|
|
Detailed Questions Address
Ownership and authorized access of systems
User account information
Statements of how systems are used
Individual access to relevant systems and/or data
Specific commands or tools used during discovery of incident
Security video or proximity card logs
U.S. Department of
Homeland Security
United States
Secret Service
Interview Termination
Thank subject for time and cooperation
Ask subject for contact information in case need arises for
clarification of material discussed during interview
U.S. Department of
Homeland Security
United States
Secret Service
Interview Psychology
Take into account subject’s perspective and culture
Establish tone for interview, important in obtaining all
necessary information available from subject
Approach may differ depending on whether investigator
initiates contact for information or investigator is called by
organization
Issue influences how investigator structures approach to
interviews
U.S. Department of
Homeland Security
United States
Secret Service
Interview Psychology
When organization calls in investigator, most of organization’s
key players already involved
Management typically supports initial stages of investigation
Obtain written documentation from everyone involved and
begin working on controlling investigation
Important to minimize mishandling or destruction of evidence
and spread of information
U.S. Department of
Homeland Security
United States
Secret Service
Investigator Initiated Contact
Identify point of contact within organization
Look up registration information for company via Internet
search engine and identify legal counsel and network
administrator
Variety of state, federal, and private registries contain
information and provide it to law enforcement agencies
Several Internet service provider lists include contact
information for major communications providers such as AOL,
Microsoft, Google, Yahoo, and others
U.S. Department of
Homeland Security
United States
Secret Service
Investigator Initiated Considerations
Is system administrator or someone with root access
responsible for activity?
Do they know suspect and are they relaying information about
the investigation to their associate?
Are there any regulatory or legal barriers to organization
providing information (ECPA, PPA, FERPA, HIPPA,
Organizational Policy, etc.)
How critical is evidence held by company to the case?
Is a life or national security at stake?
U.S. Department of
Homeland Security
United States
Secret Service
Investigator Initiated Considerations
Access to legal instruments such as subpoenas, search
warrants, FISA, or other items in timely manner?
Technical knowledge to handle systems or logs that will be
obtained from scene or require assistance?
Evidence contained or spread out over national or global
network infrastructure?
Manpower, technical knowledge, and resources to obtain
what’s needed from target organization?
U.S. Department of
Homeland Security
United States
Secret Service
Investigator Initiated Considerations
Best to identify senior management, legal counsel, and
technical heads prior to making contact
Start at top of organization’s hierarchy and work down towards
individuals responsible for managing or using various
computer and network services
Address legal issues, business impact, and concern for
organization’s needs in order to gain more cooperation
U.S. Department of
Homeland Security
United States
Secret Service
Investigator Initiated Considerations
If an investigation could be compromised by reaching out avoid
“tipping off” organization or individuals
Do research and case preparation to obtain most effective
legal authority that will allow gathering evidence and
interviewing in most effective and efficient manner
U.S. Department of
Homeland Security
United States
Secret Service
Organization Initiated Contact
Investigator will more likely have cooperation
Victim may have performed internal investigation that may or
may not have been done properly
Still need to follow up to ensure accuracy of any information
provided
Document any actions taken by people at company
Important to work with legal counsel and network
administrators
U.S. Department of
Homeland Security
United States
Secret Service
Organization Initiated Contact
Many organizations ignorant of investigation’s process and do
not use proper evidence handling procedures
Common practices used by organizations to minimize or repair
damage often hamper investigation
U.S. Department of
Homeland Security
United States
Secret Service
Organization Initiated Concerns
When compromised it is common practice to just restore
machine from base image
Often untrained system administrators or management work
on live systems and alter artifacts and time lines
More concern for system/network integrity compared to
retaining evidence or identifying cause of incident
U.S. Department of
Homeland Security
United States
Secret Service
Organization Initiated Concerns
Chain of custody issues are often not followed
Lack of network maps and diagrams
Incomplete knowledge of system functions and passwords
Poor documentation of system builds, organizational policies,
or security controls
U.S. Department of
Homeland Security
United States
Secret Service
Witness and Victims
Often provide investigator initial foundation of case and
information needed to build framework for investigation
System administrator or user of an online database may be
first to notice strange behavior or altered data
A relative or friend may discover suspected child pornography
images on a computer
In either situation, investigator needs to elicit information from
people to obtain facts that will lead them to suspect
U.S. Department of
Homeland Security
United States
Secret Service
Witness and Victims
Keep in mind, anyone could be a suspect
During initial response and interviews, obtain clear and concise
written documentation from people involved
Documentation should consist of any actions taken by
witnesses and events observed during incident
Documentation is important part of freezing crime scene and
creating permanent record of events that occurred during and
subsequent to discovery of crime
U.S. Department of
Homeland Security
United States
Secret Service
Witness and Victims
People being interviewed may have had little contact with law
enforcement and may not recognize evidence needed to
further investigation
Develop a rapport with interview subjects and guide interview
in direction that will obtain most relevant and complete
information available
U.S. Department of
Homeland Security
United States
Secret Service
Issues to Address
System administrators or people with administrative powers
may be potential suspects
Move quickly and efficiently to build case
If immediate action is not an option, ensure that suspect’s
access to evidence or sensitive material is removed
Covert tactics may be necessary if you have proper
administrative approval, legal documents, and technical
capabilities in place
U.S. Department of
Homeland Security
United States
Secret Service
Issues to Address
Obtaining witness statements about suspect’s access to
machine or data is important
Supplement network logs and/or forensic analysis with as
much traditional detective work as possible
Determine if people share machines, use passwords, or share
passwords
Recent attempts at social engineering, phone calls or any
person asking for user accounts, passwords, or other sensitive
technical information
U.S. Department of
Homeland Security
United States
Secret Service
Suspects
Traditionally, investigators interview victim and eventually a
suspect
In cyber crime cases, can be unclear who is victim or who is a
suspect
Investigator must use analytical skills to determine who should
be interviewed during an investigation and best approach to
take
U.S. Department of
Homeland Security
United States
Secret Service
U.S. Department of
Homeland Security
United States
Secret Service
Module 11 - Legal Issues
U.S. Department of
Homeland Security
United States
Secret Service
You Will Learn . . .
Search Warrants
Internet Service Providers
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 1 - Search Warrants
Affidavit
Warrant
U.S. Department of
Homeland Security
United States
Secret Service
Search Warrants
“The right of the people to be secure in their persons, houses,
papers, and effects, against unreasonable searches and
seizures, shall not be violated, and no Warrants shall issue,
but upon probable cause, supported by Oath or affirmation,
and particularly describing the place to be searched, and the
persons or things to be seized.”
U.S. Department of
Homeland Security
United States
Secret Service
Search Warrants
Authorization for search and seizure from approving authority
prior to execution of activities
Provide most reliable means of obtaining evidence
Properly crafted and executed, difficult to overcome
Preferred by Supreme Court when probable cause to believe a
crime has been committed and seeking search authority
U.S. Department of
Homeland Security
United States
Secret Service
Obtaining a Search Warrant
Be familiar with Federal Rules of Criminal Procedure Rule 41,
“Search and Seizure”
Investigator who requests search warrant must establish by
sworn affidavit some key pieces of information
Failure to establish any of these facts can result in search
warrant being denied or overturned
U.S. Department of
Homeland Security
United States
Secret Service
Facts for Issuance of Search Warrant
Description of place to be searched
Concise description of item(s) being sought
Probable Cause or facts that support belief that items being
sought are located in place described
U.S. Department of
Homeland Security
United States
Secret Service
Example Search Warrant
A copy of a modern federal search warrant is found as an
editable PDF format at:
U.S. Department of
Homeland Security
United States
Secret Service
Affidavit
Warrant typically accompanied by an attached affidavit
Affidavit will normally contain the following components:
The affiant’s statement of probable cause
Attachment A - Place To Be Searched
Attachment B - Items To Be Seized
U.S. Department of
Homeland Security
United States
Secret Service
Format
No formally required format for typical affidavit attachments,
though various agencies and jurisdictions may follow formats
developed over time
Warrant will generally give brief statements of affidavit
components and refer to affidavit for greater detail
See example in student book
U.S. Department of
Homeland Security
United States
Secret Service
(CCIPS) Guide for Warrants
United States Department of Justice, Computer Crime and
Intellectual Property Section (CCIPS), publishes useful guide
called Searching and Seizing Computers and Obtaining
Electronic Evidence in Criminal Investigations
Publication is available in hardcopy, and online at:
U.S. Department of
Homeland Security
United States
Secret Service
(CCIPS) Guide for Warrants
Appendix F of CCIPS publication, Sample Language for
Search Warrants and Accompanying Affidavits to Search and
Seize Computers, is de facto standard for warrant/affidavit
language in federal cyber investigations
U.S. Department of
Homeland Security
United States
Secret Service
Description of Place to be Searched
4th Amendment requires investigator to concisely identify and
define search location in physical terms
Often difficult to do in cyber crime investigation as physical and
virtual worlds may not share same physical space
Goal is to define boundaries of search location in manner that
area within those boundaries may be searched, but search is
not overly broad
See examples in student book
U.S. Department of
Homeland Security
United States
Secret Service
Description of Item(s) to be Seized
Investigators crafting a search warrant affidavit should carefully
consider description of items sought in seizure
In most cyber crime cases, item sought is basically information
If information can be described, different forms it may take and
different storage media upon which it may reside, may more
easily be articulated
Must establish probable cause in sworn affidavit for each item
to be seized
See example in student book
U.S. Department of
Homeland Security
United States
Secret Service
Execution of a Search Warrant
Once warrant is signed by judge, it may be served, search
initiated, and evidence collected
Most court jurisdictions require investigator to submit a Search
Warrant Return document to the court describing items
actually seized
U.S. Department of
Homeland Security
United States
Secret Service
Surreptitious Execution of Warrant
In some cases, such as those involving organized crime
figures, or violent individuals, may want to execute warrant
without knowledge of individual and without public disclosure
of warrant or affidavit until trial
In these cases, a surreptitious entry warrant may be requested
and issued
U.S. Department of
Homeland Security
United States
Secret Service
Surreptitious Execution of Warrant
Surreptitious entry warrant authorizes investigator to enter
premises and conduct search without individual’s knowledge
Affidavits, search warrants, and Search Warrant Return are
kept under seal and not made public
Similar physical search authority can be issued under FISA
provision in accordance with the USA PATRIOT ACT
U.S. Department of
Homeland Security
United States
Secret Service
Search Warrant Exceptions
U.S. Supreme Court has interpreted specific exceptions for 4th
Amendment requirement to obtain a search warrant
Know and understand circumstances under which search of
individual or premises authorized without warrant
U.S. Department of
Homeland Security
United States
Secret Service
Warrant Exceptions
Consent
Stop and Frisk
Search Incident to Arrest
Immediate threat to life or serious bodily injury
Immediate threat of the destruction of evidence
U.S. Department of
Homeland Security
United States
Secret Service
Warrant Exceptions
Fresh pursuit
Plain view
Vehicle searches
Custodial searches
Border searches
U.S. Department of
Homeland Security
United States
Secret Service
Consent Searches
Person may waive rights under 4th Amendment and consent to
search of his person or items under his control
Most common exception to warrant clause
Evidence obtained during consent search is admissible in court
as long as investigator obtained proper consent
Investigators should understand how consent is granted and
limitations
U.S. Department of
Homeland Security
United States
Secret Service
Owner Consent
Property owner has legal authority to authorize search of
premises as long as certain requirements are met:
Consent must be voluntary and not coerced
Consent must be informed
Consent can be withdrawn at any time
Consent can be limited
U.S. Department of
Homeland Security
United States
Secret Service
Owner Consent
When consent search is granted, should be obtained in writing,
signed by consenting party, dated with known good local time
and location
Most agencies have consent search form for this purpose
U.S. Department of
Homeland Security
United States
Secret Service
Voluntary Consent
To be valid, owner must consent freely and knowingly
Investigator may ask for consent to search
If permission granted by owner, investigator may search
property or premises legally
Cannot coerce owner by threats, intimidation, or power of
authority into consenting to search
U.S. Department of
Homeland Security
United States
Secret Service
Informed Consent
Not everyone capable of giving consent to search
Some are legally and mentally incompetent, unfit to make such
a decision
Those with clinically diagnosed mental conditions and severe
health problems that affect judgment, unable to intelligently
consent
Minors generally not trusted to give consent
Be familiar with court decisions in your area concerning
informed consent to search
U.S. Department of
Homeland Security
United States
Secret Service
Withdrawing Consent
Person who waives 4th Amendment rights can reassert rights
any time by telling investigator to stop search
Investigator must stop search unless in possession of some
other legal authority to continue search
Evidence located before consent is withdrawn is admissible
and can be retained investigator for further analysis
U.S. Department of
Homeland Security
United States
Secret Service
Withdrawing Consent
Prioritize places to search and items to seize when operating
under consent search in case consent is withdrawn
Maximize the effectiveness of search in the event consent is
withdrawn
Forensic copies of computer evidence should be made as
soon as possible in consent cases
U.S. Department of
Homeland Security
United States
Secret Service
Third Party Consent
Possible to obtain consent from third party for areas which are
communal to target and third party
Third party must have ownership or right to access search
area
Search area may apply to computers when multiple users
share single account
If no shared account, third party can only consent to search of
his or her account or shared storage space under his or her
control
U.S. Department of
Homeland Security
United States
Secret Service
Third Party Consent
Spouses can generally consent to search of other spouse’s
property
True as long as target has not asserted exclusive rights to
search area
Absent evidence to contrary, investigators can rely upon
consenting spouse’s assertion to authority in good faith, even if
consenting spouse later deemed not to have authority to grant
consent
U.S. Department of
Homeland Security
United States
Secret Service
Third Party Consent
Parents can generally consent on behalf of juveniles living in
premises under parent’s control
Landlords generally do not have authority to authorize search
of rented property unless such consent is authorized under a
rental agreement with tenant
U.S. Department of
Homeland Security
United States
Secret Service
Third Party Consent
Military commanders or magistrates can authorize search of
military facilities under their command, including search of
persons on those facilities
System administrators may consent to search of an entire
computer or network over which they have administrative
privileges
U.S. Department of
Homeland Security
United States
Secret Service
Immediate Threat to Life or Serious
Bodily Injury
Investigator may enter and search premise without warrant
when there is immediate threat to life or serious bodily injury
Exception allows investigator to come to immediate rescue of
individual in peril
While legally inside premises, investigator can legally seize
evidence that may be discovered during rescue attempt
U.S. Department of
Homeland Security
United States
Secret Service
Immediate Threat of the Destruction
of Evidence
An investigator may enter a premise without a warrant to stop
immediate destruction of evidence in a criminal investigation
Threat must be immediate
U.S. Department of
Homeland Security
United States
Secret Service
Fresh Pursuit
An investigator in pursuit of an individual may follow individual
into or through a premise
If evidence of a crime is observed during pursuit, investigator
may legally seize evidence
U.S. Department of
Homeland Security
United States
Secret Service
Plain View
Investigator has the right be in a physical place
Evidence of a crime visible may be seized without a warrant
Is admissible in court of law
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 2 - ISP’s
Preservation Letters
Subpoenas
Search Warrants
Available Data
Retention Schedules
U.S. Department of
Homeland Security
United States
Secret Service
Internet Service Providers’ Records
Many crimes involve use of commercial and private networks
and communications facilities
Records usually maintained by Internet Service Providers
(ISPs)
Records of accounts, billing, transactions, and content of the
communications and data
Might need to gather this pertinent information from ISPs
Should understand proper way to request records so they are
admissible as evidence in a criminal proceeding
U.S. Department of
Homeland Security
United States
Secret Service
Access to Records
Access to stored wire and electronic communications and
transactional records, governed by Chapter 121 of U.S. Code
(currently comprised of 18 USC § 2701-2711)
Enacted in 1986 by the Electronic Communications Privacy Act
(ECPA)
ECPA defines how government can obtain stored account
information from third parties
U.S. Department of
Homeland Security
United States
Secret Service
ECPA Three Information Categories
• Basic Subscriber Information - 18 U.S.C. § 2703(c)(2)
• Records or Other Information Pertaining to a Customer or
Subscriber - 18 U.S.C. § 2703(c)(1)
• Contents
U.S. Department of
Homeland Security
United States
Secret Service
Basic Subscriber Information
Name and Address
Telephone connection records, session times and durations
Length of service and types of service utilized
Telephone or instrument number or other subscriber number
or identity, including any temporarily assigned network
address; and
Means and source of payment for such service (including any
credit card or bank account number)
U.S. Department of
Homeland Security
United States
Secret Service
Records or Other Information
A catch-all for anything else that is not content
U.S. Department of
Homeland Security
United States
Secret Service
Contents
When used with respect to any wire, oral, or electronic
communication, includes any information concerning
substance, purport, or meaning of that communication
U.S. Department of
Homeland Security
United States
Secret Service
Mechanisms to Compel Disclosure
See table in student book, reproduced from U.S. DOJ
publication Searching and Seizing Computers and Obtaining
Electronic Evidence in Criminal Investigations
U.S. Department of
Homeland Security
United States
Secret Service
Express Consent
Derived from an individual’s actions as result of documents
and notices provided to individual before an incident occurs
Type of consent usually seen in logon banners or signs
advising that use of system or entry “implies” consent to be
monitored or searched
Act of entry onto system or property constitutes informed,
voluntary consent
U.S. Department of
Homeland Security
United States
Secret Service
Authority and Ownership
During initial investigation of a cyber crime, firmly establish
owner or Designated Authorization Authority of any computer
or network involved
Ownership or authority should be documented in report and
verified by supporting documentation in form of policies,
orders, copies of ownership records or written statements
U.S. Department of
Homeland Security
United States
Secret Service
Establishing and Documenting
Express Consent
When a user logs onto a computer or network, there may be
an initial warning banner that explains authority to access
computer or network as well as any implications such access
may have for the user
Banner should require some type of action by user to
acknowledge its presence and acceptance of terms
Banners that flash and disappear without user interaction may
not suffice to establish express consent
U.S. Department of
Homeland Security
United States
Secret Service
Record Retention
Storage and destruction of electronic logs and records, much
more dynamic than traditional methods of recordkeeping
Takes time to obtain court orders (up to and including
warrants)
No federal laws that require companies to preserve electronic
records for any amount of time
Some companies maintain records and logs for months, some
not at all
U.S. Department of
Homeland Security
United States
Secret Service
Preservation Request
Part of ECPA is designed to ensure available data is not lost
during time it takes to obtain preservation order
Request can be issued quickly and directly for preservation of
information for 90 days
Designed to ensure the specified information will still be there
when appropriate legal process is served
U.S. Department of
Homeland Security
United States
Secret Service
18 USC § 2703(f)(1)
“A provider of wire or electronic communication service or a
remote computing service, upon the request of a governmental
entity, shall take all necessary steps to preserve records and
other evidence in its possession pending the issuance of a
court order or other process.”
No required format for § 2703(f) requests
Most agencies have developed their own preferred format,
usually in form of a letter
Technically, request can be verbal
U.S. Department of
Homeland Security
United States
Secret Service
Subpoena
Court order requiring a person or business entity to produce
records or testimony
Failure to comply with subpoena may result in penalties or
criminal charges
Used to obtain stored transactional records (basic subscriber
information) and in some circumstances, stored wire and
electronic communications (content)
U.S. Department of
Homeland Security
United States
Secret Service
Obtaining a Subpoena
In a cyber crime investigation, investigator can request
issuance of subpoena for records under control of an individual
or business
Prosecutor has authority to issue the subpoena and have the
person or business served with the document
Once served, individual or business has right to argue before a
competent court of jurisdiction why records should not be
produced
U.S. Department of
Homeland Security
United States
Secret Service
“D” Order
Standard of proof to obtain court order under 18 U.S.C. §
2703(d) is higher than for a subpoena, but lower than for a
warrant
Information that can be obtained with a “D” order falls between
that which can be obtained by the subpoena and the warrant
Commonly used to obtain stored transactional records and
stored wire and electronic communications (content)
U.S. Department of
Homeland Security
United States
Secret Service
Obtaining a “D” Order
18 USC § 2703(d) states that a court order for the disclosure of
customer records may be issued after the following has been
submitted:
“..specific and articulable facts showing that there are
reasonable grounds to believe that the contents of a wire or
electronic communication, or the records or other information
sought, are relevant and material to an ongoing criminal
investigation.”
U.S. Department of
Homeland Security
United States
Secret Service
Obtaining a “D” Order
Orders issued under statute generally used to obtain Basic
Subscriber Information and Records or Other Information
Pertaining to a Customer or Subscriber, but not for content
Investigators should coordinate with prosecutors to obtain a D
order
Investigator will submit affidavit to apply for order
Affidavit should meet requirements set forth in section (d)
U.S. Department of
Homeland Security
United States
Secret Service
U.S. Department of
Homeland Security
United States
Secret Service
Module 12 - Fundamentals of Log
Analysis
U.S. Department of
Homeland Security
United States
Secret Service
You Will Learn . . .
Understanding Network Traffic
The Scientific Method and Intrusion Analysis
Observing Intrusion-related Activity and Generating a
Hypothesis
Predicting the Nature and Location of Intrusion Artifacts
Using Log Analysis to Evaluate an Intrusion Hypothesis
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 1 - Understanding Network
Traffic
Overview of Network Traffic
Investigation Techniques
U.S. Department of
Homeland Security
United States
Secret Service
The Internet
TCP/IP is the language of the Internet
Number of services which use TCP/IP to communicate
Example of one service, HyperText Transfer Protocol (HTTP)
U.S. Department of
Homeland Security
United States
Secret Service
Network Communication
To generates network traffic one system must serve or host
information and another system request the service data
In the case of HTTP there is a web server and a web client
Network traffic is generated when client or browser requests a
web page from the server
U.S. Department of
Homeland Security
United States
Secret Service
Network Communication
SYN: Client sends Synchronize packet to server, beginning
three-way handshake which starts conversation
SYN-ACK: Server sends Synchronization Acknowledgement,
acknowledging start of conversation
ACK: Client sends acknowledgement to server completing
three-way handshake, conversation started
U.S. Department of
Homeland Security
United States
Secret Service
Network Communication
GET: Client requests page from server
If general request to web site like www.somewhere.com
GET request is for web root document indicated with a
backslash / after get command
Otherwise name of page will be part of get request, such as
faq.html
U.S. Department of
Homeland Security
United States
Secret Service
Network Communication
200 OK: Server will send response that includes status code
for page requested
Usually code 200 OK is sent
Indicates page found and will immediately follow
Page transferred to browser program and displayed on
client system
404 Page not found: If specific page requested is not
recognized by server, 404 page not found displayed in browser
U.S. Department of
Homeland Security
United States
Secret Service
Ports in a Data Storm
There are 65535 port numbers available on most computer
systems
The Internet Assigned Numbers Authority (IANA) has role of
assigning types of traffic to port numbers
Assignments done so programmers can agree on ports used
for specific types of traffic
HTTP traffic assigned port 80
U.S. Department of
Homeland Security
United States
Secret Service
Types of Ports
Three types of port numbers, Well Known, Registered and
Dynamic Ports
Well Known Ports are numbers ranging from 0 to 1023
Registered Ports are numbers ranging from 1024 to 49151
Dynamic Ports are numbers ranging from 49152 to 65535
Documentation on current assignment of numbers can be
viewed by going to www.iana.org/assignment/port-numbers
U.S. Department of
Homeland Security
United States
Secret Service
Common Well Known Ports
(20) File Transfer Protocol (FTP)
(21) File Transfer Control (FTP)
(22) Secure Shell Remote Login
(23) Telnet
U.S. Department of
Homeland Security
United States
Secret Service
Common Well Known Ports
(25) Simple Mail Transfer Protocol (SMTP E-mail)
(53) Domain Name Service (DNS)
(80) HTTP (Web)
(443) Secure Socket Layer (HTTPS)
U.S. Department of
Homeland Security
United States
Secret Service
Common Assigned Ports
(1025) Network Blackjack
(1080) SOCKS
(1169) Tripwire
(1214) KAZAA
(1433) Microsoft SQL Server
(1689) Firefox
U.S. Department of
Homeland Security
United States
Secret Service
Investigation Techniques
Look for traffic types that are on wrong assigned ports
For example AOL Instant Messenger traffic on port 80
AOL IM is assigned port 531
U.S. Department of
Homeland Security
United States
Secret Service
Types of Traffic to Watch For
HTTP (port 80)
Most firewalls and routers will pass traffic on port 80
Popular port for malicious code transfer, or for
communication of other protocols that have been blocked
May see programs that opened backdoors on systems
transferring information on port 80
Advanced attackers might embed malicious code in HTTP
packets hoping firewalls and intrusion detection systems will
pass the information
U.S. Department of
Homeland Security
United States
Secret Service
Types of Traffic to Watch For
E-mail (port 25)
Not a common port for traffic other than e-mail
Port is worth watching simply because so many attacks
originate in e-mail messages
U.S. Department of
Homeland Security
United States
Secret Service
Types of Traffic to Watch For
USENET/NNTP (port 119)
Important protocol for law enforcement to watch
Newsgroups are used for distribution of pornography in all
forms
Protocol still used as way to transfer bootleg software,
movies, music and other copyrighted material
U.S. Department of
Homeland Security
United States
Secret Service
Types of Traffic to Watch For
Internet Relay Chat (ports 6666-6669)
IRC is another protocol used heavily for Peer-to-Peer
transfer of copyrighted and illicit materials
Malware and Botnet traffic seen on these ports as well
U.S. Department of
Homeland Security
United States
Secret Service
Types of Traffic to Watch For
File Transfer Protocol (port 21)
FTP used for transferring files
If case involves transfers of illicit information of any kind
monitor FTP traffic
There are a number of malware attacks against FTP ports
as well
U.S. Department of
Homeland Security
United States
Secret Service
Types of Traffic to Watch For
Peer-to-Peer (Any ports)
P2P protocols are some of hardest to monitor and
investigate
Two systems that are transferring information can use any
port they agree on
Transfer of a file may actually take place between multiple
systems at once
Reassembly of transferred files can be extremely difficult
U.S. Department of
Homeland Security
United States
Secret Service
Baselines
Popular way to make network traffic analysis easier is baseline
method
Method involves taking packet capture snapshots of normal
network traffic and comparing suspicious traffic captures to
baseline
Helps to quickly determine where investigation should focus
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 2 - The Scientific Method
and Intrusion Analysis
Overview of the Scientific Method
Digital Forensic Analysis and the Scientific Method
U.S. Department of
Homeland Security
United States
Secret Service
Scientific Method
A process for investigating a set of observations
Formulating a hypothesis about observed events
Using deductive/inductive logic to formulate processes for
evaluating hypothesis
Carrying out processes and using results to support,
contradict, or modify hypothesis
U.S. Department of
Homeland Security
United States
Secret Service
Scientific Method Steps
Observation: Observing one or more events or sets of
events, establish facts surrounding events to identify cause
and consequences
Hypothesis: Explains observed events, including root cause,
interrelationship, and consequences
Prediction: Possible nature and location of artifacts in
evidence that will either support or contradict hypothesis
Evaluation: Procedures that test for presence of artifacts that
support, falsify, or modify the hypothesis
U.S. Department of
Homeland Security
United States
Secret Service
Scientific Method Steps
Conclusion: Based upon results of tests performed during
Evaluation step, stating one of following:
Hypothesis is supported by facts
Hypothesis is contradicted by facts
Facts indicate that new or modified hypothesis should be
constructed due to observations or lack of relevant results
U.S. Department of
Homeland Security
United States
Secret Service
Additional Characteristics
Repeatable: Evaluations and tests conducted should be
repeatable to ensure results can be verified by others who
want to test for mistakes, confounding variables, spurious
relationships, etc.
Cyclic: May need to perform many iterations of method, tests,
and testing of hypothesis, or generate additional hypothesis to
gain a clear understanding of originally observed events
U.S. Department of
Homeland Security
United States
Secret Service
Additional Characteristics
Empirical: Evidence used in hypothesis must be based on or
derived from observation rather than pure reasoning, faith,
common sense, etc
Falsifiable: Hypothesis established and tested using Scientific
Method should be falsifiable, there should be way to test for
contradicting evidence as well as supporting evidence
Objectivity: Observations and results of evaluations must be
interpreted as objectively as possible
U.S. Department of
Homeland Security
United States
Secret Service
Variances
Not all fields of inquiry use same steps for Scientific Method,
names of steps can differ
When researching method, you might encounter different
formats within different reference sources
Implementation of Scientific Method is valid so long as it
follows principles outlined previously
U.S. Department of
Homeland Security
United States
Secret Service
Digital Forensic Analysis and the
Scientific Method
Scientific Method provides useful guide when attempting to
locate items of interest within digital media, or copies of digital
media
Useful for incident responder when attempting to identify
devices that may contain information related to series of
events
U.S. Department of
Homeland Security
United States
Secret Service
Example of Application
Incident responder responds to several IDS alerts indicating
attack against Web server
Alerts are initial observations
Responder might form a hypothesis that Web server attacked
and compromised by method indicated in alerts
To test hypothesis, analyst deduces (predicts) most probable
location of artifacts to support or contradict hypothesis that
system was successfully attacked
U.S. Department of
Homeland Security
United States
Secret Service
Example of Application
Supporting artifacts might include unauthorized Registry
entries, presence of malicious code, additional IDS alerts,
unauthorized user accounts, etc
Contradicting artifacts could be other log entries that show
observed events part of normal activity for an application
Analyst gathers data from devices containing artifacts, and
evaluates data for their presence
U.S. Department of
Homeland Security
United States
Secret Service
Example of Application
Examiner finds artifacts that support hypothesis that system
was successfully attacked
Concludes that hypothesis was correct, proceeds to write
report
Alternatively, hypothesis may have been falsified due to
discovery of artifacts indicating legitimate technical reason for
IDS alerts such as standard false positive
Investigator may not find sufficient evidence to make any
conclusion in which case he/she may create a new hypothesis
U.S. Department of
Homeland Security
United States
Secret Service
Use of Scientific Method for
Computer Intrusion Investigations
Computer network intrusions can be complex, difficult to track
Attack can span multiple networks, thousands of systems
Danger for investigative team is spending too much time
acquiring and analyzing data from unrelated systems
Scientific Method helps avoid pitfall by encouraging use of a
logical process to determine approach to investigation
U.S. Department of
Homeland Security
United States
Secret Service
Use of Scientific Method for
Computer Intrusion Investigations
Key element is link between observed events and subsequent
investigative tasks
Creating hypotheses based on observations and events,
makes it more likely you will perform analysis tasks that
produce results, less likely you will follow unproductive
tangents
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 3 - Observing Intrusion-related
Activity and Forming a Hypothesis
Common Observations
Hypothesis Formation
Incident Classification
U.S. Department of
Homeland Security
United States
Secret Service
Observations and Network Intrusions
Network intrusion investigations should normally begin with
one or more observation
Observations guide formation of hypothesis as to what
occurred
U.S. Department of
Homeland Security
United States
Secret Service
Common Primary Observations
Antivirus alerts
IDS/IPS alerts
System/applications errors
Abnormal authentication patterns
Access control list violations
Generic unusual activity
U.S. Department of
Homeland Security
United States
Secret Service
Supplementary Observations
Incident responder should make supplementary observations
before creating hypothesis
Not directly observed events, rather sets of data that
responder should collect in any security incident
U.S. Department of
Homeland Security
United States
Secret Service
Supplementary Observations
Network diagrams: Logical and physical diagrams of networks
Device documentation: Lists of device names and
configuration data, vital for devices directly involved in events
Contact information: Names, phone numbers, e-mail
addresses, etc. for witnesses and people responsible for
affected networks and systems
Other data: Other details regarding affected devices and
networks that may seem pertinent
U.S. Department of
Homeland Security
United States
Secret Service
Common Observation Attributes
Date/time: Record when event occurred, as well as duration
IP addresses: If event is log entry that includes an IP address,
or involves system with IP address, IP addresses should be
recorded
Port numbers: If event is log entry that includes port numbers,
or involves application that engages in network communication
over specific port, ports should be recorded
Host names and aliases: Host names and aliases for systems
involved in event should be recorded
U.S. Department of
Homeland Security
United States
Secret Service
Common Observation Attributes
Accounts and aliases: Specific user account or alias, should be
recorded, as well as names of specific individuals that use
account or alias, if information known
Files: At minimum, name and full path for any files involved,
attributes, hash values, file system date/time stamps
General description: General description as to nature of each
event
U.S. Department of
Homeland Security
United States
Secret Service
Hypothesis Formation
What/How - Basic description of main event(s), may include
common incident classification
Where - List known and probable physical locations and
network segment locations of incident
When - List known and probable timeframe of incident
Who - List identifying information for individual(s)/computer(s)
known to be involved or likely involved in incident
Why - List most likely motive(s)
U.S. Department of
Homeland Security
United States
Secret Service
Multiple Hypotheses
Incident may be too large and complex for single hypothesis
May need to establish multiple hypotheses to account for
different parts of incident
For instance, intrusion may have signs that attacker entered
through public Web server and several compromised
workstations
To effectively pursue each possibility, could create a
hypothesis for each potential method of entry
U.S. Department of
Homeland Security
United States
Secret Service
Multiple Hypotheses
Managers or lead investigators, may assign different
investigators to investigate each hypothesis
Could create third hypothesis to account for how attacker(s)
are extracting stolen data from network
No rule for determining how many hypothesis to create or how
detailed
Hypotheses should reflect the size and complexity of incident
U.S. Department of
Homeland Security
United States
Secret Service
Incident Classifications
Implement an incident classification schema to ensure a
common vocabulary between agency and organization
requesting assistance
Classification should be broad enough to capture major types
of incidents
U.S. Department of
Homeland Security
United States
Secret Service
Common Incident Classification
Denial of Service
Malicious Code
Unauthorized Access
Inappropriate usage
Suspicious activity
Multiple Component
Other
U.S. Department of
Homeland Security
United States
Secret Service
Denial of Service
Prevents or impairs authorized use of networks, systems, or
applications
Network service is unavailable for an unknown reason
Computer network saturated with excessive amount of traffic
Application saturated with authentication or service requests
Application or operating system not functioning for unknown
reason
U.S. Department of
Homeland Security
United States
Secret Service
Malicious Code
Program or group of programs that perform undesirable activity
Antivirus alerts
IDS alerts that indicate malicious code
A higher than normal volume of network traffic
Computer systems crash or malfunction for unknown reason
Egress communication not initiated by user or authorized
application
U.S. Department of
Homeland Security
United States
Secret Service
Unauthorized Access
Person gains logical or physical access without permission to
network, system, application, data, or other resource
User account authentication at abnormal times, or at times
user to which account assigned denies having been on system
Presence of unauthorized user accounts
Missing data
U.S. Department of
Homeland Security
United States
Secret Service
Unauthorized Access
Logged data access at abnormal times or by user account not
normally used for such access
Presence of unauthorized computer programs
Presence of large archives (TAR, RAR, Zip, etc.) of data files
for which there is no explanation
Common observations from any other type of intrusion-related
activity
U.S. Department of
Homeland Security
United States
Secret Service
Inappropriate Usage
Violations of acceptable computing use policies
Web browsing sessions to websites containing unauthorized
workplace material
Inappropriate e-mails sent to coworkers or from a work
account
Recorded network traffic that indicates presence of
unauthorized application, such as a peer-to-peer file sharing
application
U.S. Department of
Homeland Security
United States
Secret Service
Suspicious Activity
Security operations personnel notice unusual activity not
specifically related to known threat, unexplainable through
experience
Increase network activity
Increase CPU activity on a system
Unexplained network activity
U.S. Department of
Homeland Security
United States
Secret Service
Multiple Component
Multiple component classification, situation that encompasses
two or more incidents out of one
For example, malicious code infection leads to unauthorized
access to host, used to gain unauthorized access to additional
hosts
Workstation affected by a virus and scanning the network
Server relaying IRC traffic
U.S. Department of
Homeland Security
United States
Secret Service
Other
Category serves as catch all group for newly identified exploits
that do not fit in previously listed categories
Penetration Testing
Innovative ways to attack a system
Zero-day Exploits
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 4 - Predicting the Nature and
Location of Intrusion Artifacts
Predicting the Nature and Location of Intrusion Artifacts
Relating Observed Events to Network Services and Traffic
Types
Mapping Observed Activity to Traffic Flow
Using Traffic Flow and Service Type to Predict Artifact
Location
U.S. Department of
Homeland Security
United States
Secret Service
Finding Intrusion Artifacts
Mapping observed events to related applications and traffic
Map observed activity to traffic flow of network traffic
Using probable traffic flow, applications involved and traffic
types, determine devices that may house artifacts of observed
and hypothesized events
Establish plan for gathering data from identified devices, and
for identifying relevant artifacts within those data sets
U.S. Department of
Homeland Security
United States
Secret Service
Relating Events to Applications
Correlate observed events to applications involved
Help to locate potential artifacts
For instance, if event was buffer overflow IDS alert, destination
port of 80, could surmise target application may be Web server
Recognizing this, place this application on your list of potential
artifact sources, gather and analyze logs from that application
U.S. Department of
Homeland Security
United States
Secret Service
Relating Events to Applications
Identify network traffic types that correspond to observed
TCP/UDP ports
For instance, observed TCP port 25 traffic indicates SMTP
most likely involved
Identify applications related to observed and/or extrapolated
network traffic types
From example, if SMTP were likely protocol, indicative that an
e-mail server and client application probably also involved
U.S. Department of
Homeland Security
United States
Secret Service
Concept of Profiling an Event
U.S. Department of
Homeland Security
United States
Secret Service
Additional Applications
Identify applications that have capability of logging activity
related to network traffic types
Applications you have singled out
For instance, SMTP gateways would have capability of logging
data about traffic between e-mail servers and clients
U.S. Department of
Homeland Security
United States
Secret Service
Additional Applications
Identify applications directly involved in generation of observed
events
Includes security devices/applications that produced log files
that contained initial observations
Following example from previous slides, Snort IDS that
generated alert would be added to list of applications that may
contain relevant artifacts
U.S. Department of
Homeland Security
United States
Secret Service
Identifying Additional Applications
U.S. Department of
Homeland Security
United States
Secret Service
Recording Traffic Types
Locate all devices that related traffic may have passed through
For instance, if investigator believes that intrusion-related
traffic passed through specific point of ingress/egress for
network, devices at that point (firewalls, routers, IDS sensors,
etc.) could potentially contain important artifacts
U.S. Department of
Homeland Security
United States
Secret Service
Mapping Activity to Network Traffic
Obtain a logical or physical network diagram, and/or access to
a network administrator that has working knowledge of current
topology
Diagram should be broad enough to include all points of
ingress/egress from affected network segments, including
paths to Internet
Ascertain IP addresses for devices involved in incident
Identify ports and protocols corresponding to related network
protocols
U.S. Department of
Homeland Security
United States
Secret Service
Mapping Activity to Network Traffic
Use information obtained to identify all routes between affected
devices and between those devices and Internet
Record routes in notes or mark on working copies of any
network diagrams
U.S. Department of
Homeland Security
United States
Secret Service
Other Routes of Interest
Alternate points of network traffic ingress/egress from network
segment on which each device resides
Identify routes to major service network segments not inline
with default gateway
Network segments with directory servers, e-mail servers, file
and print servers, backup servers etc
U.S. Department of
Homeland Security
United States
Secret Service
Other Routes of Interest
Routes used by incoming traffic to affected network segment if
not the same as default outbound route
Routes used by public service requests to segment, internal
service requests, VPN pathways, etc
In network, check specific protocols sent through alternate
routes to reach proxy servers
If found, identify routes between affected network segment and
those proxy servers
U.S. Department of
Homeland Security
United States
Secret Service
Adding Source and Destination
U.S. Department of
Homeland Security
United States
Secret Service
Mapping Traffic Routes
U.S. Department of
Homeland Security
United States
Secret Service
Predicting Artifact Location: Devices
Determine host system for application
Determine if application uses local or remote (SAN, NAS, etc.)
storage
If remote is used, identify associated storage devices
Determine if host system is backed up on a regular basis or
and whether data backed up to local media, or remote system
If local, where are tapes or other backup media stored
If remote, identify remote backup server
U.S. Department of
Homeland Security
United States
Secret Service
Predicting Artifact Location: Devices
Determine if application is part of distributed application
system (such as a Web server with a database backend)
Identify other applications in system, and hosts on which they
reside
If multiple systems host application as part of a load-balancing
configuration, identify all systems hosting copies of application
If application configured to use proxy device when
communicating on network, identify all associated proxy
devices
U.S. Department of
Homeland Security
United States
Secret Service
Predicting Artifact Location: Devices
U.S. Department of
Homeland Security
United States
Secret Service
Predicting Artifact Location: Files
If application keep logs determine full path to log storage
location
If application or host system configured to send logs to remote
repository, identify system
Determine full path and name of files in which application
stores configuration information
U.S. Department of
Homeland Security
United States
Secret Service
Predicting Artifact Location: Files
Determine name and full path of files in which application
stores persistent and temporary data
Determine whether application requires authentication
Determine if application uses its own authentication
mechanism or forward authentication data to an outside
application (such as Active Directory)
U.S. Department of
Homeland Security
United States
Secret Service
Predicting Artifact Location: Files
Following example scenario, potential victim in attack could be
an IIS Web server that contains certain log files to be analyzed
Windows Event log
IIS log
Dr. Watson log
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 5 - Using Log Analysis to
Evaluate an Intrusion Hypothesis
Hypothesis Evaluation
Acquiring Target Log Files
Reviewing Target Log Formats
Establishing Search/Extraction Criteria
Searching Target Logs and Extracting Relevant Data
Recording and Correlating Findings
Keeping Track of New Leads
U.S. Department of
Homeland Security
United States
Secret Service
Hypothesis Evaluation
Acquire target log files
Review the format of collected logs
Establish search/extraction criteria based upon predicted
artifacts and log format
Search log files and extract relevant data
Record and correlate findings
Document unexpected findings related to case (“leads”)
U.S. Department of
Homeland Security
United States
Secret Service
Procedure Selection
Procedure can locate specific potential artifacts identified in
previous step in Scientific Method
Procedure should have been tested and peer reviewed
Procedure should be repeatable
Procedure should be as objective as possible
U.S. Department of
Homeland Security
United States
Secret Service
Acquiring Log Files
Log files may be provided directly by incident responder or
network administrator who collected them from original source
media
Could obtain physical or logical image of original storage
media containing log files, and extract logs from image
Could obtain logical copy log files from source system or
device
Regardless of method, ensure logs collected in sound manner
in accordance with maintaining integrity of evidence
U.S. Department of
Homeland Security
United States
Secret Service
Previewing Log Formats
Before analyzing, preview format to ensure you know how to
read them properly and use correct methods for searching
Search techniques significantly different between text and
binary logs
Information may be presented in different forms in text logs
Fields and format may differ and record separators
For example, time may be represented in 24-hour format or
12-hour with AM or PM specified
U.S. Department of
Homeland Security
United States
Secret Service
Determining File Type
View file extension and correlate to file type
For instance, file with “.EVT” extension is Windows Event Log
file and should be viewed with Microsoft Event Viewer
application
If unfamiliar with extension, research it online
Use GNU “file” command, does not rely on file extensions,
useful if log file does not include extension
U.S. Department of
Homeland Security
United States
Secret Service
Determining File Type
Attempt to view file with text log viewer, such as notepad.exe,
or GNU command such as “cat”, “more”, “tail”, etc
If successful, file is text log and viewable as such
File - Open dialog in Wireshark will display format of binary
capture files that it recognizes when file is highlighted
U.S. Department of
Homeland Security
United States
Secret Service
Determining Data Format
Determine if records include one line or multiple lines
Identify field and record separators
Determine where common data types (IP addresses, port
numbers, date/time, etc.) are located in each record, if
anywhere
Determine if locations are always same or vary
U.S. Department of
Homeland Security
United States
Secret Service
Search/Extraction Criteria
Known or estimated time frame
Observed or predicted source or destination IP addresses
Messages that correlate with observed or predicted activity
Observed user name or alias
Observed or predicted network protocols or traffic types
Any combination of criteria mentioned in items above
U.S. Department of
Homeland Security
United States
Secret Service
Search/Extraction Criteria
Previously listed criteria examples are guides only
No hard and fast rule for choosing specific search and
extraction criteria
Criteria must be selected based upon potential for producing
data to further investigation of hypothesis
U.S. Department of
Homeland Security
United States
Secret Service
Correlation: Timeline Unification
Normalize all log files to synchronized time and time notation
Involves changing actual date/time stamps in log file, should
only be performed on working copies of log
Record events identified during initial observation and
subsequent testing/evaluation into single timeline
Adjust time on each event as necessary as recorded
U.S. Department of
Homeland Security
United States
Secret Service
Correlation: Event Verification
Any event can be correlated with data in full network traffic
capture
Verify Web browser history with proxy server logs, both record
URL access and associated times
Verify IDS scan alerts with firewall logs
Verify IDS password attacks alerts with authentication logs
Verify e-mail header date/time stamps with e-mail gateway or
e-mail server logs
U.S. Department of
Homeland Security
United States
Secret Service
Correlation: Synchronize Times
Compare dates/times for events against multiple sources to
see if there are discrepancies in time in data sources
For instance, user IE history shows access to Web mail
occurring at 2105, Web proxy shows access occurred at 2135
Analyst could use two events to determine that proxy server
was most likely set 30 minutes behind clock on subject system
Ideally, multiple events correlate to verify time
U.S. Department of
Homeland Security
United States
Secret Service
Correlation: Synchronize Times
Compare date/time stamps embedded in files with file system
date/time stamps
Compare date/time stamp of last entry in log with file system
last accessed time
If event involved access to one or more files, check
appropriate file system date/time stamps for file
U.S. Department of
Homeland Security
United States
Secret Service
Unexpected Findings
May often discover information not directly predicted during
initial analysis of hypothesis
Can be identified as a “lead”
Information is sometimes related to hypothesis, and other
times important but outside of current investigation
Information should be recorded for follow up as needed
U.S. Department of
Homeland Security
United States
Secret Service
Lead Tracking
New leads should be documented
Leads should be recorded in Attribute List spreadsheet along
with other relevant data
Entries representing leads should be marked as to whether or
not they are relevant to current working hypothesis
Highlight other leads in a different color
List other lead entries on a separate page, tab, table, etc.
Use a column in a table to mark other lead entries as such
U.S. Department of
Homeland Security
United States
Secret Service
U.S. Department of
Homeland Security
United States
Secret Service
Module 13 - Log Sources
U.S. Department of
Homeland Security
United States
Secret Service
You Will Learn . . .
Windows Log Sources
Linux Log Sources
Solaris Log Sources
Log Searching
IDS Logs
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 1 - Windows Log Sources
Windows Logs
Windows Services Logs
U.S. Department of
Homeland Security
United States
Secret Service
Windows Logs
Windows includes Outlook or Outlook Express as a mail client
Default location for log files in Windows 2000, Server 2003 and
XP is individual user’s profile
Outlook’s MAPI accounts log found at: C:\Documents and
Settings\username\Local Settings\Temp\Opmlog.log
If user established Hotmail account in Outlook, events logged
in: C:\Documents and Settings\username\Local
Settings\Temp\Outlook Logging\Hotmail\http0.log
U.S. Department of
Homeland Security
United States
Secret Service
Microsoft SQL Databases
One of most popular database services used in businesses
Stores log files in C:\MSSQL\LOG
U.S. Department of
Homeland Security
United States
Secret Service
Log files in MSSQL\LOG
ERRORLOG - MS SQL’s default error log file
If logging configured to create new files on routine basis, or
file grows too large, additional error logs will be created with
a sequential number appended
SQLAGENT.OUT - Can contain information generated by SQL
programmer or messages generated by default in
administrative panel
Files can have numbers for versions at end
File with OUT suffix is current log
U.S. Department of
Homeland Security
United States
Secret Service
Log files in MSSQL\LOG
SQLDump9999.txt andSQLDump9999.mdmp - Special dump
files generated if SQL Server crashes or terminates
unexpectedly
Information in files generally contains memory and data
pointers at time of failure
Also possible for administrator, or attacker to force
generation of these files under special circumstances
NOTE: If server running, may not be possible to copy or open
current log files
U.S. Department of
Homeland Security
United States
Secret Service
MySQL
MySQL is free, open source database application, popular on
many Windows systems
Default location for installation of MySQL in Windows is
C:\Program Files\MySQL\MySQL Server X.X
In folder name, X.X is software’s version number
U.S. Department of
Homeland Security
United States
Secret Service
Directories and Logs in X.X Folder
Bin
Contains client programs and server program
Data
Holds log files and actual databases
Share
Has error message files
Error filename will typically start with network host name of
system MySQL is running on and end with .err suffix
U.S. Department of
Homeland Security
United States
Secret Service
Microsoft Access
Errors generated by Access stored in Windows Event logs
Information for retrieval of Event logs discussed with System
Logs
U.S. Department of
Homeland Security
United States
Secret Service
Internet Information Server (IIS)
IIS is service used by millions of Windows based servers to
host web, FTP, and e-mail services
Depending on version in use, logs can be found in different
locations
IIS normally stores logs in default folder,
Log location can be easily changed in administration control
panel
U.S. Department of
Homeland Security
United States
Secret Service
Internet Information Server (IIS)
Log files stored in C:\winnt\system32\logfiles for IIS versions 4
and 5, found on Windows NT 4.0 and Windows 2000
Log files stored in: C:\windows\system32\logfiles for IIS version
6 and 7, found on Windows XP and newer systems
U.S. Department of
Homeland Security
United States
Secret Service
Internet Information Server (IIS)
Log files named “W3SVC” followed by Site Instance ID,
numbered sequentially for each service
For example, first web site log files start with W3SVC1, and
second W3SVC2
Web enabled service originate in IIS service
FTP and DNS messages will be mingled in same W3SVC file if
services are active
U.S. Department of
Homeland Security
United States
Secret Service
Windows System Logs
Almost all other services that originate in Windows log entries
into one or all standard Event Logs
Logs divided into Application, Security and System
Use Event Viewer to view logs
Log files stored in a mixed binary format, making standard text
based tools ineffective
U.S. Department of
Homeland Security
United States
Secret Service
Windows System Logs
Can choose log file of interest from menu in Event Viewer and
export as:
Tab Delimited text
Comma Delimited text
Tab Delimited Unicode text
Comma Delimited Unicode text
Exported files can be filtered and searched using tools like
Grep and Findstr
U.S. Department of
Homeland Security
United States
Secret Service
Directory Services
If Directory Services is configured, applicable events found
under Directory Services in Event Viewer
U.S. Department of
Homeland Security
United States
Secret Service
Remote Logs
Looking at mounted share locations and names, may give
indication that logs are stored remotely
Examination of remote shares may provide folder and file
names which indicate what types of logs are stored remotely
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 2 - Linux Log Sources
Linux Logs
U.S. Department of
Homeland Security
United States
Secret Service
Linux Mail Logs
Linux is based on Unix style kernel
Mail services provided by sendmail processes
Logs for these services usually found in /var/log/maillog
U.S. Department of
Homeland Security
United States
Secret Service
Database
MySQL is most popular database program within Linux
community
MySQL logs typically found in /var/log/mysqld.log
U.S. Department of
Homeland Security
United States
Secret Service
Linux Services Files
/var/log/message: General messages and system related
errors
/var/log/auth.log: Remote Login Authentication logs
/var/log/secure: Remove Login Authentication log
/var/log/kern.log: Kernel logs
/var/log/cron.log: Crond logs, for services that start
automatically
U.S. Department of
Homeland Security
United States
Secret Service
Linux Services Files
/var/log/httpd/: Apache web server access and error logs
directory
/var/log/boot.log : System boot log
/var/log/utmp or /var/log/wtmp : Binary Login history file
/var/log/yum.log: Yum log files to track installed and uninstalled
applications
U.S. Department of
Homeland Security
United States
Secret Service
Linux Directory Management
Linux does not directly support Microsoft Active Directory
Numerous third party add-on tools available to provide the
service
Seek documentation for specific AD tool encountered and
determine location of logs for each
U.S. Department of
Homeland Security
United States
Secret Service
Linux System Logs
Most located in the /var/log/message file
U.S. Department of
Homeland Security
United States
Secret Service
Remote Logs
Looking at mounted share locations and names may provide
indication that logs are stored remotely
Examination of remote shares may identify folder and file
names which indicate what types of logs are stored remotely
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 3 - Solaris Log Sources
Solaris Logs
U.S. Department of
Homeland Security
United States
Secret Service
Solaris Mail
Depending on version of Solaris, may find file in /etc directory
called syslog.conf, and location of sendmail logs listed inside
Many ISP’s moved to custom mail software
Seek documentation on software to determine log file location
U.S. Department of
Homeland Security
United States
Secret Service
Databases
If MySQL installed on Solaris system, look for logs in default
locations of /usr/local/mysql/data or /opt/mysql/mysql/data
Oracle is popular database for Solaris systems
Determine version and release level of Oracle software
Search for default installation location of log files
U.S. Department of
Homeland Security
United States
Secret Service
Solaris Services
Most Solaris services put log messages in /var/adm/messages
log file
General catch all file for log entries in Solaris
U.S. Department of
Homeland Security
United States
Secret Service
Directory Management
Solaris doesn’t natively support Microsoft Active Directory
directly
Numerous third party add-on tools available to provide this
service
Seek out documentation for specific AD tool and determine
location of logs for each
U.S. Department of
Homeland Security
United States
Secret Service
Solaris System
Solaris system log files located in /var directory
Usually several nested directories of log files under /var
directory
Investigation may show some or all have information of
evidentiary value
Cannot open files in use
U.S. Department of
Homeland Security
United States
Secret Service
Remote Logs
Search for pipes and hard links to mounted volumes in order to
discover whether logs are stored remotely
In Solaris environment attempt to locate a certified Solaris
administrator to discover obfuscated links
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 4 - Log Searching
Log Searching
Regular Expressions
U.S. Department of
Homeland Security
United States
Secret Service
|
||
|
|
|