Network Intrusions Responder Program (NITRO). Instructor Guide - page 17

 

  Index      Manuals     Network Intrusions Responder Program (NITRO). Instructor Guide

 

Search            copyright infringement  

 

   

 

   

 

Content      ..     15      16      17      18     ..

 

 

 

Network Intrusions Responder Program (NITRO). Instructor Guide - page 17

 

 

Lesson 8 - Extortion
ƒ Overview
ƒ Attack Methodologies
ƒ Investigative Responses
U.S. Department of
Homeland Security
United States
Secret Service
Extortion on the Internet
ƒ Direct threats
ƒ Threats against tangible or non-tangible data
ƒ Threats against a web entity
ƒ Protection
U.S. Department of
Homeland Security
United States
Secret Service
Investigative Responses
ƒ Capture
ƒ Preservation
ƒ Warrants
ƒ Reporting
ƒ Education
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 9 - Network Attacks
ƒ Overview
ƒ Attack Methodologies
ƒ Investigative Responses
U.S. Department of
Homeland Security
United States
Secret Service
Attacking a Network
ƒ Network routers
ƒ Domain Name Servers
ƒ Firewalls
ƒ Intrusion Detection Systems
ƒ Wireless networking equipment
ƒ Access control systems
U.S. Department of
Homeland Security
United States
Secret Service
Investigative Responses
ƒ Capture
ƒ Preservation
ƒ Warrants
ƒ Reporting
ƒ Education
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 10 - Terrorism
ƒ Overview
ƒ Attack Methodologies
ƒ Investigative Responses
U.S. Department of
Homeland Security
United States
Secret Service
Terrorism
ƒ Systematic creation of fear in group of people rather than
individual
ƒ Intimidation
U.S. Department of
Homeland Security
United States
Secret Service
Internet Use
ƒ Psychological warfare
ƒ Propaganda
ƒ Fund-raising
ƒ Message center for coordinating activities
ƒ Launch network attacks
ƒ Data mining
U.S. Department of
Homeland Security
United States
Secret Service
Internet Use
ƒ Denial of Service attacks against enemies
ƒ Site defacements of web sites counter to their cause
ƒ Spam e-mail attacks against enemies
ƒ Phishing attacks for banking information to help fund activities
U.S. Department of
Homeland Security
United States
Secret Service
Investigative Responses
ƒ Capture
ƒ Preservation
ƒ Warrants
ƒ Reporting
ƒ Education
U.S. Department of
Homeland Security
United States
Secret Service
Module 9 - Phases of an Intrusion
U.S. Department of
Homeland Security
United States
Secret Service
You Will Learn . . .
ƒ Defining and Intrusion
ƒ Reconnaissance
ƒ Network Attacks
ƒ Entrenchment
ƒ Infiltration and Extraction
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 1 - Defining and Intrusion
ƒ Definition of an Intrusion
ƒ Goals of an Intrusion
ƒ Attacker Profiles
ƒ Phases of an Intrusion
U.S. Department of
Homeland Security
United States
Secret Service
Intrusion
ƒ Act of executing unauthorized actions against an information
system and/or its resources
ƒ Generally, considered to have taken place when someone
gains unauthorized access to a computer
ƒ When successful intrusion of single device occurs device is
considered compromised
ƒ Network intrusion is broader and includes compromise of
multiple devices on single or multiple networks
U.S. Department of
Homeland Security
United States
Secret Service
Vulnerability
ƒ A weakness in information system that could allow
unauthorized actions to be taken against system
U.S. Department of
Homeland Security
United States
Secret Service
Exploit
ƒ Tool used by an attacker to perform malicious attacks through
vulnerabilities in system
ƒ For example, error in an operating system that allows arbitrary
code execution
ƒ Program that attacker writes to perform attack against
operating system error is exploit
U.S. Department of
Homeland Security
United States
Secret Service
Threats and Threat Agents
ƒ Threats - Insider
ƒ Disgruntled employee
ƒ Uninformed employee
ƒ Threat Agents
ƒ Contractors
ƒ Recruited or placed agent
U.S. Department of
Homeland Security
United States
Secret Service
Threats and Threat Agents
ƒ Outsider
ƒ Hackers
ƒ Political activist “Hacktivist”
ƒ Information “brokers”
ƒ Foreign Governments or Corporations
ƒ Natural disasters
U.S. Department of
Homeland Security
United States
Secret Service
Goals of an Intrusion
ƒ Denial-of-Server (DoS) - Attack that makes computer resource
unavailable
ƒ Unauthorized Access - Act of gaining access to any computer
resource without express permission of owner of resource
ƒ Inappropriate Usage - Act of using computer resource in
manner deemed inappropriate for resource
U.S. Department of
Homeland Security
United States
Secret Service
Goals of an Intrusion
ƒ Other - Broad goals that may be difficult to categorize
ƒ Suspicious Activity - Any activity that does not conform to
the normal prescribed activity
ƒ Malware - Software designed to infiltrate, monitor, or
possibly damage a computer without the owner’s consent
U.S. Department of
Homeland Security
United States
Secret Service
Intruder Types
ƒ Many types of attackers and many reasons why networks and
systems attacked
ƒ Most intruders fit loosely into one of a few categories
differentiated by skill, resources, and motivation
ƒ Understanding basic intruder profiles and motivations may help
identify other compromised systems
U.S. Department of
Homeland Security
United States
Secret Service
Intruder Types
ƒ Advanced
ƒ Intermediate
ƒ Beginner
U.S. Department of
Homeland Security
United States
Secret Service
Advanced Attackers
ƒ Skilled and motivated
ƒ Generally exercise highest levels of caution and care
ƒ Slow and precise
ƒ Attempt to evade intrusion detection
ƒ Attempt to hide signs of presence
ƒ Attempt to mask source of attack
U.S. Department of
Homeland Security
United States
Secret Service
Advanced Attackers
ƒ Piggy back on another attackers data stream
ƒ Attempt to misdirect investigators by pointing to another source
ƒ Program in one or more languages and will modify or create
new exploit code/methods to support objective
ƒ Working knowledge of common system network architectures
ƒ Greatest ability to cause damage throughout network
U.S. Department of
Homeland Security
United States
Secret Service
Advanced Attackers
ƒ Can be found in organized crime, terrorist organizations,
foreign governments or next door
ƒ Motivation varies, tends to match motivations of organization if
associated
ƒ Intellectual challenge is common motivation
ƒ Sometimes categorized as Professional, State Sponsored, or
Elite
U.S. Department of
Homeland Security
United States
Secret Service
Intermediate Attacker
ƒ Attempt to follow same methodology as advanced group but
do not possess necessary skills, knowledge or experience
ƒ Moderate speed and precision
ƒ May attempt to evade intrusion detection
ƒ Attempt to remove signs of presence, but likely to miss
something
ƒ Attempt to mask source of attack
U.S. Department of
Homeland Security
United States
Secret Service
Intermediate Attacker
ƒ May have programming skills and ability to perform minor
modifications of exploit code to suit objectives
ƒ Working knowledge of common system and network
architectures
ƒ Example, could be system administrator attempting to further
his or her knowledge and abilities
ƒ Other terms for intermediate attacker, Amateur and Enthusiast
U.S. Department of
Homeland Security
United States
Secret Service
Beginner Attacker
ƒ User just getting into arena
ƒ Learning, relies on success and failures of others to teach
them basics
ƒ Tendency to rely on other’s code and scripts to do their work
ƒ Do not have basic understanding of intrusion phases
ƒ Usually fast and imprecise
ƒ Does not usually attempt to evade intrusion detection, unless a
function of tool they are using
U.S. Department of
Homeland Security
United States
Secret Service
Beginner Attacker
ƒ No attempt to hide signs of presence, unless a function of tool
ƒ May attempt to mask source of attack
ƒ Normally cannot program well, if at all, no ability to modify
exploit code to support objectives
ƒ Motivations tend to be game-oriented, attacks for as little as
bragging rights
ƒ Other terms for beginner attacker are script kiddy, kiddiot, and
packet monkey
U.S. Department of
Homeland Security
United States
Secret Service
Insiders
ƒ Person authorized to use network or system due to
membership in organization
ƒ Often underestimated or overlooked as source because
security focuses on protecting network perimeter from outside
ƒ Virtually any disgruntled employee using valid account could
take unauthorized actions against network
ƒ Level of skill is highly varied, employee’s motivations often
include some form of sabotage or retribution
U.S. Department of
Homeland Security
United States
Secret Service
Phases of an Intrusion
ƒ Not every intrusion will include all phases, specific actions will
depend on objectives and abilities
ƒ Reconnaissance - Gathering information about target
ƒ Attack - Gathering, compiling, and launching exploits
ƒ Entrenchment - Ensuring continued access to target system
and hiding traces of access
ƒ Extraction - Data theft or enabling channels for outbound
attackers to new targets
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 2 - Reconnaissance
ƒ Goals
ƒ Strategies
ƒ Techniques - General Web Browsing and Search
ƒ Techniques - Public Records and Archives Search
ƒ Techniques - Target Web Site Examination
ƒ Techniques - Identifying Physical Attack Vectors
ƒ Techniques - Live Host Identification
ƒ Techniques - Identifying Available Ports/Protocols
ƒ Techniques - Type and Version Identification
ƒ Techniques - Vulnerability Scans
U.S. Department of
Homeland Security
United States
Secret Service
Reconnaissance Goals
ƒ Target organization, including its main functions, staff
members, assets, partner organizations, etc
ƒ Target individuals, including names, functions, contact
information, credentials, etc
ƒ Target computers and networks, including addresses,
functions, installed applications, operating systems, etc
ƒ Any other information that may be beneficial
U.S. Department of
Homeland Security
United States
Secret Service
Direct versus Indirect
ƒ Reconnaissance strategies can be defined as “direct” or
“indirect”
ƒ Direct techniques involve taking actions on or against
information systems owned and/or operated by targeted
individual or organization
ƒ Actions may be observed and logged by target
ƒ Indirect strategies do not involve actions on or against target
information systems, will not be observed and logged by target
U.S. Department of
Homeland Security
United States
Secret Service
Reconnaissance Strategies
ƒ General Web browsing and searching
ƒ Public records searches
ƒ Target Web site examination
ƒ Identify physical attack vectors
ƒ Live host identification
ƒ Identification of open communication channels
ƒ Operating system and application identification
ƒ Operating system and application vulnerability scans
U.S. Department of
Homeland Security
United States
Secret Service
General Web Browsing and Search
ƒ Valuable tool during information gathering phase, especially if
used with information obtained by other means
ƒ For example, Googling an employee’s name produces home
page with personal data or postings on newsgroups and
discussion forums that yield sensitive company data
ƒ Searches of online discussion forums, such as Usenet, may
also reveal information about an organization’s security
weaknesses
U.S. Department of
Homeland Security
United States
Secret Service
Possible Artifacts
ƒ Searching and browsing 3rd party Web sites typically do not
generate any artifacts on information systems belonging to
target organization or individual
ƒ Will leave artifacts on network that hosts sites being browsed,
most notably a record of URLs accessed during attacker’s
research
U.S. Department of
Homeland Security
United States
Secret Service
Public Records
ƒ Domain Name Service (DNS)
ƒ Whois
ƒ Web site content archives
ƒ Web site defacement archives
ƒ Web server OS and Uptime
ƒ Government business registration sites
U.S. Department of
Homeland Security
United States
Secret Service
DNS
ƒ Used to maintain public record of domain names and
corresponding IP addresses
ƒ If you browse Microsoft.com, computer first asks DNS server
how to find that domain name
ƒ DNS will respond with IP addresses linked to Microsoft.com
U.S. Department of
Homeland Security
United States
Secret Service
DNS Records
ƒ IP address of the Web server(s) that hosts the Web site for a
particular domain name
ƒ IP address of the e-mail server(s) that hosts e-mail for a
particular domain name
ƒ IP addresses of the DNS servers that are authoritative for a
domain name
ƒ Host/domain names associated with an IP address
U.S. Department of
Homeland Security
United States
Secret Service
Whois Records
ƒ Several Regional Internet Registries (RIRs) responsible for
leasing IP addresses to ISPs and other large organizations
ƒ “Whois” is Internet utility that queries RIR database for public
information
ƒ Range of IP addresses assigned to an organization
ƒ Geographical address used when organization registered
domain
ƒ Names or handles, phone numbers, and e-mail addresses of
points of contact (POCs) for an organization
U.S. Department of
Homeland Security
United States
Secret Service
Web site Content Archives
ƒ Wayback Machine (http://www.archive.org) provides archival
storage for Web pages no longer available through original
provider
ƒ Wayback Machine offers ability to check for previous, less
security-conscious versions of organization’s site
U.S. Department of
Homeland Security
United States
Secret Service
Defacement Archives
ƒ Defacement archival sites provide information, archives, and
statistics regarding Web defacements
ƒ Example is Zone-H (http://www.zone-h.com)
ƒ Attackers can use Zone-h to learn if target has been defaced
previously
ƒ Record of defacement and listing of operating system and Web
server in use at time of compromise may be available
U.S. Department of
Homeland Security
United States
Secret Service
Web Server OS and Uptime Archives
ƒ Netcraft (http://news.netcraft.com) site provides network and
server-specific search functionality
ƒ Enter domain name, Netcraft will determine operating system
and uptime of server to which domain name points
ƒ Netcraft attempts to discover type of Web server application
running and will provide record of results for previous attempts
to gather information
U.S. Department of
Homeland Security
United States
Secret Service
Government Business Registration
Sites
ƒ For tax and liability purposes, federal and most state
governments require businesses submit several forms
ƒ Forms often public record and searchable on Internet for
information about potential targets
ƒ For example, the U.S. Securities and Exchange Commission’s
EDGAR (Electronic Data Gathering, Analysis, and Retrieval)
system
U.S. Department of
Homeland Security
United States
Secret Service
Possible Artifacts
ƒ Searching third-party archive and public record sites typically
will not generate artifacts on systems belonging to target
organization or individual
ƒ Will leave artifacts on network that hosts sites being browsed,
most notably record of URLs accessed during attacker’s
research
ƒ Possible that queries made against third-party DNS server will
be forwarded to DNS server owned or operated by target
organization
U.S. Department of
Homeland Security
United States
Secret Service
Target Web Site Examination
ƒ Target organization Web sites can serve an attacker as either
source of general information or as point of entry into network
ƒ During recon, the following tactics may be used when
reviewing a site:
ƒ Manual browsing
ƒ Automated crawling
ƒ URI prediction/guessing
ƒ Source code review
U.S. Department of
Homeland Security
United States
Secret Service
Manual Browsing
ƒ Manually browsing target Web site is legitimate method for
gathering intelligence about site and organization running site
ƒ Disadvantage, it is a direct technique, will leave traces on
target system and network
ƒ Can pattern can mimic legitimate user or be obfuscated by use
of various proxies or routing techniques
ƒ Browsing could also be routed through another previously
compromised box
U.S. Department of
Homeland Security
United States
Secret Service
Automated Crawling
ƒ Web crawlers (AKA Robots or Spiders) can be used to
automatically browse site and follow all available links
ƒ Results of Web page download from each link, saved for later
review.
ƒ Technique very obvious to anyone that reads logs of target
Web server or any associated reverse proxies
U.S. Department of
Homeland Security
United States
Secret Service
URI Prediction
ƒ Not all pages at Web site accessible via link
ƒ Pages not directly advertised on site or linked sometimes
found by guessing at naming convention used by site designer
ƒ Guessing naming conventions can lead to discovery of
additional pages containing valuable data
ƒ Guessing resources can lead to error logs on server
ƒ Can be generic errors or in the case of a restricted folder,
security-related errors
U.S. Department of
Homeland Security
United States
Secret Service
Source Code Review
ƒ Other than server side scripts, all HTML/XML markup
language and client-side scripts, sent to Web browser that
requests associated page
ƒ Code can be reviewed for information disclosure (in
programmer comments for example), as well as for
weaknesses in code itself
U.S. Department of
Homeland Security
United States
Secret Service
Possible Artifacts
ƒ Any record of URL requests from suspicious IP addresses or
IP ranges in logs of Web server or associated Web proxies
ƒ Logs that show broad, systematic pattern of URL requests,
characteristic of site being crawled
ƒ Logs that show failed URL access attempts that list non-
existent files close in name to actual existing files
ƒ IDS alerts referencing Web crawling or other abnormal URL
access patterns
U.S. Department of
Homeland Security
United States
Secret Service
Attack Vectors
ƒ A pathway through which an attack may be launched
ƒ Most common attack vector is via Internet, a mixture of
physical mediums
ƒ There are times when specific vectors will be useful or even
required, such as when target cannot be reached via Internet
U.S. Department of
Homeland Security
United States
Secret Service
Attack Vectors
ƒ POTS (Plain Old Telephone System)
ƒ Wireless
ƒ Direct physical access to the device
ƒ Mixed (any route across the Internet)
U.S. Department of
Homeland Security
United States
Secret Service
Identifying POTS Vectors
ƒ War-dialing is identifying computers listening for remote
connections on a POTS line, if response received, computer is
listening, further attack actions may be taken
ƒ Growing less viable as more systems use dedicated Internet
connections rather than dial-up modems
U.S. Department of
Homeland Security
United States
Secret Service
Identifying Wireless Vectors
ƒ Attackers can use computer with 802.11 network interface to
listen for frames transmitted from 802.11 compliant wireless
networks
ƒ Different 802.11 specifications, attacker would have to ensure
that attack wireless NIC(s) supported all necessary versions
ƒ Other wireless specifications not typically viable vector, but
cellular access to information systems becoming more
prevalent and Bluetooth can be used in close range situations
U.S. Department of
Homeland Security
United States
Secret Service
Identifying Physical Vectors
ƒ An attacker could obtain direct physical access to a target
device through unauthorized access to building/room
ƒ If target device is owned by organization to which attacker is
employed, physical access may already be available
U.S. Department of
Homeland Security
United States
Secret Service
Possible Artifacts
ƒ Call records that show incoming calls to phone number with
modem attached
ƒ Standard physical security violations or suspicious activity (e.g.
unknown persons in building, tripped alarms, broken locks,
etc.)
ƒ Console logins recorded in system logs during times when
building empty, or when owner of user account not present
ƒ 802.11 frames from an unknown source
ƒ Presence of physical wiretap devices on a cable or device
U.S. Department of
Homeland Security
United States
Secret Service
Live Host Identification
ƒ The process of finding target hosts and verifying they are
online responding to communication requests
ƒ Can be done through several methods:
ƒ ICMP probes/sweeps
ƒ TCP/UDP probes/sweeps
ƒ Network monitoring
U.S. Department of
Homeland Security
United States
Secret Service
ICMP Probes/Sweeps
ƒ ICMP protocol used primarily for network troubleshooting, and
commonly to test hosts to see if they are online
ƒ ICMP “Echo Request” packet used to sweep multiple IP
addresses to elicit “echo response” packet from available hosts
ƒ Also called “ping sweep”
ƒ To pass through firewalls that block ICMP Echo Requests,
other ICMP packet types may be used to elicit response from
target host
U.S. Department of
Homeland Security
United States
Secret Service
TCP/UDP Sweeps
ƒ Modern networks sometimes block ICMP at external perimeter
defenses (firewalls and routers)
ƒ TCP and UDP packets can be sent instead in attempt to
circumvent this barrier
U.S. Department of
Homeland Security
United States
Secret Service
Network Monitoring
ƒ Passively monitoring network from compromised system can
identify other hosts instead network
ƒ Amount of traffic collected and number of hosts identified will
depend greatly upon sniffer placement within logical network
architecture
U.S. Department of
Homeland Security
United States
Secret Service
Possible Artifacts
ƒ IDS alerts referencing broad scans or sweeps
ƒ Firewall logs that show blocked packets attempting to reach a
large number of hosts in a short period of time
ƒ Firewall logs that show traffic blocked based upon abnormal
protocol options (unusual ICMP types, TCP ACK packets
existing outside of a session, etc.)
U.S. Department of
Homeland Security
United States
Secret Service
Ports/Protocols
ƒ Once physical vector identified, and target verified as being
online, attacker may choose to enumerate methods by which
target computer is willing to communicate
ƒ Communication methods include:
ƒ Accepted network and transport protocols (ICMP, TCP,
UDP)
ƒ Accepted application protocols (HTTP, FTP, SMTP, etc.)
ƒ Accepted TCP/UDP port numbers
U.S. Department of
Homeland Security
United States
Secret Service
Identifying TCP/UDP Port Numbers
ƒ Also called “Port Scanning,” connection attempts can be sent
to TCP and UDP ports to determine if application is listening
ƒ Scanner may attempt to initiate TCP session to multiple ports
ƒ Response to request with a TCP syn/ack packet, indicates
there is application or OS service listening on port
U.S. Department of
Homeland Security
United States
Secret Service
Identifying TCP/UDP Port Numbers
ƒ Scanner sends packets to UDP ports to test if ports are open
ƒ Since UDP is connectionless, packets either empty, or contain
data that not valid for protocol normally used with port
ƒ If port is open, the application listening on port will respond,
ƒ If port not open, ICMP Destination Unreachable message sent
U.S. Department of
Homeland Security
United States
Secret Service
Possible Artifacts
ƒ IDS alerts referencing port/protocol scans.
ƒ Firewall logs showing blocked attempts to access large
number of ports, in close sequence, on single host, in short
time
ƒ TCP session initiated to IP address, immediately terminated,
not followed by additional communication, observable in sniffer
log
ƒ TCP session only half set up then abandoned, potentially
observable in sniffer log
U.S. Department of
Homeland Security
United States
Secret Service
Type and Version Identification
ƒ Once open communication channel to device established,
attacker may need to know type and version of listening
application and/or operating system
ƒ Attack methods are highly dependant upon target versions and
patch levels
ƒ Common methods for identifying this information include:
ƒ Banner grabbing
ƒ Packet printing
U.S. Department of
Homeland Security
United States
Secret Service
Banner Grabbing
ƒ Process of connecting to commonly available services that
provide type and version information in greeting messages
U.S. Department of
Homeland Security
United States
Secret Service
Packet Printing
ƒ TCP/IP stack is part of operating system that controls TCP/IP
network communication
ƒ Implementation of stack differs on every operating system,
produces minor variances in operating system’s response to
certain requests
ƒ Scanning tools that perform packet printing (or fingerprinting)
check for variances on target host to identify operating system
U.S. Department of
Homeland Security
United States
Secret Service
Attributes Used for Packet Printing
ƒ ICMP Error Messages
ƒ TCP Sequence Numbers
ƒ TCP Options
ƒ TCP Timestamps
ƒ TCP Retransmissions Timeouts
ƒ Fragmentation Handling
ƒ IPID Values
U.S. Department of
Homeland Security
United States
Secret Service
Possible Artifacts
ƒ IDS alerts referencing scans
ƒ Errors in logs of scanned application or service referencing
communication problems or incomplete connection attempts
U.S. Department of
Homeland Security
United States
Secret Service
Targets for Vulnerability Scans
ƒ Web servers and FTP servers
ƒ E-mail servers
ƒ File and database servers
ƒ Directory service servers
ƒ RPC
ƒ Print services
ƒ Simple services
U.S. Department of
Homeland Security
United States
Secret Service
Vulnerability Scan Techniques
ƒ Presence of known vulnerable application component files
ƒ Ability to traverse into normally non-accessible directories on
host operating system
ƒ Ability to access unauthorized files
ƒ Ability to execute unauthorized code
U.S. Department of
Homeland Security
United States
Secret Service
Vulnerability Scan Techniques
ƒ Ability to make unauthorized calls to backend application or
database servers
ƒ Ability to route unauthorized data, such as spam or another
probe, through the server
ƒ Ability to trigger backchannel communication, a communication
session originating from target to hacker
U.S. Department of
Homeland Security
United States
Secret Service
Possible Artifacts
ƒ IDS alerts referencing a possible vulnerability scan
ƒ IDS alerts referencing any attack (Some vulnerability scans
launch partial attacks to determine if they’re possible, this may
trigger an IDS)
ƒ Any extremely large volume of traffic that is widely varied,
characteristic of comprehensive (multi-protocol), blatant
vulnerability scan
ƒ Any other activity characteristic of any attack
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 3 - Network Attacks
ƒ Goals
ƒ Strategic Categories
ƒ Strategies - Authentication Attacks
ƒ Techniques - Factor Guessing/Cracking
ƒ Techniques - Credential Recover/Reset
ƒ Techniques - Credential Injection
ƒ Techniques - Credential Theft
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 3 - Network Attacks
, continued
ƒ Strategies - Unexpected Input
ƒ Techniques - Excessive Input
ƒ Techniques - Excessive Input / Buffer Overflows
ƒ Techniques - Unexpected Input Content / XSS Attacks
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 3 - Network Attacks
, continued
ƒ Techniques - Unexpected Input Content / XSS Attacks
ƒ Techniques - Unexpected Input Content / Command Injection
ƒ Techniques - Unexpected Input Timing
ƒ Techniques - Unexpected Input Timing / Temp File Attacks
ƒ Techniques - Unexpected Input Timing / Request-Response
Latency Attacks
ƒ Techniques - Unexpected Input Timing / Boot Process Attacks
U.S. Department of
Homeland Security
United States
Secret Service
Entrenchment Goals
ƒ Unauthorized Access: Obtaining access to resource (system,
network, data, etc.) that is illegal, against policy, or otherwise
unauthorized by organization/individual owning resource
ƒ Access Privilege: Obtaining ability to manipulate resource
(change, delete, deactivate, etc.) to extent not authorized by
organization/individual owning resource
ƒ Denial of Service: Preventing resource from being available to
fulfill purpose either temporarily or permanently
U.S. Department of
Homeland Security
United States
Secret Service
Entrenchment Strategic Categories
ƒ Authentication Attacks: Attacks against authentication
mechanism for purpose of obtaining credentials to system or
network
ƒ Unexpected Input: Supplying input in way that will cause
application or operating system to behave in unauthorized
fashion, either to gain unauthorized access or disrupt
functionality of target system
U.S. Department of
Homeland Security
United States
Secret Service
Authentication Attack Strategies
ƒ Factor guessing/cracking: Attempting to determine factors
(passwords for example) to allow authentication to system
ƒ Credential recovery/reset: Taking actions to cause system or
administrator to send set of credentials to attacker
ƒ Credential injection: Creation of new credentials that will allow
authentication into target system
ƒ Credential theft: Theft of credentials either through inadvertent
disclosure or methods such as sniffing network traffic
U.S. Department of
Homeland Security
United States
Secret Service
Authentication and Authorization
ƒ Authentication attacks focus on obtaining credentials for
specific individual or account, or being authenticated as person
or account without credentials
ƒ What attacker can accomplish will depend on what
compromised/unauthorized account is allowed
ƒ If attacker requires more authority on system or network,
he/she will use another authentication attack, or different
attack strategy
U.S. Department of
Homeland Security
United States
Secret Service
Authentication Factors
ƒ “Something you know”: Usernames, passwords, pass-phrases,
answers to secret questions, etc
ƒ “Something you have”: USB tokens, smart cards, RFID tokens,
cookies, encryption keys, etc
ƒ “Something you are”: Retinal patterns, thumbprints, DNA, etc
U.S. Department of
Homeland Security
United States
Secret Service
Guessing/Cracking
ƒ Attacker generate set of values that represent possible
legitimate authentication factors
ƒ Attacker tests values against authentication system or stolen
set of password hashes to determine which ones are correct, if
any
U.S. Department of
Homeland Security
United States
Secret Service
Value Generation
ƒ Brute Force: Guessing every possible value for credential
using any combination of acceptable characters
ƒ Dictionary: Using only words from a dictionary to generate a
list of potential values, some attacks allow for small variances
such as common misspellings in the list of potential values
ƒ Hybrid: Using any combination of brute force and dictionary
mehtods
U.S. Department of
Homeland Security
United States
Secret Service
Value Generation
ƒ Pattern Recognition: For server/administrator assigned factors
that follow a pattern, an attacker could use the pattern to guess
the values of other valid factors
ƒ Pre-generated Hashes: When authentication factor is a hash
value of another piece of data, such as hash of password, list
of all possible hashes for a set of values can be pre-calculated,
term “rainbow table” is used to refer to some types of pre-
generated hash sets
U.S. Department of
Homeland Security
United States
Secret Service
Value Testing
ƒ Manually typing values in one at a time
ƒ Using an automated tool such as THC Hydra to pass test
values to authentication system
ƒ Using hashes calculated against values in set of data and
comparing to hashes stolen from authentication system or
used by authentication system
U.S. Department of
Homeland Security
United States
Secret Service
Value Testing and Session Length
ƒ When a session is underway and individual or application is
authenticated, that session will sometimes last for specific
amount of time
ƒ If credentials successfully guessed/cracked, may only be good
for length of session in progress
ƒ Likely the case when factor is temporary token, such as a
cookie
U.S. Department of
Homeland Security
United States
Secret Service
Possible Artifacts
ƒ Large numbers of failed authentication attempts for single
account seen in logs of authentication system
ƒ Failed authentication attempts for one or more non-existent
user account names
ƒ Failed authentication attempts that show series of passwords
that match pattern indicative of attack
ƒ IDS logs referencing password or authentication attack
U.S. Department of
Homeland Security
United States
Secret Service
Possible Artifacts
ƒ User accounts locked out due to high number of failures
ƒ List of passwords or password hashes found in text file in
abnormal location
ƒ The presence of password/hash dumping utilities such as
pwdump (pwdump.dll)
ƒ Authentication attempts (successful or failed) at abnormal
times, or for which authorized user of account does not recall
U.S. Department of
Homeland Security
United States
Secret Service
Credential Recovery and Reset
ƒ Users lose credentials (authentication factors), forget
password, lose tokens and sometimes can’t remember their
user names
ƒ Most authentication systems include mechanism for resetting a
user’s credentials to a new value, or recovering copy of lost
credentials
U.S. Department of
Homeland Security
United States
Secret Service
Recovery/Reset Mechanisms
ƒ Password reset links on Web sites
ƒ Help desk staff (available by phone or in person) that reset or
unlock an account
ƒ Operating system and directory user account management
interfaces that allow account with sufficient privilege to reset
credentials to other accounts
U.S. Department of
Homeland Security
United States
Secret Service
Credential Recovery/Reset Attack
Techniques
ƒ Requesting a password reset, and capturing password from
network
ƒ Registering a domain name previously belonging to another
person, recreating a previously existing e-mail address at
domain name, and using e-mail address as an authentication
factor and recipient for reset credentials transmissions
ƒ Directly requesting an individual’s credentials, while using
personal information about that individual
U.S. Department of
Homeland Security
United States
Secret Service
Possible Artifacts
ƒ Successful authentication attempts for account believed to be
no longer in use
ƒ Password resets for an account that was believed to be no
longer in use
ƒ Password resets for which the legitimate user of the account
claims to not be responsible
U.S. Department of
Homeland Security
United States
Secret Service
Credential Injection
ƒ Calling a help desk and requesting creation of an account
ƒ Using an online mechanism to request an account
ƒ Can be done to gain initial access to information on Web
sites that provide information
ƒ Some Web sites might require user validate identify for
registration, using some type of personal information
ƒ Others allow input of whatever information user chooses to
provide
ƒ Directly creating user accounts using administrative utility
U.S. Department of
Homeland Security
United States
Secret Service
Possible Artifacts
ƒ Existence of user account in account repository for which there
is no legitimate authorized user
ƒ Existence of user account in account repository that does not
match account naming convention for organization
ƒ Recorded logins of account for which there is no legitimate
authorized user
ƒ Log entries referencing account creation
U.S. Department of
Homeland Security
United States
Secret Service
Credential Theft
ƒ Capturing credentials as transmitted across network
ƒ Requires attacker have control or be present on one of
network mediums through which credentials sent
ƒ Tricking an individual into revealing credentials
ƒ Social Engineering
ƒ Stolen physical tokens such as ID cards and USB tokens
U.S. Department of
Homeland Security
United States
Secret Service
Possible Artifacts
ƒ Reports of theft of physical credentials or of disclosure of
credentials to someone believed authorized to make request
ƒ Successful authentication requests at abnormal times, or for
which authorized user of account does not recall
ƒ Existence of e-mails in e-mail repository or logged by proxy
that include requests for credentials, or links to Web pages
where such requests are made
U.S. Department of
Homeland Security
United States
Secret Service
Unexpected Input Strategies
ƒ Excessive Input: Sending more input than system or
application was expecting, or is able to handle
ƒ Unexpected Input Content: Sending input content that system
or application will process incorrectly due to inability to
recognize and/or properly control input type
ƒ Unexpected Input Timing: Sending input at times that system,
application or communication session is temporarily vulnerable
to interference
U.S. Department of
Homeland Security
United States
Secret Service
Excessive Input
ƒ Take advantage of a lack of input validation
ƒ Basic attack method to supply an excessive amount of input to
an application, operating system, or network
ƒ Effect could be to crash target or break a control system and
allow attacker to perform additional unauthorized actions
ƒ Buffer Overflow Attacks
ƒ Flooding
U.S. Department of
Homeland Security
United States
Secret Service
Input Size Validation
ƒ Properly coded applications should verify user-supplied input is
of proper size, If not, truncate input or produce error message
and/or stop the process
ƒ Network devices should terminate or block all communication
from hosts supplying excessive number of packets or service
requests
U.S. Department of
Homeland Security
United States
Secret Service
Excessive Input/Buffer Overflow
ƒ Buffer is temporary storage area, usually in RAM, allocated for
manipulation of data within a process
ƒ For instance, when logging into e-mail server, 32-character
space for username
ƒ Limitation is established in code of e-mail server application
and controls how much input will be accepted from user
U.S. Department of
Homeland Security
United States
Secret Service
Buffer Overflow Attack
ƒ Purposely sends entry too large for buffer
ƒ Sends in such a way that portion of entry is written to target
computer where program instruction code stored
ƒ Attacker uses method to intentionally cause execution of code
ƒ Result of code execution could be anything, but will often be
denial-of-service, command terminal session sent back to
attacker’s computer or injection of DLL or other program code
U.S. Department of
Homeland Security
United States
Secret Service
Possible Artifacts
ƒ Unexplained errors in the log files for application or service
attacked
ƒ Intrusion detection system alerts indicating a buffer overflow
ƒ Sniffer logs show large blocks of repetitive data, such as 0x90
or other hex values
ƒ Sniffer logs show blocks of data that do not conform to normal
rules for network protocol used
ƒ IDS alerts or sniffer logs showing common post-attack events
such as reverse shells, DLL transfer, OS commands, etc.
U.S. Department of
Homeland Security
United States
Secret Service
Cross-Site Scripting (XSS)
ƒ Cross-site scripting occurs when attacker supplies script
executed by another system’s Web browser or in another
browser window accessing a different site
U.S. Department of
Homeland Security
United States
Secret Service
Cross-Site Scripting (XSS)
ƒ Attacker posts script to website that permanently stores script
ƒ Serves it to other systems when they request the web page to
which it was posted
ƒ Allows attacker to run code in another person’s browser,
“persistent” or “stored” XSS attacks
U.S. Department of
Homeland Security
United States
Secret Service
Cross-Site Scripting (XSS)
ƒ Attacker will embed script in URL
ƒ If loaded by another user, will cause Web server to supply
malicious code to requesting browser to be executed in context
of requested page
ƒ Called “non-persistent” or “reflected” XSS attacks, rely on user
or browser to load the URL
U.S. Department of
Homeland Security
United States
Secret Service
Possible Artifacts of XSS
ƒ IDS alerts referencing an XSS attack
ƒ URLs containing scripting as seen in Web server and proxy
server logs, or in Web browser history
ƒ Web pages containing embedded scripting, as seen in proxy
server logs where proxy records full page
ƒ Unusual character encodings in URLs as seen in Web server
or proxy server logs, or in Web browser histories
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 4 - Entrenchment
ƒ Goals
ƒ StrategiesTechniques - Log
ƒ CleaningTechniques - Automatic
ƒ ExecutionTechniques - Hooking
ƒ Techniques - File Type Manipulation
ƒ Techniques - Naming Conventions and Placement
ƒ Techniques - Remote Connectivity
ƒ Techniques - File System Date/Time Stamp Manipulation
U.S. Department of
Homeland Security
United States
Secret Service
Entrenchment Goals
ƒ Attack Pivot Point: Attacker requires continued control of
system to use as pivot point from which to attack other
systems and networks
ƒ Data Theft: Attacker requires continued control of system to
perform data mining operations on system and any local
storage media.
ƒ General Control: Attacker wants to maintain control of system
as asset for various other uses
U.S. Department of
Homeland Security
United States
Secret Service
Entrenchment Goal Attributes
ƒ Entrenchment requires attacker retain some ability to remotely
control or manipulate target,
ƒ Method of control must remain undetected
U.S. Department of
Homeland Security
United States
Secret Service
Entrenchment Strategies
ƒ Log Cleaning: Removing records of unauthorized activities to
hide presence
ƒ Automatic Execution: Adding configuration changes that will
cause unauthorized programs to be started when host OS
boots, or restarts
ƒ Naming Conventions and Placement: Naming unauthorized
files, processes and configuration changes in way that they
appear legitimate or otherwise benign
U.S. Department of
Homeland Security
United States
Secret Service
Entrenchment Strategies
ƒ File Type Manipulation: Changing attributes which identify a
file’s type, such as signature and extension
ƒ Hooking: Intercepting calls to operating system so as to
interfere with data returned
ƒ Remote Connectivity: Maintaining one or more channels
through which compromised system can be remotely
controlled
U.S. Department of
Homeland Security
United States
Secret Service
Entrenchment Unauthorized Code
ƒ Entrenchment activities typically involve installation of
unauthorized code
ƒ This code will serve to perform one or more of functions
identified on previous slides
ƒ Common types include backdoors, rootkits and trojans
U.S. Department of
Homeland Security
United States
Secret Service
Log Cleaning
ƒ Attacker must remove records of unauthorized activity
ƒ Common record of unauthorized activity is a log entry
ƒ Log cleaning is process of deleting individual log entries, or
clearing entire log files to achieve goal
ƒ Can be done manually, with specific log cleaner malware, or
with a general-purpose rootkit
U.S. Department of
Homeland Security
United States
Secret Service
Log Cleaning - Record Deletion
ƒ Removing individual records easy with text logs
ƒ Attacker opens log in a text editor, deletes associated lines
and saves file
ƒ Proprietary log formats are much more difficult to handle
ƒ Attacker (or tools) must understand format of log, and be able
to identify beginning and end of each entry
ƒ Log viewers that correspond to proprietary logs do not typically
include function for removing individual entry
U.S. Department of
Homeland Security
United States
Secret Service
Log Cleaning - Log Clearing
ƒ Alternative to deleting individual records, clear an entire log
ƒ Done in situations where attacker is in hurry or does not have
mechanism for deleting individual records
ƒ Downside of log clearing is that it is quite noticeable
ƒ Attacker may clear log when not concerned with hiding
intrusion but more with removing information used to trace
attack back to source (not characteristic of entrenchment)
U.S. Department of
Homeland Security
United States
Secret Service
Log Cleaning - File Deletion
ƒ Attacker may choose to delete entire log file In lieu of record
deletion or log clearing
ƒ Least desirable of log cleaning methods as deletion of log file
is most noticeable and may cause system errors or crashes
ƒ More likely when dealing with more obscure log files not as
likely to be noticed
U.S. Department of
Homeland Security
United States
Secret Service
Log Cleaning - Possible Artifacts
ƒ File system date/time stamps changed during log cleaning
ƒ Log files that have had specific entries removed may have
abnormal time gaps between remaining entries
ƒ Empty or completely missing log files
ƒ Log entry indicating log was cleared
ƒ Existence of malicious code on system that includes log
cleaning as one of its functions
U.S. Department of
Homeland Security
United States
Secret Service
Automatically Starting Malware
ƒ Common for malicious code to be installed such that it will start
automatically when Windows boots
ƒ Main mechanism for accomplishing this is by adding Registry
key that will start executable file as new process or load library
into another process
ƒ Common methods include creating “Run” keys for executables,
installing new service, or trojanize legitimate service by
changing ServiceDLL key to load malicious DLL
U.S. Department of
Homeland Security
United States
Secret Service
Automatic Execution Directories
ƒ C:\Documents and Settings\All Users\Start
Menu\Programs\Startup
ƒ C:\Documents and Settings\<username>\Start
Menu\Programs\Startup
ƒ C:\Windows\Tasks
U.S. Department of
Homeland Security
United States
Secret Service
Job Scheduling
ƒ Most operating systems include mechanism for scheduling
executions to occur with various triggers, usually date/time
ƒ For Microsoft operating systems the Windows Task Scheduler
ƒ For Linux/Unix derivatives the “cron” daemon
U.S. Department of
Homeland Security
United States
Secret Service
Possible Artifacts
ƒ Existence of Registry entries that load unauthorized
executables or libraries
ƒ Unauthorized executables in auto-start directories
ƒ Unauthorized executables specified in an INI file
ƒ Existence of “.job” files on Windows
ƒ Entries in “crontab” file in Linux/Unix derivatives
ƒ Malicious code found on system which adds automatic start
configurations when executed
U.S. Department of
Homeland Security
United States
Secret Service
Hooking
ƒ Process of intercepting calls from one program to another so
as to interfere with any data exchanged
ƒ Can be used to hide data such as processes, files and specific
file contents
U.S. Department of
Homeland Security
United States
Secret Service
The OS API
ƒ API (Application Programming Interface) defined so programs
can be written that will run on and interface with OS
ƒ Functions that use API:
ƒ Directory listings
ƒ File copy and move operations
ƒ File editing operations
ƒ Network sending and receiving
ƒ Process and thread starting, stopping and enumeration
U.S. Department of
Homeland Security
United States
Secret Service
The OS API
ƒ For instance, when Windows Explorer used to view contents of
a directory, it is done via a standard API call from explorer.exe
to Windows OS DLL file
ƒ Operations are common during every day usage of OS
ƒ During entrenchment, same API calls used to find malicious
code
ƒ Important to attacker to prevent calls from revealing signs of
malware presence
U.S. Department of
Homeland Security
United States
Secret Service
OS API Hooking
ƒ Rootkits can be used to hook API calls, intercepting them at
various points
ƒ Sensitive values can be edited out of any returned values
U.S. Department of
Homeland Security
United States
Secret Service
Possible Artifacts of API Hooking
ƒ Hash values of OS files that have been hooked through direct
modification will be modified
ƒ Modified hash values for files indicates potential presence of
API hooks in memory
ƒ Technique is used by some rootkit detection programs such as
Rootkit Revealer
ƒ Discovery of API hooks during analysis of malicious code files
found on compromised system
U.S. Department of
Homeland Security
United States
Secret Service
File Type Manipulation
ƒ Attributes that define a file’s type can be manipulated to hide
file from general searches and from some specific forensic
analysis
ƒ Changing file extension to make file appear a different file type
ƒ Changing file signature to make file appear as a different file
U.S. Department of
Homeland Security
United States
Secret Service
Possible Artifacts
ƒ File signatures that do not match extension, or vice versa
ƒ Files that have a matching signature and extension, but which
cannot be read by appropriate application
U.S. Department of
Homeland Security
United States
Secret Service
Naming Conventions Strategies
ƒ Giving files/processes the same name as a legitimate file or
process
ƒ Giving files/processes a name that is slightly modified from
name of a legitimate file or process
ƒ Assigning a name that appears similar to the names of other
files
ƒ Use of special characters within names that will cause name to
blend in with other files, or will cause name to not be rendered
in certain interfaces
U.S. Department of
Homeland Security
United States
Secret Service
Placement Strategies
ƒ Placing unauthorized files in a directory where average user
unlikely to look
ƒ Placing unauthorized files named a certain way into a directory
with other files with similar names
ƒ Using normal directory names, but in wrong location, temp
directory often used
ƒ Storing files or file fragments in disk space not currently in use
ƒ Fragmenting file and inserting it into another file in small
amounts
U.S. Department of
Homeland Security
United States
Secret Service
Possible Artifacts
ƒ Files, Registry keys and processes misspelled or in wrong
location
ƒ Files that do not have appropriate hash value or file signature
ƒ Process running in more than one instance when not typical, or
when process is child of itself
ƒ Presence of programs on system used for file hiding
ƒ File names and directory locations discovered during analysis
of malicious code
U.S. Department of
Homeland Security
United States
Secret Service
Remote Connectivity
ƒ For extended operations intruder will require dependable
access to compromised systems
ƒ Could be legitimate channel that attacker accesses with stolen
credentials, or new channel created by attacker
U.S. Department of
Homeland Security
United States
Secret Service
Subverting Legitimate
Communication Channels
ƒ SMB/CIFS & DCE/RPC
ƒWindows file sharing and remote procedure protocols
ƒ used to move data to and from, or even configure a remote
system
ƒ Requires attacker has credentials to system
ƒ most useful for manipulating a system from another device
within same network
U.S. Department of
Homeland Security
United States
Secret Service
Subverting Legitimate
Communication Channels
ƒ Remote administration applications
ƒ Terminal Services, VNC and Remote Desktop
ƒ Allow someone to open a graphical interface to another
system
ƒ Attacker can authenticate to these pre-existing applications
with stolen credentials
ƒ Other applications such as SSH and telnet used to
administer a system through a command line interface
U.S. Department of
Homeland Security
United States
Secret Service
Subverting Legitimate
Communication Channels
ƒ VPN tunnels:
ƒ Attacker can utilize tunnels that already exist to or from
compromised system to jump to other devices and/or
networks
U.S. Department of
Homeland Security
United States
Secret Service
Remote Backdoors
ƒ A non-legitimate method for listening for remote connections
from attacker to compromised system
ƒ Typically accomplished by starting process that listens for
remote connection attempts
ƒ Might be normal TCP connection attempt, or may involve
series of packets sent to specific ports in specific order which
will cause full listening socket to open (called “port knocking”)
U.S. Department of
Homeland Security
United States
Secret Service
Outbound Initiated Channels
ƒ Compromised system may sit behind firewall, prevents
inbound remote connection attempts
ƒ Alternative to process listening for inbound connection
attempts, malicious code package configured to initiate
outbound communication
ƒ Connections, called “Reverse Channels,” frequently successful
due to fact that firewall egress rules are typically less stringent
than ingress rules
U.S. Department of
Homeland Security
United States
Secret Service
Possible Artifacts: Legitimate
Channel Usage
ƒ Unusual login times for otherwise authorized account.
ƒ Logins for authorized account that user of account did not
initiate
ƒ Authentication or subsequent activity that occurs to fast for
human to be manually directing activity
ƒ Existence of malicious code on compromised system that
includes functions for connecting to remote administration
applications such as SSH or VNC
U.S. Department of
Homeland Security
United States
Secret Service
Possible Artifacts: Backdoors
ƒ Abnormal ports open on a system
ƒ Suspicious processes attached to a listening port
ƒ Inbound connection attempts to workstations
ƒ Abnormal patterns of inbound packets or connection attempts
ƒ Existence of malicious code on compromised system found to
start listening service when executed
U.S. Department of
Homeland Security
United States
Secret Service
Possible Artifacts: Outbound
Channels
ƒ DNS queries for known-bad domain names or DNS hosts
ƒ Outbound connection attempts to known-bad or suspicious IP
addresses or IP ranges
ƒ Outbound connection attempts occurring over abnormal ports
ƒ Outbound connection attempts which exhibit abnormal content
ƒ Existence of malicious code on compromised system found to
beacon to domain name or IP address when executed
U.S. Department of
Homeland Security
United States
Secret Service
File System Date/Time Stamp
Manipulation
ƒ Attacker may attempt to hide unauthorized activity by changing
associated date/time stamps
ƒ Attempt to make it appear as if activity is unrelated
U.S. Department of
Homeland Security
United States
Secret Service
Possible Artifacts
ƒ Date/time stamps for malicious code executables or DLLs that
match date/time stamps on files created much earlier than
other related activity
ƒ Date/time stamps for suspicious Registry keys that are set
much earlier than other related activity
ƒ Existence of malicious code on system found to modify
date/time stamps on files or Registry keys when executed
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 5 - Infiltration and Extraction
ƒ Sniffers
ƒ Trust Relationships
ƒ Data Extraction
U.S. Department of
Homeland Security
United States
Secret Service
Sniffers
ƒ A program used to monitor or capture network traffic
ƒ Collected data usually stored on compromised system in
hidden file
ƒ Often run as disguised processes on systems as:
ƒ Trojanzed device drives
ƒ Renamed programs configured to start at boot
ƒ Trojanized applications
U.S. Department of
Homeland Security
United States
Secret Service
Trust Relationships
ƒ Mechanism whereby users logged on and authenticated to one
server can access resources on another without need to re-
authenticate
ƒ If server A trusts users logged into server B, server A has
established a one-way trust
ƒ If server A trusts server B, and server B trusts server A, they
have established a two-way or absolute trust
ƒ If A and B have a two-way trust and B also trusts C, C can
access A through a pass through or transitive trust
U.S. Department of
Homeland Security
United States
Secret Service
Trust Relationships
ƒ Server A ¯ ------- Server B (One way trust)
ƒ Server A ¯ -------˘ Server B (Two-way or absolute trust)
ƒ Server A ¯ -------˘ Server B ¯ -----Server C (Transitive trust)
U.S. Department of
Homeland Security
United States
Secret Service
Trust Relationship Exploitation
ƒ Compromising a trusted system, domain or server
ƒ Using or exploiting the LDAP service
ƒ Forging or spoofing authentication credentials
ƒ Spoofing source information
ƒ Piggybacking off an already trusted system
ƒ Hijacking a session from a trusted system
U.S. Department of
Homeland Security
United States
Secret Service
Data Extraction
ƒ Process of obtaining data off compromised system
ƒ To avoid detection, desired data is filtered for relevancy and
sent in way that will not overload system or trigger IDS
ƒ Embedding data deep into packets often allows extraction of
data without detection
ƒ Hacker may schedule job to send data during time when
network traffic is heavy in attempt to avoid detection by using
network traffic volume
U.S. Department of
Homeland Security
United States
Secret Service
Data Extraction Methods
ƒ E-mail
ƒ Masked as services like HTTP, DNS or ARP
ƒ Backdoor connections
ƒ Services run on a regular basis
ƒ Ftp or telnet login by attacker
ƒ A print job run to a remote location or file
U.S. Department of
Homeland Security
United States
Secret Service
U.S. Department of
Homeland Security
United States
Secret Service
Module 10 - Report Writing
U.S. Department of
Homeland Security
United States
Secret Service
You Will Learn . . .
ƒ General Report Writing Techniques
ƒ Specific Report Templates
ƒ Interviewing Techniques
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 1 - General Report Writing
Techniques
ƒ Examiner Notes
ƒ Forensic Reporting
ƒ Title Page
ƒ Items Analyzed
ƒ Relevant Software
ƒ Glossary
ƒ Details of Findings
ƒ Items Provided
ƒ Hyperlinking
U.S. Department of
Homeland Security
United States
Secret Service
Forensic Report
ƒ Culmination of time intensive, painstaking work
ƒ Should reflect time, effort, professionalism put forth to acquire
information presented
ƒ Should be organized, clear, concise, free of grammatical and
punctuation errors
ƒ Consider report reflection of yourself, your skills, attention to
detail, experience and work ethic
U.S. Department of
Homeland Security
United States
Secret Service
Examiner Notes
ƒ Documentation created during investigative and analysis
processes, provides basis for examiner to report results of
case
ƒ Written notes and documentation created during investigation
should be preserved and may be discoverable
ƒ Examiner notes taken during execution of forensic
examination, along with final report of findings are foundation
on which many digital media-related cases are built
U.S. Department of
Homeland Security
United States
Secret Service
Note Taking
ƒ Essential part of a forensic examination
ƒ Assists in creation of document that will provide record of
procedures and processes performed
ƒ Examination notes should present clear timeline of actions
taken and results of actions
ƒ Properly recorded notes provide repeatable roadmap of
examination
ƒ Another examiner should be able follow notes to reproduce
same results obtained in original exam
U.S. Department of
Homeland Security
United States
Secret Service
Note Taking
ƒ Number, date, and initial all note pages using [page #] of [total
# of pages] numbering schema to account for all pages
ƒ Not uncommon for extensive periods of time to pass between
time of examination and prosecutorial action
ƒ Thorough note taking helps ensure accurate testimony as to
actions taken during examination
ƒ Follow rule, “If it wasn’t documented, it didn’t happen”
U.S. Department of
Homeland Security
United States
Secret Service
Forensic Report
ƒ Provide details about purpose for forensic analysis
ƒ Describe physical and/or logical evidence analyzed
ƒ Define related programs, terms and their relevance
U.S. Department of
Homeland Security
United States
Secret Service
Forensic Report
ƒ Clearly identify persons related to examination including
yourself, requestor, suspects, other pertinent individuals
ƒ Address relevant evidence found during examination
ƒ Clearly, concisely explain items of evidentiary value found on
suspect media during analysis
ƒ Identify location and relevance of items of evidentiary value as
relating to reason for analysis and/or investigation
U.S. Department of
Homeland Security
United States
Secret Service
Forensic Report
ƒ Should define all technical terms using common language that
non-technical investigators and prosecutors can understand
ƒ Should always contain information listed on following slide,
headings may vary from organization to organization
U.S. Department of
Homeland Security
United States
Secret Service
Report Contents
ƒ Report heading
ƒ Support requested, reason or purpose for analysis
ƒ Summary of findings
ƒ Digital media analyzed
ƒ Analysis/Suspect software listings
ƒ Glossary of technical terms
ƒ Details of findings
ƒ Items provided
U.S. Department of
Homeland Security
United States
Secret Service
Title Page
ƒ Report Header
ƒ Support Requested
ƒ Current Case Status
ƒ Summary of Findings
ƒ See Title Page example in student book
U.S. Department of
Homeland Security
United States
Secret Service
Title Page
Item
Description
Title (To:)
Indicates report’s recipient and date. This
information is usually directly related to charging
document or request for service.
From
Identifies report’s author, including name,
organization, and contact information.
Subject
Indicates type of work performed, as well as
any suspect and/or local case reference
information.
U.S. Department of
Homeland Security
United States
Secret Service
Title Page
Item
Description
Support
Concisely states what charges or allegations
Requested or
were addressed by the analysis, charging
Purpose for
jurisdiction or entity, with regard to a specific
Analysis
investigation.
Status
Indicates the current case status, usually Open
or Closed. This may change nature from a
report to a status update.
U.S. Department of
Homeland Security
United States
Secret Service
Title Page
Item
Description
Summary of
A short narrative describing type and nature
Findings
of any evidentiary items located during analysis
with respect to specific allegations or
charges. Failure to locate items that support
allegations should also be indicated here, as
well as items that may exonerate.
U.S. Department of
Homeland Security
United States
Secret Service
Title Page
Item
Description
Footer
Includes author’s name, title/rank, and a
“Released” field for approval signature. Footer
may include a legal disclaimer. All pages of the
report should be numbered in the Page X of X
format.
U.S. Department of
Homeland Security
United States
Secret Service
Items Analyzed
ƒ Items Analyzed section of report describes in detail physical
and/or logical evidence analyzed
ƒ Always include original and verified hash values of all evidence
items
U.S. Department of
Homeland Security
United States
Secret Service
Physical Items Analyzed
ƒ Manufacturer
ƒ Model, serial, and part number (when possible)
ƒ Item description
ƒ Any specific markings
U.S. Department of
Homeland Security
United States
Secret Service
Logical Items Analyzed
ƒ Items Analyzed section of report details images sent for
analysis as well as any “original” evidence items
ƒ List image files in addition to physical containers
ƒ Identify by original file name and include hash or other
validation mechanism
ƒ See Items Analyzed example in student book
U.S. Department of
Homeland Security
United States
Secret Service
Relevant Software (Analysis)
ƒ List all software applications used during forensic examination
to process or analyze suspect media
ƒ Ensure to include primary analysis tool
ƒ Identify software version and brief description of software’s
functionality or use
U.S. Department of
Homeland Security
United States
Secret Service
Relevant Software (Suspect)
ƒ Identifying software on suspect’s machine necessary
component of case
ƒ Include any software that may have created and/or interacted
with data of evidentiary value
ƒ Include any software identified as having been deleted
ƒ Pay particular attention to software commonly used to hide
data or securely erase data
U.S. Department of
Homeland Security
United States
Secret Service
Relevant Software (Suspect)
ƒ Software name and version
ƒ Full path to where application was located on suspect media
ƒ Brief description of program functionality and how it relates to
Request for Analysis and/or investigation
ƒ Be prepared to further explain items in this listing during
prosecution
ƒ See Relevant Software example in student book
U.S. Department of
Homeland Security
United States
Secret Service
Glossary
ƒ Defines technical terms, document formats, and procedure
details referenced in report that may not be readily understood
by average non-technical reader
ƒ Define only terms integral to understanding of examination
findings as presented in report
ƒ See Glossary example in student book
U.S. Department of
Homeland Security
United States
Secret Service
Details of Findings
ƒ Provides detailed information about items of evidentiary value
found on suspect media
ƒ Information should be thorough, yet concise, and only contain
details relevant to request for analysis and/or investigation
ƒ Should not contain detailed information about processes
executed that did not produce relevant information, unless
negative result is relevant
ƒ Information about non-productive processes should be in notes
U.S. Department of
Homeland Security
United States
Secret Service
Organization of Report
ƒ Several different ways to organize report
ƒ May use different organizational strategies for different
investigations
ƒ Might, for example, organize report on case that contains
many pieces of media by listing all items found on each piece
of media as one section
ƒ In other cases, may be more effective to organize data by date
and time in chronological order, e.g., cases involving email,
chat and downloads
U.S. Department of
Homeland Security
United States
Secret Service
Organization of Report
ƒ Another method, organize evidence by its relationship to a
particular criminal charge and subject
ƒ Approach works well for criminal prosecution
ƒ Allows prosecutor to quickly see evidence relevant to a
particular charge and subject
U.S. Department of
Homeland Security
United States
Secret Service
Organization of Report
ƒ Evidence can be ordered or segregated by device
ƒ Good organizational choice for case that has many pieces of
media such as a large quantity of CD’s or DVD’s
ƒ Strategy is not normally best choice when all evidence is
located on one device
U.S. Department of
Homeland Security
United States
Secret Service
Organization of Report
ƒ If evidence has multiple partitions, could further subdivide
results by individual partition
ƒ Detail partition’s file format and size
ƒ To further clarify evidence, could divide findings by each user
account or profile
ƒ Detail important files, structure, data, and discrepancies
ƒ Explain techniques, methodology, and relevance of information
in brief narrative statements whenever possible
U.S. Department of
Homeland Security
United States
Secret Service
Organization of Report
ƒ If analysis did not result in discovery of items of evidentiary
value, a simple statement should be included stating negative
results
ƒ Ensures reader does not misinterpret an omission as failure to
conduct full and competent analysis of evidence
U.S. Department of
Homeland Security
United States
Secret Service
Organization of Report
ƒ Include techniques used to locate or extract evidence
ƒ Can refer to report if asked in court how a specific piece of
evidence was located
ƒ Example, if file found by manual inspection of drive, state this,
not every search has to be done with an automated tool
ƒ Take time to develop organized structure before writing
ƒ See Details of Findings example in student book
U.S. Department of
Homeland Security
United States
Secret Service
Items Provided
ƒ Details all physical items included with report when submitted
ƒ Should include all items specified in Items Analyzed section
ƒ Include items that were generated as a result of analysis, such
as a zip disk, floppy disk, or any CD-Rs of findings, as well as
any extracted, hard copy documents
ƒ See Items Provided example in student book
U.S. Department of
Homeland Security
United States
Secret Service
Use of Hyperlinks
ƒ Hyperlinking is a way to direct readers to items referred to in
report on electronic media
ƒ Often not practical to display certain items in actual report
ƒ Example, report may reference offensive, graphic image of
child pornography
ƒ Some readers may not have need to view image
ƒ Others may be required to do so in order to confirm existence
ƒ Hyperlink allows those with need to inspect file, while sparing
others from having to view it
U.S. Department of
Homeland Security
United States
Secret Service
Use of Hyperlinks
ƒ May be so many items of interest, it would be too cumbersome
to include all actual images in written report
ƒ In this situation, hyperlink could lead to entire directory that
contains multiple files
ƒ If report is included on CD or other large media, use hyperlinks
where possible to illustrate items of evidentiary value
ƒ If not familiar with how to hyperlink, see procedure in student
book
U.S. Department of
Homeland Security
United States
Secret Service
Procedure: Create a Hyperlink in
Microsoft Word
ƒ Step/Action in student book.
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 2 - Interviewing Techniques
ƒ Cyber Crime Interviews
ƒ Interview Process
U.S. Department of
Homeland Security
United States
Secret Service
Cyber Crime Interviews
ƒ Develop leads, confirm events, and obtain a complete picture
of crime
ƒ Can help direct investigation
ƒ Assist in understanding nature of the crime, locating more
evidence, identifying suspects
ƒ May assist in revealing true scope of investigation
ƒ Can provide information needed to ensure conviction
U.S. Department of
Homeland Security
United States
Secret Service
Accusatory versus Non-Accusatory
ƒ Difference between an interview and interrogation
ƒ Purpose of interview:
ƒ Gather information that will confirm events
ƒ Develop suspects and leads
ƒ Identify facts that lead to root causes of incident
ƒ Not focused on getting an individual to confess
U.S. Department of
Homeland Security
United States
Secret Service
Interviews
ƒ Often first and best opportunity to determine what has
happened and clarify confusion or misconceptions
ƒ To develop information
ƒ To obtain information
ƒ Develop rapport with subjects
ƒ Conducted in non-confrontational manner
U.S. Department of
Homeland Security
United States
Secret Service
Interrogations
ƒ Focus on presenting facts of case and eliciting statements that
confirm suspect’s involvement
U.S. Department of
Homeland Security
United States
Secret Service
Accusatory versus Non-Accusatory
ƒ Accusatory approach may inhibit effective communication
ƒ Take into account perceptions of interviewees
ƒ Many people you will encounter during initial interviews have
little to no exposure to law enforcement outside of television
ƒ People may view interaction with government agents through
lens of personal attitudes, experiences, and beliefs about law
enforcement
ƒ Law enforcement often cast in negative light and government
agents seen as dimwitted and overbearing
U.S. Department of
Homeland Security
United States
Secret Service
Interview Process
ƒ Planning/Research
ƒ Opening/Rapport
ƒ General Questioning
ƒ Detailed Questioning
ƒ Interview Termination
U.S. Department of
Homeland Security
United States
Secret Service
Planning and Research
ƒ Conduct preliminary research on interviewee and organization
ƒ Helps to draft appropriate questions and an interviewing
approach that will be successful
ƒ knowledge and comprehension of technical subject’s area of
expertise presents professional and approachable image
ƒ Knowledge gained through planning and research enables
interviewer to ask more intelligent questions
U.S. Department of
Homeland Security
United States
Secret Service
Opening/Rapport
ƒ The initial contact is critical to obtaining cooperation
ƒ Showing respect for individual and organization and explaining
importance of questions, vital steps in obtaining cooperation
ƒ Explain to interview subjects that you need assistance in
determining facts of case and understanding issues involved
U.S. Department of
Homeland Security
United States
Secret Service
General Questioning
ƒ Start with open-ended questions that allow subject to explain
his/her knowledge of events
ƒ Questions should develop a general framework of incident
derived from subject’s personal knowledge of factual events
ƒ Important to obtain general outline of events that transpired to
document information relevant to case
U.S. Department of
Homeland Security
United States
Secret Service
General Questions Address
ƒ Key incidents that brought situation to light
ƒ Hardware involved (routers, firewalls, IDS)
ƒ Specific individuals involved in incident and actions they took
with any evidence
ƒ Physical locations of effected machines and people
ƒ Technology that will need clarification during Detailed
Questioning phase
U.S. Department of
Homeland Security
United States
Secret Service
Detailed Questions Address
ƒ Software and hardware model numbers and versions
ƒ Network monitoring and logging setup
ƒ Collection of current logs
ƒ Network diagrams
ƒ User policies
ƒ List of people who had logical and physical access
U.S. Department of
Homeland Security
United States
Secret Service

 

 

 

 

 

 

 

Content      ..     15      16      17      18     ..