Monday, March 26, 2018

Practical issues in building standard forensic workstation

As I mentioned in previous texts we are trying to setup student environment flexible enough for various forensic tools while simple to deploy on university cloud infrastructure and laboratory machines.

It is a bit of dangerous task since unification usually does not work at the end, but we hope we managed to get workable solution flexible enough for our purposes.
The first dilemma was about OS, since PC machines are given, it is possible to choose among Linux/UNIX and Windows. There are some key points to think about
  • we are windows shop, our infrastructure is windows based,
  • most commercial forensic tools are windows based, licencing issues must be taken into account too,
  • our students have windows skills already developed.

This topics point us to windows are base OS while Linux/UNIX being host for special functions. Windows 10 and Windows server 2016 provides us with nice integration ability trough Linux subsystem, where we can have window base with native Linux extensions. This can cover our workstation, server and infrastructure requirements. It means we can have one basic configuration which can be tweaked into custom end setup, reducing development time and simplifying administration.

27th November 2018
The workstation concept worked well during first half of semester, actually it was easy to extended and upgrade it to double up size of virtual lab. 

Monday, February 19, 2018

Setting up a digital forensic lab for student work and education

Setting up a digital forensic lab is not an easy process, but setting lab for student education is even harder since lab has to provide real life environment and education setup in one infrastructure setting.
Since  most of edu infrastructure are cloud  oriented it is worth of using cloud as environment  or basic infrastructure. Since tools are really heterogeneous  it is not easy to define setup and configuration.
All tools must be usable and all scenarios must be available.

We decided to use lab management software to create as much as possible open and tool-agnostic environment for work.  Foreman is simple but very streamlined open source lab management tool, being platform agnostic is its best feature.
As main lab case management tool it allows us define real life cases or educational  cases in real life style for executing all steps of digital forensic model.
Since Foreman enforce work-flow it requires additional standard paperwork, forms, to cover task control and quality assurance.
Students are defined as investigators, being tasked to execute forensic tasks defined and delivered to them trough Foreman interface. Edu personnel is  case administration and QA part of process, where getting positive grade means that investigators work has passed minimal QA controls. Handling evidence, storing, accessing tools and reports are only noted in Foreman, not done in Foreman, but this track still it is a key part of forensic process monitored by Foreman.
Such approach allows us to use practically and forensic tool available, also it provides us with real life combined not fully integrated environment where success depends not only on skills but also on administrative discipline and ability to follow procedures.

7.3.2018 Setting up  necessary paperwork for proper tools flow is complex task, it should be as real as possible, while flexible enough for variations for different types of cases. The environment should cover not only static case processing but also real-time incident situations.

Tuesday, January 23, 2018

Lecturing infrastructure

Since December 1st 2017 we are developing infrastructure for practical student work, as part of preparation for a new study "Information security and digital forensics" at TVZ.
It is a complex infrastructure, based on forensic lab, where forensic lab management system will be key tool to provide environment  for students and staff.

We are actually working based on some research work done earlier by our students and coworkers, but still there is a lot to do. I've mentored and advised plenty of student graduation thesis and seminal works with aim to keep tested set of tools and practices for this emerging curriculum.
Some basic ideas how to do this are roughly described in some of our papers like  "Uvođenje novih sadržaja u nastavu digitalne forenzike i kibernetičke sigurnosti upotrebom studentskih radovas" or "Concepts and Methodology in Mobile Devices Digital Forensics Education and Training" published on MIPRO.

Basically we have to compile education process and necessary paperwork into one streamlined environment where we can work without much fuss.  To implement whole process better to say to tweak it, excellent resources are books:

As practical approach we are opting for combination of open source and commercial tools. It will be set of tools and platforms available to students to do tasks and researches. 

Saturday, January 13, 2018

It was a long pause

It was a long pause since last post, it was eventful but somehow I have not feel to write down anything.
I've changed my job now I'm full time lecturer and TVZ Zagreb, just last Friday our new curriculum  get acceptance so I'm preparing infrastructure and all other thnigies necessary for start at September 2018

I'll post about preparations, actions lesson learned etc as it will go ..
My current work is based on the plenty of students research and development done during last years while we were shaping ideas what to do and how to do it in  our local rather poor country.

Last few years student under my mentorship work was aimed to provide set of forensics / cybersecuirity tools evaluations and tests in local enviroment. So now we have set of graduation thesis, seminal works and other papers prepared as start-up materials. Foreman, GRR, EnCase and plenty others are ready to be tailored into new curriculum.

Wednesday, September 27, 2017

last five weeks

In last five weeks, since August 19th I've done 3 separate 5 day training on 4 different commercial digital forensics platforms. So I feel all hell of digital forensic standardization, compatibility issues.
Basically it is always the same thing to do (even on the same evidence files :) ) but with deliberately different terminology, methodology a nightmare actually.
We are asking question why current state of IT security is such shamble, how things are done now are really good example of how not to do things.  This is really material for a good scientific research why such important part of life is in such horror.
I'll add some thoughts later,  at the moment amuses me parallel with maths before introduction of Indian (Arabic) numbers with 0.

30.9.2017
As tools mentioned before

  • Magnet Forensic Interent Evidence Finder
  • Encase v7 and v8
  • X-ways
  • MobileEdit Forensic Express
  • and some references to F-Response  
So you can imagine the differences and consistency problems ... 

Tuesday, September 26, 2017

Some irregular thoughts on cyber weapons

My thought about cyber weapons ..
I'm thinking how we are probably misinterpreting cyber weapons, probably because there is no bodypile at the moment. 

From web, Cyberweapon is "A cyberweapon is a malware agent employed for military, paramilitary, or intelligence objectives." it is not very helpful definition. I should say that much better definition is derived directly from term weapon where intention is much clearer. 

Anyhow we are missing part of cyber weapons and its environments where it is used. The space where cyber weapons are used should be studied and analyzed in sense to show how this space reacts and than interacts with cyber weapon. Also how cyberweapon can be prevented or minimized as possible tool for retribution.

I should say ti will be important to understand epidemiological approach to cyber weapon and space of its application. For example lets look at last cyberweapons exposure or weapon leaks. First weapon was developed, stockpiled and than used, some time after usage weapon was exposed trough leak and used by criminal organisation and other non-original users.  Here we have interesting events going on. As soon as weapon is used (activated since it can be dormant) or better to say released (like germs) it will be also available to its primary target. If weapon is active there will be some effects on the targets and target will soon find out what and how it was attacked. Results are this weapon is not secret to primary target attack, but it is still secret for most of the world. This provides primary target with opportunity to strike collateral area in attackers domain with same weapon this time reverse engendered from primary attack artifacts and traces. How this can be prevented or controled from primary attacker viewpoint ? One method is mimic the medicine and use "vaccination" process, this is the timely exposure of the attack weapon to its collateral area. Result is that collateral area is exposed, damaged a bit and effectively vaccinated to effects of weapon primary used. Looks very much like not petya events ..