Top Banner
PPB Forensics May 2010 IP Theft IT Forensic Solutions Chris Hatfield Senior Manager, IT Forensics
19

PPB Forensics – May 2010 IP Theft IT Forensic Solutions Chris Hatfield Senior Manager, IT Forensics.

Dec 16, 2015

Download

Documents

Theodora Woods
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: PPB Forensics – May 2010 IP Theft IT Forensic Solutions Chris Hatfield Senior Manager, IT Forensics.

PPB Forensics – May 2010

IP TheftIT Forensic Solutions

Chris HatfieldSenior Manager, IT Forensics

Page 2: PPB Forensics – May 2010 IP Theft IT Forensic Solutions Chris Hatfield Senior Manager, IT Forensics.

Risk Management

The process of determining the maximum acceptable level of overall risk to and from a proposed activity, then using risk assessment techniques to determine the initial level of risk and, if this is excessive, developing a strategy to ameliorate appropriate individual risks until the overall level of risk is reduced to an acceptable level.

http://en.wiktionary.org/wiki/risk_management

Page 3: PPB Forensics – May 2010 IP Theft IT Forensic Solutions Chris Hatfield Senior Manager, IT Forensics.

Security Triad

Page 4: PPB Forensics – May 2010 IP Theft IT Forensic Solutions Chris Hatfield Senior Manager, IT Forensics.

Security Triad

Page 5: PPB Forensics – May 2010 IP Theft IT Forensic Solutions Chris Hatfield Senior Manager, IT Forensics.

Authentication

Page 6: PPB Forensics – May 2010 IP Theft IT Forensic Solutions Chris Hatfield Senior Manager, IT Forensics.

Layer 1

Page 7: PPB Forensics – May 2010 IP Theft IT Forensic Solutions Chris Hatfield Senior Manager, IT Forensics.

Layer 2

Page 8: PPB Forensics – May 2010 IP Theft IT Forensic Solutions Chris Hatfield Senior Manager, IT Forensics.

Layer 3

Page 9: PPB Forensics – May 2010 IP Theft IT Forensic Solutions Chris Hatfield Senior Manager, IT Forensics.

Sources

A CB

Page 10: PPB Forensics – May 2010 IP Theft IT Forensic Solutions Chris Hatfield Senior Manager, IT Forensics.

Mobile Devices

A E

G I

C

M ON

B

F H J

K L

D

Page 11: PPB Forensics – May 2010 IP Theft IT Forensic Solutions Chris Hatfield Senior Manager, IT Forensics.

Hard Copy

BA C

Page 12: PPB Forensics – May 2010 IP Theft IT Forensic Solutions Chris Hatfield Senior Manager, IT Forensics.

Web mail, mail clients and mail servers.

Email Communication

B CA

Page 13: PPB Forensics – May 2010 IP Theft IT Forensic Solutions Chris Hatfield Senior Manager, IT Forensics.

Local, Remote and Hosted.

Data Locations

BA C

Page 14: PPB Forensics – May 2010 IP Theft IT Forensic Solutions Chris Hatfield Senior Manager, IT Forensics.

Pro-Active Solutions

Page 15: PPB Forensics – May 2010 IP Theft IT Forensic Solutions Chris Hatfield Senior Manager, IT Forensics.

Pro-Active Solutions

• Data transfer restrictions• Internet Logging• Personal email restrictions• Disable unnecessary media connections (USB/CD)• Monitor USB connections• Restrict working hours on IT equipment• Monitor/log printing habits• Monitor customer relationship software• Restrict access to only data they require access to• Log user activity• Keep reliable backups• Multi user authentication

Page 16: PPB Forensics – May 2010 IP Theft IT Forensic Solutions Chris Hatfield Senior Manager, IT Forensics.

Re-Active Solutions

POLICE POLICE POLICE POLICE POLICE POLICE POLICE POLICE POLICE

Page 17: PPB Forensics – May 2010 IP Theft IT Forensic Solutions Chris Hatfield Senior Manager, IT Forensics.

Re-Active Solutions

• Control crime scene• Equipment• Locations• People

• Contain evidence• Forensic image• Backup tapes• Physical segregation

• Evidence continuity• Do not touch original• Document all actions

Page 18: PPB Forensics – May 2010 IP Theft IT Forensic Solutions Chris Hatfield Senior Manager, IT Forensics.

Re-Active Solutions

• Conduct Forensic Analysis• Time of compromise• Extent of compromise• Threat assessment• USB access lists• Internet activity• Events timeline• Personal email activity• Business email activity• Printing activity• File access

Page 19: PPB Forensics – May 2010 IP Theft IT Forensic Solutions Chris Hatfield Senior Manager, IT Forensics.

Questions

PPB Forensics – May 2010

Joe DicksPartner, Melbourne

03 9269 4209 [email protected]

Phillip RussoDirector, Perth08 9216 7634

[email protected]

Andrew McLeishSenior Manager, Melbourne

03 9269 4276 [email protected]

Chris HatfieldSenior Manager, Sydney

02 8116 [email protected]