Lecture 6 - Digital Forensics Analysis and Validation
Digital Forensics Investigation Overview
Digital forensics involves examining electronic devices to recover and analyze data relevant to an investigation.
Key Objectives
Determine what data to analyze in a digital forensics investigation.
Explain tools used to validate data.
Explain common data-hiding techniques.
Importance of Data Analysis
Nature of investigation and amount of data process determines examination methods.
Scope creep: Expansion of investigation scope due to unexpected evidence leads to increased resources and time.
Common in criminal investigations before a trial.
Prosecution must ensure comprehensive evidence analysis.
Investigation Planning
Create an investigation plan that includes:
Goals and scope of the investigation.
Required materials and tasks.
Approach based on case type: corporate, civil, or criminal.
Steps in Digital Forensics Investigations
Utilize recently wiped media for target drives after virus check.
Inventory hardware and note the condition of the seized computer.
For static acquisitions:
Remove original drive and check CMOS date and time.
Document data acquisition process.
Process drive contents methodically.
Create a list of all folders and files.
Examine all data file contents in folders.
Recover contents of password-protected files.
Identify executables not matching hash values.
Maintain control of all evidence and findings.
Tools for Data Analysis
Autopsy supports analysis of various file systems:
Microsoft FAT, NTFS, ExFAT, UFS, ISO 9660, HFS+, Ext2fs, Ext3fs, Ext4fs.
Offers multi-user keyword search, hash databases, and file type identification.
Using Autopsy: Process Steps
Select data source.
Configure ingest modules:
Hash lookup.
File type identification.
Data Integrity Validation - Forensic Data
Ensuring collected data integrity is vital for court presentation:
Forensic tools typically hash image files for validation.
Advanced hexadecimal editors allow for specific file hashing.
Example: WinHex offers MD5 and SHA-1 algorithms.
Validating with Hexadecimal Editors
advanced hexadecimal editors offer more features including:
hashing specific files or sectors
with the hash value in hand
you can use the forensic tool to search for a suspicious file that might have had its name changed to look like an innocuous file
Data Hiding Techniques
Data hiding aims to conceal file information:
Techniques include:
Hiding partitions and changing file extensions.
Setting file attributes to hidden.
Bit-shifting and encryption.
Password protection.
Common Hiding Techniques
Changing file extensions obscures true file types:
Digital forensics check file headers against extensions.
Using OS hidden attributes conceals files.
Low-level encryption changes data order, making it unreadable.
Understanding Steganography and Steganalysis
Steganography: Hiding messages so only intended recipients can detect them.
Steganalysis: Techniques to detect steganography.
Includes various attack methods like known cover attack and chosen message attack.
Steganalysis methods
stego-only method
known cover attack
known message attack
chosen stego attack
chosen message attack
Encrypted Files and Password Recovery
Passwords and encryption methods secure files:
Key escrow technology helps recover encrypted data.
Key sizes from 128 to 4096 bits increase resilience.
Tools for password recovery:
Integrated or standalone crack tools like Last Bit, AccessData PRTK, John the Ripper, ophcrack, passware
Password recovery methods:
Brute-force: Tests all combinations.
Dictionary: Uses common words.
Rainbow tables: Fast hash lookup without conversion., faster than a brute force or dictionary attack.
salting passwords: alters hash values and makes cracking passwords more difficult
Building profiles helps of the user, helps recover / cracking passwords
Summary of Digital Forensics
Analysis practices depend on investigation type and data amount:
Wiping drives, documenting hardware and timestamps, and systematic data collection are the crux of investigations.
Advanced tools enhance efficiency and ensure the integrity of digital evidence.
Important to understand data-hiding techniques for thorough investigations.
Password recovery techniques are vital for accessing protected data successfully.