took
with any evidence
Physical locations of effected machines and people
Technology that will need clarification during Detailed
Questioning phase
U.S. Department of
Homeland Security
United States
Secret Service
Detailed Questions Address
Software and hardware model numbers and versions
Network monitoring and logging setup
Collection of current logs
Network diagrams
User policies
List of people who had logical and physical access
U.S. Department of
Homeland Security
United States
Secret Service
|
||
|
|
|