DEV Community

Timothy Imanuel
Timothy Imanuel

Posted on

Network Forensics: Sources of Evidence & Network Security (Week 2)

This week, we explore the sources of digital evidence, the history of early malware, and the core protocols used to secure network communications, specifically VPNs and IPSec.

The Dawn of Malware: Viruses and Worms

Understanding the history and behavior of malicious software is critical for any forensic investigator.

Early Milestones

  • The First Virus: Created in 1983 by Len Adelman, five years before a virus was released onto the broader internet. It was implanted into the UNIX vd command and successfully granted all system rights within an hour during controlled lab tests. It was later tested on VMS, VM/370, and Tops-20 with the same results.
  • The Morris Worm: Launched by Robert Morris on November 2, 1988. It invaded approximately 6,000 computers, which was 10% of the internet at the time, within hours. Instructions to stop the worm were posted online, but the hosting computer was disabled by the worm before anyone could read them. Estimated damage ranged from $10,000 to $97 million, highlighting how difficult it is to estimate the cost of cybercrime.

Types of Viruses and Worms

  • Macro Virus: Usually infects Microsoft Office and Outlook Express. They are cross-platform, as the Microsoft products give them a base platform to run in. They are usually passed by trading documents, and the viruses can email themselves out using the address book in Outlook. They automatically activate by being named the same as macros (e.g., AutoOpen, AutoClose), which run automatically when opening or closing a document.
  • Multipartite: Infects both the boot sector and files. It spreads via the network, infecting files which in turn infect the boot sector.
  • Stealth: Inserts code between the end application and the kernel. It gives results to the application that the application would expect. It may remove itself from the media while the system is running to avoid virus detection, then copies itself back to the media when the system is shut down.

Securing Communications: VPNs and IPSec

To protect data, modern networks rely on Virtual Private Networks (VPNs) and the IPSec protocol suite.

Virtual Private Networks (VPNs)

A VPN is a connection between private networks over a public network, and it is most likely encrypted. There are two main types:

  • Remote Access (Transport Mode): Allows access to the private network for mobile or home users, acting as an extension of the traditional dial-up network.
  • Site-to-Site (Tunnel Mode): Used to connect remote corporate networks, replacing leased and frame relay lines.

IPSec Fundamentals

IPSec provides several vital layers of protection:

  • Data Integrity: IPSec uses HMAC (Hashed Message Authentication Code) to verify that packets are not altered in transit. It appends a secret key to a message, hashes it, and sends both to the remote site. The remote site compares the hashes to ensure integrity. It currently uses HMAC-MD5 (128-bit hash) or the stronger HMAC-SHA-1 (160-bit hash).
  • Origin Authentication: Verifies the true sender of the information.
  • Anti-Replay: Prevents an attacker from intercepting and reusing a data packet.
  • Data Confidentiality: Ensures the actual data remains hidden.

IPSec Security Protocols

IPSec uses two primary protocols to send data:

  1. Authentication Header (AH): Used when confidentiality is not an issue. It ensures data integrity, provides origin authentication, and provides anti-replay protection.
  2. Encapsulating Security Payload (ESP): Provides encryption for confidentiality, plus all the protections offered by AH.

Both protocols can operate in two modes:

  • Transport Mode: Used between two hosts and secures the higher layer protocols only. For ESP, it takes the data in the IP packet and encrypts it, then creates another IP packet with an ESP header, the encrypted data, and a hash.
  • Tunnel Mode: Used between two security gateways (e.g., VPN router, firewall) and secures the entire IP packet. It provides confidentiality by encrypting the IP header itself. Because the entire IP packet is encrypted, the outside world has no idea about the design and layout of the LAN, nor do they know what specific machine it came from or is going to.

The 5 Steps of Setting Up a VPN

Establishing a secure VPN connection involves five distinct steps:

  1. Determine Data: Determine what data needs to go through the VPN.
  2. IKE Phase 1 (Internet Key Exchange): Negotiate policy sets, authenticate peers, and set up the secure channel between peers.
  3. IKE Phase 2: Negotiate the security parameters used in the IPSec tunnel. This creates a Security Association (SA) that dictates the algorithms and transport mode. Security Parameter Indexes (SPIs) are sent with each packet to index back to this transform information.
  4. IPSec Session: Data is sent to the remote site using the negotiated SA information.
  5. Tunnel Termination: The SA information and shared key are removed. If more data needs to be communicated, the VPN restarts at Step 2.

Top comments (0)