Thursday, June 30, 2016

Classroom and training preparation


Recently I've been involved in training abroad, mostly Middle east and Asia, some interesting figures shows up. There is procedure when we negotiate training in someoneelse classroom, we always send a minimal requirements to training partner. Basically we have to get confirmation if we can use classroom,  
Somehow this procedure failed, recently we have almost 75% of partners provided classrooms not satisfying minimal requirements.  Incredible combination of wrong configurations, wrong OS, heavy infected machines, broken hardware, wrong type of machines (MACs instead of PCs), power problems, everything bundled up,  you just  mention it. In all this situation there was a common line, we were negotiating with another company who was than facilitating things, in fact we were never in touch with technical staff responsible for classroom. A broken phone problem. Looks like this is unsolvable issue cultural thing, so how to prevent or mitigate such problems ?
Obvious solution, one where  to quit course and force partner to accept responsibility and pay penalities for mistakes will not work. So we are left with be smart, plan, prepare and adopt in your budget limits, This rules out "bringing the whole HW and SW class in one big pelican box" a wonderful solution but way to costly.
To be honest I love to have even a small pelican box with me, something reliable in wilderness, but 
we can only  afford approach where pelican box is small one , with minimal HW :) 

On what facts we can rely :

  1. classrooms are based on intel machines 
    • mixes of configurations, from dual core 32 bit machines up, 
    • minimum  USB 2.0 ports, bootable from USB
    • various localisations keyboard layouts / languages
    • most of machines does not have CD workable drive 
  1. networking is usually there (wifi or wired) but can't be relied on
  2. computers are in various states of OS and SW anarchy 

Strategy to win such classroom :

1) we will use existing classroom computers but in safe and reliable way,

  • boot each student PC into reliable and safe linux configuration and use appropriate virtual machine for student work
  • boot can be from USB or over network or from CD (rarely)

2) for clasroom server use trainer or trainer backup machine

  • again use virtual machine 
  •  boot from safe boot source, usb or network or from CD (rarely)

3) for networking use existing infrastructure or wifi over usb and 3G/4G hotspot on local mobile device, can be challenging

From this requirements you can easily draw a list of HW and SW which fits into one small pelican box ,  but a huge set of planning, testing and preparations, I'll cover that later

13.7.2016 List of devices and tools for such classrom



Items
Tablet / smartphone as local 3G/4G wifi hotspot, 8 conncetions
USB 3.0 stick with write block HW switch, 32 GB or more
USB 3.0 HUB with 4 ports and power
USB wifi module with windows & linux drivers
Labtops: 64 bit 4 core, 3 HD, 16 GB+, 4 USB 3.0 ports, GB etherent
USB 3.0 external disks and enclOsures
(with encRyprtIon)
CD with various linux distributions
USB CD rom / DVD
PCMCIA usb 3.0 card
USB 3.0/2.0 cables
USB 3.0/2.0 connectros / gender changers
Powersupplies for all devices and spares
Extension cords, power connetors etc
Tools, labels, stickers
Pelican box

Monday, June 13, 2016

Some thougths on research, education and valorisation for cybersecuirty

Dhaka,
Bangladesh,
11.6.2016

Vision on research, education and valorization for cybersecurity

There is a huge problem based on the introduction of modern deeply penetrating computer based technologies into society and into personal life of every individual. The term cybersecurity is just one small but crucial part of controlling this problem or better to say understanding it. We do not yet understand how and why these technologies will change our society, we don't even have reliable definitions of cyber and cyber-related issues. Even among professionals in the field we don't have complete understanding or a good intuition, I don't like to mention other involved but deeply ignorant parts of society, from general population to top decision makers. For some of this issues we can find parallels in the past, my deep concern is that we are not understanding this processes, maybe we are even using wrong methods to explore and analyze situation. Some of this events looks more like biological and medical than technical phenomena, more like great medieval plaques when we observe behavior and possible impacts on our society.
For this reasons I believe cybersecurity should be looked on as something essential for modern society, practically like a role medicine have achieved today with same organizational approach to the society highly trained and highly ethical professionals and widespread general knowledge with practice of hygiene, in this case recently developed cyberhygine. The analogy should be even wider, we should think about introducing biological and medical ideas and concepts into our approach to cybersecurity.
In lecturing and research, we should concentrate on the good general IT knowledge and technical perspective in various technologies, proving students with skills and ability for fast adopting new knowledge. We should widen the knowledge of students providing them with social, legal and historical perspective for events and technologies what is crucial, I believe, for understanding future events and trends. Such approach is currently painfully missing leaving students without knowledge about interaction among technology society, history and law.
For example, network security is crucial part of the cybersecurity but for most of the current networking curriculums, networking is presented as just set of standards and developments. Networking in a sense of security needs a holistic description of technology development and its impact on society. In that context parallels with US DOD approach in solving railway transport problems during civil war and solving communication problems introducing TCP/IP in cold war looks very similar with very same effects on society, there are commonalities even in morphing and developing a new types of crimes. Without such approach networking especially TCP/IP is just technical issues of set of protocols, not something opening new social development, a whole new wild west frontier. Providing such historical, social and legal context to teaching we enable students to grasp dynamics and get better understanding of current events and future developments. Applying this approach to cybersecurity we have to provide students not only with historical context, but with legislative and human context of crime and law also. As to get better understanding on human element of “cyber” I believe we can introduce reading fictions authors like Stanislav Lem, Isaac Asimov because of their intriguing insight.
For IT side we should provide students with IT skills in programming (especially defensive programming), scripting languages, theory of operating systems, networking, language theory, digital forensics, system and network administrations and security, big data handling, artificial intelligence and other relevant IT and science fields (especially practical mathematical knowledge).
Teaching should include practical work and theory but in a sense that student should be able to solve problems using scientific methods based on accepted theoretical knowledge, not just doing repetitive hands-on tasks or being frozen in theoretical framework. The key quality will be stress on analyzing problem, understanding it, finding solution and implementing it with evaluation of results, not just trying tools and raw computing power. Also we should stress the ethical approach and legal problems in solving complex real situations. By my observations we should also include more women in cybersecurity education, not only because of lack of women in cybersecurity but at least because of qualities of better group work in solving problems.
To achieve this goal there should be adequate technical resources (laboratories, classrooms, simulators with appropriate tools and equipment), cooperation with other academia, business, law enforcement locally and internationally. Practical work can be done in virtual and simulated environments but there should be student exposure to physical equipment and real working conditions, minimum of 10% of practical should be with real hardware. Academic research should provide framework and improve practicals while practical problems and solutions should be based on theoretically predicted scenarios or conquered real life events. There should be mandatory involvement of lecturing personnel in practicals and in supporting of CERT type organization with goal to keep practical skills up to date and understanding student community. I should suggest rotational approach with 25% of personnel in lecturing theory, 25% doing practical with students, 25% doing research, liaison and 25% in other activities. To keep with development practical should be modified or replaced yearly a good measure will be 30% changed per year, same for the theoretical part.


Wednesday, June 1, 2016

EnCase direct servlet preview

I've done a short ppt on how direct servlet is created and used in EnCase. Recently we often have such  questions so to simplify my work I've done small ppt which follows manual and put in on the Slideshare. It is easier to discuss with ppt than with going trough manual pages.

Monday, May 30, 2016

Managing digital forensic lab

For last few weeks I found myself in awkward situation, almost like echo from some previous jobs,
preparing materials for training titled "Managing digital forensic laboratory".  This is almost accidental event, a first run of that training since we announced it few years ago.
The story behind course is strange by itself too, It all started as result of a failure. There was one nice big project about setting up digital forensic lab, for dual purpose forensics and education. Huge effort was put into project, especially in preparation for managing lab materials and intro course for that. Since project didn't realise we did logical move, reused prepared materials, and squeezed into 3 day trainng expandable to 5 days.  Basic theory  is based on excellent "Building a Digital Forensic.Laboratory: Establishing and Managing a Successful Facility"book by Andrew Jones and Craig Valli. I've decided to add additional things based of recent development for datacenters and open source tools for compatibility and certification based on "Sarbanes-Oxley IT Compliance Using Open Source Tools, 2nd Edition" where we can show how to inexpensively build a managing and control infrastructure even on knoppix.  For lab case management I've decided to implement Foreman tool  and mention comparation with other case management tools like FTK lab.
To cover datacenter approach and introduce good practice in managing a lot of computing power, what is always missing  I've decided to use "Enterprise Data Center Design and Methodology"
By: Rob Snevely. There is a lot of other papers and web resources to mention and talk about ...

Thursday, May 19, 2016

FER lecture "Moć forenzičkih alata"

Yesterday I done small 60 minutes lecture on my old UNI, going there always brings nostalgia back, remebering and daydreaming. What always  hits you is how many years have passed. Faces looks same, bright, young only difference are labtops and smartphones all around, when I saw myself in reflection I feel a pang of jealousy,  Amstrad 6128 and  ZX81 from my days will be helplesly  lost among new thingies around. Even mighty VAX under ULTRIX too..

With such thoughts, new wrinkles on my face, and new glasess I've get into old lecture room, same where 20 years ago we were playing with Expect langugage scripts  tailoring   some Cisco ATM switches configuration for experimental live video streaming.

This time skill was needed only to find right presenter stick all other was working more or less as expected. My battred Dell labtop was working well, MS Powerpoint 2016 has frozen only once, probably just to show who is the boss. In the audience was few familiar faces, in first row left my young and gifted colleague Savina Gruicic.

On the FER lecture home page there are links to video capture and links to presentation.

Dr Pale did intro words and I've started. My plan was to do short as possible, skimming on top of digital forensic topics, badmouth a bit about current tools and practices, show brief run trough Encase v6,v7 Ufed, get people thinking about and asking, hardest of all forcing myself to keep in 60 minutes boundaries.  People there are all from computer science community, I just need to show a topic, put a few words on context and let them think laudly :)
At the end we put in some new cyber-X words, Cyber-Hygiene and Cyber-illiteracy really it is fun to do Cyber words.
There was plenty of questions I can recall only a few,  Like where you can get careere and trainign for digital forensic in Croatia, it was hard to answer since in 2 weeks I'll do some work in Daka, Bangladesh to eran my living :) ..



Thursday, May 5, 2016

Setting up EnCase classroom in Polytechnic of Zagreb

Just today we managed to setup EnCase classroom with 10 workplaces. It was pleasure and fun, relaxed work with everyone cooperating. Really relaxing action

20.5.2016 Still no official photos from classroom... I don't know if this is just laziness or hush-hush

Actually this is the first official classroom for digital forensic with state of art commercial software. around 

Tuesday, May 3, 2016

Cyber attacks and energy dependecy

In the sense of recent attacks on power providing infrastructure around the globe, I've remembered my thoughts when I was last time in Gulf countries, Bahrain and Saudi Arabia. These countries are even intuitively related to energy. If you think on oil and petrol first association is usually oil and money reach gulf countries. If you think more there is also a most modern technology there, since it can be easily bought and requires minimal local workforce to deal with it. It is same for all other aspects of life conclusion Is this combination is extremely vulnerable to cyber threats. They are impossibly depend on energy and technology to live everyday life, more than any the place on earth, only maybe the scientific base on Antarctica is more dependent. Last incidents show can misconfiguration or lack of proactivity can lead to disaster. What makes me thinking are recent fires in Dubai and some other issue which show “quality” control problems, and such problems are important in cyber attacks. It will be nice to have time and opportunity to work more, looks like very good situation for preventive digital forensics, but because of sheer size something vendor agnostic like Google GRR tool. 

4th May 2016,
Nice article on "Procurement: Saudis In Search Of Their Lost Work Ethic" StrartegyPage.com, which talks about quality problem, wokrforce etc, things so important in cyber vulnerability.