Sunday, April 12, 2015

DataFoucs 2015 - 31 March 2015 - Zagreb, Croatia

I've been forgetting to put a few lines about DataFocus 2015 in Zagreb from the 31st March 2015.  It's the fourth and got the best reviews.  As far as I was concerned, I was to remain only on the margins of the conference and on the lunch actively trying to avoid any responsibilities and enjoy good food and interesting lectures. However, this was not meant to be. There were a lot of interesting talks and a lot of interesting tools, NUIX, Belkasoft, FTK, EnCase, Oxygen. At the end there were a lot of happy winners with the lotttery, especially among our Police Accademy students. 


Workshops were fully attended with people popping in at the last minute. My own small contribution was an unusual one. For such events with international lecturers something can go wrong, Murphy's law is always somewhere around, and there is always a backup plan for emergencies, This time, lecturers for first lecture at legal track "Legal and Investigative Aspects of Bitcoin" were unable to get to Zagreb on time, the day before DataFocus.  Since the subject was extremely interesting it was decided not to replace the lecture with the scheduled backup, but to replace the lecturer with apologies and hopefully some add-on value. As the task landed on me, I had to do my best in preparing for that lecture in one day. To make things worse my knowledge about Bitcon, at the time, was twopence worth. In short it was a long 24 hours, I even decline attending the VIP dinner the night before the conference because I was studying :) :)

The original material by Vaciago Giuseppe and Dal Checco Paolo was very good and concise but, to me, a lot of details seemed missing. So I used resources from the excellent online book "Mastering Bitcoin By: Andreas M. Antonopoulos".  The further I went through the book the more impressed and intrigued I got. The author of Bitcoin was really a genius in more than one field.  The lecture went well, my friend Blerim Krasniqi has taken some pictures of lecture, it all went well.







Tuesday, March 24, 2015

IT Risk Seminar, Zagreb March 2015

Left to right: Me and Jerko Burić
Last Thursday (19th of March 2015), I attended the local IT Risk Seminar together with my colleague Jerko Burić. As Jerko was giving his presentation on Cyberforensics I was networking and answering questions that came from insurance companies. Most questions were about how to raise awareness within different organizations regarding cyber risks and cyber and digital security.

As the initial post covering the goal of the event said: "The seminar is intended for IT Risk corporate sector, the IT sector and the insurance and banking and Croatian regions. The conference program is rich in speakers - top experts from the field of cyber security and IT security risks from the Croatian and Europe." It was an extremely interesting mix of presenters and attendees. It is not often that you find Digital Forensic experts in the same place as insurance companies and bank representatives.  I was rather surprised that there were only a few law enforcement agencies, but then again, this was targeting the insurance companies and forensic experts.

As I was aware of a local insurance company -which will remained unnamed- that has been working on fine-tuning a possible insurance policy covering Insurance for Cyber Crime for the last 4 years, it was interesting to see the presentation from the UK by Mike Shen. He really crunched down the numbers showing how much an actual incident would cost on all different levels, including the digital forensic related technical services. Only part of his presentation is available here.

The lectures from EUCert, our local Cert and law enforcement shows important development among all involved in the security investigation process. The key event was last year's Zeus malware outbursts, where all agencies involved were finally cooperating, from banks to clients and law enforcement agencies. Without which any policy would have been a failure!

The fun part of this event for me was when I was having a good laugh while witnessing the heated discussion panel. I can't remember being around people that got so fired up in public. Maybe I'm not supposed to mention this, but life is about being real. We have to give them credit for having the courage to sit together and discuss all this.

Conclusions from this event for me are that companies are now starting to see Digital and Cyber Security as a real threat.  If an insurance company intends to go into the deep and offer this insurance, covering the company's digital fortress, they'll have to take quite a lot into consideration, not only how to qualify a customer (like a health check) but how to insure the customer stayed healthy before they got hit. Just this idea and it's set up with an insurance company can give any engineer a good splitting headache. I believe it can be challenging to locate statistical information with regards to actual digital forensic incidents worldwide, as they are not all reported to one governing body. But, if there is a will there will be a way. Then again, facing business continuity plans and reality, we have to ask ourselves:  Which bank would go public saying they've been hacked, if they can keep it quite and deal with it as fast as possible?

Anyway, as a technical guy, it is best for me to leave the insurance policy set up to the insurance companies :) They'll know where to find me if they need detailed and outlined digital forensic processes and setups.




Saturday, February 7, 2015

Modern Cars and Digital Forensics

There is one article on EnCase blog, "The Car of the Future May be a Forensic Gold Mine"

Looks like a discussion about car and digital forensics started on CEIC 2014 which then spread to LinkedIn groups. Very interesting topic, also very frustrating since most of the current digital forensic tools are not up for the task. It is possible to extract data from cars but only partially, and by using available general purpose tools on forensically well know car subsystems, like GPS. There are plenty of examples of car GPS systems with other subsystems analyses as well as CAN analyses. This should provide a great improvement over early investigations with cruise system error related accidents and deaths. This story requires a lot of research, even though the case is still ongoing, due to the important fact that the relevant data was not extracted from the car systems, so we there is a serious problem there.
More recent story "BMW Fixes Software Flaw that Affected 2.2 Million Cars (February 2, 2015)"
published on SANS which shows the spread of the problem to almost the size of the fleet of mobile devices.

To be honest, modern car digital forensic more like scada system analyses than anything else. Even worse,  the car systems are not designed to be forensically reliable or even computationally safe. Car systems are designed to be reliable as old mechanical control systems in cars were before.  Electronics, communications and interacting electronic/computing systems makes this situation even worse. 
I would recommend that anyone dealing with car forensics or security should go to Nancy Leveson's page  and read few papers.




Sunday, January 18, 2015

RFOR is finishing at VISTE

Lecturing at this academic year is just about to  finish, it is exam time coming, time to wrap up and lessons learned not only for students but for teachers too.

As for the the first run of the Digital Forensics Basics (RFOR) on Vsite I have my doubts and fears if I done things as it is supposed to be.  Class was small 18 people, easy to work and enjoyable maybe a bit to much chance for lecturers ego trip sometimes.

Results are OK, but that can be misleading, I still feel we need more practical work with commercial tools. To add some practice work we added some python scripting, based on "Python Forensics" and some elements from "Violent Python", all trough SIFT workstation from SANS.

As we are at computer science and engineering school a lot of things are already known, so we'he been concentrated to general principles and ideas, not so much on the methods and tools.

My colleague  Darijo Puntarić was busy with laboratory exercises, as CCIE he added a lot of good stuff especially to network forensic part.





An article about law enforcement and high end computer skills

This one is posted at one of the sites I've read often, "Information Warfare: Scary Monsters Pursue The FBI"  title is a bit scary, actually shows the problem  if law enforcement has to  be about computer security issues. To be honest most of the organisation of any kind has this problem  if they are not from start based on computing technology.  Unfortunately even such powerful organizations as FBI or DOJ   somehow lack strategic approach and understanding of the problem. At first glance it is OK, found you re in trouble and there is someone who can help you .. cooperate use resources and prepare but for what and how,  results are showing this is missing. 

Monday, January 12, 2015

Digital Forensic Tools and parallelism - initial thoughts

Without going deep into any theoretical discussion it is quit obvious that digital forensic tasks are actually very well suited for parallel processing. The key issue is readonly access to data in most data intensive operations, but also in other parallelism can be applied too taking into account nature of digital forensic process and its dataprocessing steps:
  • acquisition, 
  • analyses and 
  • reporting. 
If we discuss different each step in forensic process we can see how parallelism can be used.
First data processing step in any digital forensics task is acquisition of data from device or media .

Device acquisition is serial task, since  without live access we have only one channel  the devices. Parallelism here is more question of device itself than forensic tool. As for example if we have more than one access channel to  device data  and we are in read only mode acquisition can be parallel too.
Key element is readonly access to data.

In other steps  like during analyses,  situation is just slightly different.  It is usually data extraction and reconstruction which results finally in data size reduction, Data which we are using in this step is under read-only access, while results of processing are written and maybe again read back into process.  This two modes of data access are well separated in analyses process. Each analyses task can go  in parallel with other tasks without corrupting data. In most situation this new result are actually metadata. Such metadata is much smaller than original data, and can be put back into analyses cycle if it is necessary. As it is shown for most of the analyses step parallelism also  can be used.

To illustrate this in more details we can discuss important forensic tasks indexing and  raw search.
Indexing is specific since it can generate almost same volume of data as the original data. It is also highly repetitive task, since it depends new recovered or unlocked documents to be indexed and data added to existing index structure. Operations are very disk intensive  but again can be done effectively in parallel, especially if index structure is stored in database way. It maybe sound strange but raw search is very close to index process, especially in phase of building index structure, in fact it is the same, simply said we have to extract raw data from disk and in that data find words which are indexed. Exactly the same as raw search do.  Conclusion again is the same parallelism can be used too, also parallelism is important for indexing and search tasks since it requires processing  huge amount of data .

Forensic data processing  usually generates metadata which presents a new logical view on the original data. Good examples are bookmarks, so much loved in digital forensics.

As for report creating again the same approach works, from data and bookmarks report is compiled, data is not changed in that process, so it can be parallelised too.

So what is conclusion ?
Parallelism is highly desirable in digital forensics, but we don't have tools which are very effective in using parallelism, This is something what is happening just now with various level of success for different vendors.
My opinion is that vendors are landlocked in their tools and the real advantage of parallelism is in type of forensic tools which can be fully automated and  can freely and easily cooperate, being scripted and capable of working standardised on the highly parallel computing infrastructure:)

I'll elaborate on this later, while talking about what such tools and systems have to be able to do and which already existing knowledge we have.









Monday, January 5, 2015

MS Windows, Python and Digital Forensics woes

Since Vista comes it turns out that it is impossible to compile and add into Python on windows essential libraries like libewf  It is very frustrating and senseless , but this is MS way of things ..
It boils down to undocumented features and behaviour of required low level windows calls and instrumentation. My colleague Jakob spend a lot of time to try and test all available compiling procedures but nothing worked in the end. It all worked once in 2009 and earlier but not today.
This event troubles us a because of planned training propositions, since we have to introduce additional unix topics  where tools work as it is supposed to work.