Thursday, May 28, 2015

CyberCrime training in Bahrain


I've just been one among trainers on the "Training Course on Combating CyberCrime", organised by Judicial and Legal Institute, Kingdom of Bahrain in cooperation with GPEN, Global Prosecutors E-Crime Network.  It was very interesting event, very successful and really high above usual, perfect organisation by our hosts, judges, prosecutors, police officers from all Arab gulf states, with immense interest and will to participate, 
Instead of pure "slide & lecture" scenario, it was full interaction, questions, answers, case comments with perfect simultaneous translation,  Language is always problem, not only pure mother tongue to mother tongue, but also more important in our situation technical language to legal language and tradition. 
I'm sure that training gets its purpose, interaction and cooperation among all participants was from start, that was the key goal, basically all definitions and answers were provided by participants, trainers were more moderators and ones who asked hard questions.
The discussion and events makes me think about terms we use and its meaning I think I should write one post on word Cyber which is often used this days

Sunday, May 10, 2015

Competition workshop

Recently I was involved in a digital forensic workshop for a competition agency.

It is an interesting issue because a great deal of work in competition enforcement agencies today is related to handling digital evidence. There are a lot of document on the international competition  network site which lively present the state of anti cartel practice. Each anti cartel agency has its own procedures and history but there is one common thing, introduction of digital evidence support. Some agencies are even completely moved to electronic documents while others are handling paper documents or being completely on the paper documentation. The process which leads to digitization and accepting digital evidence is not an easy one, it takes a lot of time and effort, and usually requires thinking about procedures and documentation workflow in the anti cartel agency. Such processes can take a long time and have a lot of mishaps.
I was involved in preparing a  raid simulation as the basic part of the workshop, very nice  operation with a lot of things to learn.  The result of workshop was a set of forms and blueprints which give the full planing capability for the agency. The idea was well tested from disaster recovery and business continuity practices. A simple approach where you create a set of procedures and documents which drive you through the whole event, it also gives a nice opportunity for role play approach and testing scenarios. I hope we did a good thing.
Later on DataFocus2015 Mr. Mislav Kršulović from Croatian Competition Agency did presentation about "Dawn raid in practice", To my great pleasure this state of art example from real life showed our workshop was very close to reality.

Students and Image Forensics

After a long wait, I finally have a candidate from Vsite who is interested in image forensics, a perfect challenge. There are a lot of talks about tools, applications and methods on how to use image forensics in our law enforcement community.

Digital image forensics is a big field running at a very fast pace. Our position is more towards practical application and tools for handling and comparing images rather than basic scientific work. Most of the practical problems in our local community are in the classification and recognition of  images extracted from mobiles devices, computers etc. It boils down to handling hashes and effectively working with a huge number of files. I believe we will have to tackle this part of the situation in order to propose or implement a solution which can automate such tasks. 

We will all have to discuss the possibilities in order to combine the fresh inquisitive mind of the students with the tools and realities of law enforcement, while at the same time getting some practical results.  My idea is to shape a practical part for a graduation thesis into practical tools or systems which have to be used in real life and also to be a proof of concepts for further work and expansion,

I really hope for some nice student work, useful tools and a few published articles.

I'll post about how events will go, can be interesting and inspiring too.



Wednesday, April 29, 2015

Articles for Mipro 2015 conference

Mipro is nice technical conference in Opatija, our mother company IN2 is a sponsor so we put set of articles about digital forensics and security. There are very strict reviewers but we managed to get trough. I wrote about experience in mobile forensics  professional training since 2012 under posh title "Concepts and methodology in mobile devices digital forensics education and training". It is about relating our experience with issues mentioned in Stephen Pearson and Richard Watson book : “DigitalTriage Forensics”, Syngress ,July 13, 2010,  ISBN-13: 978-1-59749-596-7, and  Gary C. Kessler presentation :“Is Mobile Device ForensicsReally "Forensics"?”,  NIST Mobile Forensics Workshop, Gaithersburg, MD, June 2014. Paper get a rough recension, a lot of requests for clarifying,  I suppose the subject was interesting. I'll add article when it will available trough official conference site.
 "Digital Triage Forensics" is my old favorite, I loved since I read it.  Book  address practical issues in putting whole organization into motion, not only mobile  forensics issues. Unfortunately tools used are outdated, plenty of new versions and changes come since 2010,  but everything else is still extremely useful, especially if you are working with military or police. 

Sunday, April 12, 2015

DataFoucs 2015 - 31 March 2015 - Zagreb, Croatia

I've been forgetting to put a few lines about DataFocus 2015 in Zagreb from the 31st March 2015.  It's the fourth and got the best reviews.  As far as I was concerned, I was to remain only on the margins of the conference and on the lunch actively trying to avoid any responsibilities and enjoy good food and interesting lectures. However, this was not meant to be. There were a lot of interesting talks and a lot of interesting tools, NUIX, Belkasoft, FTK, EnCase, Oxygen. At the end there were a lot of happy winners with the lotttery, especially among our Police Accademy students. 


Workshops were fully attended with people popping in at the last minute. My own small contribution was an unusual one. For such events with international lecturers something can go wrong, Murphy's law is always somewhere around, and there is always a backup plan for emergencies, This time, lecturers for first lecture at legal track "Legal and Investigative Aspects of Bitcoin" were unable to get to Zagreb on time, the day before DataFocus.  Since the subject was extremely interesting it was decided not to replace the lecture with the scheduled backup, but to replace the lecturer with apologies and hopefully some add-on value. As the task landed on me, I had to do my best in preparing for that lecture in one day. To make things worse my knowledge about Bitcon, at the time, was twopence worth. In short it was a long 24 hours, I even decline attending the VIP dinner the night before the conference because I was studying :) :)

The original material by Vaciago Giuseppe and Dal Checco Paolo was very good and concise but, to me, a lot of details seemed missing. So I used resources from the excellent online book "Mastering Bitcoin By: Andreas M. Antonopoulos".  The further I went through the book the more impressed and intrigued I got. The author of Bitcoin was really a genius in more than one field.  The lecture went well, my friend Blerim Krasniqi has taken some pictures of lecture, it all went well.







Tuesday, March 24, 2015

IT Risk Seminar, Zagreb March 2015

Left to right: Me and Jerko Burić
Last Thursday (19th of March 2015), I attended the local IT Risk Seminar together with my colleague Jerko Burić. As Jerko was giving his presentation on Cyberforensics I was networking and answering questions that came from insurance companies. Most questions were about how to raise awareness within different organizations regarding cyber risks and cyber and digital security.

As the initial post covering the goal of the event said: "The seminar is intended for IT Risk corporate sector, the IT sector and the insurance and banking and Croatian regions. The conference program is rich in speakers - top experts from the field of cyber security and IT security risks from the Croatian and Europe." It was an extremely interesting mix of presenters and attendees. It is not often that you find Digital Forensic experts in the same place as insurance companies and bank representatives.  I was rather surprised that there were only a few law enforcement agencies, but then again, this was targeting the insurance companies and forensic experts.

As I was aware of a local insurance company -which will remained unnamed- that has been working on fine-tuning a possible insurance policy covering Insurance for Cyber Crime for the last 4 years, it was interesting to see the presentation from the UK by Mike Shen. He really crunched down the numbers showing how much an actual incident would cost on all different levels, including the digital forensic related technical services. Only part of his presentation is available here.

The lectures from EUCert, our local Cert and law enforcement shows important development among all involved in the security investigation process. The key event was last year's Zeus malware outbursts, where all agencies involved were finally cooperating, from banks to clients and law enforcement agencies. Without which any policy would have been a failure!

The fun part of this event for me was when I was having a good laugh while witnessing the heated discussion panel. I can't remember being around people that got so fired up in public. Maybe I'm not supposed to mention this, but life is about being real. We have to give them credit for having the courage to sit together and discuss all this.

Conclusions from this event for me are that companies are now starting to see Digital and Cyber Security as a real threat.  If an insurance company intends to go into the deep and offer this insurance, covering the company's digital fortress, they'll have to take quite a lot into consideration, not only how to qualify a customer (like a health check) but how to insure the customer stayed healthy before they got hit. Just this idea and it's set up with an insurance company can give any engineer a good splitting headache. I believe it can be challenging to locate statistical information with regards to actual digital forensic incidents worldwide, as they are not all reported to one governing body. But, if there is a will there will be a way. Then again, facing business continuity plans and reality, we have to ask ourselves:  Which bank would go public saying they've been hacked, if they can keep it quite and deal with it as fast as possible?

Anyway, as a technical guy, it is best for me to leave the insurance policy set up to the insurance companies :) They'll know where to find me if they need detailed and outlined digital forensic processes and setups.




Saturday, February 7, 2015

Modern Cars and Digital Forensics

There is one article on EnCase blog, "The Car of the Future May be a Forensic Gold Mine"

Looks like a discussion about car and digital forensics started on CEIC 2014 which then spread to LinkedIn groups. Very interesting topic, also very frustrating since most of the current digital forensic tools are not up for the task. It is possible to extract data from cars but only partially, and by using available general purpose tools on forensically well know car subsystems, like GPS. There are plenty of examples of car GPS systems with other subsystems analyses as well as CAN analyses. This should provide a great improvement over early investigations with cruise system error related accidents and deaths. This story requires a lot of research, even though the case is still ongoing, due to the important fact that the relevant data was not extracted from the car systems, so we there is a serious problem there.
More recent story "BMW Fixes Software Flaw that Affected 2.2 Million Cars (February 2, 2015)"
published on SANS which shows the spread of the problem to almost the size of the fleet of mobile devices.

To be honest, modern car digital forensic more like scada system analyses than anything else. Even worse,  the car systems are not designed to be forensically reliable or even computationally safe. Car systems are designed to be reliable as old mechanical control systems in cars were before.  Electronics, communications and interacting electronic/computing systems makes this situation even worse. 
I would recommend that anyone dealing with car forensics or security should go to Nancy Leveson's page  and read few papers.