Wednesday, June 1, 2016

EnCase direct servlet preview

I've done a short ppt on how direct servlet is created and used in EnCase. Recently we often have such  questions so to simplify my work I've done small ppt which follows manual and put in on the Slideshare. It is easier to discuss with ppt than with going trough manual pages.

Monday, May 30, 2016

Managing digital forensic lab

For last few weeks I found myself in awkward situation, almost like echo from some previous jobs,
preparing materials for training titled "Managing digital forensic laboratory".  This is almost accidental event, a first run of that training since we announced it few years ago.
The story behind course is strange by itself too, It all started as result of a failure. There was one nice big project about setting up digital forensic lab, for dual purpose forensics and education. Huge effort was put into project, especially in preparation for managing lab materials and intro course for that. Since project didn't realise we did logical move, reused prepared materials, and squeezed into 3 day trainng expandable to 5 days.  Basic theory  is based on excellent "Building a Digital Forensic.Laboratory: Establishing and Managing a Successful Facility"book by Andrew Jones and Craig Valli. I've decided to add additional things based of recent development for datacenters and open source tools for compatibility and certification based on "Sarbanes-Oxley IT Compliance Using Open Source Tools, 2nd Edition" where we can show how to inexpensively build a managing and control infrastructure even on knoppix.  For lab case management I've decided to implement Foreman tool  and mention comparation with other case management tools like FTK lab.
To cover datacenter approach and introduce good practice in managing a lot of computing power, what is always missing  I've decided to use "Enterprise Data Center Design and Methodology"
By: Rob Snevely. There is a lot of other papers and web resources to mention and talk about ...

Thursday, May 19, 2016

FER lecture "Moć forenzičkih alata"

Yesterday I done small 60 minutes lecture on my old UNI, going there always brings nostalgia back, remebering and daydreaming. What always  hits you is how many years have passed. Faces looks same, bright, young only difference are labtops and smartphones all around, when I saw myself in reflection I feel a pang of jealousy,  Amstrad 6128 and  ZX81 from my days will be helplesly  lost among new thingies around. Even mighty VAX under ULTRIX too..

With such thoughts, new wrinkles on my face, and new glasess I've get into old lecture room, same where 20 years ago we were playing with Expect langugage scripts  tailoring   some Cisco ATM switches configuration for experimental live video streaming.

This time skill was needed only to find right presenter stick all other was working more or less as expected. My battred Dell labtop was working well, MS Powerpoint 2016 has frozen only once, probably just to show who is the boss. In the audience was few familiar faces, in first row left my young and gifted colleague Savina Gruicic.

On the FER lecture home page there are links to video capture and links to presentation.

Dr Pale did intro words and I've started. My plan was to do short as possible, skimming on top of digital forensic topics, badmouth a bit about current tools and practices, show brief run trough Encase v6,v7 Ufed, get people thinking about and asking, hardest of all forcing myself to keep in 60 minutes boundaries.  People there are all from computer science community, I just need to show a topic, put a few words on context and let them think laudly :)
At the end we put in some new cyber-X words, Cyber-Hygiene and Cyber-illiteracy really it is fun to do Cyber words.
There was plenty of questions I can recall only a few,  Like where you can get careere and trainign for digital forensic in Croatia, it was hard to answer since in 2 weeks I'll do some work in Daka, Bangladesh to eran my living :) ..



Thursday, May 5, 2016

Setting up EnCase classroom in Polytechnic of Zagreb

Just today we managed to setup EnCase classroom with 10 workplaces. It was pleasure and fun, relaxed work with everyone cooperating. Really relaxing action

20.5.2016 Still no official photos from classroom... I don't know if this is just laziness or hush-hush

Actually this is the first official classroom for digital forensic with state of art commercial software. around 

Tuesday, May 3, 2016

Cyber attacks and energy dependecy

In the sense of recent attacks on power providing infrastructure around the globe, I've remembered my thoughts when I was last time in Gulf countries, Bahrain and Saudi Arabia. These countries are even intuitively related to energy. If you think on oil and petrol first association is usually oil and money reach gulf countries. If you think more there is also a most modern technology there, since it can be easily bought and requires minimal local workforce to deal with it. It is same for all other aspects of life conclusion Is this combination is extremely vulnerable to cyber threats. They are impossibly depend on energy and technology to live everyday life, more than any the place on earth, only maybe the scientific base on Antarctica is more dependent. Last incidents show can misconfiguration or lack of proactivity can lead to disaster. What makes me thinking are recent fires in Dubai and some other issue which show “quality” control problems, and such problems are important in cyber attacks. It will be nice to have time and opportunity to work more, looks like very good situation for preventive digital forensics, but because of sheer size something vendor agnostic like Google GRR tool. 

4th May 2016,
Nice article on "Procurement: Saudis In Search Of Their Lost Work Ethic" StrartegyPage.com, which talks about quality problem, wokrforce etc, things so important in cyber vulnerability. 

Friday, April 8, 2016

Some raw thoughts on current digital forensics, IT security and data science

Recently I’ve been tasked with writing down some thoughts as discussion ideas and teasers on current digital forensics, It security and data science. Some of this were floating around for a long time more as reaction to events than real effort to do a serious discussion.
At first glance digital forensics and data science does not have much in common, especially when we are talking about how digital forensics is approached and executed today. What is usually not taken into the account is the fact that digital forensics is the part of both computer and forensic science, two very different science fields. At the moment digital forensics is a new field getting incorporated into forensics, digital specifics should be recognized and incorporated into traditional forensic environment.
For start definitions should be stated. First we can introduce forensics and digital forensics. Forensics is “The application of scientific knowledge to legal problems" (Merriam-Webster), what includes forensic medicine, physics, chemistry, dentistry, fingerprints, DNA, firearm analysis, accounting all traditional sciences. In the other hand for the digital forensics we have first idea of “Forensic Computing” by V. Venema, D. Farmer late in 1990’s: „Gathering and analyzing data in a manner as free from distortion or bias as possible to reconstruct data or what has happened in the past on a system.”. When this definition of forensic computing is expanded with digital evidence we get what is in current sense digital forensics. By Wikipedia “Digital forensics and Computer forensics” is: defined as “Computer forensics, sometimes known as computer forensic science is a branch of digital forensic science pertaining to evidence found in computers and digital storage media. The goal of computer forensics is to examine digital media in a forensically sound manner with the aim of identifying, preserving, recovering, analyzing and presenting facts and opinions about the digital information”. In this context digital evidence or electronic evidence is defined as “any probative information stored or transmitted in digital form that a party to a court case may use at trial.”
To make things difficult digital evidence is the key element of digital forensics, what makes it hard to accept in the traditional forensics and law where sound physical evidence is golden standard. Also forensics science is not dealing with big amount of data but with specific science scenarios and analysis resulting in limited datasets, what causes different sensitivity and understanding of the data and computer science.
Even the basic Locard principle on which forensic science is build up, has its digital twist; Lockard’s Exchange Principle is "Every contact leaves a trace" (Prof. Edmond Locard, c. 1910). It is perfectly correct, log analysis was one of the first evolved branches of IT security and digital forensics. .One of the key forensic principles is not to change evidence; when applied to digital forensics means working with read only data copies with hash signatures providing proof of data not being changed. Translating this to practical computing means ability to do parallel processing limited only by media and processing bandwidth.
The core problem of digital forensics today is the problem of processing huge volumes of data. To be honest this is really a big unspoken obstacle which is often overlooked, sometimes not understood by digital forensic practitioners and even vendors. Disks size skyrocket from megabytes to tens of terabytes; this sheer volume of data where relevant digital evidence is hidden is a huge problem. Only to create a forensic copy of one terabyte disk you need at least 3 hours and this is even before any analysis can be done. After that step even more time consuming process of digital evidence finding and extraction is started and it takes usually much longer - sometimes days are used in this process. This step is analysis in digital forensics and is conceptually very close to datamining process.
Current mainstream digital forensic tools are not capable of efficient parallelism, automation or scripting and are limited to Microsoft Windows platforms on Intel architecture, “general purpose PC paradigm” which is not best choice for fast and efficient data processing.

Current problems and computing development makes this issues practically unsolvable without using knowledge and experience form other computing science fields, especially from data science. From data point of view, we can separate digital forensics into two broad categories: classic postmortem forensics and live forensic, in sense where we are dealing with static data or dynamically changing data. In both situations we have to work with raw data and transform it into meaningful digital evidence. This is even more significant if we are talking about incident response in modern networked systems. We can approach each end node involved in incident as data source which has to be collected and analyzed; a situation where we have very different types of data from raw binary disk and memory images to process structures, elaborate log information or local agent database. At the moment all this data is handled separately, not as a part of one picture. To address this issues in efficient way data science knowledge should be used, to refine methods and tools in digital forensics. 

11.04.2016 link to draft presentation  for this discussion 

Wednesday, April 6, 2016

Datafocus 2016 and day after

Our small digital forensic conference finished yesterday,  nice event a lot of people some interesting lectures and good food.  Our colleague Steve Gregory caused a lot of interest, this year he was on MagnetForensic booth just across his former company booth. Steve was here since our first event becoming practically avatar for EnCase and GuidanceSoftware, this year he changed colors and caused a lot of "what are you doing on this boot and in this shirt" questions.  On Guid booth was Mr.Jeff Hedlesky,
Forensic Evangelist from Guidance Software, answering  questions about changes and events in GuiddanceSoftware. Looks like CEIC or EnFuse this year will be interesting probably dispersing some fears  and providing some long expected news. 
For me the most interesting lectures was by Steven Manson about intrepretation of electronic evidence.