Top Banner
Session ID: Session Classification: SungKyong Un ETRI CLEW04 Intermediate THE FUTURE OF DIGITAL FORENISCS
36

The Future of Digital Forensics

Oct 21, 2014

Download

Technology

RSA Asia Pacific 2013 Conference(Singapore, Jun 5-6) presentation
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: The Future of Digital Forensics

Session ID:

Session Classification:

SungKyong UnETRI

CLE‐W04

Intermediate

THE FUTURE OF DIGITAL FORENISCS

Page 2: The Future of Digital Forensics

Forensics

Source: mlhradio@flickr

Page 3: The Future of Digital Forensics

Digital Forensics

Page 4: The Future of Digital Forensics

► DFRWS (2001) defines► The use of scientifically derived and proven methods toward the

preservation, collection, validation, identification, analysis, interpretation, documentation and presentation of digital evidence derived from digital sources for the purpose of facilitating or furthering the reconstruction of events found to be criminal, or helping to anticipate unauthorized actions shown to be disruptive to planned operations.

Digital Forensics

Page 5: The Future of Digital Forensics

Digital Forensics Procedure

Start

Identify Storage

Duplicate?

Duplicate

Imaging?

Imaging

Analysis

Report

End

No

No

Yes

Yes

Write Protect

Write Protect

Source : TTAS.KO-12.0058

“Computer Forensics Guideline”

Page 6: The Future of Digital Forensics

Imaging

Hardware Duplicatorsource: http://www.solstice-inc.com

HDD Imaingsource : joncrel@flickr

Page 7: The Future of Digital Forensics

Recovery

Page 8: The Future of Digital Forensics

Keyword Search

source : Konrad Andrews@flickr

Page 9: The Future of Digital Forensics

Index Search

Page 10: The Future of Digital Forensics

Registry

Page 11: The Future of Digital Forensics

Web History

Page 12: The Future of Digital Forensics

Email

Page 13: The Future of Digital Forensics

Messenger

Page 14: The Future of Digital Forensics

Anti-Forensics - Eraser

Magnatic Erasersource: http://www.garner-product.com

Automatic Erasersource: http://www.wiebetech.com

Page 15: The Future of Digital Forensics

Anti-Forensics - Encryption

Apple FileVaultEncrypted File System (AES)Mac OS X v10.3

MS BitLockerDrive Encryption (AES)Windows Vista, 7

MS Office Encryption OptionVarious Algorithm

Page 16: The Future of Digital Forensics

Anti-Forensics - Countermeasure

GPU based parallel password searchSource : ETRI

FPGA based password searchSource : www.tableau.com

Page 17: The Future of Digital Forensics

The Present

Page 18: The Future of Digital Forensics

SmartPhone Forensics

Page 19: The Future of Digital Forensics

SmartPhone Forensics

Item Dummy Smart

Target Models >1,000/Year >10/Year

OS Symbian, Qualcomm iOS, Android, Windows Mobile, BlackberryOS

Interface Various USB

Acquisition Logical, Physical Logical, Physical,Backup

Data Phone book, Call history, SMS, Photo, Schedule

+ Email, Web History, Map, Location, SNS, Message, 

App, ID/PW

DB Format Various Sqlite

3rd Party App ‐ App Market

Page 20: The Future of Digital Forensics

Analysis - Briefing

Page 21: The Future of Digital Forensics

Analysis - Timeline

Page 22: The Future of Digital Forensics

Analysis – Web Browsing

Page 23: The Future of Digital Forensics

Analysis – Location & Routing

Page 24: The Future of Digital Forensics

Analysis – App

Category App

Phone Call Skype, Viber, Google Voice, ...

Message Cacao Talk, iMessage, Twitter DM, Facebook Message, ...

SNS Twitter, Facebook, me2day, ...

Storage Dropbox, uCloud, SugarSync, Box.net, iCloud, ...

Key DataVault, 1Password, Strip, ...

Page 25: The Future of Digital Forensics

Analysis – Communication Network

source: http://www.i2group.com

Page 26: The Future of Digital Forensics

Analysis – Social Network

Page 27: The Future of Digital Forensics

The Future

Page 28: The Future of Digital Forensics

Problem or Inconvience

Large Storage Search Space++ 1TB 14H? (20MB/s)

New Device/Service New Tools Buy/Educate?Forensics=Tool Expert?

New Environment Internet(Blog,Cafe, SNS)

Smart PhoneCloud Computing(Seizure & Search Warrant?)

Binary Search Index Search What if keyword is not known?

Page 29: The Future of Digital Forensics

New Viewpoint

Investigating the case, not the device Need information, not data

Multiple device/services per user Need multi(source) data integration

Continuous device/service creation/change Need a framework to host

Multiple remote sites Need mobility & connectivity

Volatile evidences Need acquisition method & third party attestation

Page 30: The Future of Digital Forensics

The Future of Digital Forensics

Data Centric Analysis Conduct Centric Analysis

Forensic Tools Forensic Services

Page 31: The Future of Digital Forensics

► Multi-source Evidence Acquisition► Relationship Analysis► Intuitive Analysis► Automatic Analysis Based on the Profile

Conduct Centric Analysis

Page 32: The Future of Digital Forensics

► Parallel/Distributed Platform for Large Data Handling► Adapting Fast Changing Device/Tools► User Mobility & Connectivity

Forensic Services

Page 33: The Future of Digital Forensics

Forensic Cloud: Forensics as a Service

AttestationForensic File Filter

ForensicVFS

Multi‐vision GUI Mobile GUI Web GUI

PW/Anti‐Forensic

Front‐End Layer

Presentation Layer

Data Processing Layer

Platform Layer Single Platform (Win/Linux) Distributed Platform (Cloud/Grid)

Data CategorizationForensic Index File/Memory Analysis

Multi‐source Acquisition

Online Forensic Data Acquisition

Real‐time Digital Forensic Service

Visualization

e‐Discovery Service

Forensic Cloud Technology Framework

Centralized Repository

Analysis Automation e‐Discovery Review/Reporting

Page 34: The Future of Digital Forensics

Forensic Cloud: Forensics as a Service

디지털 증거실시간 공증 기술

Forensic File Filter

ForensicVFS

Windows GUI Smart Phone GUI Web GUI

패스워드 해독/안티포렌식 기술

Front‐End Layer

Client Layer

Data Processing Layer

Platform Layer Single Platform (Win/Linux) Distributed Platform (Cloud/Grid)

데이터식별/분류/연관성

분석 기술

포렌식 인덱스/고속검색 기술

시스템 파일/물리메모리 분석 기술

멀티 소스 데이터획득/변환 기술

온라인 포렌식데이터 수집 기술

Real‐time Digital Forensic Service

시각화 기술

e‐Discovery Service

Forensic Cloud Technology Framework

Centralized Repository

분석 자동화 기술 e‐Discovery기술Review/Reporting 

기술

Parallel/Distributed Computing Core Function Acceleration 

Visualization Intuitive Analysis

Mobile Support  User Mobility/Connectivity

Page 35: The Future of Digital Forensics

Forensic Cloud: Forensics as a Service

Data CategorizationRelationship Analysis

VisualizationForensicVFS

ForensicFilter

AnalysisAutomation

eDiscovery

OnlineForensic DataAcquisition

Attestation

Multi-sourceData Acquization

/Conversion

Keyword Search

File/MemoryAnalysis

Review/Reporting

AntiForensic

Indexed Search

PWRecovery

Forensic Cloud

Page 36: The Future of Digital Forensics

Forensic Cloud: Forensics as a Service

source: http://en.wikipedia.org/wiki/File:Sun_Modular_Datacenter_SunEBC.JPG