In this post, we will dive into the fundamentals of network forensics, how it compares to traditional digital forensics, and the methodology used by investigators to track down cybercriminals.
What is Network Forensics?
Network forensics is defined as "a sub-branch of digital forensics relating to the monitoring and analysis of computer network traffic for the purposes of information gathering, legal evidence, or intrusion detection".
Unlike traditional "dead box" forensics (where data is static, preserved once power is removed, and relatively easy to image), network data is constantly changing. Because of this, investigators face unique challenges:
- Pinpointing the direct location of the necessary evidence is problematic.
- Physical access to network devices can be difficult, and most network devices lack persistent data storage.
- Investigators must minimize the investigation's impact on the business network.
- Legal precedence is sometimes conflicting and not yet fully standardized.
Why Do We Need to Worry About Network Crime?
Cybercrime is an incredibly expensive problem. The FBI estimates that cybercrime costs more than $100 billion per year.
Furthermore, attacks are no longer just coming from "basement hackers". Threats can originate from both inside and outside the network, including:
- Employees
- Business competition
- Professional hackers for hire
- City-states
Types of Evidence in an Investigation
Understanding the various types of evidence is crucial when conducting an investigation:
- Real evidence: Physical objects that play a relevant role in the crime (e.g., physical HDD, USB, computer box, keyboard).
- Best evidence: Primary evidence that can be produced in court (e.g., a recovered file, or a bit-for-bit snapshot of a network transaction).
- Direct evidence: Eyewitness accounts.
- Circumstantial evidence: Evidence linked with other evidence to draw a conclusion (e.g., an email signature, USB serial number).
- Hearsay: Second-hand information (e.g., a text file containing a personal letter).
- Business records: Routinely generated documentation, like contracts, employee policies, and system logs.
- Digital evidence: Electronic evidence, including emails, IMs, and logs.
The OSCAR Investigative Methodology
To effectively and legally handle network incidents, investigators often rely on the OSCAR methodology: Obtain, Strategize, Collect, Analyze, and Report.
1. Obtain Information
The first step involves gathering all preliminary information regarding the incident:
- Incident description: How the incident was discovered, known persons involved, systems and/or data involved, and actions taken by the organization since discovery.
- The Environment: Understanding the working business model, enforceable policies, network topology, available resources (staff, equipment, funding, time), and incident response management procedures.
2. Strategize
With the initial information in hand, investigators need to build a plan:
- Understand the goals and timeframe for the investigation.
- Organize resources and document potential evidence sources.
- Estimate the value of the evidence versus the effort to obtain it, and prioritize based on this estimate.
- Set up a schedule for regular communication between investigators.
- Note: This plan is fluid and will most likely need adjustments.
3. Collect Evidence
This phase requires extreme care to ensure the evidence remains legally admissible:
- Document, document, document!
- Lawfully capture evidence and make cryptographically verifiable copies.
- Setup secure storage of collected evidence and establish a chain of custody.
- Crucial Rule: Use legally obtained, reputable tools, and analyze the copies only.
4. Analyze
Now it is time to dig into the collected data:
- Establish a well-documented timeline of activities.
- Show correlation with multiple sources of evidence.
- Highlight and further investigate events that are potentially more relevant to the incident, corroborating all evidence.
- Make educated interpretations of the evidence to build working theories, but always separate your interpretations from the facts.
5. Report
The final step is to present the findings. Every report must be:
- Understandable by non-technical people.
- Complete and meticulous.
- Defensible in every detail.
- Completely factual.
Top comments (0)