Forensic Focus - Computer Forensics, Computer Forensic Training, Digital Forensics
LoginRegisterForumsColumnistsPapersEducationGraduatesReviewsInterviewsNewsletterJobsEventsBlogAdvertise
Search Forensic Focus
Custom Search

Find us on Facebook
Follow Forensic Focus on Twitter
Columnists
"I erred." "I was mistaken."
Craig Ball
Single Sign On
Simon Biles
Copyright and games console modification
Dan Gaskell
To GUI or not to GUI?
Chris Hargreaves
'Web 2.0' as evidence
Sean McLinden
Sometimes it’s all about timing
Sam Raincock
Avoiding common job application errors
David Sullivan
Scalability: A Big Headache
Dominik Weber
Graduate Recruitment

computer forensics graduate jobs

Main Menu
MY ACCOUNT
COMMUNITY
EMPLOYMENT
EDUCATION
RESOURCES
MISC
Follow Forensic Focus

Join newsletter

Join LinkedIn group

Follow on Twitter

Subscribe to news

Subscribe to forums

Subscribe to blog

Subscribe to tweets

Members' blogs

External feeds

Bookmark & share: Bookmark and Share

Computer Forensics Newsletter
Newsletter

You must be a
registered user
to receive our newsletter

Register Now!

Computer incident response - DO NOT PANIC

by Karl Obayi - Solicitor

http://www.itevidence.co.uk

This article seeks to advance some basic steps to be adopted in case you are confronted with a computer incident that calls for appropriate response. The incident in question could emanate from three major fronts.

- Internal attacks
- External attacks
- System malfunction

There is a pervading assumption, that the main source of computer security breach is predicated on external attacks. This is a faulty premise that creates room for lapses in internal security protocols. External attacks usually succeed due to some form of internal lapse in the computer network structure and security policy implementation. Failure can range from - failure to apply relevant software updates, applying patches, updating anti virus software, checking server event logs, Router logs, Firewall logs, Switch logs, user logon privileges etc. The list is endless; to cap it is the role of the enemy within - a member of staff, a contractor, a disgruntled IT Manager who seeks revenge for his abysmal dismissal or layoff or job dissatisfaction.

External attacks used to be the preserve of the very young who joyously celebrate their discovery of hacker tools to deface web sites and announce their arrival into the technological age. This is no longer the situation. External attacks are now coordinated events informed by the demands of corporate espionage, commercial gains and sometimes political objectives. Statistics show, that no one Computer network is free from some form of attack. The question is not, if a computer Network will be attacked; it is when. The moral is, to be ready when the attack happens.

A computer incident response can be triggered not just by an external or internal attack, but also by what I refer to as a system meltdown. Very often we forget that computers are machines, with parts that are susceptible to wear and tear. Computers are machines that run on special codes (programmes and applications) designed by humans with all their imperfections. If the problems do not arise from the wear and tear of the physical aspect of the computer, the problem may arise from outdated updates, outdated antivirus software, the activities of a lazy programmer who has deliberately refused to check his code before packaging the software for consumption.

The point being made here is that not all computer incidents will arise from an external or internal attack. Once this mind set is cultivated, it is thereafter easy to expand the scope of our proactive and reactive steps in response to computer incidents.

Litigation readiness demands the existence of an incident response protocol, if it can be shown through substantive evidence that the security of a computer network is inherently porous, this opens up plausible legal challenges as to alternative possibilities for a computer attack. This makes the job of isolating and locating ownership of an attach on a computer network.

My first caution, in responding to a computer incident is – DO NOT PANIC.

Unnecessary complications have been introduced into an already complex situation because someone panicked and took a wrong course of action. It is no accident that very often when a real or imagined security breach occurs, Computer users, IT teams and management go into panic mode and resort to knee jerk reactions to investigating computer incidents.

Panic results from the absence of a response protocol or the none adherence to an existing protocol. What is a Computer incident response protocol? It is set of formal instructions that proactively describe and prescribe steps to be taken in case of a computer incident. As discussed earlier a computer incident can be an internal attack, external attack or simply a system meltdown. You will notice I used the word formal. The protocol must be in writing and not stored in the brain of the iT manager or Company executive who is hardly in the office.

The evidence of panic when an incident occurs is that no one has the slightest clue on how to proceed with an investigation, on what to investigate and who is to investigate. Ignorant IT staff shouts out instructions for Network and power cables to be pulled from mains sockets an overzealous IT manger begins to access all manner and shape of log files and embarks on exercising his newly acquired command line skills – all of this to the detriment of a properly coordinated investigation.

The proof or otherwise of the existence of a set of facts is based on credible evidence. With computer investigations, credible evidence results from being able to answer the who, when, and how questions surrounding a computer incident. When panic takes over, instead of a coordinated approach to investigating a Computer incident, irreparable damage is done to digital evidence by uninformed internal investigation .

Otherwise credible computer evidence lose their probative value due to ignorant and blind access of suspected accounts. Personal and network shares, security logs, system accounts, computer settings. results in modifying file attributes and a tainted time line of file usage. This leads to problems with determining time chain sequence with respect to when production files and system logs were accessed, modified and created.

It creates legal problems associated with scope of authority and breach of privacy laws. If you have to access the computer of a member of staff to investigate possible breach resulting in a computer incident, you better make sure your scope of authority as disclosed in your letter of employment or contract, grants these investigative powers and that you are well equipped by training to conduct the relevant investigation. Any move to the contrary will introduce legal complications to an already complex situation.

A further implication from the above is associated with the authenticity of digital evidence produced from computers. There are basically two aspects to this issue. Given the ease with which digital documents can be modified and fraudulently manipulated, there is need for some form of assurance that an investigator or examiner has not deliberately or carelessly tampered with digital evidence. Forensic examiners will usually work on an exact duplicate of a file or image acquired from a digital storage device. There exist mathematical algorithms for deciding that a copy of a file is the exact replica of the original. These algorithms come in different flavours – MD5 or SHA1 etc. These algorithms essentially produce matching numbers of the original and duplicate of a file to prove that the original evidence has not being tampered with.

The 2nd leg of this assurance strategy is referred to as chain of custody. In other to rebut any presumption of tampering, the document custodian must show via an appropriate log book a verifiable chain of custody that there was no tampering from evidence extraction, analysis, storage and eventual presentation. Where there is a break in the chain; plausible reasons for such a deviation from the accepted practice must be advanced in the custody report.

Unfortunately, when Panic takes over during a computer incident investigation, there is little or no room for an assurance strategy to be executed. File authentication and chain of custody evidence integrity, become alien and obstructive concepts. Sadly, this hasty and uncoordinated approach to investigation ultimately cost time, money and may amount to a career limiting move for the IT manager or forensic investigator.

Panic also leads to the loss of crucial evidence. When the IT Manager or IT help desk pulls out the network cable and the Power plug on a suspect server or PC, they have also in that one uninformed move closed the door on any chance of collecting vital evidence that is volatile on the computer system especially evidence located in the computer memory technically referred to as RAM (Random Access Memory)

Panic during a computer incident response must be avoided at all cost. All it helps to achieve is complicate matters further. Panic is the product of lack of preparation and the absence of formalised procedures, prescribing steps to be adopted during a computer incident crisis.

How do you avoid Panic? Simple. Take pro-active steps, which are documented and audited from time to time. Pro-active steps include:

- Putting in place an incident response team. The team membership should include IT, Human resources, legal and Management. The management representative should have the authority to make binding decisions at the board level.

- There must be in place a Computer incident response Manual – it does not have to run into a million pages. A functional Manual that is professionally produced by an incident response professional .The dusty health and safety manual with a little modification will not suffice for this purpose.

- The incident response Manual must specifically identify individuals and their deputies to specific assignments in case of an incident.

- A clear reporting ladder must be included in the Manual – who decides that an employee computer should be imaged for investigative purposes? Who decides that the police should be called in if fraud or child porn is found on a suspect computer? Who will be the contact for the company if a 3rd party professional team is called in? When and who will report to management?

- Who carries out the investigation? Do they have the requisite authority? Do they have the requisite training?

The above points do not entirely cover the minute details required for a long term incident response manual. However, they are a good starting point for your incident response protocol. A fuller response manual needs to be produced by a trained security and investigative professional after carrying out a gap analysis.

In conclusion, when a computer incident occurs, do not panic. Panic is no substitute for pro-active preparation. When in doubt call in a professional. Where you already have an Incident response Manual in place, periodically call in an independent professional to audit your state of response readiness.




--
Karl Obayi - Solicitor
Computer Forensics Attorney
Principal Legal Consultant
iTevidence
http://www.itevidence.co.uk

Phone: +44 (0) 20 8408 1616
Fax: +44 (0) 20 8408 1617
Mobile: +44 (0) 75 999 77770


Forensic Education

computer forensics education choices COURSE DIRECTORY

User Info

Welcome Anonymous

Nickname

Membership:
Latest: vanya66
New Today: 7
New Yesterday: 19
Overall: 15536

People Online:
Members: 2
Visitors: 129
Bots: 6
Staff: 0
Staff Online:

No staff members are online!
Latest Jobs

Computer Forensic - Associate - London - £45,000-£55,000pa+
Last post by ForensicsRecruiter in Computer Forensics Job Vacancies on Sep 01, 2010 at 14:34:53

Computer Forensic Specialist - Team Lead - London £55-£80k+
Last post by ForensicsRecruiter in Computer Forensics Job Vacancies on Sep 01, 2010 at 14:23:04

COMPUTER FORENSIC/EDISCOVERY CONTRACT ROLE, LONDON 4-8 WEEKS
Last post by ScottBurkeman in Computer Forensics Job Vacancies on Aug 27, 2010 at 16:29:03

Computer Forensic Vacancy South Wales
Last post by stezer2000 in Computer Forensics Job Vacancies on Aug 19, 2010 at 09:41:54

CF Investigator (LE experience). London
Last post by DavidSullivan in Computer Forensics Job Vacancies on Aug 18, 2010 at 17:00:41

Computer/Video Forensic Examiners (Fredericksburg, VA, USA)
Last post by snorris in Computer Forensics Job Vacancies on Aug 18, 2010 at 00:09:50

Senior Forensic Computer Examiner - London
Last post by pgro in Computer Forensics Job Vacancies on Aug 17, 2010 at 13:26:19

Phd studentship available at University of Surrey.
Last post by apurva.rustagi in Computer Forensics Job Vacancies on Aug 16, 2010 at 22:52:52

Consultant- London- £25K-£40K
Last post by Teval in Computer Forensics Job Vacancies on Aug 05, 2010 at 07:37:45

Forensic Consultant - Singapore
Last post by darrencerasi in Computer Forensics Job Vacancies on Aug 05, 2010 at 01:00:18

Computer Forensics Blog
· 'Web 2.0' as evidence
· Scalability: A Big Headache
· Single Sign On
· Authentication and Authorisation
· UK student competition: Win free training on "Investigating Connection Records" course
· 10% Discount on Connection Records/Intro to CSA Training (UK)
· Mobile Forensics Training: Investigating Connection Records (UK, Aug 23/24)
· Windows Search forensics
· Computer Forensics - sometimes it’s all about timing
· Forensic Focus 2010 survey

read more...
Members' Blogs

Start Blogging

What is Computer Forensics?
Computer forensics (or forensic computing) is the use of specialized techniques for recovery, authentication, and analysis of electronic data with a view to presenting evidence in a court of law.
Computer Forensics Downloads
  1: Forensic Examination of Digital Evidence: A Guide for Law Enforcement (pdf)
  2: ACPO Good Practice Guide for Computer based Electronic Evidence
  3: Electronic Crime Scene Investigation: A Guide for First Responders (pdf)
  4: Ancysoft Data Recovery Software
  5: Forensics Plan Guide & Forensic Cookbook
  6: HELIX incident response CD
  7: PDA Forensic Tools:An Overview and Analysis
  8: Recover My Files
  9: Autopsy Forensic Browser Version 2.03 (source code)
  10: Handy Recovery
Forensic Focus

Forensic Focus

Copy and paste the text below to insert the button displayed above on your site. Thanks for your support!


Use of this website signifies your agreement to the Terms of Use/Privacy Policy available here.

All logos and trademarks in this site are property of their respective owner. The comments are property of their posters, all the rest © 2010 Forensic Focus


Interactive software released under GNU GPL, Code Credits, Privacy Policy
.: fisubsilver shadow phpbb2 style by Daz :: CPG-Nuke port by norseman :: ported to CPG-Dragonfly by jamin :.