Network Intrusions Responder Program (NITRO). Instructor Guide - page 19

 

  Index      Manuals     Network Intrusions Responder Program (NITRO). Instructor Guide

 

Search            copyright infringement  

 

   

 

   

 

Content      ..     17      18      19     

 

 

 

 

Network Intrusions Responder Program (NITRO). Instructor Guide - page 19

 

 

Log Searching
ƒ Flexibility is important feature for tool used to search through
log files
ƒ Wide variety of log files
ƒ Require search for different types of values
ƒ Tools and techniques must be usable regardless of log type
and search values
U.S. Department of
Homeland Security
United States
Secret Service
GREP
ƒ GREP (Global Regular Expressions Print)
ƒ Newer version EGREP (The E stands for “Extended”)
ƒ Primary applications used for searching and filtering text logs
ƒ Use regular expressions to define search parameters
ƒ Used because regular expressions are most common method
for defining search parameters, and used in many other
applications, such as PERL, Snort, and EnCase
U.S. Department of
Homeland Security
United States
Secret Service
GREP
ƒ GREP typically found in Unix, Linux, and OS X environments
ƒ Versions available for Windows operating systems
U.S. Department of
Homeland Security
United States
Secret Service
Findstr
ƒ Windows does not natively ship with GREP
ƒ Does include Findstr, similar command line utility to find
specific strings of text in log file or other type text file
ƒ Typing “findstr /?” at command prompt displays quick help
screen of options and command format
U.S. Department of
Homeland Security
United States
Secret Service
Findstr Options
ƒ /I to disable case sensitivity
ƒ /S to search all files in current directory and subdirectories
ƒ /R to allow use of regular expressions
ƒ /N to print line numbers
ƒ /G:filename to use a file of key strings to search for
U.S. Department of
Homeland Security
United States
Secret Service
Regular Expressions
ƒ Patterns used for executing searches and filters
ƒ Accomplished by combining literal text and special characters,
called metacharacters, to create a pattern used to search files
U.S. Department of
Homeland Security
United States
Secret Service
Examples of Set Pattern Items
ƒ IP addresses
ƒ Dates and time
ƒ Phone numbers
ƒ URLs
ƒ Credit card numbers
ƒ Social Security numbers
U.S. Department of
Homeland Security
United States
Secret Service
Regular Expressions
ƒ Should understand regular expressions and how to use them
effectively to search or filter text logs
ƒ Many tools incorporate regular expression engines into
functionality
ƒ Some GNU command line tools, such as grep/egrep, sed and
awk, and many text editors, allow searching and/or
replacement of text through use of regular expressions
ƒ Regular Expression engines and syntax may vary slightly from
product to product
U.S. Department of
Homeland Security
United States
Secret Service
Literal Character Searches
ƒ Simplest type of regular expression is literal representation of
target value
ƒ For example, search for “jsmith” in log.txt by simply telling
egrep to search for string “jsmith”
[prompt]# egrep “jsmith” log.txt
ƒ Most programs search files one line at a time
ƒ Command line above will return each line in file that contains
string “jsmith” to whatever output is specified
U.S. Department of
Homeland Security
United States
Secret Service
Regular Expression Example
ƒ Example of a search for a literal string is shown on next slide
ƒ Log file searched for string “jsmith” using egrep
ƒ Notice, any line that included “jsmith” was matched, even one
that begins with “jjsmith”
ƒ It does not matter what is before or after target string, only that
it exists
ƒ “jsmith” could be a stand-alone string, or part of a string such
as “jsmithsonian”
U.S. Department of
Homeland Security
United States
Secret Service
Regular Expression Example
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 5 - IDS Logs
ƒ IDS Logs
U.S. Department of
Homeland Security
United States
Secret Service
Intrusion Detection Systems
ƒ Intrusion Detection Systems (IDS), prolific, found in many
networked environments
ƒ Probably find most logs generated by these systems are binary
rather than text
ƒ When files encountered, may require use of proprietary
program to view or convert files to text
ƒ Some save logs in libpcap format, can use packet sniffer tools
like Wireshark to open, view and export
U.S. Department of
Homeland Security
United States
Secret Service
Snort
ƒ Popular IDS and intrusion reporting tool
ƒ Free application, allows administrators to flag alerts, on both
live and captured traffic
ƒ After parsing traffic, will generate text log displaying alerts of
suspicious traffic encountered
ƒ Requires complex set of steps to configure, and configuration
will change with each type of log or capture
ƒ By default, Snort’s log files on Linux, Unix, or OS X system,
found in /var/log/snort
U.S. Department of
Homeland Security
United States
Secret Service
U.S. Department of
Homeland Security
United States
Secret Service
Module 14 - Log Analysis
U.S. Department of
Homeland Security
United States
Secret Service
You Will Learn . . .
ƒ Binary Traffic Analysis
ƒ Manual Log Analysis
ƒ Automated Log Analysis Tools
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 1 - Binary Traffic Analysis
ƒ Introduction to Wireshark
ƒ Converting Binary Logs to Text Format
ƒ Filtering and Searching in Wireshark
ƒ Colorizing Data Using Filters in Wireshark
ƒ Generating Statistics with Wireshark
ƒ Exporting Data from Wireshark
U.S. Department of
Homeland Security
United States
Secret Service
Wireshark
ƒ Powerful open source protocol analyzer
ƒ Opens a variety of binary log formats
ƒ Act as a sniffer
ƒ Translates, decodes, known protocols from binary to human
readable format
ƒ Displays highly detailed information on frame-by-frame basis
ƒ Provides search of capture log for frames that match specific
criteria
ƒ Automatically reconstruct TCP sessions
U.S. Department of
Homeland Security
United States
Secret Service
Procedure: Importing Logs into
Wireshark
ƒ This is a Step / Action exercise in student book.
U.S. Department of
Homeland Security
United States
Secret Service
Viewing Binary Logs in Wireshark
ƒ Top Pane: Summary of captured frames, including frame
number, date and time, source IP, destination IP, protocol and
basic description
ƒ Middle Pane: Decoded protocol header information, organized
inversely to order of each protocol within OSI model
ƒ Bottom Pane: Full frame contents in hexadecimal on left side
with any included clear text displayed on right
U.S. Department of
Homeland Security
United States
Secret Service
Procedure: Creating a Filter with
Wireshark
ƒ This is a Step / Action exercise in student book.
U.S. Department of
Homeland Security
United States
Secret Service
Procedure: Creating a Color Filter
with Wireshark
ƒ This is a Step / Action exercise in student book.
U.S. Department of
Homeland Security
United States
Secret Service
Binary vs. Text Format
ƒ More efficient at times to change binary logs to text format
ƒ As text, logs can be manipulated using text log filtering
techniques to quickly find target data
ƒ Change binary logs to text format with tcpdump
ƒ Default output of tcpdump is text format
U.S. Department of
Homeland Security
United States
Secret Service
Tcpdump Command
ƒ [prompt]# tcpdump -r log.cap > log.txt
ƒ Command directs tcpdump to read file log.cap, and place a
text interpretation of contents into text file log.txt
ƒ By default tcpdump does not print full contents of each packet,
just summary data
U.S. Department of
Homeland Security
United States
Secret Service
Wireshark Binary Log Filtering
ƒ Capture filters: Interface used to filter data while being
captured from network; uses tcpdump syntax
ƒ Display filters: Interface used to filter currently displayed traffic
ƒ Color filters: Interface used to apply colors to certain packets
based upon a filter expression
ƒ Find menu: Standard find menu that allows packet to be
searched by hex value or string, can also use to enter display
filters
U.S. Department of
Homeland Security
United States
Secret Service
Procedure: Setting Up Capture Filter
ƒ This is a Step / Action exercise in student book.
U.S. Department of
Homeland Security
United States
Secret Service
Procedure: Creating a Display Filter
ƒ This is a Step / Action exercise in student book.
U.S. Department of
Homeland Security
United States
Secret Service
Creating a Display Filter
U.S. Department of
Homeland Security
United States
Secret Service
Creating Display Filter for Keyword
ƒ Display filter can be created for a keyword
ƒ Displays only packets that contain search term
ƒ Done with “frame contains” display filter,
ƒ Can be used to filter for presence of keyword anywhere in
packet
ƒ The “frame contains” filter can be found through normal display
filter wizard
U.S. Department of
Homeland Security
United States
Secret Service
Display Filter for Keyword
U.S. Department of
Homeland Security
United States
Secret Service
Creating Hex Value Filter Display
ƒ The “frame contains” expression syntax also used to filter for
hexadecimal values
ƒ Hex value is entered in place of keyword, colons used to
separate value into pairs
U.S. Department of
Homeland Security
United States
Secret Service
Entering Display Filter Expressions
ƒ When filter expression created using Display Filter wizard, text
for filter entered in Display Filter field in main window
ƒ Filter expressions can be entered directly as text into field
instead of using wizard
ƒ When entering display filter, if filter has valid syntax,
backg1round color of display filter field will be green, if not valid
it will be red
U.S. Department of
Homeland Security
United States
Secret Service
Valid Display Filter
U.S. Department of
Homeland Security
United States
Secret Service
Display Filter Syntax
ƒ See student book for examples of display filter syntax to
include altering and combing filters.
U.S. Department of
Homeland Security
United States
Secret Service
Procedure: Creating Color Filters
ƒ This is a Step / Action exercise in student book.
U.S. Department of
Homeland Security
United States
Secret Service
Procedure: Searching in Wireshark
ƒ This is a Step / Action exercise in student book.
U.S. Department of
Homeland Security
United States
Secret Service
Wireshark Statistics Menu
ƒ “Statistics” menu in the menu bar for generating various
statistics about log data
U.S. Department of
Homeland Security
United States
Secret Service
Endpoints List
ƒ In the Statistics menu, provides lists of statistics that revolve
around addresses and TCP/UDP ports
ƒ Separate window displays statistics
ƒ Useful to see what IP addresses and ports are in a given
binary capture
U.S. Department of
Homeland Security
United States
Secret Service
Endpoints Window
U.S. Department of
Homeland Security
United States
Secret Service
Protocol Hierarchy Statistics
ƒ Option in Statistics menu, provides a list of protocols that were
seen in a given capture, and volumes of protocol activity
ƒ May be possible to determine applications being used on
network from this information and provide snapshot of activity
ƒ Wireshark does not recognize all protocols, and may miss a
protocol used over a non-standard port
U.S. Department of
Homeland Security
United States
Secret Service
Protocol Hierarchy Statistics
U.S. Department of
Homeland Security
United States
Secret Service
Conversations List
ƒ “Conversations” option in Statistics menu offers lists of
source/destination address combinations
ƒ Wireshark presents source and destination address
combinations communicating in capture, and number of
packets between each pair
ƒ Packet volume is shown for each direction of communication
between pair
U.S. Department of
Homeland Security
United States
Secret Service
Conversations Window
U.S. Department of
Homeland Security
United States
Secret Service
HTTP Requests Stats Tree
ƒ Wireshark can create custom list of HTTP get requests based
upon specified display filter
ƒ For example, a display filter for a specific IP address, shows all
get requests for that IP
ƒ Creating this statistic requires several steps
ƒ See student book for HTTP Requests example and steps
U.S. Department of
Homeland Security
United States
Secret Service
Exporting Statistics
ƒ Send copy of any generated statistics to file
ƒ Option within some Wireshark statistics windows
ƒ Statistics windows capable of exporting data will have “Copy”
button on window
U.S. Department of
Homeland Security
United States
Secret Service
Exporting Statistics
U.S. Department of
Homeland Security
United States
Secret Service
Exporting Statistics
ƒ Pressing the copy button only puts the data into the copy
buffer
ƒ To save data, paste into a file
ƒ Typical text file application such as Notepad will suffice
ƒ Data should not be pasted directly into a spreadsheet because
it will be placed into single cell
ƒ Pasted data is in comma-delimited format, includes column
headings
ƒ Only tab currently displayed in statistic window is copied
U.S. Department of
Homeland Security
United States
Secret Service
Example Pasted Statistics
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 2 - Manual Log Analysis
ƒ Filtering and Searching Text Logs
ƒ Regular Expressions
ƒ Deciding What to Search For
ƒ Example Log
U.S. Department of
Homeland Security
United States
Secret Service
Filtering and Searching Text Logs
ƒ Identify all log entries with a specific value or range of values
ƒ Modify view of one or more log files based upon existence of
an arbitrarily defined parameter
U.S. Department of
Homeland Security
United States
Secret Service
Filtering and Searching Toolset
ƒ Flexibility is most important feature for tool used to perform
filtering and searching
ƒ Wide variety of log files encountered that will require search for
different types of values
ƒ Tools and techniques must be usable regardless of log type
and value for which you are searching
U.S. Department of
Homeland Security
United States
Secret Service
Filtering and Searching Toolset
ƒ GREP (Global Regular Expressions Print)
ƒ Newer version EGREP (Extended Global Regular Expressions
Print)
ƒ Primary application used for searching and filtering text logs
ƒ Use regular expressions to define search parameters
ƒ Regular expressions are most common method for defining
search parameters, used in other applications, such as PERL,
Snort, and EnCase
U.S. Department of
Homeland Security
United States
Secret Service
Keywords
ƒ Need a clear understanding of what you are searching for
ƒ Rarely will ‘shotgun’ or broad focused search turn up useable
data
ƒ Decide on keywords that might be available in log file and
might produce possible artifacts of intrusion
U.S. Department of
Homeland Security
United States
Secret Service
Sample Keywords for IIS Attack
ƒ “Error” or “err”
ƒ “Overflow”
ƒ “Password” or “Pass”
ƒ “Admin”
ƒ “Unauthorized”
ƒ IP addresses of interest
U.S. Department of
Homeland Security
United States
Secret Service
WordPad is Not Your Friend
ƒ A tool like WordPad or Notepad can be used for these types of
searches
ƒ Data returned is not easily useable and does not allow filtering
of information returned for clarity or further use
ƒ Versions of Grep for Windows operating systems available
from several sites
ƒ GUI version, WinGrep, available at http://www.wingrep.com
U.S. Department of
Homeland Security
United States
Secret Service
Example Log
ƒ Review the logs from an exploited web server on the next slide
ƒ Logs are from the IIS server on the day of the attack
ƒ Look at first few lines of log to determine program and version
that created the file, and start and end dates of file
ƒ Helpful to know approximate time attack occurred
U.S. Department of
Homeland Security
United States
Secret Service
Example Log
U.S. Department of
Homeland Security
United States
Secret Service
IP Search
ƒ Log is from attacked server, searching for server’s IP address
not useful since each entry should have the IP address
ƒ If IP address of attacker is known, search for that
ƒ In a NAT environment the IP could have been used or reused
by another user in same log
ƒ Better to save IP searches for later in order to search for
specific IP and times together
U.S. Department of
Homeland Security
United States
Secret Service
String Search
ƒ Attacker used an administrative account to log into server
ƒ To do this, would have entered username and password
ƒ Good starting point
ƒ Using GREP, type: ‘pass’ IIS5211_6.txt
ƒ Will search for string “pass” in every line of log file IIS5211_6.tx
ƒ Result of such search on next slide
U.S. Department of
Homeland Security
United States
Secret Service
Searching for Password
U.S. Department of
Homeland Security
United States
Secret Service
Searching for Password
ƒ Notice, on previous slide, a series of attempts to guess the
password file for the system
ƒ Not normal network traffic
ƒ First clue of one method attempted by attacker
ƒ Farther down the list is an attempt to get on the login page in
admin directory
ƒ The attacker is trying different account names and password
combinations
U.S. Department of
Homeland Security
United States
Secret Service
Searching for Password
U.S. Department of
Homeland Security
United States
Secret Service
Suspicious Text
ƒ 2006-05-31 20:49:52 W3SVC508294276 10.8.1.39 GET
/admin/login.asp
username=testFUZZCRTL&password=testpass 80
ƒ The text FUZZCTRL should appear suspicious
ƒ Might be legitimate username or password or might not
ƒ Search of Internet for FUZZCTRL finds reference to
vulnerability scanning web proxy called Suru
ƒ See examples of server attack that match lines shown
U.S. Department of
Homeland Security
United States
Secret Service
Response
ƒ Now correlate known tool with IP address and time frame
ƒ Allows you to now proceed with plan to contact ISP for domain
that attacker is coming from
ƒ Follow your agencies policy for contacting, serving
preservation letters and obtaining warrants for information on
attacker
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 3 - Automated Log Analysis
Tools
ƒ Sawmill
U.S. Department of
Homeland Security
United States
Secret Service
Sawmill
ƒ Tool to assist an analyst in parsing network text logs
ƒ Processes various text logs generated by a variety of network
security devices
ƒ Converts text logs to a cross-linked report that allows analysts
to customize the report according to output requirements
ƒ Provides functionality for organizing logs into an easy-to-read
report
U.S. Department of
Homeland Security
United States
Secret Service
Download Information
ƒ Sawmill can be purchased and downloaded from:
ƒ Initial download and installation comes with a 30 day, unlimited
profile license
U.S. Department of
Homeland Security
United States
Secret Service
Procedure: Installing and
Configuring Sawmill
ƒ This is a Step / Action exercise in student book.
U.S. Department of
Homeland Security
United States
Secret Service
The Administrative Interface
U.S. Department of
Homeland Security
United States
Secret Service
Procedure: Creating a Report Profile
ƒ This is a Step / Action exercise in student book.
U.S. Department of
Homeland Security
United States
Secret Service
The Report Environment
U.S. Department of
Homeland Security
United States
Secret Service
Report Header
ƒ Profile name - Name of active profile which is being displayed
ƒ Admin link - Link to administrative functions, such as profile
lists
ƒ Logout - A link to log out of Sawmill
ƒ Help - Help documentation
U.S. Department of
Homeland Security
United States
Secret Service
Sawmill’s Administrative Interface
U.S. Department of
Homeland Security
United States
Secret Service
Report Toolbar
ƒ Reports - Used to access other loaded reports from current
reports view
ƒ Config - Used to change profile options
ƒ Calendar - Date/time filter can be set to view single day,
month or year
ƒ Date Range - Range of days can be selected to use as
date/time filter
ƒ Filter - Used to configure global filter options for any of report
fields, dynamically affect all reports
U.S. Department of
Homeland Security
United States
Secret Service
Report Menu
U.S. Department of
Homeland Security
United States
Secret Service
Zoom To Filters
U.S. Department of
Homeland Security
United States
Secret Service
Final Output Report (Log Detail)
U.S. Department of
Homeland Security
United States
Secret Service
Final Output Report, cont’d
U.S. Department of
Homeland Security
United States
Secret Service
Single Page Summary
U.S. Department of
Homeland Security
United States
Secret Service
Module 15 - Live Data Collection and
Analysis
U.S. Department of
Homeland Security
United States
Secret Service
You Will Learn . . .
ƒ Data Collection
ƒ Introduction to LiveWire
ƒ LiveDiscover
ƒ LiveWire - Initial inquiry
ƒ LiveWire - Evidence Collection
ƒ LiveWire - Malicious Code Analysis
ƒ Alternate Data Collection Tools
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 1 - Data Collection
ƒ Locating Physical Devices in Server Environment
ƒ Attaching Storage Equipment
U.S. Department of
Homeland Security
United States
Secret Service
Network Architecture
ƒ Logical topology map shows how devices connected logically,
not necessarily physically
ƒ Network architecture indicates where devices are physically
located
ƒ Network devices that provide possible path for incident are
considered to be “in-line” to investigation
ƒ Devices that carried traffic relating to incident, may hold crucial
information, should be located and analyzed
U.S. Department of
Homeland Security
United States
Secret Service
Logical Assessment
ƒ Logical assessment involves obtaining network topologies to
get rough estimate of where sensors can be placed for
investigation
ƒ Network topology maps may not exist or be severely outdated
ƒ Investigator can update topology through interviews or by
performing a physical assessment
U.S. Department of
Homeland Security
United States
Secret Service
Physical Assessment
ƒ Includes tracing wire and cable to physical components on
network to create a wiring diagram
ƒ Wiring diagram shows physical connections between devices
onsite and can help determine accuracy of logical assessment
ƒ Investigator can use several cable testing devices, like a tone
generator, to verify cable locations
U.S. Department of
Homeland Security
United States
Secret Service
Physical Assessment
ƒ In large network environments, servers and network devices
are assigned some form of inventory control, such as bar code
or unique name
ƒ May be necessary to search through rows of server racks to
locate an identification tag on server of interest
U.S. Department of
Homeland Security
United States
Secret Service
Physical Site Examination
ƒ Examine physical site to determine physical data paths and
relationship to overall physical environment
ƒ Understanding relationships provides basis for determining
what is or is not physically possible on network
U.S. Department of
Homeland Security
United States
Secret Service
Physical Site Examination
ƒ Physically locate target host
ƒ Physically locate device to which target host is connected
ƒ Physically locate devices that fall into path of investigation
ƒ Verify network documentation (if available)
U.S. Department of
Homeland Security
United States
Secret Service
Verifying Network Configuration
ƒ Investigator needs a starting point to verify network setup and
actual location of network devices for an unfamiliar network
ƒ Almost every network has connection to Internet or some
external network
ƒ External link typically best starting point to begin tracing wire
U.S. Department of
Homeland Security
United States
Secret Service
Verifying Network Configuration
ƒ Tracing wire used to determine how devices are physically
connected
ƒ If wire cannot be traced other devices like a network tone
generator can be used to determine its termination location
ƒ Use of some devices could require unplugging cable and
severing existing connections
ƒ Could alert suspect(s) of ongoing investigation
U.S. Department of
Homeland Security
United States
Secret Service
Physically Locating Target Host
ƒ Collect all identifying information regarding device from review
of network documentation and interview with system
administrator
ƒ Use information and physical assessment of network to locate
device
U.S. Department of
Homeland Security
United States
Secret Service
Physically Locating Nearest Device
ƒ Use identifying information obtained during review of network
documentation
ƒ Record termination location for each network-capable cable
connected to machine
ƒ Could be RJ45 or RJ11 socket on nearest wall, hub or switch,
or some other device
ƒ If cable terminates at wall socket, record socket’s ID number
and locate it on patch panel that aggregates cables for that
area of facility
U.S. Department of
Homeland Security
United States
Secret Service
Data Storage
ƒ Many investigations result in large evidence files that must be
collected
ƒ Sufficient data storage to copy and preserve evidence files is
imperative
ƒ Retrieved data should always be redirected to forensically
clean evidence collection drive
ƒ Never save output of investigation to local system’s hard drive,
may compromise evidence and could potentially fill computer’s
disk space
U.S. Department of
Homeland Security
United States
Secret Service
Data Storage
ƒ Storage equipment can connect to collection machine by many
different connection types
ƒ Common types are: USB, Firewire, and eSATA
ƒ External hard drives with these configurations come in many
different capacities
ƒ General rule is to allocate as much disk space as possible for
each investigation
U.S. Department of
Homeland Security
United States
Secret Service
Wiping and Verification
ƒ Evidence should be stored on a forensically clean drive
ƒ Evidence storage drive must be thoroughly wiped
ƒ Overwriting every bit on drive using known character or set of
characters
ƒ Process should be verified to ensure success
ƒ Failure to complete process can result in claims of
contaminated evidence, jeopardizing credibility of evidence
U.S. Department of
Homeland Security
United States
Secret Service
Wiping Guidelines
ƒ Clearly identify media to be wiped and segregate from other
media
ƒ Have only essential media in system during wiping operations
ƒ Ensure correct media selected before executing wipe utility
ƒ Remove wiped media from machine immediately after wiping
and store separately
ƒ Annotate in case notes media wiped prior to use
ƒ Label media with software version and command line used
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 2 - Introduction to LiveWire
ƒ Live Digital Investigations
ƒ LiveWire Installation
ƒ LiveDiscover Installation
ƒ Updating LiveWire
ƒ Updating LiveDiscover
ƒ LiveWire Initial Setup
U.S. Department of
Homeland Security
United States
Secret Service
Live Digital Investigations
ƒ Traditional computer examinations examine media from a
system that has had power removed, or dead-box
ƒ Live Digital Investigations performed on running systems prior
to removal of power
U.S. Department of
Homeland Security
United States
Secret Service
Why Live?
ƒ Ever increasing use of memory resident programs and utilities
revert to obfuscated or encrypted state at power off
ƒ Becoming necessary to seize information from volatile areas
BEFORE plug is pulled
U.S. Department of
Homeland Security
United States
Secret Service
Reasons for a Live Investigation
ƒ Rapid response requires remote investigation
ƒ Network size limits flexibility
ƒ Encrypted file system requires live capture
ƒ System of interest is mobile
ƒ Commercial system cannot be shutdown
U.S. Department of
Homeland Security
United States
Secret Service
How LiveWire Works
ƒ Complex series of scripts, programs and tools
ƒ Uses customized version of Apache web server on
investigation system to provide menus, displays and reports in
a graphic user interface
ƒ Includes embedded version of Gargoyle malware detection
software, also a product of Wetstone
ƒ Requires administrative privileges to access and retrieve data
from a target system
U.S. Department of
Homeland Security
United States
Secret Service
How LiveWire Works
ƒ Uses a Connect-Act-Disconnect model for communicating with
a host on network
ƒ Software logs into target, obtains information and logs out of
system
U.S. Department of
Homeland Security
United States
Secret Service
Risks
ƒ Use of Livewire can be detected on target
ƒ Could compromise clandestine operation
ƒ User on target system may notice degradation of network
performance for short period
ƒ Use may be noticeable as process running in Task Manager of
target
U.S. Department of
Homeland Security
United States
Secret Service
Minimum Requirements
ƒ Microsoft Windows XP
ƒ 100 Meg Bytes of free disk space
ƒ 128 Meg Bytes RAM
ƒ Pentium 200 Mhz
ƒ Network Interface Card
ƒ CD ROM Drive for Installation
ƒ VGA Resolution Monitor
ƒ Mouse
U.S. Department of
Homeland Security
United States
Secret Service
Procedure: LiveWire Installation
ƒ This is a Step / Action in student book.
U.S. Department of
Homeland Security
United States
Secret Service
Procedure: Installation of
LiveDiscover
ƒ This is a Step / Action in student book.
U.S. Department of
Homeland Security
United States
Secret Service
Procedure: Updating LiveWire
ƒ This is a Step / Action in student book.
U.S. Department of
Homeland Security
United States
Secret Service
Procedure: Updating LiveDiscover
ƒ This is a Step / Action in student book.
U.S. Department of
Homeland Security
United States
Secret Service
LiveWire Initial Setup
ƒ Setup Administrator account
ƒ Create an Investigator account
U.S. Department of
Homeland Security
United States
Secret Service
Procedure: LiveWire Setup
ƒ This is a Step / Action in student book.
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 3 - LiveDiscover
ƒ LiveDiscover Network Scanning
U.S. Department of
Homeland Security
United States
Secret Service
LiveDiscover
ƒ Used to rapidly identify and assess resources on network
ƒ Information gathered used to enable LiveWire tools to perform
live analysis of machine across a network
ƒ Can quickly scan single target or whole range of IP addresses
ƒ Performs in-depth scan to include report of vulnerabilities of
systems
ƒ Each scan stored and saved in its own database
U.S. Department of
Homeland Security
United States
Secret Service
LiveDiscover Interface
ƒ Provides tabbed interface for navigation
ƒ Primary tabs displayed horizontally across top of page
ƒ Each page displays information or options pertaining to
specific details or configurations
U.S. Department of
Homeland Security
United States
Secret Service
Interface Tabs
ƒ Discovery Tab - input for addresses to be scanned, up to four
different network ranges can be scanned at same time
ƒ Network Tab - tree structure created showing different devices
discovered for subnet as well as detailed information gathered
about devices
ƒ Responses Tab - displays discovered data grouped together,
selecting any options displays all items found matching criteria
U.S. Department of
Homeland Security
United States
Secret Service
Interface Tabs
ƒ Reports Tab - facilitates generation of many different report
display formats, reports can contain text as well as colored
graphs
ƒ Script Tab - accesses different pre-built discovery scripts
stored in database, customized scripts can be added
ƒ Settings Tab - contains configurations used during live
discovery process
ƒ Utilities Tab - options for scripts and results from other scans
to be imported into the current database
U.S. Department of
Homeland Security
United States
Secret Service
Performing a LiveDiscovery Network
Scan
ƒ This is a Step / Action in student book.
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 4 -Volatile Data Analysis
ƒ LiveWire Initial Inquiry
ƒ System State
ƒ Current User Activity
ƒ Active Network State
U.S. Department of
Homeland Security
United States
Secret Service
Initial Inquiry
ƒ First part of process when performing investigation or analysis
of system using LiveWire
ƒ Will retrieve available information from remote computer at
time of scan
ƒ Has potential to degrade performance on target system
ƒ Could alert user of activity on his or her system
ƒ Advanced user may be able to determine analysis taking place
U.S. Department of
Homeland Security
United States
Secret Service
Performing LiveWire Initial Inquiry
ƒ This is a Step / Action in student book.
U.S. Department of
Homeland Security
United States
Secret Service
LiveWire - Display Acquired
System State Summary
ƒ This is a Step / Action in student book.
U.S. Department of
Homeland Security
United States
Secret Service
LiveWire - Acquire Physical RAM
and Registry
ƒ This is a Step / Action in student book.
U.S. Department of
Homeland Security
United States
Secret Service
LiveWire - Current User Activity
ƒ This is a Step / Action in student book.
U.S. Department of
Homeland Security
United States
Secret Service
Display Captured Network Details
ƒ This is a Step / Action in student book.
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 5 - Evidence Collection
ƒ File System Status
ƒ Physical vs. Logical
ƒ Collection and Preservation
ƒ Hashing
U.S. Department of
Homeland Security
United States
Secret Service
Procedure: Capture Disk Information
ƒ This is a Step / Action in student book.
U.S. Department of
Homeland Security
United States
Secret Service
Body File Acquisition
ƒ This is a Step / Action in student book.
U.S. Department of
Homeland Security
United States
Secret Service
Physical vs. Logical Image
ƒ Physical image is a bit-for-bit duplicate of a media storage
device
ƒ A logical image only contains data from the active file system
of a storage device
ƒ From forensics standpoint, physical image preferable to logical
image because it may contain more evidence
U.S. Department of
Homeland Security
United States
Secret Service
Physical Images
ƒ Contain information from entire physical device or designated
portion of it
ƒ Are not file system-specific
ƒ Capture all sectors within a designated area of a device, both
in the system and data areas (including all files, unallocated
space, swap space, etc.)
ƒ Are typically placed in an Image file (a logical file that
contains the bit-for-bit copy)
U.S. Department of
Homeland Security
United States
Secret Service
Physical Imaging
ƒ EnCase
ƒ dcfldd
ƒ Enables recovery for analysis of deleted data or information
that resided in slack space on original drive
ƒ Slack space can contain information from whatever previously
occupied the space
U.S. Department of
Homeland Security
United States
Secret Service
Logical Images
ƒ Only contain information from active file system
ƒ Contain only enough information to reproduce logical
volumes or parts of them
ƒ Are file system-specific
ƒ Allow registry and other system files to be backed up, but
only if specifically requested
U.S. Department of
Homeland Security
United States
Secret Service
Logical Images
ƒ Do not capture slack space, free space, or partition information
ƒ Do not capture files that are open at time of imaging
ƒ Do not capture any files that you do not have access to read
ƒ Do not capture temporary files, such as pagefile.sys,
win386.swp, etc.
U.S. Department of
Homeland Security
United States
Secret Service
Logical Imaging
ƒ Microsoft’s Windows Backup
ƒ Creates image files of an entire active file system
ƒ Logical image only contains active files
ƒ Not possible to recover and analyze any deleted files or slack
space
U.S. Department of
Homeland Security
United States
Secret Service
On-site Imaging Guidelines
ƒ May face considerable time and material constraints
ƒ May have to perform actions in strange environment with
unknown equipment
ƒ Challenges to accomplishing even simple actions, such as
finding appropriate settings in BIOS or gaining access to
inside of machine
ƒ Preparation helps mitigate problems
ƒ Deviation from general procedures for any reason should be
documented
U.S. Department of
Homeland Security
United States
Secret Service
Physical Disk Imaging
ƒ This is a Step / Action in student book.
U.S. Department of
Homeland Security
United States
Secret Service
Collecting Files
ƒ This is a Step / Action in student book.
U.S. Department of
Homeland Security
United States
Secret Service
LiveWire Hashing
ƒ LiveWire uses MD5 for hashing
ƒ MD5 (Message Digest 5) creates a 128-bit message digest
that is “unique” to message
ƒ MD5 is currently accepted standard for verification by majority
of computer forensic community
U.S. Department of
Homeland Security
United States
Secret Service
Hashes Defined
ƒ Hash (or message digest) is a numerical value generated by
applying a mathematical algorithm against a data set
ƒ Hashing algorithms take variable length input and output a
“unique” fixed-length result
ƒ Nearly impossible to find two different data sets that naturally
have same hash values
ƒ Hash value analogous to fingerprint of file
ƒ File hash value can be used to identify file no matter where
found
U.S. Department of
Homeland Security
United States
Secret Service
Hashes Defined
ƒ If file’s data does not change in any way, same algorithm can
be applied infinite number of times, resulting alphanumeric
values will never change
ƒ If hash value does change, it can be assumed file has been
modified
ƒ Comparing hash values is excellent way to check integrity of
files
ƒ Hashing algorithms are “one-way” can be created from file or
device data, but cannot recreate data from hash
U.S. Department of
Homeland Security
United States
Secret Service
Generating Hashes for the Inquiry
ƒ This is a Step / Action in student book.
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 6 - Malicious Code Analysis
ƒ Malicious Program Search
U.S. Department of
Homeland Security
United States
Secret Service
Types of Malicious Programs
ƒ Many different types of malicious programs and categories
ƒ Many programs may not show that machine was compromised
but could hint about interests or intentions of user
ƒ Types of programs on machine could identify personality of
user, could indicate expertise and guide investigator’s search
ƒ For instance, if encryption program such as TrueCrypt found,
should raise concern that encrypted volumes may be present
and may be hiding critical evidence
U.S. Department of
Homeland Security
United States
Secret Service
Malicious Code Scans
ƒ LiveWire has ability to search many different categories of
malicious code
ƒ LiveWire scans compare hash signatures of files on system
against the National Software Reference Library (NSRL)
database
ƒ The NSRL is a free database released by National Institute of
Standards and Technology (NIST)
U.S. Department of
Homeland Security
United States
Secret Service
Common Malicious Code Categories
ƒ Anti Forensics
ƒ Encryption
ƒ Key Loggers
ƒ P2P Tools
U.S. Department of
Homeland Security
United States
Secret Service
Common Malicious Code Categories
ƒ Password crackers
ƒ Rootkits
ƒ Steganography
ƒ Wireless
U.S. Department of
Homeland Security
United States
Secret Service
Malicious Program Search
ƒ This is a Step / Action in student book.
U.S. Department of
Homeland Security
United States
Secret Service
Lesson 7 - Alternate Data Collection
Tools
ƒ Windows Forensic Toolkit
ƒ Helix
U.S. Department of
Homeland Security
United States
Secret Service
Sysinternals - PsTools
ƒ Utilities developed by Mark Russinovich
ƒ Collection of tools capable of performing many different
analysis functions on local or remote systems
ƒ Latest version of collection can be downloaded from
Microsoft.com
U.S. Department of
Homeland Security
United States
Secret Service
psinfo.exe
ƒ Retrieves system information on target system
ƒ Uptime
ƒ Kernel version
ƒ Product type
ƒ Service pack
ƒ Kernel build number
U.S. Department of
Homeland Security
United States
Secret Service
psinfo.exe
ƒ Registered organization
ƒ Register owner
ƒ Install date
ƒ IE version
ƒ System root
U.S. Department of
Homeland Security
United States
Secret Service
psinfo.exe
ƒ Processors
ƒ Processor speed
ƒ Processor type
ƒ Physical memory
ƒ Video driver
U.S. Department of
Homeland Security
United States
Secret Service
pslist.exe
ƒ Lists processes currently running on remote system
U.S. Department of
Homeland Security
United States
Secret Service
psloggedon.exe
ƒ Displays list of currently logged on users on remote system for
both local and remote users
U.S. Department of
Homeland Security
United States
Secret Service
psexec.exe
ƒ Advanced utility used to execute commands on remote system
ƒ Ability to copy a program from local system to remote target
and execute program interactively
U.S. Department of
Homeland Security
United States
Secret Service
psfile.exe
ƒ Used to view files that are opened remotely on target system
U.S. Department of
Homeland Security
United States
Secret Service
psgetsid.exe
ƒ Retrieves SID of target system
U.S. Department of
Homeland Security
United States
Secret Service
psloglist.exe
ƒ Retrieves logs from target system
ƒ By default psloglist.exe will show contents of System event log
ƒ Application, security, or other log can be retrieved if specified
U.S. Department of
Homeland Security
United States
Secret Service
psservice.exe
ƒ Retrieves list of running services on target system
U.S. Department of
Homeland Security
United States
Secret Service
Helix Live CD
ƒ Specially customized distribution of Knoppix created and
maintained by e-fense, Inc.
ƒ Geared toward forensics and incident response
ƒ Created to be used as internal tool for incident response and
forensics to create forensically sound images
ƒ Released to public November 2003
ƒ Two different operating modes, Windows and Linux
U.S. Department of
Homeland Security
United States
Secret Service
Helix Windows Mode
ƒ Created with Windows executables and contains many tools
for incident response on Windows machines
ƒ Runs standard windows applications to gather information from
a “Live” running system
ƒ Useful where systems cannot be shut down or where potential
evidence would be destroyed by taking system offline
ƒ Helix will make changes to system, exact use should be
documented
U.S. Department of
Homeland Security
United States
Secret Service
Helix Windows Mode
ƒ To use, place CD in target system
ƒ Click Accept on initial warning screen as displayed on the
following slide
U.S. Department of
Homeland Security
United States
Secret Service
Helix Windows Mode
U.S. Department of
Homeland Security
United States
Secret Service
Helix Windows Mode
ƒ After accepting Warning, the screen on the following slide will
be displayed
ƒ Icons on left side of window can be selected for use of
associated functions
ƒ The toolbar also contains options that will provide access to
data collection functions
ƒ Use Quick Launch and Win Audit option on toolbar to acquire
information on Windows system quickly and easily
U.S. Department of
Homeland Security
United States
Secret Service
Helix Windows Mode
U.S. Department of
Homeland Security
United States
Secret Service
Helix Windows Mode
ƒ Another feature of windows mode is ability to acquire images
of live system
ƒ Can be done using Live Acquisition feature of CD
ƒ Image physical memory, physical drive, or logical partitions
ƒ Save images to attached device, network share or to evidence
capture machine using NetCat
U.S. Department of
Homeland Security
United States
Secret Service
Helix Windows Mode
U.S. Department of
Homeland Security
United States
Secret Service
Helix Windows Mode
ƒ FTK Imager also available on CD to create forensic images,
can save in different formats such as raw dd and E01 (encase)
images
ƒ Located on menu bar under Quick launch > FTK Imager
ƒ FTK Imager allows for imaging physical and logical drives
U.S. Department of
Homeland Security
United States
Secret Service
Helix Windows Mode
Tools Available in Windows Mode
Command Shell
FTK Imager
Sys Info Viewer
Drive Manager
Win Audit
Zero View
Per-Search
WFT
NetCat
VNC Server
PuttySSH
File Recovery
Rootkit Revealer
Screen Capture
Password Viewers
U.S. Department of
Homeland Security
United States
Secret Service
Helix - Linux Live CD Mode
ƒ Linux mode of Helix is pure Live CD that allows for “dead box”
forensics
ƒ Allows user to investigate computer system without forensically
changing any data on drive
ƒ Many tasks can be carried out with Helix, such as forensically
duplicating disks and analyzing the forensic disk images
ƒ To start Helix in Linux mode system will need to be booted to
the bootable Helix CD
ƒ BIOS on motherboard must be configured properly
U.S. Department of
Homeland Security
United States
Secret Service
Linux Disk Mounting and Imaging
ƒ When Helix is booted into Linux mode, it automatically mounts
storage devices in read only mode
ƒ Will also mount devices with noatime option, prevents change
to access times of files stored on disk
ƒ Helix mounts drives read-only by default, but can be forced to
mount devices read-write by typing:
mount -rw <device> <mount point>
U.S. Department of
Homeland Security
United States
Secret Service
Linux Disk Mounting and Imaging
ƒ Once Helix fully booted, screen will appear similar to image on
next slide
ƒ Will show a list of all storage media mounted on left side of
screen
ƒ Task bar located at bottom of screen
ƒ “Start” menu is icon of Helix CD cover
U.S. Department of
Homeland Security
United States
Secret Service
Helix Default Screen
U.S. Department of
Homeland Security
United States
Secret Service
Linux Disk Mounting and Imaging
ƒ Several GUI utilities
included on disk for
creating forensically sound
images such as Adepto,
Air, and Linen
U.S. Department of
Homeland Security
United States
Secret Service
Linux Live CD Forensic Tools
ƒ Helix provides tools for investigating collected disk images
ƒ Autopsy, shown on next slide, is popular Linux tool for viewing
and searching images
ƒ Autopsy is GUI interface to suite of command line forensic
tools named The Sleuth Kit
U.S. Department of
Homeland Security
United States
Secret Service
Autopsy Default Screen
U.S. Department of
Homeland Security
United States
Secret Service
Linux Live CD Forensic Tools
ƒ Another option available is PyFlag
ƒ Fforensic and log analysis application created by Australian
Department of Defense
ƒ PyFlag uses backend database to assist managing large
amounts of data, web driven, can be deployed on central
server and used by several users at same time
ƒ PyFlag able to examine forensic evidence from disk images,
logs, and network captures
U.S. Department of
Homeland Security
United States
Secret Service
PyFlag Default Screen
U.S. Department of
Homeland Security
United States
Secret Service
Live CD Benefits
ƒ Useful for testing, evaluating, or learning without need of
dedicated hardware
ƒ Many Linux distributions available as Live CDs, freely
downloaded from Internet, each designed for specific task
ƒ Helix just one example of feature rich Live CD created for a
certain purpose, forensics and incident response
ƒ Helix provides multiple options for investigations whether
suspect machine turned off or up and running
U.S. Department of
Homeland Security
United States
Secret Service

 

 

 

 

 

 

 

Content      ..     17      18      19