Forensic Focus - Computer Forensics, Computer Forensic Training, Digital Forensics
LoginRegisterForumsColumnistsPapersEducationGraduatesReviewsInterviewsNewsletterJobsEventsBlogAdvertise
Search Forensic Focus
Custom Search

Find us on Facebook
Follow Forensic Focus on Twitter
Columnists
"I erred." "I was mistaken."
Craig Ball
Single Sign On
Simon Biles
Copyright and games console modification
Dan Gaskell
To GUI or not to GUI?
Chris Hargreaves
'Web 2.0' as evidence
Sean McLinden
Sometimes it’s all about timing
Sam Raincock
Avoiding common job application errors
David Sullivan
Scalability: A Big Headache
Dominik Weber
Graduate Recruitment

computer forensics graduate jobs

Main Menu
MY ACCOUNT
COMMUNITY
EMPLOYMENT
EDUCATION
RESOURCES
MISC
Follow Forensic Focus

Join newsletter

Join LinkedIn group

Follow on Twitter

Subscribe to news

Subscribe to forums

Subscribe to blog

Subscribe to tweets

Members' blogs

External feeds

Bookmark & share: Bookmark and Share

Computer Forensics Newsletter
Newsletter

You must be a
registered user
to receive our newsletter

Register Now!

Interview with Simon Biles, Thinking Security - 27/11/08


Simon Biles, together with his wife, runs an Information Security Consultancy - Thinking Security - from near Oxford in the UK. He is currently consulting with HM Revenue and Customs on Security Architecture. He is also studying for an MSc from Cranfield in Forensic Computing and is an Associate Lecturer with the Open University on their Information Security Management postgraduate course. He posts as "Azrael" on the Forensic Focus forums (in case you were wondering).


Forensic Focus: Simon, can you tell us something about your background?

Simon Biles: Underneath it all I'm a UNIX SysAdmin to the core! I started using Linux at University because I was too lazy to walk to the CS or AI labs to work on the real UNIX machines (Suns and SGIs), so I installed it on my own PC in halls, I then discovered that I could do dial up and connect to the University network and it all grew from there... I was very lucky to work part time in a local ISP running Linux and Windows web and database servers, from there I did more UNIX SysAdmining for a small software company that did high end Computational Fluid Dynamics - this meant that I got to play with multiprocessor Suns, HPs, IBMs, SGIs and Linux clusters as the only UNIX person in the company! Owing to a merger though I was made redundant, and decided it was a good time to strike out on my own - I invested some of my redundancy money in training, and since then have worked on security for The Institute of Cancer Research, JP Morgan Chase, Cable and Wireless, Vodafone, The Science and Technology Facilities Council and HM Revenue and Customs as well as a few other smaller companies.


Forensic Focus: Why did you decide to specialise in computer security?

Simon Biles: Bad careers advice at school! I wanted to work in Forensics, but my careers advisor told me that the best route was through audit and accountancy, so I did some work experience in a local accountancy firm, and, with apologies to my accountant friends now, nothing in the world is so mind numbingly boring as accountancy! So I read Computer Science and Artificial Intelligence at Uni, and was just interested in security from then... It took a while until my redundancy before I really got to grips with it, although I got to work with many aspects before that - firewalls, users & group permissions, VPNs between offices and the occasional IDS.


Forensic Focus: What exactly does your role as a security consultant involve?

Simon Biles: I seem to occupy an interesting little niche market, I've done a fair bit of work with Single Sign On systems ( Kerberos & Shibboleth ) so sometimes I'm asked specifically about those - but mostly I'm a technical generalist and it is the overview of architecture and how it hangs together that people employ me for... Without wishing to make myself sound unprofessional, it's a bit of a "Jack of all Trades" situation (although I'd strongly resist the "Master of none" completion to that sentence!) - how's about "Holistic Security" - that sounds better! :-)


Forensic Focus: What is a typical week in your working life?

Simon Biles: This week, which is fairly typical, I've finalised and issued a Risk Management and Accreditation Document, which is a report to the business about the risks that I perceive that they have outstanding in their infrastructure the culmination of about two months worth of research and I've started a new one, I've consulted on the implementation of a new system management service, I've attended about 6 meetings (about 3 of which were worth going to... and which ranged from 1 hour to 3 hours) and, which has been the most entertaining, I've had a secure system that I've been trying to break ...


Forensic Focus: Can you tell us something about where you work at the moment?

Simon Biles: A little... I currently work for HM Revenue and Customs, owing to some well publicised security incidents with HMRC data (Google 'em if you don't know...Won't take long!) [all before my time I hasten to add!], HMRC is concentrating very hard on improving all aspects of security - that's what I'm here doing...


Forensic Focus: You've co-authored a couple of books ("The Snort Cookbook" and "Hacking Exposed Linux") and written a number of papers for Microsoft and others - how do you find the process of writing for a technical audience and what do you make of the current crop of computer forensics books?

Simon Biles: I enjoy writing - I wish I could write fiction, but I don't have the imagination for it! Writing technical things is a good compromise, I don't have to make anything up - just do some research - but I get to put my own words to the meaning - hopefully making it interesting, entertaining and educational along the way.

Funnily enough, I don't think I've really read that many current forensic books - I had a look at the iPhone Forensics from O'Reilly the other day, but without an iPhone to play with, it was a bit lost on me! I'm big on the classics though - "File System Forensic Analysis" by Brian Carrier, "Forensic Discovery" by Dan Farmer & Wietse Venema, "Forensic Computing: A Practitioners Guide" by Tony Sammes and Brian Jenkinson - and there is one that I think has massive value to someone who came from a non-investigatory background - "Principles and Practice of Criminalistics" by Keith Inman and Norah Rudin - the trouble is that it is such a fast moving field, that books tend to become dated rather quickly - these ones focus more on attitude and fundamentals than the latest peer-to-peer, for that kind of thing I find forums, blogs, wikis and scientific papers more relevant in general.


Forensic Focus: Broadly speaking, how knowledgable are computer security professionals with regard to computer forensics?

Simon Biles: That's a really good question - I think that there is a fundamental understanding of the concept, but I think that generally that's where it stops. At a risk of upsetting the reading audience, I suspect that generally the opposite is true the other way round!

As with all things, occasionally you meet people who are more clued up in both fields...


Forensic Focus: In your experience, are those who misuse computers becoming better informed about computer forensics procedures and becoming more skilled at covering their tracks?

Simon Biles: In my experience, no, plus ca change, plus ca meme chose ... The people who are good were always good, and they are professionals usually very similar to ourselves ( Organised Crime, Foreign Intelligence, etc. ), the bottom end of the spectrum are the script kiddies, who don't know what they are doing _at all_ and are just running a programme that they got from somewhere else. What is interesting is that some of the tools are improving, but when it's used by a monkey, it tends to make little difference!


Forensic Focus: What trends do you see in computer security and what implications might those trends have for computer forensics professionals?

Simon Biles: There is a major move towards the use of whole disk encryption, encryption of removable devices and encryption of communication. Not only in Government, where it is long overdue, but also in the private sector. Unfortunately I think that this will, in the long run, make life more complicated for Forensic work.

On the bright side though, there is a good recognition that firewalls aren't the be all and end all of security, there is more "defence in depth", more logging, and more host and network based IDS. I think that over time, forensics is likely to move from host to network, in the same way, and that this will counteract the lack of information held directly on a host.

All of this is driven by the general IT trend towards cloud computing, networked data and 100% internet enabled devices.


Forensic Focus: You're currently studying for an MSc in forensic computing at Cranfield University, what are your impressions of the course and what advice would you give to prospective students?

Simon Biles: I enjoy the course, and I think that I have learnt a huge amount - I question if I have learnt as much from what I am supposed to learn as opposed to the environment being very conducive to asking questions and exploring tangents with some very, very knowledgeable people. I am a firm believer that a solid founding in fundamentals is vital in anything, and this course provides that - there has, in the past been criticism of the teaching of "irrelevant" fundamentals - but it should be remembered that the people attending this course are from a wide range of backgrounds, and whilst I find the explanations of TCP/IP networking and filesystems easy, I assure you, they are much better at the laws of evidence than I am ! A good grounding makes for a good examiner in my opinion.


Forensic Focus: Do you think that the personal qualities required to be a computer security specialist are the same as those required by someone working in the field of computer forensics? If not, how do they differ?

Simon Biles: I do think that there is a lot of common ground - attention to detail, technical knowledge & an ability to learn and experiment, an ability to develop and adhere to procedures and processes, a sense of humour... I think at the end of the day, the two professions are opposite sides of the same coin.


Forensic Focus: What is the most rewarding part of your job?

Simon Biles: I like walking away from a system knowing that I have left it, and the data contained within it, in a better state than when I arrived. It is particularly satisfying when it improves protection for real people, as opposed to just corporate money making :-)

Forensic Focus: What aspect of your job do you find most challenging?

Simon Biles: "Two things are infinite: the universe and human stupidity; and I'm not sure about the universe." - Albert Einstein

Need I say more ?


Forensic Focus: What do you do to relax when you're not working?

Simon Biles: Aside from spending time with my family which is a fantastic release, I enjoy getting out in the countryside around where I live - I find that living in an office block and a car for over 10 hours a day makes me go insane unless I get muddy feet at least once a week. ( That, and I'm trying to kill the Ogre Chieftain in a deserted mine in Oblivion on the PS3, trouble is he keeps kicking my arse. :-P )




--

Simon can be contacted through the Thinking Security website at www.thinking-security.com


Forensic Education

computer forensics education choices COURSE DIRECTORY

User Info

Welcome Anonymous

Nickname

Membership:
Latest: vanya66
New Today: 7
New Yesterday: 19
Overall: 15536

People Online:
Members: 3
Visitors: 30
Bots: 8
Staff: 0
Staff Online:

No staff members are online!
Latest Jobs

Computer Forensic - Associate - London - £45,000-£55,000pa+
Last post by ForensicsRecruiter in Computer Forensics Job Vacancies on Sep 01, 2010 at 14:34:53

Computer Forensic Specialist - Team Lead - London £55-£80k+
Last post by ForensicsRecruiter in Computer Forensics Job Vacancies on Sep 01, 2010 at 14:23:04

COMPUTER FORENSIC/EDISCOVERY CONTRACT ROLE, LONDON 4-8 WEEKS
Last post by ScottBurkeman in Computer Forensics Job Vacancies on Aug 27, 2010 at 16:29:03

Computer Forensic Vacancy South Wales
Last post by stezer2000 in Computer Forensics Job Vacancies on Aug 19, 2010 at 09:41:54

CF Investigator (LE experience). London
Last post by DavidSullivan in Computer Forensics Job Vacancies on Aug 18, 2010 at 17:00:41

Computer/Video Forensic Examiners (Fredericksburg, VA, USA)
Last post by snorris in Computer Forensics Job Vacancies on Aug 18, 2010 at 00:09:50

Senior Forensic Computer Examiner - London
Last post by pgro in Computer Forensics Job Vacancies on Aug 17, 2010 at 13:26:19

Phd studentship available at University of Surrey.
Last post by apurva.rustagi in Computer Forensics Job Vacancies on Aug 16, 2010 at 22:52:52

Consultant- London- £25K-£40K
Last post by Teval in Computer Forensics Job Vacancies on Aug 05, 2010 at 07:37:45

Forensic Consultant - Singapore
Last post by darrencerasi in Computer Forensics Job Vacancies on Aug 05, 2010 at 01:00:18

Computer Forensics Blog
· 'Web 2.0' as evidence
· Scalability: A Big Headache
· Single Sign On
· Authentication and Authorisation
· UK student competition: Win free training on "Investigating Connection Records" course
· 10% Discount on Connection Records/Intro to CSA Training (UK)
· Mobile Forensics Training: Investigating Connection Records (UK, Aug 23/24)
· Windows Search forensics
· Computer Forensics - sometimes it’s all about timing
· Forensic Focus 2010 survey

read more...
Members' Blogs

Start Blogging

What is Computer Forensics?
Computer forensics (or forensic computing) is the use of specialized techniques for recovery, authentication, and analysis of electronic data with a view to presenting evidence in a court of law.
Computer Forensics Downloads
  1: Forensic Examination of Digital Evidence: A Guide for Law Enforcement (pdf)
  2: ACPO Good Practice Guide for Computer based Electronic Evidence
  3: Electronic Crime Scene Investigation: A Guide for First Responders (pdf)
  4: Ancysoft Data Recovery Software
  5: Forensics Plan Guide & Forensic Cookbook
  6: HELIX incident response CD
  7: PDA Forensic Tools:An Overview and Analysis
  8: Recover My Files
  9: Autopsy Forensic Browser Version 2.03 (source code)
  10: Handy Recovery
Forensic Focus

Forensic Focus

Copy and paste the text below to insert the button displayed above on your site. Thanks for your support!


Use of this website signifies your agreement to the Terms of Use/Privacy Policy available here.

All logos and trademarks in this site are property of their respective owner. The comments are property of their posters, all the rest © 2010 Forensic Focus


Interactive software released under GNU GPL, Code Credits, Privacy Policy
.: fisubsilver shadow phpbb2 style by Daz :: CPG-Nuke port by norseman :: ported to CPG-Dragonfly by jamin :.