Forensic Teams Take On Hackers

Incident-response and digital forensic tools and techniques keep data safe, but they can be costly to implement.

When it comes to securing data, ignorance is not bliss. Attackers increasingly are installing back doors that enable them to capture transactions as they're transmitted over the network. Consider the TJX attack: Credit card data was stolen for months, with no one the wiser. The sophistication of today's cybercriminals is evidenced by the 2008 CSI Computer Crime & Security Survey's results indicating that stealthy, highly targeted attacks have gone from hypothetical a few years ago to a significant problem today. Forget glory, it's now all about the money.

Because attackers are primarily motivated by financial gain, as soon as they have your data, it's being converted into profit by selling identities and corporate secrets and draining bank accounts. Speed is vital, so the time may be right to assemble a forensic SWAT team trained to locate high-risk threats, armed with the latest investigative software, and empowered to work directly with legal counsel to report breaches in accordance with policy.


More Security Insights

Webcasts

More >>

White Papers

More >>

Reports

More >>

METHOD IN THE MADNESS

Acquiring evidence in a forensically sound manner isn't difficult with the proper tools and training, but policies and procedures must be put in place that ensure the repeatability, accuracy, completeness, and verifiability of evidence as proscribed by the Federal Rules of Evidence. The same protocol should be used to handle every breach, whether it's a targeted attack or a malware infection. That means the first job for your new forensic team is to put policies in place and develop investigative methodologies. Policies must explicitly give investigators the authority to perform digital forensics on corporate assets. In addition to clearly written policies, there must be a forensic methodology that's followed for acquiring, handling, and analyzing evidence. The methodology must be repeatable and defensible, whether it be in front of the human resources department or a judge and jury. The key is being able to explain what forensic actions were done and why.

STEM THE TIDE

AccessData, Guidance Software, and Mandiant are at the forefront of producing enterprise versions of robust, collaborative incident-response and forensic tools. Both AccessData's and Guidance Software's suites allow for remote access to computers so investigators can retrieve details from running systems. Mandiant's Intelligent Response has comparable capabilities but is more focused on incident response.

The caveat to these enterprise incident-response and forensic tools is that they can cost tens to hundreds of thousands of dollars to fully implement throughout an enterprise, and the majority of the investigator's actions must be done through the product's interface, limiting use of other forensic tools. This isn't the case for one of the newest companies entering this market, Agile Risk Management.

DIG DEEPER
For more information on enterprise forensics tools and techniques, and a guide on reporting breaches to federal authorities,
Agile's F-Response product allows investigators to mount Windows hard drives and physical memory remotely and in a read-only manner so they can perform forensically sound "live" analysis of running Windows systems. The remote systems' hard drives and physical memory appear as normal attached drives to the investigator's system, allowing IT to use any forensic product for analysis. F-Response is not limited to Windows; there are beta versions for Linux and Mac OS X available now.

The area of forensics that's received the most vendor attention and research over the past two years is Windows memory analysis. Every enterprise forensic tool has added memory imaging capabilities in the past 12 to 18 months, with varying capabilities for in-depth analysis of acquired images. The Volatility Framework is an open source tool leading the way with its ability to list running processes, open network ports, and files opened and DLLs loaded by each process; it can also extract executables from memory for further analysis.

HBGary is a leader in the commercial Windows memory analysis field. Its Responder can image Windows physical memory, analyze memory images from other tools, perform analysis of memory to determine details such as those found by the Volatility Framework, and automatically reverse-engineer malware.

Impact Assessment: In-House Forensics

(click image for larger view)

Continue to the sidebar:
To Data Breach? Who Ya Gonna Call?


Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
Subscribe to RSS

Resource Links