Tuesday, January 23, 2018

Lecturing infrastructure

Since December 1st 2017 we are developing infrastructure for practical student work, as part of preparation for a new study "Information security and digital forensics" at TVZ.
It is a complex infrastructure, based on forensic lab, where forensic lab management system will be key tool to provide environment  for students and staff.

We are actually working based on some research work done earlier by our students and coworkers, but still there is a lot to do. I've mentored and advised plenty of student graduation thesis and seminal works with aim to keep tested set of tools and practices for this emerging curriculum.
Some basic ideas how to do this are roughly described in some of our papers like  "Uvođenje novih sadržaja u nastavu digitalne forenzike i kibernetičke sigurnosti upotrebom studentskih radovas" or "Concepts and Methodology in Mobile Devices Digital Forensics Education and Training" published on MIPRO.

Basically we have to compile education process and necessary paperwork into one streamlined environment where we can work without much fuss.  To implement whole process better to say to tweak it, excellent resources are books:

As practical approach we are opting for combination of open source and commercial tools. It will be set of tools and platforms available to students to do tasks and researches. 

Saturday, January 13, 2018

It was a long pause

It was a long pause since last post, it was eventful but somehow I have not feel to write down anything.
I've changed my job now I'm full time lecturer and TVZ Zagreb, just last Friday our new curriculum  get acceptance so I'm preparing infrastructure and all other thnigies necessary for start at September 2018

I'll post about preparations, actions lesson learned etc as it will go ..
My current work is based on the plenty of students research and development done during last years while we were shaping ideas what to do and how to do it in  our local rather poor country.

Last few years student under my mentorship work was aimed to provide set of forensics / cybersecuirity tools evaluations and tests in local enviroment. So now we have set of graduation thesis, seminal works and other papers prepared as start-up materials. Foreman, GRR, EnCase and plenty others are ready to be tailored into new curriculum.

Wednesday, September 27, 2017

last five weeks

In last five weeks, since August 19th I've done 3 separate 5 day training on 4 different commercial digital forensics platforms. So I feel all hell of digital forensic standardization, compatibility issues.
Basically it is always the same thing to do (even on the same evidence files :) ) but with deliberately different terminology, methodology a nightmare actually.
We are asking question why current state of IT security is such shamble, how things are done now are really good example of how not to do things.  This is really material for a good scientific research why such important part of life is in such horror.
I'll add some thoughts later,  at the moment amuses me parallel with maths before introduction of Indian (Arabic) numbers with 0.

30.9.2017
As tools mentioned before

  • Magnet Forensic Interent Evidence Finder
  • Encase v7 and v8
  • X-ways
  • MobileEdit Forensic Express
  • and some references to F-Response  
So you can imagine the differences and consistency problems ... 

Tuesday, September 26, 2017

Some irregular thoughts on cyber weapons

My thought about cyber weapons ..
I'm thinking how we are probably misinterpreting cyber weapons, probably because there is no bodypile at the moment. 

From web, Cyberweapon is "A cyberweapon is a malware agent employed for military, paramilitary, or intelligence objectives." it is not very helpful definition. I should say that much better definition is derived directly from term weapon where intention is much clearer. 

Anyhow we are missing part of cyber weapons and its environments where it is used. The space where cyber weapons are used should be studied and analyzed in sense to show how this space reacts and than interacts with cyber weapon. Also how cyberweapon can be prevented or minimized as possible tool for retribution.

I should say ti will be important to understand epidemiological approach to cyber weapon and space of its application. For example lets look at last cyberweapons exposure or weapon leaks. First weapon was developed, stockpiled and than used, some time after usage weapon was exposed trough leak and used by criminal organisation and other non-original users.  Here we have interesting events going on. As soon as weapon is used (activated since it can be dormant) or better to say released (like germs) it will be also available to its primary target. If weapon is active there will be some effects on the targets and target will soon find out what and how it was attacked. Results are this weapon is not secret to primary target attack, but it is still secret for most of the world. This provides primary target with opportunity to strike collateral area in attackers domain with same weapon this time reverse engendered from primary attack artifacts and traces. How this can be prevented or controled from primary attacker viewpoint ? One method is mimic the medicine and use "vaccination" process, this is the timely exposure of the attack weapon to its collateral area. Result is that collateral area is exposed, damaged a bit and effectively vaccinated to effects of weapon primary used. Looks very much like not petya events ..

Recent huge databreaches

Since last few weeks a set of really important databreaches were posted. Looks rather real about current state of affairs. I'm wondering if this is because of some offensive escalation in attacks or just more effective monitoring or more strict reporting rules ?
Anyhow it is hard to find impact results for this databreaches I start to worry if this is maybe result of an effort to do a real economical damage ?
We will see in the future how things will develop

30.9.2017
Reports about size and impacts of recent databreaches are still coming with new information. The Delloite story is going one and getting more scary.  Maybe we are here talking of new type of asymmetric warfare ? All events and strategic value of data stolen, information learned and knowledge achieved is frightening. Also we don't know about other economical targtes in same class if and how being affected. Just think about what analysts and strategic usage of all this data collected can do do US economy and indirectly to military power.
Looks like my paranoia kick in, into some global conspiracy theory :) But why not it is like adding a new dimension to existing human activities and one dimension in which all activities are interconnected, accessible and almost not defended. 

Monday, May 29, 2017

Mipro 2017 conference in Opatija

MIPRO 2017 finished last week in Opatija. It is a nice conference where we usually presents a few papers. This year I've put there a cooperation with my former student Antonio Zekic. Paper was supposed to be something else but it morphed differently, into "Uvođenje novih sadržaja u nastavu digitalne forenzike i kibernetičke sigurnosti upotrebom studentskih radova"

The day before I was presenting there was lecture  "Životni ciklus elektroničkog dokaza" at Faculty of Law, University of Rijeka. It was a two hours talk about digital forensics and digital evidence for law students. more or less usual intro, but this time I feel some better more alive examples and cases are needed.

Saturday, April 1, 2017

Incident response and forensic tools my fears

Since 2008 when we mastered Encase Enterprise and its derivatives it was our tool of choice for enterprise / system level of forensic data collecting. It was reliable and easy to use for data collecting with ability to script "specific" tasks. Also it was easy to put collected data to other tools for further tasks.  It had its quirks and really not to helpful user interface but it was much better than anything else on the market.  Unfortunately with version 7 things start to become worse and now, last few months with version 8 we have continuous problems. It is not so much with tool but with licencing, getting extension certificates, reliability of licence manager, documentation, support response , etc. Last change from Safe/NAS configuration in v7 to Safe for enterprise and LM for distributed licencing caused surge of problem with customers. At the moment it almost looks like situation when Cellebrite was hacked,  when Cellebrite support database was compromised. Anyhow whatever cause is, conclusion is even tool is functional, because of this licensing issues it is not reliable enough to be used reliably in any real incident situation.  In the lab environment in sterile and not being time bound it is OK for forensic analyses, but for incident response in compromised network it is simple not reliable enough, especially in a sense of targeted attacked, like recent SWIFT affair.  Anything of that type with strategic implications is situation where we can expect well organised and prepared attack aiming at weak points of response chain, For such attacker it will be relatively easy to attack licensing and authentication mechanisms of EnCase enterprise tool to disable it, and trough this rendering IR useless or at least very slow. There is even more cunning, an paranoid scenario, which will include attack on GuidanceSoftware itself to damage its capabilities to maintain licences and certificates for products, Current SMS extension scheme which is now in action, with current  forced moving customers from "bad" v7 to new v8 is almost perfect opportunity for such idea.  
Having all this in mind some alternative should be found, I was working with several tools to see its features in such conditions and still there is no silver bullet, Conclusion is to have a set of tools which complicate things a lot, with stress on ability of early detection. Combination of GRR as opensource at one end of spectrum to Fidelis cybersecurity at the other one looks as a good but complicated situation.