Network Intrusions Responder Program (NITRO). Instructor Guide - page 18

 

  Index      Manuals     Network Intrusions Responder Program (NITRO). Instructor Guide

 

Search            copyright infringement  

 

   

 

   

 

Content      ..     16      17      18      19     ..

 

 

 

Network Intrusions Responder Program (NITRO). Instructor Guide - page 18

 

 

Detailed Questions Address
ƒ Ownership and authorized access of systems
ƒ User account information
ƒ Statements of how systems are used
ƒ Individual access to relevant systems and/or data
ƒ Specific commands or tools used during discovery of incident
ƒ Security video or proximity card logs
U.S. Department of
Homeland Security
United States
Secret Service
Interview Termination
ƒ Thank subject for time and cooperation
ƒ Ask subject for contact information in case need arises for
clarification of material discussed during interview
U.S. Department of
Homeland Security
United States
Secret Service
Interview Psychology
ƒ Take into account subject’s perspective and culture
ƒ Establish tone for interview, important in obtaining all
necessary information available from subject
ƒ Approach may differ depending on whether investigator
initiates contact for information or investigator is called by
organization
ƒ Issue influences how investigator structures approach to
interviews
U.S. Department of
Homeland Security
United States
Secret Service
Interview Psychology
ƒ When organization calls in investigator, most of organization’s
key players already involved
ƒ Management typically supports initial stages of investigation
ƒ Obtain written documentation from everyone involved and
begin working on controlling investigation
ƒ Important to minimize mishandling or destruction of evidence
and spread of information
U.S. Department of
Homeland Security
United States
Secret Service
Investigator Initiated Contact
ƒ Identify point of contact within organization
ƒ Look up registration information for company via Internet
search engine and identify legal counsel and network
administrator
ƒ Variety of state, federal, and private registries contain
information and provide it to law enforcement agencies
ƒ Several Internet service provider lists include contact
information for major communications providers such as AOL,
Microsoft, Google, Yahoo, and others
U.S. Department of
Homeland Security
United States
Secret Service
Investigator Initiated Considerations
ƒ Is system administrator or someone with root access
responsible for activity?
ƒ Do they know suspect and are they relaying information about
the investigation to their associate?
ƒ Are there any regulatory or legal barriers to organization
providing information (ECPA, PPA, FERPA, HIPPA,
Organizational Policy, etc.)
ƒ How critical is evidence held by company to the case?
ƒ Is a life or national security at stake?
U.S. Department of
Homeland Security
United States
Secret Service
Investigator Initiated Considerations
ƒ Access to legal instruments such as subpoenas, search
warrants, FISA, or other items in timely manner?
ƒ Technical knowledge to handle systems or logs that will be
obtained from scene or require assistance?
ƒ Evidence contained or spread out over national or global
network infrastructure?
ƒ Manpower, technical knowledge, and resources to obtain
what’s needed from target organization?
U.S. Department of
Homeland Security
United States
Secret Service
Investigator Initiated Considerations
ƒ Best to identify senior management, legal counsel, and
technical heads prior to making contact
ƒ Start at top of organization’s hierarchy and work down towards
individuals responsible for managing or using various
computer and network services
ƒ Address legal issues, business impact, and concern for
organization’s needs in order to gain more cooperation
U.S. Department of
Homeland Security
United States
Secret Service
Investigator Initiated Considerations
ƒ If an investigation could be compromised by reaching out avoid
“tipping off” organization or individuals
ƒ Do research and case preparation to obtain most effective
legal authority that will allow gathering evidence and
interviewing in most effective and efficient manner
U.S. Department of
Homeland Security
United States
Secret Service
Organization Initiated Contact
ƒ Investigator will more likely have cooperation
ƒ Victim may have performed internal investigation that may or
may not have been done properly
ƒ Still need to follow up to ensure accuracy of any information
provided
ƒ Document any actions taken by people at company
ƒ Important to work with legal counsel and network
administrators
U.S. Department of
Homeland Security
United States
Secret Service
Organization Initiated Contact
ƒ Many organizations ignorant of investigation’s process and do
not use proper evidence handling procedures
ƒ Common practices used by organizations to minimize or repair
damage often hamper investigation
U.S. Department of
Homeland Security
United States
Secret Service
Organization Initiated Concerns
ƒ When compromised it is common practice to just restore
machine from base image
ƒ Often untrained system administrators or management work
on live systems and alter artifacts and time lines
ƒ More concern for system/network integrity compared to
retaining evidence or identifying cause of incident
U.S. Department of
Homeland Security
United States
Secret Service
Organization Initiated Concerns
ƒ Chain of custody issues are often not followed
ƒ Lack of network maps and diagrams
ƒ Incomplete knowledge of system functions and passwords
ƒ Poor documentation of system builds, organizational policies,
or security controls
U.S. Department of
Homeland Security
United States
Secret Service
Witness and Victims
ƒ Often provide investigator initial foundation of case and
information needed to build framework for investigation
ƒ System administrator or user of an online database may be
first to notice strange behavior or altered data
ƒ A relative or friend may discover suspected child pornography
images on a computer
ƒ In either situation, investigator needs to elicit information from
people to obtain facts that will lead them to suspect
U.S. Department of
Homeland Security
United States
Secret Service
Witness and Victims
ƒ Keep in mind, anyone could be a suspect
ƒ During initial response and interviews, obtain clear and concise
written documentation from people involved
ƒ Documentation should consist of any actions taken by
witnesses and events observed during incident
ƒ Documentation is important part of freezing crime scene and
creating permanent record of events that occurred during and
subsequent to discovery of crime
U.S. Department of
Homeland Security
United States
Secret Service
Witness and Victims
ƒ People being interviewed may have had little contact with law
enforcement and may not recognize evidence needed to
further investigation
ƒ Develop a rapport with interview subjects and guide interview
in direction that will obtain most relevant and complete
information available
U.S. Department of
Homeland Security
United States
Secret Service
Issues to Address
ƒ System administrators or people with administrative powers
may be potential suspects
ƒ Move quickly and efficiently to build case
ƒ If immediate action is not an option, ensure that suspect’s
access to evidence or sensitive material is removed
ƒ Covert tactics may be necessary if you have proper
administrative approval, legal documents, and technical
capabilities in place
U.S. Department of
Homeland Security
United States
Secret Service
Issues to Address
ƒ Obtaining witness statements about suspect’s access to
machine or data is important
ƒ Supplement network logs and/or forensic analysis with as
much traditional detective work as possible
ƒ Determine if people share machines, use passwords, or share
passwords
ƒ Recent attempts at social engineering, phone calls or any
person asking for user accounts, passwords, or other sensitive
technical information
U.S. Department of
Homeland Security
United States
Secret Service
Suspects
ƒ Traditionally, investigators interview victim and eventually a
suspect
ƒ In cyber crime cases, can be unclear who is victim or who is a
suspect
ƒ Investigator must use analytical skills to determine who should
be interviewed during an investigation and best approach to
take
U.S. Department of
Homeland Security
United States
Secret Service
U.S. Department of
Homeland Security
United States
Secret Service
Module 11 - Legal Issues
U.S. Department of
Homeland Security
United States
Secret Service
You Will Learn . . .
ƒ Search Warrants
ƒ Internet Service Providers
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 1 - Search Warrants
ƒ Affidavit
ƒ Warrant
U.S. Department of
Homeland Security
United States
Secret Service
Search Warrants
The right of the people to be secure in their persons, houses,
papers, and effects, against unreasonable searches and
seizures, shall not be violated, and no Warrants shall issue,
but upon probable cause, supported by Oath or affirmation,
and particularly describing the place to be searched, and the
persons or things to be seized.”
U.S. Department of
Homeland Security
United States
Secret Service
Search Warrants
ƒ Authorization for search and seizure from approving authority
prior to execution of activities
ƒ Provide most reliable means of obtaining evidence
ƒ Properly crafted and executed, difficult to overcome
ƒ Preferred by Supreme Court when probable cause to believe a
crime has been committed and seeking search authority
U.S. Department of
Homeland Security
United States
Secret Service
Obtaining a Search Warrant
ƒ Be familiar with Federal Rules of Criminal Procedure Rule 41,
“Search and Seizure”
ƒ Investigator who requests search warrant must establish by
sworn affidavit some key pieces of information
ƒ Failure to establish any of these facts can result in search
warrant being denied or overturned
U.S. Department of
Homeland Security
United States
Secret Service
Facts for Issuance of Search Warrant
ƒ Description of place to be searched
ƒ Concise description of item(s) being sought
ƒ Probable Cause or facts that support belief that items being
sought are located in place described
U.S. Department of
Homeland Security
United States
Secret Service
Example Search Warrant
ƒ A copy of a modern federal search warrant is found as an
editable PDF format at:
U.S. Department of
Homeland Security
United States
Secret Service
Affidavit
ƒ Warrant typically accompanied by an attached affidavit
ƒ Affidavit will normally contain the following components:
ƒ The affiant’s statement of probable cause
ƒ Attachment A - Place To Be Searched
ƒ Attachment B - Items To Be Seized
U.S. Department of
Homeland Security
United States
Secret Service
Format
ƒ No formally required format for typical affidavit attachments,
though various agencies and jurisdictions may follow formats
developed over time
ƒ Warrant will generally give brief statements of affidavit
components and refer to affidavit for greater detail
ƒ See example in student book
U.S. Department of
Homeland Security
United States
Secret Service
(CCIPS) Guide for Warrants
ƒ United States Department of Justice, Computer Crime and
Intellectual Property Section (CCIPS), publishes useful guide
called Searching and Seizing Computers and Obtaining
Electronic Evidence in Criminal Investigations
ƒ Publication is available in hardcopy, and online at:
U.S. Department of
Homeland Security
United States
Secret Service
(CCIPS) Guide for Warrants
ƒ Appendix F of CCIPS publication, Sample Language for
Search Warrants and Accompanying Affidavits to Search and
Seize Computers, is de facto standard for warrant/affidavit
language in federal cyber investigations
U.S. Department of
Homeland Security
United States
Secret Service
Description of Place to be Searched
ƒ 4th Amendment requires investigator to concisely identify and
define search location in physical terms
ƒ Often difficult to do in cyber crime investigation as physical and
virtual worlds may not share same physical space
ƒ Goal is to define boundaries of search location in manner that
area within those boundaries may be searched, but search is
not overly broad
ƒ See examples in student book
U.S. Department of
Homeland Security
United States
Secret Service
Description of Item(s) to be Seized
ƒ Investigators crafting a search warrant affidavit should carefully
consider description of items sought in seizure
ƒ In most cyber crime cases, item sought is basically information
ƒ If information can be described, different forms it may take and
different storage media upon which it may reside, may more
easily be articulated
ƒ Must establish probable cause in sworn affidavit for each item
to be seized
ƒ See example in student book
U.S. Department of
Homeland Security
United States
Secret Service
Execution of a Search Warrant
ƒ Once warrant is signed by judge, it may be served, search
initiated, and evidence collected
ƒ Most court jurisdictions require investigator to submit a Search
Warrant Return document to the court describing items
actually seized
U.S. Department of
Homeland Security
United States
Secret Service
Surreptitious Execution of Warrant
ƒ In some cases, such as those involving organized crime
figures, or violent individuals, may want to execute warrant
without knowledge of individual and without public disclosure
of warrant or affidavit until trial
ƒ In these cases, a surreptitious entry warrant may be requested
and issued
U.S. Department of
Homeland Security
United States
Secret Service
Surreptitious Execution of Warrant
ƒ Surreptitious entry warrant authorizes investigator to enter
premises and conduct search without individual’s knowledge
ƒ Affidavits, search warrants, and Search Warrant Return are
kept under seal and not made public
ƒ Similar physical search authority can be issued under FISA
provision in accordance with the USA PATRIOT ACT
U.S. Department of
Homeland Security
United States
Secret Service
Search Warrant Exceptions
ƒ U.S. Supreme Court has interpreted specific exceptions for 4th
Amendment requirement to obtain a search warrant
ƒ Know and understand circumstances under which search of
individual or premises authorized without warrant
U.S. Department of
Homeland Security
United States
Secret Service
Warrant Exceptions
ƒ Consent
ƒ Stop and Frisk
ƒ Search Incident to Arrest
ƒ Immediate threat to life or serious bodily injury
ƒ Immediate threat of the destruction of evidence
U.S. Department of
Homeland Security
United States
Secret Service
Warrant Exceptions
ƒ Fresh pursuit
ƒ Plain view
ƒ Vehicle searches
ƒ Custodial searches
ƒ Border searches
U.S. Department of
Homeland Security
United States
Secret Service
Consent Searches
ƒ Person may waive rights under 4th Amendment and consent to
search of his person or items under his control
ƒ Most common exception to warrant clause
ƒ Evidence obtained during consent search is admissible in court
as long as investigator obtained proper consent
ƒ Investigators should understand how consent is granted and
limitations
U.S. Department of
Homeland Security
United States
Secret Service
Owner Consent
ƒ Property owner has legal authority to authorize search of
premises as long as certain requirements are met:
ƒ Consent must be voluntary and not coerced
ƒ Consent must be informed
ƒ Consent can be withdrawn at any time
ƒ Consent can be limited
U.S. Department of
Homeland Security
United States
Secret Service
Owner Consent
ƒ When consent search is granted, should be obtained in writing,
signed by consenting party, dated with known good local time
and location
ƒ Most agencies have consent search form for this purpose
U.S. Department of
Homeland Security
United States
Secret Service
Voluntary Consent
ƒ To be valid, owner must consent freely and knowingly
ƒ Investigator may ask for consent to search
ƒ If permission granted by owner, investigator may search
property or premises legally
ƒ Cannot coerce owner by threats, intimidation, or power of
authority into consenting to search
U.S. Department of
Homeland Security
United States
Secret Service
Informed Consent
ƒ Not everyone capable of giving consent to search
ƒ Some are legally and mentally incompetent, unfit to make such
a decision
ƒ Those with clinically diagnosed mental conditions and severe
health problems that affect judgment, unable to intelligently
consent
ƒ Minors generally not trusted to give consent
ƒ Be familiar with court decisions in your area concerning
informed consent to search
U.S. Department of
Homeland Security
United States
Secret Service
Withdrawing Consent
ƒ Person who waives 4th Amendment rights can reassert rights
any time by telling investigator to stop search
ƒ Investigator must stop search unless in possession of some
other legal authority to continue search
ƒ Evidence located before consent is withdrawn is admissible
and can be retained investigator for further analysis
U.S. Department of
Homeland Security
United States
Secret Service
Withdrawing Consent
ƒ Prioritize places to search and items to seize when operating
under consent search in case consent is withdrawn
ƒ Maximize the effectiveness of search in the event consent is
withdrawn
ƒ Forensic copies of computer evidence should be made as
soon as possible in consent cases
U.S. Department of
Homeland Security
United States
Secret Service
Third Party Consent
ƒ Possible to obtain consent from third party for areas which are
communal to target and third party
ƒ Third party must have ownership or right to access search
area
ƒ Search area may apply to computers when multiple users
share single account
ƒ If no shared account, third party can only consent to search of
his or her account or shared storage space under his or her
control
U.S. Department of
Homeland Security
United States
Secret Service
Third Party Consent
ƒ Spouses can generally consent to search of other spouse’s
property
ƒ True as long as target has not asserted exclusive rights to
search area
ƒ Absent evidence to contrary, investigators can rely upon
consenting spouse’s assertion to authority in good faith, even if
consenting spouse later deemed not to have authority to grant
consent
U.S. Department of
Homeland Security
United States
Secret Service
Third Party Consent
ƒ Parents can generally consent on behalf of juveniles living in
premises under parent’s control
ƒ Landlords generally do not have authority to authorize search
of rented property unless such consent is authorized under a
rental agreement with tenant
U.S. Department of
Homeland Security
United States
Secret Service
Third Party Consent
ƒ Military commanders or magistrates can authorize search of
military facilities under their command, including search of
persons on those facilities
ƒ System administrators may consent to search of an entire
computer or network over which they have administrative
privileges
U.S. Department of
Homeland Security
United States
Secret Service
Immediate Threat to Life or Serious
Bodily Injury
ƒ Investigator may enter and search premise without warrant
when there is immediate threat to life or serious bodily injury
ƒ Exception allows investigator to come to immediate rescue of
individual in peril
ƒ While legally inside premises, investigator can legally seize
evidence that may be discovered during rescue attempt
U.S. Department of
Homeland Security
United States
Secret Service
Immediate Threat of the Destruction
of Evidence
ƒ An investigator may enter a premise without a warrant to stop
immediate destruction of evidence in a criminal investigation
ƒ Threat must be immediate
U.S. Department of
Homeland Security
United States
Secret Service
Fresh Pursuit
ƒ An investigator in pursuit of an individual may follow individual
into or through a premise
ƒ If evidence of a crime is observed during pursuit, investigator
may legally seize evidence
U.S. Department of
Homeland Security
United States
Secret Service
Plain View
ƒ Investigator has the right be in a physical place
ƒ Evidence of a crime visible may be seized without a warrant
ƒ Is admissible in court of law
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 2 - ISP’s
ƒ Preservation Letters
ƒ Subpoenas
ƒ Search Warrants
ƒ Available Data
ƒ Retention Schedules
U.S. Department of
Homeland Security
United States
Secret Service
Internet Service Providers’ Records
ƒ Many crimes involve use of commercial and private networks
and communications facilities
ƒ Records usually maintained by Internet Service Providers
(ISPs)
ƒ Records of accounts, billing, transactions, and content of the
communications and data
ƒ Might need to gather this pertinent information from ISPs
ƒ Should understand proper way to request records so they are
admissible as evidence in a criminal proceeding
U.S. Department of
Homeland Security
United States
Secret Service
Access to Records
ƒ Access to stored wire and electronic communications and
transactional records, governed by Chapter 121 of U.S. Code
(currently comprised of 18 USC § 2701-2711)
ƒ Enacted in 1986 by the Electronic Communications Privacy Act
(ECPA)
ƒ ECPA defines how government can obtain stored account
information from third parties
U.S. Department of
Homeland Security
United States
Secret Service
ECPA Three Information Categories
• Basic Subscriber Information - 18 U.S.C. § 2703(c)(2)
• Records or Other Information Pertaining to a Customer or
Subscriber - 18 U.S.C. § 2703(c)(1)
• Contents
U.S. Department of
Homeland Security
United States
Secret Service
Basic Subscriber Information
ƒ Name and Address
ƒ Telephone connection records, session times and durations
ƒ Length of service and types of service utilized
ƒ Telephone or instrument number or other subscriber number
or identity, including any temporarily assigned network
address; and
ƒ Means and source of payment for such service (including any
credit card or bank account number)
U.S. Department of
Homeland Security
United States
Secret Service
Records or Other Information
ƒ A catch-all for anything else that is not content
U.S. Department of
Homeland Security
United States
Secret Service
Contents
ƒ When used with respect to any wire, oral, or electronic
communication, includes any information concerning
substance, purport, or meaning of that communication
U.S. Department of
Homeland Security
United States
Secret Service
Mechanisms to Compel Disclosure
ƒ See table in student book, reproduced from U.S. DOJ
publication Searching and Seizing Computers and Obtaining
Electronic Evidence in Criminal Investigations
U.S. Department of
Homeland Security
United States
Secret Service
Express Consent
ƒ Derived from an individual’s actions as result of documents
and notices provided to individual before an incident occurs
ƒ Type of consent usually seen in logon banners or signs
advising that use of system or entry “implies” consent to be
monitored or searched
ƒ Act of entry onto system or property constitutes informed,
voluntary consent
U.S. Department of
Homeland Security
United States
Secret Service
Authority and Ownership
ƒ During initial investigation of a cyber crime, firmly establish
owner or Designated Authorization Authority of any computer
or network involved
ƒ Ownership or authority should be documented in report and
verified by supporting documentation in form of policies,
orders, copies of ownership records or written statements
U.S. Department of
Homeland Security
United States
Secret Service
Establishing and Documenting
Express Consent
ƒ When a user logs onto a computer or network, there may be
an initial warning banner that explains authority to access
computer or network as well as any implications such access
may have for the user
ƒ Banner should require some type of action by user to
acknowledge its presence and acceptance of terms
ƒ Banners that flash and disappear without user interaction may
not suffice to establish express consent
U.S. Department of
Homeland Security
United States
Secret Service
Record Retention
ƒ Storage and destruction of electronic logs and records, much
more dynamic than traditional methods of recordkeeping
ƒ Takes time to obtain court orders (up to and including
warrants)
ƒ No federal laws that require companies to preserve electronic
records for any amount of time
ƒ Some companies maintain records and logs for months, some
not at all
U.S. Department of
Homeland Security
United States
Secret Service
Preservation Request
ƒ Part of ECPA is designed to ensure available data is not lost
during time it takes to obtain preservation order
ƒ Request can be issued quickly and directly for preservation of
information for 90 days
ƒ Designed to ensure the specified information will still be there
when appropriate legal process is served
U.S. Department of
Homeland Security
United States
Secret Service
18 USC § 2703(f)(1)
“A provider of wire or electronic communication service or a
remote computing service, upon the request of a governmental
entity, shall take all necessary steps to preserve records and
other evidence in its possession pending the issuance of a
court order or other process.”
ƒ No required format for § 2703(f) requests
ƒ Most agencies have developed their own preferred format,
usually in form of a letter
ƒ Technically, request can be verbal
U.S. Department of
Homeland Security
United States
Secret Service
Subpoena
ƒ Court order requiring a person or business entity to produce
records or testimony
ƒ Failure to comply with subpoena may result in penalties or
criminal charges
ƒ Used to obtain stored transactional records (basic subscriber
information) and in some circumstances, stored wire and
electronic communications (content)
U.S. Department of
Homeland Security
United States
Secret Service
Obtaining a Subpoena
ƒ In a cyber crime investigation, investigator can request
issuance of subpoena for records under control of an individual
or business
ƒ Prosecutor has authority to issue the subpoena and have the
person or business served with the document
ƒ Once served, individual or business has right to argue before a
competent court of jurisdiction why records should not be
produced
U.S. Department of
Homeland Security
United States
Secret Service
“D” Order
ƒ Standard of proof to obtain court order under 18 U.S.C. §
2703(d) is higher than for a subpoena, but lower than for a
warrant
ƒ Information that can be obtained with a “D” order falls between
that which can be obtained by the subpoena and the warrant
ƒ Commonly used to obtain stored transactional records and
stored wire and electronic communications (content)
U.S. Department of
Homeland Security
United States
Secret Service
Obtaining a “D” Order
ƒ 18 USC § 2703(d) states that a court order for the disclosure of
customer records may be issued after the following has been
submitted:
“..specific and articulable facts showing that there are
reasonable grounds to believe that the contents of a wire or
electronic communication, or the records or other information
sought, are relevant and material to an ongoing criminal
investigation.”
U.S. Department of
Homeland Security
United States
Secret Service
Obtaining a “D” Order
ƒ Orders issued under statute generally used to obtain Basic
Subscriber Information and Records or Other Information
Pertaining to a Customer or Subscriber, but not for content
ƒ Investigators should coordinate with prosecutors to obtain a D
order
ƒ Investigator will submit affidavit to apply for order
ƒ Affidavit should meet requirements set forth in section (d)
U.S. Department of
Homeland Security
United States
Secret Service
U.S. Department of
Homeland Security
United States
Secret Service
Module 12 - Fundamentals of Log
Analysis
U.S. Department of
Homeland Security
United States
Secret Service
You Will Learn . . .
ƒ Understanding Network Traffic
ƒ The Scientific Method and Intrusion Analysis
ƒ Observing Intrusion-related Activity and Generating a
Hypothesis
ƒ Predicting the Nature and Location of Intrusion Artifacts
ƒ Using Log Analysis to Evaluate an Intrusion Hypothesis
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 1 - Understanding Network
Traffic
ƒ Overview of Network Traffic
ƒ Investigation Techniques
U.S. Department of
Homeland Security
United States
Secret Service
The Internet
ƒ TCP/IP is the language of the Internet
ƒ Number of services which use TCP/IP to communicate
ƒ Example of one service, HyperText Transfer Protocol (HTTP)
U.S. Department of
Homeland Security
United States
Secret Service
Network Communication
ƒ To generates network traffic one system must serve or host
information and another system request the service data
ƒ In the case of HTTP there is a web server and a web client
ƒ Network traffic is generated when client or browser requests a
web page from the server
U.S. Department of
Homeland Security
United States
Secret Service
Network Communication
ƒ SYN: Client sends Synchronize packet to server, beginning
three-way handshake which starts conversation
ƒ SYN-ACK: Server sends Synchronization Acknowledgement,
acknowledging start of conversation
ƒ ACK: Client sends acknowledgement to server completing
three-way handshake, conversation started
U.S. Department of
Homeland Security
United States
Secret Service
Network Communication
ƒ GET: Client requests page from server
ƒ If general request to web site like www.somewhere.com
GET request is for web root document indicated with a
backslash / after get command
ƒ Otherwise name of page will be part of get request, such as
faq.html
U.S. Department of
Homeland Security
United States
Secret Service
Network Communication
ƒ 200 OK: Server will send response that includes status code
for page requested
ƒ Usually code 200 OK is sent
ƒ Indicates page found and will immediately follow
ƒ Page transferred to browser program and displayed on
client system
ƒ 404 Page not found: If specific page requested is not
recognized by server, 404 page not found displayed in browser
U.S. Department of
Homeland Security
United States
Secret Service
Ports in a Data Storm
ƒ There are 65535 port numbers available on most computer
systems
ƒ The Internet Assigned Numbers Authority (IANA) has role of
assigning types of traffic to port numbers
ƒ Assignments done so programmers can agree on ports used
for specific types of traffic
ƒ HTTP traffic assigned port 80
U.S. Department of
Homeland Security
United States
Secret Service
Types of Ports
ƒ Three types of port numbers, Well Known, Registered and
Dynamic Ports
ƒ Well Known Ports are numbers ranging from 0 to 1023
ƒ Registered Ports are numbers ranging from 1024 to 49151
ƒ Dynamic Ports are numbers ranging from 49152 to 65535
ƒ Documentation on current assignment of numbers can be
U.S. Department of
Homeland Security
United States
Secret Service
Common Well Known Ports
ƒ (20) File Transfer Protocol (FTP)
ƒ (21) File Transfer Control (FTP)
ƒ (22) Secure Shell Remote Login
ƒ (23) Telnet
U.S. Department of
Homeland Security
United States
Secret Service
Common Well Known Ports
ƒ (25) Simple Mail Transfer Protocol (SMTP E-mail)
ƒ (53) Domain Name Service (DNS)
ƒ (80) HTTP (Web)
ƒ (443) Secure Socket Layer (HTTPS)
U.S. Department of
Homeland Security
United States
Secret Service
Common Assigned Ports
ƒ (1025) Network Blackjack
ƒ (1080) SOCKS
ƒ (1169) Tripwire
ƒ (1214) KAZAA
ƒ (1433) Microsoft SQL Server
ƒ (1689) Firefox
U.S. Department of
Homeland Security
United States
Secret Service
Investigation Techniques
ƒ Look for traffic types that are on wrong assigned ports
ƒ For example AOL Instant Messenger traffic on port 80
ƒ AOL IM is assigned port 531
U.S. Department of
Homeland Security
United States
Secret Service
Types of Traffic to Watch For
ƒ HTTP (port 80)
ƒ Most firewalls and routers will pass traffic on port 80
ƒ Popular port for malicious code transfer, or for
communication of other protocols that have been blocked
ƒ May see programs that opened backdoors on systems
transferring information on port 80
ƒ Advanced attackers might embed malicious code in HTTP
packets hoping firewalls and intrusion detection systems will
pass the information
U.S. Department of
Homeland Security
United States
Secret Service
Types of Traffic to Watch For
ƒ E-mail (port 25)
ƒ Not a common port for traffic other than e-mail
ƒ Port is worth watching simply because so many attacks
originate in e-mail messages
U.S. Department of
Homeland Security
United States
Secret Service
Types of Traffic to Watch For
ƒ USENET/NNTP (port 119)
ƒ Important protocol for law enforcement to watch
ƒ Newsgroups are used for distribution of pornography in all
forms
ƒ Protocol still used as way to transfer bootleg software,
movies, music and other copyrighted material
U.S. Department of
Homeland Security
United States
Secret Service
Types of Traffic to Watch For
ƒ Internet Relay Chat (ports 6666-6669)
ƒ IRC is another protocol used heavily for Peer-to-Peer
transfer of copyrighted and illicit materials
ƒ Malware and Botnet traffic seen on these ports as well
U.S. Department of
Homeland Security
United States
Secret Service
Types of Traffic to Watch For
ƒ File Transfer Protocol (port 21)
ƒ FTP used for transferring files
ƒ If case involves transfers of illicit information of any kind
monitor FTP traffic
ƒ There are a number of malware attacks against FTP ports
as well
U.S. Department of
Homeland Security
United States
Secret Service
Types of Traffic to Watch For
ƒ Peer-to-Peer (Any ports)
ƒ P2P protocols are some of hardest to monitor and
investigate
ƒ Two systems that are transferring information can use any
port they agree on
ƒ Transfer of a file may actually take place between multiple
systems at once
ƒ Reassembly of transferred files can be extremely difficult
U.S. Department of
Homeland Security
United States
Secret Service
Baselines
ƒ Popular way to make network traffic analysis easier is baseline
method
ƒ Method involves taking packet capture snapshots of normal
network traffic and comparing suspicious traffic captures to
baseline
ƒ Helps to quickly determine where investigation should focus
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 2 - The Scientific Method
and Intrusion Analysis
ƒ Overview of the Scientific Method
ƒ Digital Forensic Analysis and the Scientific Method
U.S. Department of
Homeland Security
United States
Secret Service
Scientific Method
ƒ A process for investigating a set of observations
ƒ Formulating a hypothesis about observed events
ƒ Using deductive/inductive logic to formulate processes for
evaluating hypothesis
ƒ Carrying out processes and using results to support,
contradict, or modify hypothesis
U.S. Department of
Homeland Security
United States
Secret Service
Scientific Method Steps
ƒ Observation: Observing one or more events or sets of
events, establish facts surrounding events to identify cause
and consequences
ƒ Hypothesis: Explains observed events, including root cause,
interrelationship, and consequences
ƒ Prediction: Possible nature and location of artifacts in
evidence that will either support or contradict hypothesis
ƒ Evaluation: Procedures that test for presence of artifacts that
support, falsify, or modify the hypothesis
U.S. Department of
Homeland Security
United States
Secret Service
Scientific Method Steps
ƒ Conclusion: Based upon results of tests performed during
Evaluation step, stating one of following:
ƒ Hypothesis is supported by facts
ƒ Hypothesis is contradicted by facts
ƒ Facts indicate that new or modified hypothesis should be
constructed due to observations or lack of relevant results
U.S. Department of
Homeland Security
United States
Secret Service
Additional Characteristics
ƒ Repeatable: Evaluations and tests conducted should be
repeatable to ensure results can be verified by others who
want to test for mistakes, confounding variables, spurious
relationships, etc.
ƒ Cyclic: May need to perform many iterations of method, tests,
and testing of hypothesis, or generate additional hypothesis to
gain a clear understanding of originally observed events
U.S. Department of
Homeland Security
United States
Secret Service
Additional Characteristics
ƒ Empirical: Evidence used in hypothesis must be based on or
derived from observation rather than pure reasoning, faith,
common sense, etc
ƒ Falsifiable: Hypothesis established and tested using Scientific
Method should be falsifiable, there should be way to test for
contradicting evidence as well as supporting evidence
ƒ Objectivity: Observations and results of evaluations must be
interpreted as objectively as possible
U.S. Department of
Homeland Security
United States
Secret Service
Variances
ƒ Not all fields of inquiry use same steps for Scientific Method,
names of steps can differ
ƒ When researching method, you might encounter different
formats within different reference sources
ƒ Implementation of Scientific Method is valid so long as it
follows principles outlined previously
U.S. Department of
Homeland Security
United States
Secret Service
Digital Forensic Analysis and the
Scientific Method
ƒ Scientific Method provides useful guide when attempting to
locate items of interest within digital media, or copies of digital
media
ƒ Useful for incident responder when attempting to identify
devices that may contain information related to series of
events
U.S. Department of
Homeland Security
United States
Secret Service
Example of Application
ƒ Incident responder responds to several IDS alerts indicating
attack against Web server
ƒ Alerts are initial observations
ƒ Responder might form a hypothesis that Web server attacked
and compromised by method indicated in alerts
ƒ To test hypothesis, analyst deduces (predicts) most probable
location of artifacts to support or contradict hypothesis that
system was successfully attacked
U.S. Department of
Homeland Security
United States
Secret Service
Example of Application
ƒ Supporting artifacts might include unauthorized Registry
entries, presence of malicious code, additional IDS alerts,
unauthorized user accounts, etc
ƒ Contradicting artifacts could be other log entries that show
observed events part of normal activity for an application
ƒ Analyst gathers data from devices containing artifacts, and
evaluates data for their presence
U.S. Department of
Homeland Security
United States
Secret Service
Example of Application
ƒ Examiner finds artifacts that support hypothesis that system
was successfully attacked
ƒ Concludes that hypothesis was correct, proceeds to write
report
ƒ Alternatively, hypothesis may have been falsified due to
discovery of artifacts indicating legitimate technical reason for
IDS alerts such as standard false positive
ƒ Investigator may not find sufficient evidence to make any
conclusion in which case he/she may create a new hypothesis
U.S. Department of
Homeland Security
United States
Secret Service
Use of Scientific Method for
Computer Intrusion Investigations
ƒ Computer network intrusions can be complex, difficult to track
ƒ Attack can span multiple networks, thousands of systems
ƒ Danger for investigative team is spending too much time
acquiring and analyzing data from unrelated systems
ƒ Scientific Method helps avoid pitfall by encouraging use of a
logical process to determine approach to investigation
U.S. Department of
Homeland Security
United States
Secret Service
Use of Scientific Method for
Computer Intrusion Investigations
ƒ Key element is link between observed events and subsequent
investigative tasks
ƒ Creating hypotheses based on observations and events,
makes it more likely you will perform analysis tasks that
produce results, less likely you will follow unproductive
tangents
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 3 - Observing Intrusion-related
Activity and Forming a Hypothesis
ƒ Common Observations
ƒ Hypothesis Formation
ƒ Incident Classification
U.S. Department of
Homeland Security
United States
Secret Service
Observations and Network Intrusions
ƒ Network intrusion investigations should normally begin with
one or more observation
ƒ Observations guide formation of hypothesis as to what
occurred
U.S. Department of
Homeland Security
United States
Secret Service
Common Primary Observations
ƒ Antivirus alerts
ƒ IDS/IPS alerts
ƒ System/applications errors
ƒ Abnormal authentication patterns
ƒ Access control list violations
ƒ Generic unusual activity
U.S. Department of
Homeland Security
United States
Secret Service
Supplementary Observations
ƒ Incident responder should make supplementary observations
before creating hypothesis
ƒ Not directly observed events, rather sets of data that
responder should collect in any security incident
U.S. Department of
Homeland Security
United States
Secret Service
Supplementary Observations
ƒ Network diagrams: Logical and physical diagrams of networks
ƒ Device documentation: Lists of device names and
configuration data, vital for devices directly involved in events
ƒ Contact information: Names, phone numbers, e-mail
addresses, etc. for witnesses and people responsible for
affected networks and systems
ƒ Other data: Other details regarding affected devices and
networks that may seem pertinent
U.S. Department of
Homeland Security
United States
Secret Service
Common Observation Attributes
ƒ Date/time: Record when event occurred, as well as duration
ƒ IP addresses: If event is log entry that includes an IP address,
or involves system with IP address, IP addresses should be
recorded
ƒ Port numbers: If event is log entry that includes port numbers,
or involves application that engages in network communication
over specific port, ports should be recorded
ƒ Host names and aliases: Host names and aliases for systems
involved in event should be recorded
U.S. Department of
Homeland Security
United States
Secret Service
Common Observation Attributes
ƒ Accounts and aliases: Specific user account or alias, should be
recorded, as well as names of specific individuals that use
account or alias, if information known
ƒ Files: At minimum, name and full path for any files involved,
attributes, hash values, file system date/time stamps
ƒ General description: General description as to nature of each
event
U.S. Department of
Homeland Security
United States
Secret Service
Hypothesis Formation
ƒ What/How - Basic description of main event(s), may include
common incident classification
ƒ Where - List known and probable physical locations and
network segment locations of incident
ƒ When - List known and probable timeframe of incident
ƒ Who - List identifying information for individual(s)/computer(s)
known to be involved or likely involved in incident
ƒ Why - List most likely motive(s)
U.S. Department of
Homeland Security
United States
Secret Service
Multiple Hypotheses
ƒ Incident may be too large and complex for single hypothesis
ƒ May need to establish multiple hypotheses to account for
different parts of incident
ƒ For instance, intrusion may have signs that attacker entered
through public Web server and several compromised
workstations
ƒ To effectively pursue each possibility, could create a
hypothesis for each potential method of entry
U.S. Department of
Homeland Security
United States
Secret Service
Multiple Hypotheses
ƒ Managers or lead investigators, may assign different
investigators to investigate each hypothesis
ƒ Could create third hypothesis to account for how attacker(s)
are extracting stolen data from network
ƒ No rule for determining how many hypothesis to create or how
detailed
ƒ Hypotheses should reflect the size and complexity of incident
U.S. Department of
Homeland Security
United States
Secret Service
Incident Classifications
ƒ Implement an incident classification schema to ensure a
common vocabulary between agency and organization
requesting assistance
ƒ Classification should be broad enough to capture major types
of incidents
U.S. Department of
Homeland Security
United States
Secret Service
Common Incident Classification
ƒ Denial of Service
ƒ Malicious Code
ƒ Unauthorized Access
ƒ Inappropriate usage
ƒ Suspicious activity
ƒ Multiple Component
ƒ Other
U.S. Department of
Homeland Security
United States
Secret Service
Denial of Service
ƒ Prevents or impairs authorized use of networks, systems, or
applications
ƒ Network service is unavailable for an unknown reason
ƒ Computer network saturated with excessive amount of traffic
ƒ Application saturated with authentication or service requests
ƒ Application or operating system not functioning for unknown
reason
U.S. Department of
Homeland Security
United States
Secret Service
Malicious Code
ƒ Program or group of programs that perform undesirable activity
ƒ Antivirus alerts
ƒ IDS alerts that indicate malicious code
ƒ A higher than normal volume of network traffic
ƒ Computer systems crash or malfunction for unknown reason
ƒ Egress communication not initiated by user or authorized
application
U.S. Department of
Homeland Security
United States
Secret Service
Unauthorized Access
ƒ Person gains logical or physical access without permission to
network, system, application, data, or other resource
ƒ User account authentication at abnormal times, or at times
user to which account assigned denies having been on system
ƒ Presence of unauthorized user accounts
ƒ Missing data
U.S. Department of
Homeland Security
United States
Secret Service
Unauthorized Access
ƒ Logged data access at abnormal times or by user account not
normally used for such access
ƒ Presence of unauthorized computer programs
ƒ Presence of large archives (TAR, RAR, Zip, etc.) of data files
for which there is no explanation
ƒ Common observations from any other type of intrusion-related
activity
U.S. Department of
Homeland Security
United States
Secret Service
Inappropriate Usage
ƒ Violations of acceptable computing use policies
ƒ Web browsing sessions to websites containing unauthorized
workplace material
ƒ Inappropriate e-mails sent to coworkers or from a work
account
ƒ Recorded network traffic that indicates presence of
unauthorized application, such as a peer-to-peer file sharing
application
U.S. Department of
Homeland Security
United States
Secret Service
Suspicious Activity
ƒ Security operations personnel notice unusual activity not
specifically related to known threat, unexplainable through
experience
ƒ Increase network activity
ƒ Increase CPU activity on a system
ƒ Unexplained network activity
U.S. Department of
Homeland Security
United States
Secret Service
Multiple Component
ƒ Multiple component classification, situation that encompasses
two or more incidents out of one
ƒ For example, malicious code infection leads to unauthorized
access to host, used to gain unauthorized access to additional
hosts
ƒ Workstation affected by a virus and scanning the network
ƒ Server relaying IRC traffic
U.S. Department of
Homeland Security
United States
Secret Service
Other
ƒ Category serves as catch all group for newly identified exploits
that do not fit in previously listed categories
ƒ Penetration Testing
ƒ Innovative ways to attack a system
ƒ Zero-day Exploits
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 4 - Predicting the Nature and
Location of Intrusion Artifacts
ƒ Predicting the Nature and Location of Intrusion Artifacts
ƒ Relating Observed Events to Network Services and Traffic
Types
ƒ Mapping Observed Activity to Traffic Flow
ƒ Using Traffic Flow and Service Type to Predict Artifact
Location
U.S. Department of
Homeland Security
United States
Secret Service
Finding Intrusion Artifacts
ƒ Mapping observed events to related applications and traffic
ƒ Map observed activity to traffic flow of network traffic
ƒ Using probable traffic flow, applications involved and traffic
types, determine devices that may house artifacts of observed
and hypothesized events
ƒ Establish plan for gathering data from identified devices, and
for identifying relevant artifacts within those data sets
U.S. Department of
Homeland Security
United States
Secret Service
Relating Events to Applications
ƒ Correlate observed events to applications involved
ƒ Help to locate potential artifacts
ƒ For instance, if event was buffer overflow IDS alert, destination
port of 80, could surmise target application may be Web server
ƒ Recognizing this, place this application on your list of potential
artifact sources, gather and analyze logs from that application
U.S. Department of
Homeland Security
United States
Secret Service
Relating Events to Applications
ƒ Identify network traffic types that correspond to observed
TCP/UDP ports
ƒ For instance, observed TCP port 25 traffic indicates SMTP
most likely involved
ƒ Identify applications related to observed and/or extrapolated
network traffic types
ƒ From example, if SMTP were likely protocol, indicative that an
e-mail server and client application probably also involved
U.S. Department of
Homeland Security
United States
Secret Service
Concept of Profiling an Event
U.S. Department of
Homeland Security
United States
Secret Service
Additional Applications
ƒ Identify applications that have capability of logging activity
related to network traffic types
ƒ Applications you have singled out
ƒ For instance, SMTP gateways would have capability of logging
data about traffic between e-mail servers and clients
U.S. Department of
Homeland Security
United States
Secret Service
Additional Applications
ƒ Identify applications directly involved in generation of observed
events
ƒ Includes security devices/applications that produced log files
that contained initial observations
ƒ Following example from previous slides, Snort IDS that
generated alert would be added to list of applications that may
contain relevant artifacts
U.S. Department of
Homeland Security
United States
Secret Service
Identifying Additional Applications
U.S. Department of
Homeland Security
United States
Secret Service
Recording Traffic Types
ƒ Locate all devices that related traffic may have passed through
ƒ For instance, if investigator believes that intrusion-related
traffic passed through specific point of ingress/egress for
network, devices at that point (firewalls, routers, IDS sensors,
etc.) could potentially contain important artifacts
U.S. Department of
Homeland Security
United States
Secret Service
Mapping Activity to Network Traffic
ƒ Obtain a logical or physical network diagram, and/or access to
a network administrator that has working knowledge of current
topology
ƒ Diagram should be broad enough to include all points of
ingress/egress from affected network segments, including
paths to Internet
ƒ Ascertain IP addresses for devices involved in incident
ƒ Identify ports and protocols corresponding to related network
protocols
U.S. Department of
Homeland Security
United States
Secret Service
Mapping Activity to Network Traffic
ƒ Use information obtained to identify all routes between affected
devices and between those devices and Internet
ƒ Record routes in notes or mark on working copies of any
network diagrams
U.S. Department of
Homeland Security
United States
Secret Service
Other Routes of Interest
ƒ Alternate points of network traffic ingress/egress from network
segment on which each device resides
ƒ Identify routes to major service network segments not inline
with default gateway
ƒ Network segments with directory servers, e-mail servers, file
and print servers, backup servers etc
U.S. Department of
Homeland Security
United States
Secret Service
Other Routes of Interest
ƒ Routes used by incoming traffic to affected network segment if
not the same as default outbound route
ƒ Routes used by public service requests to segment, internal
service requests, VPN pathways, etc
ƒ In network, check specific protocols sent through alternate
routes to reach proxy servers
ƒ If found, identify routes between affected network segment and
those proxy servers
U.S. Department of
Homeland Security
United States
Secret Service
Adding Source and Destination
U.S. Department of
Homeland Security
United States
Secret Service
Mapping Traffic Routes
U.S. Department of
Homeland Security
United States
Secret Service
Predicting Artifact Location: Devices
ƒ Determine host system for application
ƒ Determine if application uses local or remote (SAN, NAS, etc.)
storage
ƒ If remote is used, identify associated storage devices
ƒ Determine if host system is backed up on a regular basis or
and whether data backed up to local media, or remote system
ƒ If local, where are tapes or other backup media stored
ƒ If remote, identify remote backup server
U.S. Department of
Homeland Security
United States
Secret Service
Predicting Artifact Location: Devices
ƒ Determine if application is part of distributed application
system (such as a Web server with a database backend)
ƒ Identify other applications in system, and hosts on which they
reside
ƒ If multiple systems host application as part of a load-balancing
configuration, identify all systems hosting copies of application
ƒ If application configured to use proxy device when
communicating on network, identify all associated proxy
devices
U.S. Department of
Homeland Security
United States
Secret Service
Predicting Artifact Location: Devices
U.S. Department of
Homeland Security
United States
Secret Service
Predicting Artifact Location: Files
ƒ If application keep logs determine full path to log storage
location
ƒ If application or host system configured to send logs to remote
repository, identify system
ƒ Determine full path and name of files in which application
stores configuration information
U.S. Department of
Homeland Security
United States
Secret Service
Predicting Artifact Location: Files
ƒ Determine name and full path of files in which application
stores persistent and temporary data
ƒ Determine whether application requires authentication
ƒ Determine if application uses its own authentication
mechanism or forward authentication data to an outside
application (such as Active Directory)
U.S. Department of
Homeland Security
United States
Secret Service
Predicting Artifact Location: Files
ƒ Following example scenario, potential victim in attack could be
an IIS Web server that contains certain log files to be analyzed
ƒ Windows Event log
ƒ IIS log
ƒ Dr. Watson log
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 5 - Using Log Analysis to
Evaluate an Intrusion Hypothesis
ƒ Hypothesis Evaluation
ƒ Acquiring Target Log Files
ƒ Reviewing Target Log Formats
ƒ Establishing Search/Extraction Criteria
ƒ Searching Target Logs and Extracting Relevant Data
ƒ Recording and Correlating Findings
ƒ Keeping Track of New Leads
U.S. Department of
Homeland Security
United States
Secret Service
Hypothesis Evaluation
ƒ Acquire target log files
ƒ Review the format of collected logs
ƒ Establish search/extraction criteria based upon predicted
artifacts and log format
ƒ Search log files and extract relevant data
ƒ Record and correlate findings
ƒ Document unexpected findings related to case (“leads”)
U.S. Department of
Homeland Security
United States
Secret Service
Procedure Selection
ƒ Procedure can locate specific potential artifacts identified in
previous step in Scientific Method
ƒ Procedure should have been tested and peer reviewed
ƒ Procedure should be repeatable
ƒ Procedure should be as objective as possible
U.S. Department of
Homeland Security
United States
Secret Service
Acquiring Log Files
ƒ Log files may be provided directly by incident responder or
network administrator who collected them from original source
media
ƒ Could obtain physical or logical image of original storage
media containing log files, and extract logs from image
ƒ Could obtain logical copy log files from source system or
device
ƒ Regardless of method, ensure logs collected in sound manner
in accordance with maintaining integrity of evidence
U.S. Department of
Homeland Security
United States
Secret Service
Previewing Log Formats
ƒ Before analyzing, preview format to ensure you know how to
read them properly and use correct methods for searching
ƒ Search techniques significantly different between text and
binary logs
ƒ Information may be presented in different forms in text logs
ƒ Fields and format may differ and record separators
ƒ For example, time may be represented in 24-hour format or
12-hour with AM or PM specified
U.S. Department of
Homeland Security
United States
Secret Service
Determining File Type
ƒ View file extension and correlate to file type
ƒ For instance, file with “.EVT” extension is Windows Event Log
file and should be viewed with Microsoft Event Viewer
application
ƒ If unfamiliar with extension, research it online
ƒ Use GNU “file” command, does not rely on file extensions,
useful if log file does not include extension
U.S. Department of
Homeland Security
United States
Secret Service
Determining File Type
ƒ Attempt to view file with text log viewer, such as notepad.exe,
or GNU command such as “cat”, “more”, “tail”, etc
ƒ If successful, file is text log and viewable as such
ƒ File - Open dialog in Wireshark will display format of binary
capture files that it recognizes when file is highlighted
U.S. Department of
Homeland Security
United States
Secret Service
Determining Data Format
ƒ Determine if records include one line or multiple lines
ƒ Identify field and record separators
ƒ Determine where common data types (IP addresses, port
numbers, date/time, etc.) are located in each record, if
anywhere
ƒ Determine if locations are always same or vary
U.S. Department of
Homeland Security
United States
Secret Service
Search/Extraction Criteria
ƒ Known or estimated time frame
ƒ Observed or predicted source or destination IP addresses
ƒ Messages that correlate with observed or predicted activity
ƒ Observed user name or alias
ƒ Observed or predicted network protocols or traffic types
ƒ Any combination of criteria mentioned in items above
U.S. Department of
Homeland Security
United States
Secret Service
Search/Extraction Criteria
ƒ Previously listed criteria examples are guides only
ƒ No hard and fast rule for choosing specific search and
extraction criteria
ƒ Criteria must be selected based upon potential for producing
data to further investigation of hypothesis
U.S. Department of
Homeland Security
United States
Secret Service
Correlation: Timeline Unification
ƒ Normalize all log files to synchronized time and time notation
ƒ Involves changing actual date/time stamps in log file, should
only be performed on working copies of log
ƒ Record events identified during initial observation and
subsequent testing/evaluation into single timeline
ƒ Adjust time on each event as necessary as recorded
U.S. Department of
Homeland Security
United States
Secret Service
Correlation: Event Verification
ƒ Any event can be correlated with data in full network traffic
capture
ƒ Verify Web browser history with proxy server logs, both record
URL access and associated times
ƒ Verify IDS scan alerts with firewall logs
ƒ Verify IDS password attacks alerts with authentication logs
ƒ Verify e-mail header date/time stamps with e-mail gateway or
e-mail server logs
U.S. Department of
Homeland Security
United States
Secret Service
Correlation: Synchronize Times
ƒ Compare dates/times for events against multiple sources to
see if there are discrepancies in time in data sources
ƒ For instance, user IE history shows access to Web mail
occurring at 2105, Web proxy shows access occurred at 2135
ƒ Analyst could use two events to determine that proxy server
was most likely set 30 minutes behind clock on subject system
ƒ Ideally, multiple events correlate to verify time
U.S. Department of
Homeland Security
United States
Secret Service
Correlation: Synchronize Times
ƒ Compare date/time stamps embedded in files with file system
date/time stamps
ƒ Compare date/time stamp of last entry in log with file system
last accessed time
ƒ If event involved access to one or more files, check
appropriate file system date/time stamps for file
U.S. Department of
Homeland Security
United States
Secret Service
Unexpected Findings
ƒ May often discover information not directly predicted during
initial analysis of hypothesis
ƒ Can be identified as a “lead”
ƒ Information is sometimes related to hypothesis, and other
times important but outside of current investigation
ƒ Information should be recorded for follow up as needed
U.S. Department of
Homeland Security
United States
Secret Service
Lead Tracking
ƒ New leads should be documented
ƒ Leads should be recorded in Attribute List spreadsheet along
with other relevant data
ƒ Entries representing leads should be marked as to whether or
not they are relevant to current working hypothesis
ƒ Highlight other leads in a different color
ƒ List other lead entries on a separate page, tab, table, etc.
ƒ Use a column in a table to mark other lead entries as such
U.S. Department of
Homeland Security
United States
Secret Service
U.S. Department of
Homeland Security
United States
Secret Service
Module 13 - Log Sources
U.S. Department of
Homeland Security
United States
Secret Service
You Will Learn . . .
ƒ Windows Log Sources
ƒ Linux Log Sources
ƒ Solaris Log Sources
ƒ Log Searching
ƒ IDS Logs
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 1 - Windows Log Sources
ƒ Windows Logs
ƒ Windows Services Logs
U.S. Department of
Homeland Security
United States
Secret Service
Windows Logs
ƒ Windows includes Outlook or Outlook Express as a mail client
ƒ Default location for log files in Windows 2000, Server 2003 and
XP is individual user’s profile
ƒ Outlook’s MAPI accounts log found at: C:\Documents and
Settings\username\Local Settings\Temp\Opmlog.log
ƒ If user established Hotmail account in Outlook, events logged
in: C:\Documents and Settings\username\Local
Settings\Temp\Outlook Logging\Hotmail\http0.log
U.S. Department of
Homeland Security
United States
Secret Service
Microsoft SQL Databases
ƒ One of most popular database services used in businesses
ƒ Stores log files in C:\MSSQL\LOG
U.S. Department of
Homeland Security
United States
Secret Service
Log files in MSSQL\LOG
ƒ ERRORLOG - MS SQL’s default error log file
ƒ If logging configured to create new files on routine basis, or
file grows too large, additional error logs will be created with
a sequential number appended
ƒ SQLAGENT.OUT - Can contain information generated by SQL
programmer or messages generated by default in
administrative panel
ƒ Files can have numbers for versions at end
ƒ File with OUT suffix is current log
U.S. Department of
Homeland Security
United States
Secret Service
Log files in MSSQL\LOG
ƒ SQLDump9999.txt andSQLDump9999.mdmp - Special dump
files generated if SQL Server crashes or terminates
unexpectedly
ƒ Information in files generally contains memory and data
pointers at time of failure
ƒ Also possible for administrator, or attacker to force
generation of these files under special circumstances
ƒ NOTE: If server running, may not be possible to copy or open
current log files
U.S. Department of
Homeland Security
United States
Secret Service
MySQL
ƒ MySQL is free, open source database application, popular on
many Windows systems
ƒ Default location for installation of MySQL in Windows is
C:\Program Files\MySQL\MySQL Server X.X
ƒ In folder name, X.X is software’s version number
U.S. Department of
Homeland Security
United States
Secret Service
Directories and Logs in X.X Folder
ƒ Bin
ƒ Contains client programs and server program
ƒ Data
ƒ Holds log files and actual databases
ƒ Share
ƒ Has error message files
ƒ Error filename will typically start with network host name of
system MySQL is running on and end with .err suffix
U.S. Department of
Homeland Security
United States
Secret Service
Microsoft Access
ƒ Errors generated by Access stored in Windows Event logs
ƒ Information for retrieval of Event logs discussed with System
Logs
U.S. Department of
Homeland Security
United States
Secret Service
Internet Information Server (IIS)
ƒ IIS is service used by millions of Windows based servers to
host web, FTP, and e-mail services
ƒ Depending on version in use, logs can be found in different
locations
ƒ IIS normally stores logs in default folder,
ƒ Log location can be easily changed in administration control
panel
U.S. Department of
Homeland Security
United States
Secret Service
Internet Information Server (IIS)
ƒ Log files stored in C:\winnt\system32\logfiles for IIS versions 4
and 5, found on Windows NT 4.0 and Windows 2000
ƒ Log files stored in: C:\windows\system32\logfiles for IIS version
6 and 7, found on Windows XP and newer systems
U.S. Department of
Homeland Security
United States
Secret Service
Internet Information Server (IIS)
ƒ Log files named “W3SVC” followed by Site Instance ID,
numbered sequentially for each service
ƒ For example, first web site log files start with W3SVC1, and
second W3SVC2
ƒ Web enabled service originate in IIS service
ƒ FTP and DNS messages will be mingled in same W3SVC file if
services are active
U.S. Department of
Homeland Security
United States
Secret Service
Windows System Logs
ƒ Almost all other services that originate in Windows log entries
into one or all standard Event Logs
ƒ Logs divided into Application, Security and System
ƒ Use Event Viewer to view logs
ƒ Log files stored in a mixed binary format, making standard text
based tools ineffective
U.S. Department of
Homeland Security
United States
Secret Service
Windows System Logs
ƒ Can choose log file of interest from menu in Event Viewer and
export as:
ƒ Tab Delimited text
ƒ Comma Delimited text
ƒ Tab Delimited Unicode text
ƒ Comma Delimited Unicode text
ƒ Exported files can be filtered and searched using tools like
Grep and Findstr
U.S. Department of
Homeland Security
United States
Secret Service
Directory Services
ƒ If Directory Services is configured, applicable events found
under Directory Services in Event Viewer
U.S. Department of
Homeland Security
United States
Secret Service
Remote Logs
ƒ Looking at mounted share locations and names, may give
indication that logs are stored remotely
ƒ Examination of remote shares may provide folder and file
names which indicate what types of logs are stored remotely
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 2 - Linux Log Sources
ƒ Linux Logs
U.S. Department of
Homeland Security
United States
Secret Service
Linux Mail Logs
ƒ Linux is based on Unix style kernel
ƒ Mail services provided by sendmail processes
ƒ Logs for these services usually found in /var/log/maillog
U.S. Department of
Homeland Security
United States
Secret Service
Database
ƒ MySQL is most popular database program within Linux
community
ƒ MySQL logs typically found in /var/log/mysqld.log
U.S. Department of
Homeland Security
United States
Secret Service
Linux Services Files
ƒ /var/log/message: General messages and system related
errors
ƒ /var/log/auth.log: Remote Login Authentication logs
ƒ /var/log/secure: Remove Login Authentication log
ƒ /var/log/kern.log: Kernel logs
ƒ /var/log/cron.log: Crond logs, for services that start
automatically
U.S. Department of
Homeland Security
United States
Secret Service
Linux Services Files
ƒ /var/log/httpd/: Apache web server access and error logs
directory
ƒ /var/log/boot.log : System boot log
ƒ /var/log/utmp or /var/log/wtmp : Binary Login history file
ƒ /var/log/yum.log: Yum log files to track installed and uninstalled
applications
U.S. Department of
Homeland Security
United States
Secret Service
Linux Directory Management
ƒ Linux does not directly support Microsoft Active Directory
ƒ Numerous third party add-on tools available to provide the
service
ƒ Seek documentation for specific AD tool encountered and
determine location of logs for each
U.S. Department of
Homeland Security
United States
Secret Service
Linux System Logs
ƒ Most located in the /var/log/message file
U.S. Department of
Homeland Security
United States
Secret Service
Remote Logs
ƒ Looking at mounted share locations and names may provide
indication that logs are stored remotely
ƒ Examination of remote shares may identify folder and file
names which indicate what types of logs are stored remotely
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 3 - Solaris Log Sources
ƒ Solaris Logs
U.S. Department of
Homeland Security
United States
Secret Service
Solaris Mail
ƒ Depending on version of Solaris, may find file in /etc directory
called syslog.conf, and location of sendmail logs listed inside
ƒ Many ISP’s moved to custom mail software
ƒ Seek documentation on software to determine log file location
U.S. Department of
Homeland Security
United States
Secret Service
Databases
ƒ If MySQL installed on Solaris system, look for logs in default
locations of /usr/local/mysql/data or /opt/mysql/mysql/data
ƒ Oracle is popular database for Solaris systems
ƒ Determine version and release level of Oracle software
ƒ Search for default installation location of log files
U.S. Department of
Homeland Security
United States
Secret Service
Solaris Services
ƒ Most Solaris services put log messages in /var/adm/messages
log file
ƒ General catch all file for log entries in Solaris
U.S. Department of
Homeland Security
United States
Secret Service
Directory Management
ƒ Solaris doesn’t natively support Microsoft Active Directory
directly
ƒ Numerous third party add-on tools available to provide this
service
ƒ Seek out documentation for specific AD tool and determine
location of logs for each
U.S. Department of
Homeland Security
United States
Secret Service
Solaris System
ƒ Solaris system log files located in /var directory
ƒ Usually several nested directories of log files under /var
directory
ƒ Investigation may show some or all have information of
evidentiary value
ƒ Cannot open files in use
U.S. Department of
Homeland Security
United States
Secret Service
Remote Logs
ƒ Search for pipes and hard links to mounted volumes in order to
discover whether logs are stored remotely
ƒ In Solaris environment attempt to locate a certified Solaris
administrator to discover obfuscated links
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 4 - Log Searching
ƒ Log Searching
ƒ Regular Expressions
U.S. Department of
Homeland Security
United States
Secret Service

 

 

 

 

 

 

 

Content      ..     16      17      18      19     ..