Top Banner
All the gear! ! and no idea Scalable, fast & forensically sound incident response using “NOOBS” Andrew Sheldon MSc.
23

Scalable, fast & forensically sound incident response ... · All the gear! ! and no idea Scalable, fast & forensically sound incident response using “NOOBS” Andrew Sheldon MSc.

Sep 15, 2018

Download

Documents

phungphuc
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Scalable, fast & forensically sound incident response ... · All the gear! ! and no idea Scalable, fast & forensically sound incident response using “NOOBS” Andrew Sheldon MSc.

All the gear! ! and no idea

Scalable, fast & forensically sound

incident response using “NOOBS”

Andrew Sheldon MSc.

Page 2: Scalable, fast & forensically sound incident response ... · All the gear! ! and no idea Scalable, fast & forensically sound incident response using “NOOBS” Andrew Sheldon MSc.

There are 3 BIG issues

Page 3: Scalable, fast & forensically sound incident response ... · All the gear! ! and no idea Scalable, fast & forensically sound incident response using “NOOBS” Andrew Sheldon MSc.

Annual computer sales since 1986 Source: www.guardian.co.uk

1986 1987 1988 1989 1990 1991 1992 1993 1994 1995 1996 1997 1998 1999 2000 2001 2002 2003 2004 2005 2006 2007 2008 2009

75

150

225

300

Mill

ions

of u

nits

per

yea

r

The number of “POTENTIAL CRIME

SCENES” increase every year

Page 4: Scalable, fast & forensically sound incident response ... · All the gear! ! and no idea Scalable, fast & forensically sound incident response using “NOOBS” Andrew Sheldon MSc.

Growth in hard disk capacity Source: www.guardian.co.uk

1986 1987 1988 1989 1990 1991 1992 1993 1994 1995 1996 1997 1998 1999 2000 2001 2002 2003 2004 2005 2006 2007 2008 2009

500

1000

1500

2000

Cap

acity

in G

IGA

BYT

ES

Crime scenes keep getting BIGGER

Size of disks

Page 5: Scalable, fast & forensically sound incident response ... · All the gear! ! and no idea Scalable, fast & forensically sound incident response using “NOOBS” Andrew Sheldon MSc.

There’re not enough FORENSIC ANALYSTS

Page 6: Scalable, fast & forensically sound incident response ... · All the gear! ! and no idea Scalable, fast & forensically sound incident response using “NOOBS” Andrew Sheldon MSc.

The number of examinations will grow even faster

What does the future hold?

TIME

The number of analysts will continue

to grow over time

Page 7: Scalable, fast & forensically sound incident response ... · All the gear! ! and no idea Scalable, fast & forensically sound incident response using “NOOBS” Andrew Sheldon MSc.

results in a high proportion of UNNECESSARY EXAMINATIONS

Ratio of front-line

“responders”

to back-room “experts”

THE SECONDARY CAUSE?

Page 8: Scalable, fast & forensically sound incident response ... · All the gear! ! and no idea Scalable, fast & forensically sound incident response using “NOOBS” Andrew Sheldon MSc.

It also results in

MORE TRAVEL

HIGHER COSTS

WASTED TIME

Page 9: Scalable, fast & forensically sound incident response ... · All the gear! ! and no idea Scalable, fast & forensically sound incident response using “NOOBS” Andrew Sheldon MSc.

WHAT DOES ALL THIS

MEAN

Page 10: Scalable, fast & forensically sound incident response ... · All the gear! ! and no idea Scalable, fast & forensically sound incident response using “NOOBS” Andrew Sheldon MSc.

We’ll KEEP getting what we’ve always had

If we KEEP doing what we’ve always done!

Too much work & too little time

Page 11: Scalable, fast & forensically sound incident response ... · All the gear! ! and no idea Scalable, fast & forensically sound incident response using “NOOBS” Andrew Sheldon MSc.

Say HELLO to the ”NOOBS”

Perhaps we should EMPOWER THE FRONT LINE To make informed decisions

Page 12: Scalable, fast & forensically sound incident response ... · All the gear! ! and no idea Scalable, fast & forensically sound incident response using “NOOBS” Andrew Sheldon MSc.

THE BREATHALYSER ANALOGY

Effective at the FRONT LINE

Limited SKILLS required

Easy to DEPLOY

Supports SUSPICIONS

There are some very good precedents

Page 13: Scalable, fast & forensically sound incident response ... · All the gear! ! and no idea Scalable, fast & forensically sound incident response using “NOOBS” Andrew Sheldon MSc.

THE A&E ANALOGY

Not all BRAIN SURGEONS

Few SIMPLE tools

Limited TRAINING

Prioritises CASELOAD

Page 14: Scalable, fast & forensically sound incident response ... · All the gear! ! and no idea Scalable, fast & forensically sound incident response using “NOOBS” Andrew Sheldon MSc.

So, how do we do it?!

A formal & controlled process for...

•  Assessing risk •  Identifying targets •  Collecting data •  Filtering information •  Classifying results •  Prioritising actions •  Allocating resources

High Call in the experts

Medium Seek advice from experts

Low Perform triage or imaging

Page 15: Scalable, fast & forensically sound incident response ... · All the gear! ! and no idea Scalable, fast & forensically sound incident response using “NOOBS” Andrew Sheldon MSc.

WE KNOW HOW TO APPLY THE

RULES

Page 16: Scalable, fast & forensically sound incident response ... · All the gear! ! and no idea Scalable, fast & forensically sound incident response using “NOOBS” Andrew Sheldon MSc.

Which help filter the RELEVENT

Page 17: Scalable, fast & forensically sound incident response ... · All the gear! ! and no idea Scalable, fast & forensically sound incident response using “NOOBS” Andrew Sheldon MSc.

Prioritise RESOURCES

Page 18: Scalable, fast & forensically sound incident response ... · All the gear! ! and no idea Scalable, fast & forensically sound incident response using “NOOBS” Andrew Sheldon MSc.

BUT !

We must control the NOOBS

with more than just a BOOT CD or thumb drive

Page 19: Scalable, fast & forensically sound incident response ... · All the gear! ! and no idea Scalable, fast & forensically sound incident response using “NOOBS” Andrew Sheldon MSc.

we have to

PACKAGE THE

SCIENCE

Page 20: Scalable, fast & forensically sound incident response ... · All the gear! ! and no idea Scalable, fast & forensically sound incident response using “NOOBS” Andrew Sheldon MSc.

Play time ;-)

Live demos

• Remote Forensics –  Respond to an incident in the USA, using Encase, via a mobile

phone

• Digital Triage –  Demonstrate how a NOOB can find the evidence forensically

(and avoid giving you unnecessary work)

Page 21: Scalable, fast & forensically sound incident response ... · All the gear! ! and no idea Scalable, fast & forensically sound incident response using “NOOBS” Andrew Sheldon MSc.

Forensic Incident Management Server

(FIMS)

Case Manager In USA

Forensic Analyst In LONDON

Request forensic Assistance for job in New York

Reviews CASE request Authorises

Analyst Downloads Credentials

Accesses evidence Using credentials

Accepts CASE

Remote Forensics Process

NOOB Does the

“hands on” task

Forensic analyst Sends instructions

from FIMS to NOOB

Evidence In USA

POD

Page 22: Scalable, fast & forensically sound incident response ... · All the gear! ! and no idea Scalable, fast & forensically sound incident response using “NOOBS” Andrew Sheldon MSc.

QUESTIONS?

Page 23: Scalable, fast & forensically sound incident response ... · All the gear! ! and no idea Scalable, fast & forensically sound incident response using “NOOBS” Andrew Sheldon MSc.

Thank You

Andrew Sheldon MSc. Evidence Talks Ltd

[email protected] Tel: 0845 125 4400

54 68 61 6E 6B 20 59 6F 75