|
|
Common Network Crimes
Network Intrusion Responder Program
Attack Methodologies
Bogus Charities
The most famous of the bogus charities in recent years is the Web
site that collected hundreds of thousands of dollars in the name of
victims of the September 11th terrorist attacks. The money actually
went to a scammer‟s bank account and the 9/11 victims never saw
a penny of it.
Playing to a person‟s sympathies is a popular fraud tactic and it is
seen in many different forms on Web pages. Some have been bold
enough to actually put small disclaimers at the bottom of the page
notifying anyone willing to read it that the money would not
actually go to the charity.
5-12
For Official Use Only - Law Enforcement Sensitive
01/09
Network Intrusion Responder Program
Common Network Crimes
Investigative Responses
Capture
As you investigate online fraud, it is important to capture the
fraudulent site as soon as possible. Most fraudulent sites are gone
in a very short amount of time and the evidence will be lost.
Preservation
In some cases, you may have to obtain the original site files and/or
the Internet Service Provider logs from the server. This usually
requires you to present a preservation letter to the ISP‟s point-of-
contact for law enforcement.
Warrants
Once preservation letters have been delivered, you should obtain
the warrants to seize the data. Note that in some cases the data you
are trying to obtain may already be deleted from the ISP‟s server
by the time you investigate the crime.
Reporting
First and foremost you should refer to your agency‟s Standard
Operating Procedures for internal reporting methods for these
offenses. Depending on your agency, you may be required to
report offenses up the chain to State and/or Federal enforcement
agencies. In the case of offenses that reach outside the borders of
the United States, you should seek assistance from international
enforcement groups.
Education
Where possible, provide victims with information on classes or
other places where they can receive assistance with learning how
to protect themselves from fraud attacks.
Recording
Observations can be recorded in many different forms, including
Observations
written notes, office documents, and databases. You should use the
approved and tested method used by your organization. This
course uses a spreadsheet template for recording this data.
01/09
For Official Use Only - Law Enforcement Sensitive
5-13
Common Network Crimes
Network Intrusion Responder Program
This page intentionally left blank.
5-14
For Official Use Only - Law Enforcement Sensitive
01/09
Network Intrusion Responder Program
Common Network Crimes
Lesson 3 - Identity Theft
Introduction
In 2007, there were an estimated 8.4 million reported cases of
identity theft in the U.S. That number is down from the reported
10.1 million in 2003. Even with the decline the identity theft
problem is ever present in society today.
Purpose of this
The purpose of this lesson is to learn how identity theft is
Lesson
perpetrated online.
Objectives
After completing this lesson, you will be able to:
Discuss some of the common online identity theft techniques
Explain the methodologies used in these cases
Describe some of the responses to these attacks
In this Lesson
The following table shows the contents of this lesson.
Topic
See Page
Identity Theft
5-16
Investigative Responses
5-18
01/09
For Official Use Only - Law Enforcement Sensitive
5-15
Common Network Crimes
Network Intrusion Responder Program
Identity Theft
Overview
As you have seen in the previous lessons in this module, there are
numerous ways in which a criminal can gain enough information
to assume someone else‟s identity. The most sophisticated
criminals will use numerous social engineering methods to gather
information on a victim. As investigators, we use some of the same
offline sources to gather information on subjects:
Search engines: Using Google, Dogpile, Yahoo or other search
engines to search for a name, address, phone number, license
plate, etc.
Public information sites: County tax records, marital records,
vehicle license information and many other forms of public
records are searchable online.
Group sites: MySpace, Facebook, and many other community
sites can be a good source of information. People tend to put
pictures of themselves on these sites and do not notice things in
the backg0round like addresses and license plates that can be
used to gather even more information.
Commercial sites: Many companies and agencies are taking
employee information off their Web sites, but some are not. It
is possible to find information on people from press releases
and company phone and e-mail lists.
Membership sites: Many clubs and membership groups have
lists of members with phone numbers and addresses, and
sometimes even birth dates on their Web sites.
The Internet is a vast research engine that allows someone to look
for information on virtually any topic. Information on people is as
easy to find as any other piece of information.
5-16
For Official Use Only - Law Enforcement Sensitive
01/09
Network Intrusion Responder Program
Common Network Crimes
Identity Theft, continued
Attack
If the criminal can find one piece of information on a target victim,
Methodologies
the criminal can use any number of tools or sites on the Internet to
gather information very easily. Here are just a few examples of
ways in which this can be done.
In this example we are using the Google search engine, but you
can use these methods with any search tool.
Information
Description
Type
Name
Simply type the name enclosed in single quotes
to narrow the search to the full name on any
page that Google has seen. If the name is too
common or if too many results are returned, use
the plus sign to link the name to a city. For
example: „John Smith‟ + „Austin, TX‟
Phone
Entering the phone number into the search box
will return sites that list the address associated
with the phone number and the name to which
the number is registered. „555-1212‟
Social
The number of returns found from searching for
Security
a social security number is diminishing, but it is
Number
sometimes possible to find sites that have this
information.
Address
Searching for an address usually returns the
registered owner of the property and his or her
contact information. Searching for an address in
Google Earth shows you the exact location of
the property and in most cases a satellite photo.
License plate
A search for a license plate can in some states
return the name and address of the registered
owner.
Pretexting
In recent years there has been a growth in occurrences of
pretexting, the act of using small bits of information about a
subject to gather more details from businesses and vendors.
With this attack, an attacker can call a business or service and
pretend to be the victim. Using information already gathered, the
attacker can then persuade the business to disclose further
information, or even change information in the account to allow
the attacker full control of the account.
01/09
For Official Use Only - Law Enforcement Sensitive
5-17
Common Network Crimes
Network Intrusion Responder Program
Investigative Responses
Capture
As you investigate ID theft, it is important to gather as much
original information as possible.
Preservation
In some cases, you may have to obtain the original Web or e-mail
content and/or the Internet Service Provider logs from the server.
This usually requires you presenting a preservation letter to the
ISP‟s point-of-contact for law enforcement.
Warrants
Once preservation letters have been delivered, you should acquire
the warrants to seize the data. Note that in some cases the data you
are trying to obtain may already be deleted from the ISP‟s server
by the time you investigate the crime.
Reporting
First and foremost you should refer to your agency‟s Standard
Operating Procedures for internal reporting methods for these
offenses. Depending on your agency, you may be required to
report offenses up the chain to State and/or Federal enforcement
agencies. In the case of offenses that reach outside the borders of
the United States, you should seek assistance from international
enforcement groups.
Education
Where possible, provide victims with information on classes or
other places where they can get assistance on learning how to
protect themselves from e-mail fraud attacks.
5-18
For Official Use Only - Law Enforcement Sensitive
01/09
Network Intrusion Responder Program
Common Network Crimes
Lesson 4 - Social Threats
Introduction
The Internet has created a layer of perceived anonymity for
criminals. This has led to an increase in social threats perpetrated
on the Internet.
Purpose of this
The purpose of this lesson is to learn how social threats are
Lesson
perpetrated online.
Objectives
After completing this lesson, you will be able to:
Describe some of the common online social threats
Discuss the methodologies used in these cases
Explain some of the responses to these attacks
In this Lesson
The following table shows the contents of this lesson.
Topic
See Page
Social Threats
5-20
Attack Methodologies
5-21
Investigative Responses
5-22
01/09
For Official Use Only - Law Enforcement Sensitive
5-19
Common Network Crimes
Network Intrusion Responder Program
Social Threats
Predators
The Internet provides a communication shield that allows people
to hide or disguise their true identity. Because users are not seen,
they have the ability to misrepresent themselves and lead others to
believe they are different than they really are. This has been
utilized by predators effectively for years now. Children especially
are vulnerable to online predators because they are excited with
the technology of the Internet and anxious to make friends quickly.
The problem is not just restricted to young people. Anyone that
frequents chat rooms or other online communities is accessible to
predators.
Stalkers
Just like predators, stalkers search for victims online and then
begin the stalking process. As you saw in previous lessons, the
amount of information available to a stalker or predator can be
significant.
In some cases, the stalker will not actually be known to the victim
until the cycle elevates to dangerous levels. Many stalking cases
are discovered after the stalker has been monitoring the victim for
some time.
Cyberbullying
The term cyberbullying is a term used in reference to children, not
adults. When the Internet is used to bully, harass, embarrass, or
demean a child it is considered cyberbullying.
Cyberbullying is a complex topic because the ways it can be
perpetrated is only limited by a child‟s imagination. It should be
noted that the roles of the bully and the victim may reverse one or
more times during the attack. The investigator may have to review
data over a long period of time to determine the start and cause of
the attack.
Also note that in extreme cases cyberbullying has led to murder
and suicide.
5-20
For Official Use Only - Law Enforcement Sensitive
01/09
Network Intrusion Responder Program
Common Network Crimes
Attack Methodologies
E-mail
E-mail is the preferred initial method for many of the social threat
attackers. It is a simple matter to spoof an e-mail or send e-mail
from an anonymous source. This causes stress for the victim
because he or she thinks the e-mail is from a bad source or
unknown origin.
The e-mails may start innocuously and seem like they are from a
secret admirer. They usually escalate to disturbing topics and
threats depending on the attacker‟s desires.
Chat
If the attacker can engage the victim in a chat room, he or she can
start a conversation that, like e-mail, can seem harmless at first but
usually escalates to disturbing levels and even open threats.
It is also possible for the attacker to use wording in chat rooms in
such a way as to turn the others in the chat room against the
victim. This tactic is common in cases of cyberbullying.
Texting
The ability to send messages and images to and from cell phones is
a popular tactic for social threats. Taking pictures of victims in
public settings without their knowledge and then sending it to
them can cause mental anguish to the victim. In this situation, the
victim knows that the criminal was close enough to take the
picture. This creates a sense of personal space violation for the
victim.
Using text on a cell phone is also a control issue for the attacker,
who believes he can reach the victim anywhere and at any time.
Impersonation
Attackers can use identity theft or simple impersonation to publish
information on Web sites, forums and chat rooms that appears to
be from the victim. This is done to enlist more people in the attack
via proxy.
01/09
For Official Use Only - Law Enforcement Sensitive
5-21
Common Network Crimes
Network Intrusion Responder Program
Investigative Responses
Capture
As you investigate social threats, it is important to gather original
Web content and e-mail messages. Most e-mail clients and Web-
based clients have either a menu option or a button that you can
click to view the original content.
Preservation
In some cases you may have to obtain the original e-mail or Web
site files and/or the Internet Service Provider logs from the server.
This usually requires you to present a preservation letter to the
ISP‟s point-of-contact for law enforcement.
Warrants
Once preservation letters have been delivered, you must obtain the
warrants to seize the data. Note that in some cases the data you are
trying to obtain may already be deleted from the ISP‟s server by
the time you investigate the crime.
Reporting
First and foremost you should refer to your agency‟s Standard
Operating Procedures for internal reporting methods for these
offenses. Depending on your agency, you may be required to
report offenses up the chain to State and/or Federal enforcement
agencies. In the case of offenses that reach outside the borders of
the United States, you should seek assistance from international
enforcement groups.
Education
Where possible, provide victims with information on classes or
other places where they can obtain assistance on learning how to
protect themselves from social threats.
5-22
For Official Use Only - Law Enforcement Sensitive
01/09
Network Intrusion Responder Program
Common Network Crimes
Lesson 5 - Internal Threats
Introduction
Without a doubt, the greatest network threat is the internal threat.
Persons with knowledge of the internal workings of a system or
company have the greatest capability to cause damage.
Purpose of this
The purpose of this lesson is to learn how internal threats are
Lesson
perpetrated.
Objectives
After completing this lesson, you will be able to:
Describe some of the common internal threats
Discuss the methodologies used in these cases
Explain some of the responses to these attacks
In this Lesson
The following table shows the contents of this lesson.
Topic
See Page
Internal Threats Overview
5-24
Investigative Responses
5-26
01/09
For Official Use Only - Law Enforcement Sensitive
5-23
Common Network Crimes
Network Intrusion Responder Program
Internal Threats Overview
Inappropriate
With inappropriate usage of a computer or network, a person
Usage
violates acceptable computing use policies. Observations that may
lead to this classification include:
Web browsing sessions to Web sites containing unauthorized
workplace viewing material
Inappropriate e-mails sent to coworkers or from a work
account
Installing unauthorized software onto workplace resources
Embezzlement
Embezzlement is the theft or inappropriate use of money and
goods provided to a person in trust. Property that is entrusted to an
employee which is then used wrongly is an example of
embezzlement. Here are other examples of embezzlement:
Taking equipment home and using it without proper
permission
Installing copies of company software on personal machines
Using other network assets without proper permission
Extortion
Disgruntled IT managers and others with access to sensitive
information within an organization have changed access codes and
then held the information hostage in exchange for money, and
usually a promise of no prosecution. This is an example of
extortion. A fact surprising to many in law enforcement is that
these attempts have worked, and continue to work, because
companies do not want negative publicity. This is especially true
with banks and financial institutions.
5-24
For Official Use Only - Law Enforcement Sensitive
01/09
Network Intrusion Responder Program
Common Network Crimes
Internal Threats Overview, continued
Espionage
If a person is hired by a company or agency to obtain information
and pass it on to a competitor or rival government, he or she is
guilty of espionage. Like other forms of insider threats, espionage
is particularly effective if a dissatisfied employee can be identified
and manipulated.
If the information is classified by the U.S. Government, then the
charge may be elevated to treason.
Sabotage
When employees feel like they are unappreciated, or have been
slighted by the company, they may seek to impact their supervisor
or the company in retaliation. The retaliation may come in the
form of modified data that negatively affects the company, or in
the form of a program that may cause a slowing or stoppage of
data within the company.
Some of these attacks are executed in such a way that the
employee will make a show of coming in and fixing the problem
in order to elevate his status within the organization.
01/09
For Official Use Only - Law Enforcement Sensitive
5-25
Common Network Crimes
Network Intrusion Responder Program
Investigative Responses
Capture
As you investigate internal threats, it is important to obtain as
much information from the company or agency as possible.
Human resource offices usually have the most to offer an
investigator. You should also gather as much original evidence
files and material as soon as possible.
Preservation
In some cases, you may have to obtain the original evidence and/or
the Internet Service Provider logs from the servers. This usually
requires you presenting a preservation letter to the ISP‟s point-of-
contact for law enforcement.
Warrants
Once preservation letters have been delivered, you should obtain
on the warrants to seize the data. Note that in some cases the data
you are trying to obtain may already be deleted from the ISP‟s
server by the time you investigate the crime.
Reporting
First and foremost you should refer to your agency‟s guidance or
Standard Operating Procedures for internal reporting methods for
these offenses. Depending on your agency, you may be required to
report offenses up the chain to State and/or Federal enforcement
agencies. In the case of offenses that reach outside the borders of
the United States, you should seek assistance from international
enforcement groups.
Education
Where possible, provide victims with information on classes or
other places where they can obtain assistance on learning how to
protect themselves from internal threats.
5-26
For Official Use Only - Law Enforcement Sensitive
01/09
Network Intrusion Responder Program
Common Network Crimes
Lesson 6 - Malicious Code
Introduction
Malicious code is the generic term for attacks that use scripts or
programs to exploit security vulnerabilities. Worms, trojans,
viruses, and backdoors are all examples of malicious code.
Purpose of this
The purpose of this lesson is to learn how malicious code is
Lesson
perpetrated.
Objectives
After completing this lesson, you will be able to:
Describe some of the common malicious code threats
Discuss the methodologies used in these cases
Explain some of the responses to these attacks
In this Lesson
The following table shows the contents of this lesson.
Topic
See Page
Malicious Code Attacks
5-28
Investigative Responses
5-29
01/09
For Official Use Only - Law Enforcement Sensitive
5-27
Common Network Crimes
Network Intrusion Responder Program
Malicious Code Attacks
Viruses
A virus is malicious code that is attached to another object, such as
an application or document. The virus itself will not run until the
object is opened in some way.
Trojans
A trojan horse program appears to be a useful utility or game
program that you want, but instead it delivers a malicious program
as soon as the utility or game starts.
Worms
A worm is a program which does not need a host program to run
or replicate itself. Typically worms use the network to transmit
copies of itself to other computers thereby replicating and
consuming network bandwidth.
Spyware
Spyware is often recognized as software that monitors the user
without his or her knowledge. This definition is certainly true in
most cases. However, most spyware can control and direct users as
well. This is done by slowing the loading of Web pages that the
creators of the spyware do not want the user to see. Some may also
divert traffic to a competitor‟s Web page instead of the intended
target.
Adware
Like spyware, adware monitors what the user does. With this
information, the creators of the adware display advertisements that
they think may be of interest to the user. Programs that display ads
until you pay the shareware fee are considered adware as well.
Most adware reports back to its owners on the users‟ activities.
Rootkits
Once an attacker has gained access to a machine, he or she usually
installs a rootkit. Rootkits come in different versions depending on
what it is the attacker wants to accomplish. Most rootkits install
versions of operating system utilities and commands that hide the
existence of the attacker on the machine and give the attacker easy
access at the same time.
5-28
For Official Use Only - Law Enforcement Sensitive
01/09
Network Intrusion Responder Program
Common Network Crimes
Investigative Responses
Capture
As you investigate malware, it is important to obtain as much of
the original evidence data from the victim‟s machine as possible.
Keep in mind that these files may be considered viral. Therefore,
you should treat the files with care in order not to infect your
forensic systems.
Preservation
In some cases, you may have to obtain the original content and/or
the Internet Service Provider logs from the server. This usually
requires for you to present a preservation letter to the ISP‟s point-
of-contact for law enforcement.
Warrants
Once preservation letters have been delivered, you should obtain
the warrants to seize the data. Note that in some cases the data you
are trying to obtain may already be deleted from the ISP‟s server
by the time you investigate the crime.
Reporting
First and foremost you should refer to your agency‟s Standard
Operating Procedures for internal reporting methods for these
offenses. Depending on your agency, you may be required to
report offenses up the chain to State and/or Federal enforcement
agencies. In the case of offenses that reach outside the borders of
the United States, you should seek assistance from international
enforcement groups.
Education
Where possible, provide victims with information on classes or
other places where they can obtain assistance on learning how to
protect themselves from malware attacks.
01/09
For Official Use Only - Law Enforcement Sensitive
5-29
Common Network Crimes
Network Intrusion Responder Program
This page intentionally left blank.
5-30
For Official Use Only - Law Enforcement Sensitive
01/09
Network Intrusion Responder Program
Common Network Crimes
Lesson 7 - Denial of Service Attacks
Introduction
For some attackers, simply making a resource unavailable is the
satisfaction of the attack. The Denial of Service attack is the goal
of these criminals.
Purpose of this
The purpose of this lesson is to learn how a Denial of Service
Lesson
attack is perpetrated.
Objectives
After completing this lesson, you will be able to:
Describe some of the common Denial of Service threats
Discuss the methodologies used in these cases
Explain some of the responses to these attacks
In this Lesson
The following table shows the contents of this lesson.
Topic
See Page
Denial of Service
5-32
Investigative Responses
5-33
01/09
For Official Use Only - Law Enforcement Sensitive
5-31
Common Network Crimes
Network Intrusion Responder Program
Denial of Service
DoS Attack
Denial of Service (DoS) attacks are a common method to attack
Web sites and servers. These attacks inundate a Web site with
traffic that crashes the server, making the Web site‟s content and
services unavailable. DoS attacks often target major e-business
sites in an attempt to prevent customers from accessing the site for
hours, or even days, at a time.
Here are several ways in which a Denial of Service attack is
accomplished:
Flooding the target computer with more information than it can
handle, causing a system crash or reset
Interfering with the communications channel in such a way
that others cannot access the system
Starting a number of processes that consumes all available
resources on the target system, making the system unable to
respond to requests
Changing access codes to prevent authorized users from
accessing the system
Distributed Denial When multiple systems attack a target system it is called a
of Service Attack
Distributed Denial of Service Attack. The multiple systems usually
are other compromised systems that are controlled by the same
attacker. DDoS attacks are normally facilitated by a large botnet
that is created for such a purpose, or is leased out from a botnet
owner to an attacker for a specific attack.
5-32
For Official Use Only - Law Enforcement Sensitive
01/09
Network Intrusion Responder Program
Common Network Crimes
Investigative Responses
Capture
As you investigate DoS attacks, it is important to gather as much
of the original attack information as you can. Ideally, network
traffic captures are some of the best sources of investigational data.
However, this kind of evidence is rarely available.
Preservation
In some cases, you may have to obtain the original traffic and/or
the Internet Service Provider logs from the server. This usually
requires for you to present a preservation letter to the ISP‟s point-
of-contact for law enforcement.
Warrants
Once preservation letters have been delivered, you should obtain
the warrants to seize the data. Note that in some cases the data you
are trying to obtain may already be deleted from the ISP‟s server
by the time you investigate the crime.
Reporting
First and foremost you should refer to your agency‟s Standard
Operating Procedures for internal reporting methods for these
offenses. Depending on your agency, you may be required to
report offenses up the chain to State and/or Federal enforcement
agencies. In the case of offenses that reach outside the borders of
the United States, you should seek assistance from international
enforcement groups.
Education
Where possible, provide victims with information on classes or
other places where they can obtain assistance on learning how to
protect themselves from DoS attacks.
01/09
For Official Use Only - Law Enforcement Sensitive
5-33
Common Network Crimes
Network Intrusion Responder Program
This page intentionally left blank.
5-34
For Official Use Only - Law Enforcement Sensitive
01/09
Network Intrusion Responder Program
Common Network Crimes
Lesson 8 - Extortion
Introduction
Creating a sense of fear in a victim and then asking for money to
make the fear stop is the goal of an extortionist. The Internet has
allowed this old-school criminal activity to continue in a modern
medium.
Purpose of this
The purpose of this lesson is to learn how extortion is perpetrated
Lesson
online.
Objectives
After completing this lesson, you will be able to:
Describe some of the common extortion threats
Discuss the methodologies used in these cases
Explain some of the responses to these attacks
In this Lesson
The following table shows the contents of this lesson.
Topic
See Page
Extortion on the Internet
5-36
Investigative Responses
5-38
01/09
For Official Use Only - Law Enforcement Sensitive
5-35
Common Network Crimes
Network Intrusion Responder Program
Extortion on the Internet
Direct Threats
One of the oldest methods of extorting money through the Internet
is the e-mail threat. The criminal typically sends an e-mail to the
victim stating that a murder contract has been taken out on him by
an enemy. Then the criminal offers to stop the contract if the
victim is willing to pay a certain amount. The criminal usually
offers to supply enough information to allow the victim to contact
the police and have the enemy arrested.
Other versions of this attack are direct threats against a loved one,
a pet or an object of value to the victim. The threat can be anything
from causing the object damage or taking the object and
demanding a ransom for its return.
Threats Against
A criminal can also use extortion by denying access to the owner
Tangible or
of an information system by changing the access control of the
Non-Tangible
system. This is sometimes seen as part of an insider threat when an
Data
administrator of a system locks the user out of the system and
demands something in return for granting access.
Other forms of this type of attack include when the criminal
removes data from a system and offers a disk or other media with
the missing data in exchange for something. Quite often the data
being held in this type of case is something that would be
potentially embarrassing or damaging to the victim if it were
released to others.
5-36
For Official Use Only - Law Enforcement Sensitive
01/09
Network Intrusion Responder Program
Common Network Crimes
Extortion on the Internet, continued
Threats Against a Yet another type of extortion is when an attacker takes control of a
Web Entity
Web server, disables it, and then locks the owners out. The
attacker requests a ransom for the key to re-open the system.
Historically, a criminal seldom succeeds in collecting money by
holding a Web server for ransom. The usual goal is simply to
cause a disruption of service that makes life difficult for the site
owner. Only in a few cases has money actually changed hands, and
in many of those, the owner still had to rebuild the server to close
the vulnerability.
Protection
In some cases, the money is asked for before an attack takes place.
This is called “protection” by the attacker and only occasionally is
actually paid by the victim. Usually the attack takes place anyway.
01/09
For Official Use Only - Law Enforcement Sensitive
5-37
Common Network Crimes
Network Intrusion Responder Program
Investigative Responses
Capture
As you investigate extortion, it is important to obtain as much of
the original evidence as possible.
Preservation
In some cases, you may have to obtain the original e-mail, Web
content and/or the Internet Service Provider logs from the server.
This usually requires for you to present a preservation letter to the
ISP‟s point-of-contact for law enforcement.
Warrants
Once preservation letters have been delivered, you should obtain
the warrants to seize the data. Note that in some cases the data you
are trying to obtain may already be deleted from the ISP‟s server
by the time you investigate the crime.
Reporting
First and foremost you should refer to your agency‟s r Standard
Operating Procedures for internal reporting methods of these
offenses. Depending on your agency, you may be required to
report offenses up the chain to State and/or Federal enforcement
agencies. In the case of offenses that reach outside the borders of
the United States, you should seek assistance from international
enforcement groups.
Education
Where possible, provide victims with information on classes or
other places where they can obtain assistance on learning how to
protect themselves from extortion.
5-38
For Official Use Only - Law Enforcement Sensitive
01/09
Network Intrusion Responder Program
Common Network Crimes
Lesson 9 - Network Attacks
Introduction
Up to this point most of the attacks have been aimed at a person or
a specific system or group of systems. Now we will look at the
attacks that target the equipment and systems that comprise an
entire network.
Purpose of this
The purpose of this lesson is to learn how network attacks are
Lesson
perpetrated.
Objectives
After completing this lesson, you will be able to:
Describe some of the common network attacks
Discuss the methodologies used in these cases
Explain some of the responses to these attacks
In this Lesson
The following table shows the contents of this lesson.
Topic
See Page
Network vs. System Level Attacks
5-40
Investigative Responses
5-41
01/09
For Official Use Only - Law Enforcement Sensitive
5-39
Common Network Crimes
Network Intrusion Responder Program
Network vs. System Level Attacks
Attacking a
When criminals want to damage a company or agency as much as
Network
possible they will attack the network itself. Such attacks will not
only disrupt an organization‟s Internet presence, but also all of its
internal communications and productivity. These attacks come in
the form of:
Attacks against routers for the network
Attempts to compromise Domain Name Servers on the
network
Attacks against firewalls and Intrusion Detection Systems
Attacks against wireless networking equipment
Attacks against access control systems for the network
These attacks have the potential to disrupt the communications on
the target network. The criminal can disrupt the daily work flow of
the target network by changing the equipment that systems use to
lookup traffic routing, or sabotaging equipment that allows
communication on and with the target network.
5-40
For Official Use Only - Law Enforcement Sensitive
01/09
Network Intrusion Responder Program
Common Network Crimes
Investigative Responses
Capture
As you investigate network attacks, it is important to attempt to
obtain any network traffic captures during the attack. In many
cases, this information may not be available.
Preservation
In some cases, you may have to obtain the original attack data
and/or the Internet Service Provider logs from the server. This
usually requires for you to present a preservation letter to the ISP‟s
point-of-contact for law enforcement.
Warrants
Once preservation letters have been delivered, you should obtain
the warrants to seize the data. Note that in some cases the data you
are trying to obtain may already be deleted from the ISP‟s server
by the time you investigate the crime.
Reporting
First and foremost you should refer to your agency‟s Standard
Operating Procedures for internal reporting methods for these
offenses. Depending on your agency, you may be required to
report offenses up the chain to State and/or Federal enforcement
agencies. In the case of offenses that reach outside the borders of
the United States, you should seek assistance from international
enforcement groups.
Education
Where possible, provide victims with information on classes or
other places where they can receive assistance on learning how to
protect themselves from network attacks.
01/09
For Official Use Only - Law Enforcement Sensitive
5-41
Common Network Crimes
Network Intrusion Responder Program
This page intentionally left blank.
5-42
For Official Use Only - Law Enforcement Sensitive
01/09
Network Intrusion Responder Program
Common Network Crimes
Lesson 10 - Terrorism
Introduction
Historical accounts vary but it is generally agreed that terrorism
has been on the Internet since its early inception. In modern times,
the Internet is widely used by terrorist organizations to
communicate and plan attacks and events on a global scale.
Purpose of this
The purpose of this lesson is to learn how terrorist attacks are
Lesson
perpetrated across the Internet.
Objectives
After completing this lesson, you will be able to:
Describe some of the common terrorist attacks
Discuss the methodologies used in these cases
Explain some of the responses to these attacks
In this Lesson
The following table shows the contents of this lesson.
Topic
See Page
Internet Terrorist Methodologies
5-44
Investigative Responses
5-45
01/09
For Official Use Only - Law Enforcement Sensitive
5-43
Common Network Crimes
Network Intrusion Responder Program
Internet Terrorist Methodologies
Various
Terrorism is the act or threats of force against civilian populations
Categories
to create a political or ideological objective. This electronic
definition of terrorism falls into many categories and includes
crimes we have already reviewed. Terrorists use any methodology
available to them and the lines between terrorism and extortion can
be easily blurred. However, if you keep in mind that terrorism is
the systematic creation of fear in a group of people rather than an
individual, terrorism will be easier to detect.
The group can be defined in the simplest terms as being aimed at
religious, political and moral groups. If the attacks are designed to
instill fear and aimed at a religious group, a political faction, or
any other group that is defined by a common relationship, you
have a terrorist attack.
Internet Uses
There are several ways in which terrorist organizations use the
Internet. Their Web sites are used as psychological warfare,
propaganda machines, fundraising opportunities and as messaging
centers for coordinating activities. They also use Internet
connections for data mining and launching network attacks.
Attacks
Terrorists will use any and all attack vectors if they think it will
further their cause. These attacks include:
Denial of Service attacks against perceived enemies
Site defacements of Web sites that are counter to their cause
Spam e-mail attacks against enemies and propaganda e-mail
Phishing attacks for banking information to help fund activities
The only real difference between many of the attacks you have
learned about and terrorist activities are the end uses of the
information.
5-44
For Official Use Only - Law Enforcement Sensitive
01/09
Network Intrusion Responder Program
Common Network Crimes
Investigative Responses
Capture
As you investigate terrorist attacks, it is important to obtain as
much original evidence as possible.
Preservation
In some cases you may have to obtain the original E-mail or web
content and/or the Internet Service Provider logs from the server.
This usually requires you presenting a preservation letter to the
law enforcement point-of-contact.
Warrants
Once preservation letters have been delivered, you should start on
the warrants to seize the data. Note that in some cases the data you
are trying to obtain may already be gone from the ISP‟s server by
the time you investigate the crime.
Reporting
First and foremost you should refer to your agency‟s guidance or
Standard Operating Procedures for methods of internal reporting
of these offenses. Depending on your agency you may be required,
or requested, to report offenses up the chain to State and/or Federal
enforcement agencies. In the case of offenses that reach outside the
borders of the United States, you should seek assistance from
international enforcement groups.
Education
Where possible, provide the victims with information on classes or
other places where they can get assistance with learning how to
protect themselves from terrorist attacks.
01/09
For Official Use Only - Law Enforcement Sensitive
5-45
Common Network Crimes
Network Intrusion Responder Program
This page intentionally left blank.
5-46
For Official Use Only - Law Enforcement Sensitive
01/09
Network Intrusion Responder Program
Phases of an Intrusion
Module 6
Phases of an Intrusion
Overview
Network intrusions can be technically complex and difficult to
identify. To find traces of an intrusion, it is necessary to
understand how intruders conduct their attacks on a system. Many
times the hacker will take a very methodical approach by gathering
information about a network, probing the network, probing a
particular system, attacking the system, and escalating his
privileges. Once a hacker becomes entrenched in a system, he can
use that system to mine information and launch more attacks
against other systems.
Purpose of this
The purpose of this module is to provide an overview of the
Module
various phases and classifications of an intrusion. You will
examine common profiles of an attacker and recognize evidence
left behind during the various stages of an intrusion.
Objectives
After completing this module, you will be able to:
Define a network intrusion
Explain the phases and goals of an intrusion
Examine the different attack profiles
Explain the type of information an attacker can gather with and
without actively engaging the target
Evaluate the goals, strategies, and techniques of various types
of attacks
Evaluate the goals, strategies, and techniques for entrenchment
Evaluate the goals, strategies, and techniques for extraction
In this Module
The following table shows the contents of this module.
Topic
See Page
Lesson 1 - Defining an Intrusion
6-3
Lesson 2 - Reconnaissance
6-11
Lesson 3 - Network Attacks
6-29
Lesson 4 - Entrenchment
6-45
Lesson 5 - Infiltration and Extraction
6-67
01/09
For Official Use Only - Law Enforcement Sensitive
6-1
Phases of an Intrusion
Network Intrusion Responder Program
This page intentionally left blank.
6-2
For Official Use Only - Law Enforcement Sensitive
01/09
Network Intrusion Responder Program
Phases of an Intrusion
Lesson 1 - Defining an Intrusion
Introduction
Technically complex network intrusions can be difficult to
identify. To understand how to find traces of an intrusion, you
need to understand how intruders conduct their attacks on a
system.
Purpose of this
The purpose of this lesson is to learn the basics of how network
Lesson
intrusions are conducted.
Objectives
After completing this lesson, you will be able to:
Define a network intrusion.
Discuss the vulnerabilities that attackers look for in a target
In this Lesson
The following table shows the contents of this lesson.
Topic
See Page
Definition of an Intrusion
6-4
Goals of an Intrusion
6-5
Attacker Profiles
6-6
Phases of an Intrusion
6-9
01/09
For Official Use Only - Law Enforcement Sensitive
6-3
Phases of an Intrusion
Network Intrusion Responder Program
Definition of an Intrusion
Intrusion
An intrusion is the act of executing unauthorized actions against an
information system and/or its resources.
An intrusion is considered to have taken place when someone
gains unauthorized access to a computer. This is an intrusion on a
single device and that device is now considered to be
compromised. A network intrusion is broader and includes the
compromise of multiple devices on a single or multiple networks.
Vulnerability
A vulnerability is a weakness in an information system that could
allow unauthorized actions to be taken against that system.
Exploit
An exploit is a tool used by an attacker to perform malicious
attacks through vulnerabilities in a system.
For example, an error in an operating system that allows arbitrary
code execution is a vulnerability. The program that the attacker
writes to perform the attack against that operating system error is
an exploit.
Threats and
A threat is a possible source of danger for an information system.
Threat Agents
A threat agent is a specific person or event that executes
unauthorized actions against a system. Listed below are possible
threats and threat agents:
Threats - Insider
o Disgruntled employee
o Uninformed employee
Threat Agents
o Contractors
o Recruited or placed agent
Outsider
o Hackers
o Political activist “Hacktivist”
o Information “brokers”
o Foreign Governments or Corporations
Natural disasters
6-4
For Official Use Only - Law Enforcement Sensitive
01/09
Network Intrusion Responder Program
Phases of an Intrusion
Goals of an Intrusion
Goals of an
There are several goals of a successful network intrusion. Each can
Intrusion
stand alone or can be combined into a blended attack. They can be
classified as the following:
Denial of Server (DoS) - An attack that makes a computer
resource unable to communicate on the network.
Unauthorized Access - The act of gaining access to any
computer resource without the express permission of the owner
of that resource.
Inappropriate Usage - The act of using a computer resource in
a manner that has been deemed not appropriate for that
resource.
Other - These are broad goals that may be difficult to
categorize:
o Suspicious Activity - Any activity that does not
conform to the normal prescribed activity
o Malware - Software designed to infiltrate, monitor,
or possibly damage a computer without the owner’s
consent.
Note: During your cases, you may encounter a combination of
two or more goals.
01/09
For Official Use Only - Law Enforcement Sensitive
6-5
Phases of an Intrusion
Network Intrusion Responder Program
Attacker Profiles
Intruder Types
There are many types of attackers and many reasons why networks
and systems are attacked. However, most intruders fit loosely into
one of a few categories, which differentiate attackers by skill,
resources, and motivation. Understanding these basic intruder
profiles may help you identify other compromised systems. The
basic intruder profiles are categorized as:
Advanced
Intermediate
Beginner
Advanced
An advanced attacker is very skilled and motivated. Individuals
who fit into this category will generally exercise the highest levels
of caution and care and will exhibit the following attributes:
Slow and precise
Attempt to evade intrusion detection
Attempt to hide the signs of their presence
Attempt to mask the source of their attack
Piggy back on another attacker’s data stream
Misdirection that points to another source
Program in one or more languages and will modify or create
new exploit code or methods to support their objective
Working knowledge of common system and network
architectures
Have the greatest ability to cause damage throughout a
network
This category of attacker can be found in organized crime, terrorist
organizations, foreign governments or next door. Their motivation
varies, as it tends to match the motivations of the organization.
However, intellectual challenge is a common motivation because
compromising a network can be like completing a complex puzzle.
Some of the other terms used in this category are: Professional,
State Sponsored, Elite.
6-6
For Official Use Only - Law Enforcement Sensitive
01/09
Network Intrusion Responder Program
Phases of an Intrusion
Attacker Profiles, continued
Intermediate
Intermediate attackers attempt to follow the same methodology as
the advanced group, but simply do not possess the necessary skills,
knowledge or experience. They exhibit the following attributes:
Moderate speed and precision
May attempt to evade intrusion detection
Attempt to remove signs of their presence, but are more likely
to miss something
Attempt to mask the source of their attack
May have some programming skills and will be able to
perform minor modifications of exploit code to suit their
objectives.
Working knowledge of common system and network
architectures
A system administrator attempting to further his or her knowledge
and abilities provides an example of an immediate hacker. Other
terms used are Amateur and Enthusiast.
Beginner
Beginners are users who are just getting into this arena. They are
learning the art and rely on the success and failures of others to
teach them the basics. They have a tendency to rely on other
people’s code and scripts to do their work. Because they do not
have a basic understanding of the intrusion phases, their focus is
usually on one or two of them. Beginners exhibit the following
attributes:
Usually fast and imprecise
Will not usually attempt to evade intrusion detection, unless
that is a function of the tool they are using
Will not attempt to hide the signs of their presence, unless that
is a function of the tool they are using
May attempt to mask the source of their attack
Normally cannot program well, if at all, and will not be able to
modify exploit code to support objectives. Instead, the
objectives change to suite the code at their disposal.
The motivations for this classification of attacker tend to be game-
oriented. A system will be attacked for as little as bragging rights.
Other terms used for this attacker are script kiddy, kiddiot, and
packet monkey.
01/09
For Official Use Only - Law Enforcement Sensitive
6-7
Phases of an Intrusion
Network Intrusion Responder Program
Attacker Profiles, continued
Insiders
An insider is a person who has already been authorized to use a
network or system, due to his or her part in the organization.
Insiders are often underestimated or overlooked as the source of an
attack because network security focuses on protecting the network
perimeter from outside hackers.
Virtually any disgruntled employee using a valid account could
decide to take unauthorized actions against a network. The level of
skill is highly varied, but the employee’s motivations often include
some form of sabotage or retribution.
6-8
For Official Use Only - Law Enforcement Sensitive
01/09
Network Intrusion Responder Program
Phases of an Intrusion
Phases of an Intrusion
Phases of an
There are several traditional phases of a successful network
Intrusion
intrusion. Not every intrusion will include all of these phases
because the specific actions of the attacker will depend on his or
her objectives and abilities. These phases are briefly described
below and will be explained in more detail throughout this module.
Reconnaissance - Gathering information about a target
Attack - Gathering, compiling, and launching exploits
Entrenchment - Ensuring continued access to the target system
and hiding traces of that access
Extraction - Data theft or enabling channels for outbound
attackers to new targets
01/09
For Official Use Only - Law Enforcement Sensitive
6-9
Phases of an Intrusion
Network Intrusion Responder Program
This page intentionally left blank.
6-10
For Official Use Only - Law Enforcement Sensitive
01/09
Network Intrusion Responder Program
Phases of an Intrusion
Lesson 2 - Reconnaissance
Introduction
Reconnaissance is the act of gathering the information about a
target in order to conduct an intrusion or to continue one already in
progress.
Purpose of this
The purpose of this lesson is to explain how attackers can footprint
Lesson
a target computer system or network before initiating an attack.
Objectives
After completing this lesson, you will be able to:
Explain the purposes and methods of reconnaissance
Explain the difference between direct and indirect
methodologies
Discuss some specific tools and techniques used to conduct
reconnaissance
In this Lesson
The following table shows the contents of this lesson.
Topic
See Page
Goals
6-12
Strategies
6-13
Techniques - General Web Browsing and
6-14
Search
Techniques - Public Records and Archives
6-15
Search
Techniques - Target Web Site Examination
6-18
Techniques - Identifying Physical Attack
6-20
Vectors
Techniques - Live Host Identification
6-22
Techniques - Identifying Available
6-23
Ports/Protocols
Techniques - Type and Version Identification
6-25
Techniques - Vulnerability Scans
6-26
01/09
For Official Use Only - Law Enforcement Sensitive
6-11
Phases of an Intrusion
Network Intrusion Responder Program
Goals
Reconnaissance
Reconnaissance is the process of gathering information about a
Goals
potential intrusion target. This involves identifying any data that
will assist in that intrusion. Data is gathered about:
The target organization, including its main functions, staff
members, assets, partner organizations, etc.
Target individuals, including names, functions, contact
information, credentials, etc.
Target computers and networks, including addresses,
functions, installed applications, operating systems, etc.
Any other information that may be beneficial
6-12
For Official Use Only - Law Enforcement Sensitive
01/09
Network Intrusion Responder Program
Phases of an Intrusion
Strategies
Direct versus
Reconnaissance strategies can be defined as “direct” or “indirect.”
Indirect
Direct techniques involve taking actions on or against information
systems owned and/or operated by the targeted individual or
organization. As such, these actions may be observed and logged
by the target.
Indirect strategies are those that do not involve actions on or
against target information systems, and therefore will not be
observed and logged by the target in most cases.
Reconnaissance
Strategies used during reconnaissance include:
Strategies
Web browsing and searching
Public records searches
Target Web site examination
Identify physical attack vectors
Live host identification
Identification of open communication channels
Operating system and application identification
Operating system and application vulnerability scans
01/09
For Official Use Only - Law Enforcement Sensitive
6-13
Phases of an Intrusion
Network Intrusion Responder Program
Techniques - General Web Browsing and Searching
General Web
General Web searches can be a valuable tool during the
Browsing and
information gathering phase, especially when the searches are
Search
conducted using data obtained through other reconnaissance
methods.
For instance, a staff member’s name may have been identified on
the target’s Web site. Searching for that name through a search
engine, such as Google, may produce a home page with personal
data or postings on newsgroups and discussion forums. This may
in turn yield sensitive company data that should not have been
posted on the Internet, such as the staff member’s username and
hints at passwords.
Searches of online discussion forums, such as Usenet, may also
reveal information about an organization’s security weaknesses. IT
professionals will often post networking questions to online
forums in an attempt to solicit advice. Reading these postings can
provide information about unresolved security problems.
Possible Artifacts
Searching and browsing 3rd party Web sites will typically not
generate any artifacts on the information systems belonging to the
target organization or individual. They will leave artifacts on the
network that hosts the sites being browsed, most notably a record
of URLs accessed during the attacker’s research.
6-14
For Official Use Only - Law Enforcement Sensitive
01/09
Network Intrusion Responder Program
Phases of an Intrusion
Techniques - Public Records and Archives Search
Public Records
Public records are any public source of data maintained by a third
party. Relevant public records include:
Domain Name Service (DNS)
Whois
Web site content archives
Web site defacement archives
Web server OS and Uptime
Government business registration sites
DNS
DNS is used to maintain the public record of domain names and
the IP addresses to which they correspond. When you Web browse
to Microsoft.com, your computer first asks a DNS server how to
find that domain name. DNS will respond with the IP addresses
that are linked to Microsoft.com. Records kept by DNS include:
IP address of the Web server(s) that hosts the Web site for a
particular domain name
IP address of the e-mail server(s) that hosts e-mail for a
particular domain name
IP addresses of the DNS servers that are authoritative for a
domain name
Host/domain names associated with an IP address
This information provides attackers with the IP addresses of
various servers within an organization that provide specific
services (Web, e-mail and DNS), which may be vulnerable to
attack.
While DNS queries normally occur automatically when an
application requires resolution of a domain name, they can be
conducted manually with several applications, including nslookup,
which is found natively on many systems.
01/09
For Official Use Only - Law Enforcement Sensitive
6-15
Phases of an Intrusion
Network Intrusion Responder Program
Techniques - Public Records and Archives Search,
continued
Whois
There are several Regional Internet Registries (RIRs) that are
responsible for leasing IP addresses to ISPs and other large
organizations. “Whois” is an Internet utility that queries an RIR
database for public information, which includes:
Range of IP addresses assigned to an organization
Geographical address used when the organization registered
for the domain
Names or handles, phone numbers, and e-mail addresses of the
points of contact (POCs) for an organization
There are many Web sites that can be used to perform a whois
query. For example www.arin.net/whois/ can be used to directly
query the American Registry for Internet Numbers, which covers
IP address assignments to the U.S. and Canada.
Web site Content The Wayback Machine (http://www.archive.org) provides archival
Archives
storage for Web pages that are no longer available through the
original provider. An organization may have realized that at some
point it included sensitive information on its Web site and
subsequently removed the entire Web site. The Wayback Machine
offers the ability to check for previous, less security-conscious
versions of an organization’s site. There may be other Web site
archives available online.
6-16
For Official Use Only - Law Enforcement Sensitive
01/09
Network Intrusion Responder Program
Phases of an Intrusion
Techniques - Public Records and Archives Search,
continued
Defacement
Defacement archival sites provide information, archives, and
Archives
statistics regarding Web defacements. An example is Zone-H
(http://www.zone-h.com). Attackers can use Zone-h to find out if a
target has previously been defaced, a record of that defacement,
and a listing of the operating system and Web server in use by the
compromised server. There may be other such archives available
online.
Web Server OS
Netcraft (http://news.netcraft.com) is a site that provides network
and Uptime
and server-specific search functionality. If you enter a domain
Archives
name, Netcraft will determine the operating system and uptime of
the server to which the domain name points. It will also attempt to
discover the type of Web server application running and it will
provide a record of the results for previous attempts to gather this
information.
Government
For an organization to be recognized as a business for tax and
Business
liability purposes, the federal government and most state
Registration Sites
governments require several forms to be submitted. These forms
may be considered public record and are often searchable on the
Internet for information about a potential target.
For example, the U.S. Securities and Exchange Commission
maintains the database EDGAR (Electronic Data Gathering,
Analysis, and Retrieval) system. Organizations required to file
with the SEC have publicly recorded information in the EDGAR
database, which can be found at:
Possible Artifacts
Searching third-party archive and public record sites will typically
not generate any artifacts on the information systems belonging to
the target organization or individual. They will leave artifacts on
the network that hosts the sites being browsed, most notably a
record of URLs accessed during the attacker’s research.
It is also possible that queries made against a third-party DNS
server will be forwarded to a DNS server owned or operated by the
target organization.
01/09
For Official Use Only - Law Enforcement Sensitive
6-17
Phases of an Intrusion
Network Intrusion Responder Program
Techniques - Target Web Site Examination
Target Web Site
Web sites made available by a target organization can serve an
Examination
attacker as either a source of general information or as a point of
entry into a target network. During recon, the following tactics
may be used when reviewing a site.
Manual browsing
Automated crawling
URI prediction/guessing
Source code review
Manual Browsing Manually browsing a target Web site is a legitimate method for
gathering intelligence about that site and about the organization
that runs the site. The disadvantage of such browsing is that it is a
direct technique that will leave traces on the target system and
network. This can be mitigated by using a browsing pattern that
mimics the way a legitimate user might browse the site.
Manual browsing can also be obfuscated by the use of various
proxies or routing techniques. This could be through the use of
TOR or another type of free proxy, but could also be routed
through another previously compromised box. Many of the free
proxies have well-known IP addresses and might be blocked by
Web servers or firewalls.
Automated
Web crawlers, which are also known as Robots or Spiders, can be
Crawling
used to automatically browse a site and follow all available links.
The results of the Web page download that results from each link
is saved for later review. This technique is very obvious to anyone
that bothers to read the logs of the target Web server or any
associated reverse proxies.
6-18
For Official Use Only - Law Enforcement Sensitive
01/09
Network Intrusion Responder Program
Phases of an Intrusion
Techniques - Target Web Site Examination, continued
URI Prediction
Not all pages in a Web site are accessible via a link. Pages that are
not directly advertised on a site or linked can sometimes be found
by guessing at the naming convention used by the site designer.
For instance, if there is a www.examplesite.com/page1, then it
follows that there may be a www.examplesite.com/page2.
Guessing these naming conventions can lead to the discovery of
additional pages containing valuable data.
Guessing these resources can lead to error logs on the server.
These can be generic errors or in the case of a folder that is
restricted, security-related errors.
Source Code
Other than server side scripts, all HTML/XML markup language
Review
and client-side scripts are sent to the Web browser that requests the
associated page. This code can be reviewed for information
disclosure (e.g., in programmer comments), as well as for
weaknesses in the code itself.
Possible Artifacts
Possible artifacts of target Web site examination include:
Any record of URL requests from suspicious IP addresses or
IP ranges in the logs of the Web server or any associated Web
proxies.
Logs that show a broad, systematic pattern of URL requests,
which is characteristic of a site being crawled (as observed in
Web servers and proxies).
Logs that show failed URL access attempts that list non-
existent files which are close in name to actual existing files.
This is characteristic of an attempt to guess at a naming
convention. (Again, as observed in Web servers and proxies.)
IDS alerts referencing Web crawling or other abnormal URL
access patterns.
01/09
For Official Use Only - Law Enforcement Sensitive
6-19
Phases of an Intrusion
Network Intrusion Responder Program
Techniques - Identifying Physical Attack Vectors
Attack Vectors
An attack vector is a pathway through which an attack may be
launched.
Physical Attack
The most common attack vector is via the public Internet, which is
Vectors
a mixture of physical mediums. There are times when specific
vectors will be useful or even required, such as when the target
cannot be reached via the Internet. Other vectors include:
POTS (Plain Old Telephone System)
Wireless
Direct physical access to the device
Mixed (any route across the Internet)
Identifying POTS War-dialing is identifying computers listening for remote
Vectors
connections on a POTS line. This is done by feeding a set of
telephone numbers to a computer program, which will use a
modem to dial each of those numbers. If a modem response is
received, then there is a computer listening at that number, and
further attack actions may be taken against it.
War-dialing a telephone through the POTS system is growing less
viable as more systems use dedicated Internet connections rather
than dial-up modems.
Identifying
Attackers can use a computer with an 802.11 network interface to
Wireless Vectors
listen for frames transmitted from 802.11 compliant wireless
networks. Because there are different 802.11 specifications, an
attacker would have to ensure that their wireless NIC(s) supported
all necessary versions. Other wireless specifications are not
typically a viable vector, but cellular access to information systems
is becoming more prevalent and Bluetooth can be used in very
close range situations.
6-20
For Official Use Only - Law Enforcement Sensitive
01/09
Network Intrusion Responder Program
Phases of an Intrusion
Techniques - Identifying Physical Attack Vectors, continued
Identifying
An attacker could obtain direct physical access to a target device
Physical Vectors
through obtaining unauthorized access to a building or a room. If
the target device is owned by the organization to which the
attacker is employed, physical access may already be available.
Possible Artifacts
Possible artifacts of an attempt to identify or test a physical attack
vector include:
Call records that show incoming calls to a phone number with
a modem attached
Standard physical security violations or suspicious activity
(e.g., unknown persons in a building, tripped alarms, broken
locks, etc.)
Local console logins recorded in system logs during times
when a building was empty, or when the individual to whom
the user account was assigned was not present.
802.11 frames from an unknown source
The presence of physical wiretap devices on a cable or device
01/09
For Official Use Only - Law Enforcement Sensitive
6-21
Phases of an Intrusion
Network Intrusion Responder Program
Techniques - Live Host Identification
Live Host
Live host identification is the process of finding target hosts and
Identification
verifying that they are online and responding to communication
requests. This can be done through several methods:
ICMP (Internet Control Message Protocol) probes/sweeps
TCP/UDP probes/sweeps
Network monitoring
ICMP
ICMP is a protocol used primarily for network troubleshooting,
Probes/Sweeps
and is commonly used to test hosts to see if they are online. The
ICMP “Echo Request” packet is used to sweep multiple IP
addresses to elicit an “echo response” packet from available hosts.
This is also called a “ping sweep.” In an effort to pass through
firewalls that block ICMP Echo Requests, other ICMP packet
types may be used to elicit a response from a target host.
TCP/UDP Sweeps Modern networks sometimes block ICMP at external perimeter
defenses, such as firewalls and routers. To circumvent this barrier,
TCP and UDP packets can be sent instead.
Network
Passively monitoring a network from a compromised system can
Monitoring
also be used to identify other hosts inside a network. The amount
of traffic collected and number of hosts identified will depend
greatly upon where the sniffer is placed within the logical network
architecture.
Possible Artifacts
Possible artifacts of live host identification include:
IDS alerts referencing broad scans or sweeps
Firewall logs that show blocked packets attempting to reach a
large number of hosts in a short period of time
Firewall logs that show traffic blocked based upon abnormal
protocol options (unusual ICMP types, TCP ACK packets
existing outside of a session, etc.)
6-22
For Official Use Only - Law Enforcement Sensitive
01/09
Network Intrusion Responder Program
Phases of an Intrusion
Techniques - Identifying Available Protocols/Ports
Ports/Protocols
Once a physical vector is identified, and a target has been verified
as being online, an attacker may choose to enumerate the logical
methods by which the target computer is willing to communicate.
These methods include:
Accepted network and transport protocols (ICMP, TCP, UDP)
Accepted application protocols (HTTP, FTP, SMTP, etc.)
Accepted TCP/UDP port numbers
Identifying
Also called “Port Scanning,” connection attempts can be sent to
Accepted
TCP and UDP ports to determine if there is an application listening
TCP/UDP Port
on that port. Responses may include one of the following:
Numbers
A scanner will attempt to initiate a TCP session to multiple
ports. If the remote computer responds to the request with a
TCP syn/ack packet, then there is an application or OS service
listening on that port.
A scanner will send packets to UDP ports to test to see if they
are opened. Since UDP is connectionless, these packets will
either be empty, or contain data that is not valid for the
protocol normally used with that port. If the port is opened, the
application listening on that port will respond, if it is not open,
an ICMP Destination Unreachable message will be sent.
Note: Firewalls may behave differently when they block a
connection attempt, dropping packets (no response) instead
of allowing the destination computer to respond.
01/09
For Official Use Only - Law Enforcement Sensitive
6-23
Phases of an Intrusion
Network Intrusion Responder Program
Techniques - Identifying Available Protocols/Ports
Possible Artifacts
Possible artifacts of port/protocol scans include:
IDS alerts referencing port/protocol scans.
Firewall logs showing blocked attempts to access a large
number of ports on a single host, especially if they are in close
sequence or if the requests occur during a short period of time.
A TCP session that is initiated to an IP address and then
immediately terminated, and not followed by any additional
communication. This sequence would be observable in a
sniffer log.
A TCP session that is only half set up and then abandoned is
potentially observable in a sniffer log.
6-24
For Official Use Only - Law Enforcement Sensitive
01/09
Network Intrusion Responder Program
Phases of an Intrusion
Techniques - Type and Version Identification
Type and Version Once an open communication channel to a device has been
Identification
established, the attacker may need to know the type and version of
the listening application and/or operating system. This is because
attack methods are highly dependant upon target versions and
patch levels. Common methods for identifying this information
include:
Banner grabbing
Packet printing
Banner Grabbing Banner grabbing is the process of connecting to commonly
available services that provide type and version information in
their greeting messages.
Packet Printing
The TCP/IP stack is the part of the operating system that controls
any TCP/IP network communication. Because the implementation
of the stack is different on every operating system, this produces
minor variances in the operating system’s response to certain
network requests.
Scanning tools that perform packet printing (or fingerprinting)
check for these variances on a target host to identify its operating
system. Common TCP/IP attributes that can be used for packet
printing include:
ICMP Error Messages
TCP Sequence Numbers
TCP Options
TCP Timestamps
TCP Retransmissions Timeouts
Fragmentation Handling
IPID Values
Possible Artifacts
Possible artifacts include:
IDS alerts referencing scans
Errors in the logs of the scanned application or service
referencing communication problems or incomplete connection
attempts
01/09
For Official Use Only - Law Enforcement Sensitive
6-25
Phases of an Intrusion
Network Intrusion Responder Program
Techniques - Vulnerability Scans
Targets for
Vulnerability scans are probes that test specific applications or
Vulnerability
operating system services for possible vulnerabilities by issuing
Scans
application or service-specific commands that may reveal known
weaknesses in the software. Commonly scanned services include:
Web servers and FTP servers
E-mail servers
File and database servers
Directory service servers
RPC
Print services
Simple services
Vulnerability Scan The purpose for scanning applications is tied to the nature of the
Techniques
program. For instance, a database server may be scanned for the
ability to access data without authenticating, whereas an e-mail
server may be scanned for its ability to be used as a spam relay.
Vulnerability scans look for the presence of known vulnerable
application component files, as well as the ability to:
Traverse into normally non-accessible directories on the host
operating system
Access unauthorized files
Execute unauthorized code
Make unauthorized calls to backend application or database
servers
Route unauthorized data, such as spam or another probe,
through the server
Trigger backchannel communication, a communication session
originating from the target to the hacker
6-26
For Official Use Only - Law Enforcement Sensitive
01/09
Network Intrusion Responder Program
Phases of an Intrusion
Techniques - Vulnerability Scans, continued
Possible Artifacts
Possible artifacts of vulnerability scans include:
IDS alerts referencing a possible vulnerability scan
IDS alerts referencing any attack. Some vulnerability scans
launch partial attacks to determine if they are possible, and this
may trigger an IDS.
Any extremely large volume of traffic that is also widely
varied. This is characteristic of a comprehensive, multi-
protocol, blatant vulnerability scan.
Any other activity characteristic of any form of attack, as seen
in the next lesson of this text.
01/09
For Official Use Only - Law Enforcement Sensitive
6-27
Phases of an Intrusion
Network Intrusion Responder Program
This page intentionally left blank.
6-28
For Official Use Only - Law Enforcement Sensitive
01/09
Network Intrusion Responder Program
Phases of an Intrusion
Lesson 3 - Network Attacks
Introduction
In the attack phase, an intruder takes the actions necessary to gain
unauthorized access or privilege to a network, or damage a system.
Purpose of this
The purpose of this lesson is to explain how an attacker gains
Lesson
control of a system or data resource, or executes a denial of service
attack against that resource.
Objectives
After completing this lesson, you will be able to:
Explain the goals of an attack
List the major strategies used to conduct an attack
Explain some of the specific techniques that an attacker can
use to obtain control or elevated privilege
Explain some of the specific techniques that an attacker can
use to damage the functionality of a system or network
In this Lesson
The following table shows the contents of this lesson.
Topic
See Page
Goals
6-30
Strategic Categories
6-31
Strategies - Authentication Attacks
6-32
Techniques - Factor Guessing/Cracking
6-33
Techniques - Credential Recover/Reset
6-37
Techniques - Credential Injection
6-39
Techniques - Credential Theft
6-40
Strategies - Unexpected Input
6-41
Techniques - Excessive Input
6-42
Techniques - Excessive Input / Buffer
6-43
Overflows
Techniques - Unexpected Input Content / XSS
6-44
Attacks
01/09
For Official Use Only - Law Enforcement Sensitive
6-29
Phases of an Intrusion
Network Intrusion Responder Program
Goals
Entrenchment
An attack is an action taken to further one of the following goals:
Goals
Unauthorized Access: Obtaining access to a resource (i.e.,
system, network, data, etc.) that is illegal, against policy, or
otherwise unauthorized by the organization or individual
owning that resource.
Access Privilege: Obtaining the ability to manipulate a
resource (i.e., change, delete, deactivate, etc.) to an extent not
authorized by the organization or individual owning that
resource.
Denial of Service: Preventing a resource from being available
to fulfill its purpose either temporarily or permanently.
Unauthorized access and privilege are often both goals of the same
attack. In many instances, they can be achieved through a single
attack technique. Other times, an initial attack is used to gain
access, and subsequent attacks are used to obtain the proper
privilege.
Terminology Note The term “Denial of Service” (DoS) is often used to indicate an
attack that is performed by flooding a network link or interface.
The term “Distributed Denial of Service” (DDoS) is used when
this attack is sourced from many different hosts.
This text uses the term denial of service in the general sense of any
action that prevents a target from performing its normal actions
within its normal time frame.
6-30
For Official Use Only - Law Enforcement Sensitive
01/09
Network Intrusion Responder Program
Phases of an Intrusion
Strategic Categories
Entrenchment
There are many different ways to compromise a system or
Strategic
network. Most attack strategies fall into one of the following broad
Categories
categories, although there are exceptions:
Authentication Attacks: Attacks against an authentication
mechanism for the purpose of obtaining credentials to a system
or network.
Unexpected Input: Supplying input in a way that will cause an
application or operating system to behave in an unauthorized
fashion, either to gain unauthorized access or to disrupt the
functionality of the target system.
01/09
For Official Use Only - Law Enforcement Sensitive
6-31
Phases of an Intrusion
Network Intrusion Responder Program
Strategies - Authentication Attacks
Authentication
Authentication attacks use the following strategies, which will be
Attack Strategies
explained later in this lesson. In addition to these, an attacker may
simply already be authorized to use an information system either
based on explicitly granted credentials, or based on the fact that a
system does not require authentication.
Factor guessing/cracking: Attempting to determine the factors
(e.g., passwords) that will allow the attacker to successfully
authenticate to a system.
Credential recovery/reset: Taking actions that will cause a
system or administrator to either resend a set of credentials to
an attacker, or simply send the current credentials to an
attacker.
Credential injection: Creation of new credentials that will
allow authentication into a target system.
Credential theft: Theft of credentials either through inadvertent
disclosure or methods such as sniffing network traffic.
Authentication
Authentication attacks focus on obtaining a set of credentials for a
and Authorization
specific individual or account, or being authenticated as that
person or account without credentials. What the attacker is able to
do once this has been accomplished will depend on what the
compromised/unauthorized account is allowed to do. If an attacker
requires more authority on a system or network, then he or she will
have to use another authentication attack or try a different attack
strategy.
6-32
For Official Use Only - Law Enforcement Sensitive
01/09
Network Intrusion Responder Program
Phases of an Intrusion
Techniques - Factor Guessing/Cracking
Authentication
Authentication factor is a piece of data that is used to identify an
Factors
individual, and authenticate him into an information system. Most
authentication factors fit into one of the following categories:
“Something you know”: Usernames, passwords, pass-phrases,
answers to secret questions, etc.
“Something you have”: USB tokens, smart cards, RFID tokens,
cookies, encryption keys, etc.
“Something you are”: Retinal patterns, thumbprints, DNA, etc.
Usernames and passwords are still the most common
authentication factors.
Guessing/Cracking One of the most direct ways to access an information system is
through an already existing channel with legitimate credentials.
Obtaining the credentials is sometimes as simple as guessing at the
value, and attempting to authenticate. If the authentication fails,
you guess again. This is sometimes called a “password attack.”
However, the general method can be used for factors other than
passwords.
Factor guessing or cracking techniques require taking the
following actions:
1. The attacker generates a set of values that represent possible
legitimate authentication factors.
2. The attacker tests those values against the authentication
system or a stolen set of password hashes to determine which
ones are correct, if any.
01/09
For Official Use Only - Law Enforcement Sensitive
6-33
Phases of an Intrusion
Network Intrusion Responder Program
Techniques - Factor Guessing/Cracking, continued
Value Generation
There are several techniques used to generate the values that will
be tested against an authentication system:
Brute Force: Guessing every possible value for a credential
using any combination of acceptable characters. For instance,
if attempting to guess a password, you might begin with “a” -
“z”, then “aa”, then “ab”, etc.
Dictionary: Using only words from a dictionary to generate a
list of potential values. Some dictionary attacks will also allow
for small variances such as common misspellings in the list of
potential values.
Hybrid: Using any combination of brute force and dictionary
methods for value generation.
Pattern Recognition: For server/administrator assigned factors
(especially mathematically generated factors) that follow a
pattern, an attacker could use the pattern to guess the values of
other valid factors. Assigned factors include items like cookies
and URLs. Patterns can also be recognized in user-created
factors. For instance, administrators may always assign new
users their last name as their initial password, forcing the user
to change it upon first login.
Pre-generated Hashes: When the authentication factor is a hash
value of another piece of data, such as the hash of a password,
a list of all possible hashes for a set of values can be pre-
calculated. The term “rainbow table” is used to refer to some
types of pre-generated hash sets.
The data type for the values depends on the authentication factors
required by the system. ASCII characters are used for passwords
and usernames, whereas long numbers or hash values might be
used to represent codes found in tokens.
6-34
For Official Use Only - Law Enforcement Sensitive
01/09
Network Intrusion Responder Program
Phases of an Intrusion
Techniques - Factor Guessing/Cracking, continued
Value Testing
Once an attacker has decided upon a value set, then those values
must be tested against an authentication system. This can be done
by:
Manually typing the values in, one at a time.
Using an automated tool such as THC Hydra to pass test values
to the authentication system as fast as possible, or with a
specific timing. Automated tools may be the only method
available when attempting to emulate a token.
Using hashes calculated against values in a set of data and
comparing them to hashes stolen from an authentication
system or used by an authentication system.
Value Testing and When a session is underway and an individual or application is
Session Length
authenticated, that session will sometimes last for a specific
amount of time. If credentials are successfully guessed/cracked,
they may only be good for the length of a session already in
progress.
This is more likely the case when the factor is a temporary token,
such as a cookie. For example, an attacker could guess at the
proper value of a cookie used for authenticating to Web mail. But
the cookie may have expired if the interface to the account has
been inactive for a certain period of time.
01/09
For Official Use Only - Law Enforcement Sensitive
6-35
|
||
|
|
|