Digital Forensics Notes - lect 15
Digital Forensics Best Practice and the Law
Stuxnet Worm
Stuxnet is a malicious computer worm discovered in 2010.
It targeted Iran's nuclear program, specifically programmable logic controllers (PLCs).
PLCs automate electromagnetical processes in machinery and industrial processes, like centrifuges used for uranium enrichment.
It Exploited four zero-day flaws to target Windows systems and Siemens STEP seven software that controlled centrifuges.
Zero-Day Vulnerability
A zero-day vulnerability is a software vulnerability unknown to those who could mitigate it.
Zero-day attacks are difficult to preempt because no counteractive measures are in place yet.
Stuxnet Analysis
Symantec investigated Stuxnet, finding it contained approximately 15,000 lines of code.
The code was analyzed to understand its behaviors and targets.
Initially, the target was identified as specific equipment, but later linked to a uranium enrichment facility after four months.
Stuxnet did not attack over the Internet but likely via infected USB drives.
Infection Method
Infected USB drives were theorized to have been planted in areas accessible to workers at Natanz.
Plugging the USB drive into a computer would immediately infect it.
Stuxnet's Operation
Stuxnet copies itself onto a computer as soon as the infected USB is connected even for a few seconds.
It uses stolen digital signatures to masquerade as legitimate software from trusted vendors like Microsoft.
Once loaded, Stuxnet spreads through various methods, including other flash drives, file servers, and print spoolers.
It acts as a carrier on home computers without causing direct damage, focusing solely on the target computer in Natanz.
Target and Destruction
Stuxnet seeks out mini-computers (PLCs) running factory automation, specifically Siemens modules that control centrifuges.
Once found, it manipulates the centrifuges to spin at twice their intended speed.
It overrides safety mechanisms, preventing operators from stopping the process, leading to the destruction of the centrifuges.
Stuxnet provides fake readouts to operators, making it appear that the centrifuges are running normally.
Cyber Warfare Implications
Stuxnet represents a new form of cyber warfare.
It leverages anonymity in cyberspace, making attacks difficult to trace and disrupt.
Digital Forensics Evidence
Sources of Evidence
Digital forensics involves more than computers, including smartphones, USB disks, digital cameras, and GPS devices.
Network forensics analyzes network traffic like emails using packet sniffers.
Wireshark is a common packet sniffer software.
Encrypted information, even when detected, is difficult to decipher.
Locations to Examine
Allocated Space: The space allocated to a file may contain fragments of previously stored files.
Unallocated Space: Deleted but recoverable files.
Digital forensics software is required to recover such files.
Locard's Exchange Principle
Applies to digital forensics; every action leaves traces.
Wherever he steps, whatever he touches, whatever he leaves, even unconsciously, will serve as a silent witness against him.
ACPO Guidelines (Association of Chief Police Officers)
*Replaced by the National Police Chiefs Council (NPCC).
Guidelines for police officers and forensics practitioners.
Version 4 focuses on evidence recovery methods.
Version 5 emphasizes legal and procedural aspects.
Due to the size of modern hard disks, the focus is on finding relevant files rather than analyzing all files.
The prosecution must prove evidence is unaltered from its original state.
Hashing
Hashing algorithms like MD5 and SHA-1 are used to ensure data integrity.
SHA-1 distills information into a 43-character code.
Changing one bit of information completely changes the hash.
Hashes cannot be reversed to retrieve original information.
Calculate hash of the original and after copying to compare.
Four Key Principles
Data Preservation: No action should alter data that may be used in court.
Use a write blocker to create a bit-for-bit copy (image).
Partial copying may be necessary due to large data amounts.
Competence: Individuals accessing original data must be competent.
Digital forensics experts should perform the role.
Audit Trail: A record of all processes applied to evidence must be created.
An independent third party should be able to achieve the same result.
Responsibilities: The case officer is responsible for adhering to the law and principles.
Seizing Computer Equipment
Do not attempt to recover information without expertise.
Pull the power supply to prevent changes to the evidence.
Avoid shutting down the computer through the operating system.
Pulling the power will result in lost volatile data.
Capture volatile data (passwords, unencrypted programs) using computer forensics before pulling the power.
The Forensic Process
Acquisition:
Obtain consents and legal documents.
Document the scene without altering anything.
Forensic duplication: Create a bit-for-bit copy (image) using a write blocker.
Use hashing (MD5, SHA-1) for file integrity checks.
Identification:
Physically identify and tag digital equipment.
Determine where the evidence came from logically (folders, logical drives, partitions).
Identify the type of evidence (file type, extension, file signature).
Evaluation:
How was the data produced?
Who produced it, and when?
Is the evidence relevant?
Are there signs of foul play (e.g., Trojan defense)?
Presentation:
Interpret data and provide a report for non-experts.
Defend findings in court.
Legislation
Computer Misuse Act
Section 1: Unauthorized access to computer material. (up to two years sentence)
Section 2: Unauthorized access with intent to commit or facilitate further offense. (five years or more sentence).
Section 3: Unauthorized modification of computer material. (ten years max. sentence).
Covers informational data not covered by the Criminal Damage Act 1971.
Protection of Children Act
Taking, making, or possessing indecent photographs of a child is an offense.
Distributing such images is an offense.
Possessing with intent to distribute is an offense.
Criminal Justice and Public Order Act 1994
Amended Protection of Children Act to include pseudo-photographs.
Sexual Offences Act 2003
Increased the age of a child from 16 to 18.
Added a defense for indecent photographs of a child over 16 created by a long-term partner.
Added a defense for creating indecent images for criminal investigation.
Actus Reus and Mens Rea
Actus Reus: (guilty act) Images found on a computer.
Mens Rea: (guilty mind) Proof that images were deliberately saved or searched for.
Both actus reus and mens rea must be present to prove a crime.
Stuxnet Worm
Stuxnet is a sophisticated malicious computer worm discovered in 2010, notable for its complexity and targeted nature.
It specifically targeted Iran's nuclear program. It targeted programmable logic controllers (PLCs).
PLCs are used to automate electromagnetical processes in machinery and industrial processes, such as the centrifuges used for uranium enrichment. These centrifuges are critical for the process of enriching uranium, making the PLCs a key target.
It exploited four zero-day flaws to target Windows systems and Siemens STEP seven software that controlled centrifuges. These vulnerabilities were unknown to the software vendors, making them particularly dangerous.
Zero-Day Vulnerability
A zero-day vulnerability is a software vulnerability that is unknown to those who could mitigate it, including vendors and security experts. This lack of awareness means there are no patches or fixes available when the vulnerability is first exploited.
Zero-day attacks are difficult to preempt because no counteractive measures are in place yet. Organizations are left vulnerable until a solution is developed and implemented.
Stuxnet Analysis
Symantec investigated Stuxnet, finding it contained approximately 15,000 lines of code. This extensive codebase indicates the complexity and resources involved in creating such malware.
The code was analyzed to understand its behaviors and targets. Reverse engineering was used to dissect the code and determine its functionality.
Initially, the target was identified as specific equipment, but later linked to a uranium enrichment facility in Natanz after four months. This discovery highlighted the strategic intent behind the malware.
Stuxnet did not attack over the Internet but likely via infected USB drives. This method allowed it to bypass traditional network security measures.
Infection Method
Infected USB drives were theorized to have been planted in areas accessible to workers at Natanz. The malware could then spread internally within the facility.
Plugging the USB drive into a computer would immediately infect it. The worm would automatically execute without requiring user interaction, ensuring rapid propagation.
Stuxnet's Operation
Stuxnet copies itself onto a computer as soon as the infected USB is connected, even for a few seconds. This rapid replication is crucial for its spread.
It uses stolen digital signatures to masquerade as legitimate software from trusted vendors like Microsoft and Realtek. This helps it evade detection by security software.
Once loaded, Stuxnet spreads through various methods, including other flash drives, file servers, and print spoolers. This multi-pronged approach ensures extensive propagation within the network.
It acts as a carrier on home computers without causing direct damage, focusing solely on the target computer in Natanz. This minimizes the risk of detection and allows it to remain dormant until it reaches its intended target.
Target and Destruction
Stuxnet seeks out mini-computers (PLCs) running factory automation, specifically Siemens modules that control centrifuges. It targets specific industrial control systems to achieve its objectives.
Once found, it manipulates the centrifuges to spin at twice their intended speed. This overspeed leads to excessive wear and tear, causing the centrifuges to break down.
It overrides safety mechanisms, preventing operators from stopping the process, leading to the destruction of the centrifuges. This ensures that the damage is irreversible.
Stuxnet provides fake readouts to operators, making it appear that the centrifuges are running normally. This deception prevents timely intervention, exacerbating the damage.
Cyber Warfare Implications
Stuxnet represents a new form of cyber warfare. It demonstrated the potential for malware to cause physical damage to critical infrastructure.
It leverages anonymity in cyberspace, making attacks difficult to trace and disrupt. This poses significant challenges for attribution and defense.
Digital Forensics Evidence
Sources of Evidence
Digital forensics involves more than computers, including smartphones, USB disks, digital cameras, and GPS devices. The scope is broad, encompassing any device capable of storing digital data.
Network forensics analyzes network traffic like emails using packet sniffers. This can uncover communication patterns and data transfers.
Wireshark is a common packet sniffer software. It allows for the capture and analysis of network packets.
Encrypted information, even when detected, is difficult to decipher without the correct decryption keys or methods. Encryption adds a layer of complexity to digital investigations.
Locations to Examine
Allocated Space: The space allocated to a file may contain fragments of previously stored files, known as file slack. These fragments can provide valuable clues.
Unallocated Space: Deleted but recoverable files. Data recovery techniques can be used to retrieve this information.
Digital forensics software is required to recover such files. These tools are designed to bypass operating system limitations and access raw data.
Locard's Exchange Principle
Applies to digital forensics; every action leaves traces. This principle is fundamental to forensic investigations.
Wherever he steps, whatever he touches, whatever he leaves, even unconsciously, will serve as a silent witness against him. This highlights the importance of meticulous evidence collection and analysis.
ACPO Guidelines (Association of Chief Police Officers)
*Replaced by the National Police Chiefs Council (NPCC).
Guidelines for police officers and forensics practitioners. These provide a framework for conducting digital investigations in a legally sound and forensically robust manner.
Version 4 focuses on evidence recovery methods. It outlines best practices for acquiring and preserving digital evidence.
Version 5 emphasizes legal and procedural aspects. It ensures that investigations comply with relevant laws and regulations.
Due to the size of modern hard disks, the focus is on finding relevant files rather than analyzing all files. This triage approach helps to streamline investigations and prioritize resources.
The prosecution must prove evidence is unaltered from its original state to ensure its admissibility in court.
Hashing
Hashing algorithms like MD5 and SHA-1 are used to ensure data integrity. These algorithms generate a unique fingerprint of a file.
SHA-1 distills information into a 43-character code. This fixed-size output allows for easy comparison of files.
Changing one bit of information completely changes the hash. This sensitivity to change makes hashing a reliable method for detecting tampering.
Hashes cannot be reversed to retrieve original information. This one-way function ensures that the hash cannot be used to reconstruct the original data.
Calculate hash of the original and after copying to compare. If the hashes match, it confirms that the copy is identical to the original.
Four Key Principles
Data Preservation: No action should alter data that may be used in court.
Use a write blocker to create a bit-for-bit copy (image). This prevents any modifications to the original evidence.
Partial copying may be necessary due to large data amounts. A targeted approach can save time and resources.
Competence: Individuals accessing original data must be competent.
Digital forensics experts should perform the role. They have the necessary skills and knowledge to handle digital evidence properly.
Audit Trail: A record of all processes applied to evidence must be created. This documentation ensures transparency and accountability.
An independent third party should be able to achieve the same result. This reproducibility validates the findings.
Responsibilities: The case officer is responsible for adhering to the law and principles. They ensure that the investigation is conducted ethically and legally.
Seizing Computer Equipment
Do not attempt to recover information without expertise. Inexperienced handling can compromise the evidence.
Pull the power supply to prevent changes to the evidence. This is a quick way to stop the system from writing new data.
Avoid shutting down the computer through the operating system. This can trigger changes to system files.
Pulling the power will result in lost volatile data. This includes data stored in RAM, which can be valuable.
Capture volatile data (passwords, unencrypted programs) using computer forensics before pulling the power. Tools like FTK Imager can be used to acquire this data.
The Forensic Process
Acquisition:
Obtain consents and legal documents. Ensure that you have the legal authority to seize and examine the evidence.
Document the scene without altering anything. Photographs and detailed notes should be taken.
Forensic duplication: Create a bit-for-bit copy (image) using a write blocker. This ensures that the original evidence remains unaltered.
Use hashing (MD5, SHA-1) for file integrity checks. Verify that the copy matches the original.
Identification:
Physically identify and tag digital equipment. Use unique identifiers to track each piece of evidence.
Determine where the evidence came from logically (folders, logical drives, partitions). Understand the file system structure.
Identify the type of evidence (file type, extension, file signature). Use file signature analysis to confirm the file type.
Evaluation:
How was the data produced? Understand the context in which the data was created.
Who produced it, and when? Determine the author and creation date of the data.
Is the evidence relevant? Focus on data that is pertinent to the investigation.
Are there signs of foul play (e.g., Trojan defense)? Look for evidence of tampering or malicious activity.
Presentation:
Interpret data and provide a report for non-experts. The report should be clear and concise.
Defend findings in court. Be prepared to explain the forensic process and justify your conclusions.
Legislation
Computer Misuse Act
Section 1: Unauthorized access to computer material. (up to two years sentence) This covers basic hacking offenses.
Section 2: Unauthorized access with intent to commit or facilitate further offense. (five years or more sentence). This addresses more serious offenses, such as accessing data to commit fraud.
Section 3: Unauthorized modification of computer material. (ten years max. sentence). This covers offenses such as creating and spreading viruses.
Covers informational data not covered by the Criminal Damage Act 1971. This ensures that data is protected from unauthorized modification or deletion.
Protection of Children Act
Taking, making, or possessing indecent photographs of a child is an offense. This covers the creation and possession of illegal images.
Distributing such images is an offense. This addresses the sharing and dissemination of illegal content.
Possessing with intent to distribute is an offense. This covers individuals who possess images with the intention of sharing them.
Criminal Justice and Public Order Act 1994
Amended Protection of Children Act to include pseudo-photographs. This broadened the scope of the law to include computer-generated images.
Sexual Offences Act 2003
Increased the age of a child from 16 to 18. This provided greater protection to vulnerable individuals.
Added a defense for indecent photographs of a child over 16 created by a long-term partner. This addresses specific circumstances where the relationship is consensual.
Added a defense for creating indecent images for criminal investigation. This allows law enforcement to create and possess images for legitimate purposes.
Actus Reus and Mens Rea
Actus Reus: (guilty act) Images found on a computer. This is the physical act of committing the crime.
Mens Rea: (guilty mind) Proof that images were deliberately saved or searched for. This is the mental state of the accused.
Both