x
Forensics for Managers
Ryan Washington
MBA, CISSP, CCE, CEH, NSA/IAM
703-961-9456 Extension 128
Forensics for Managers x Ryan Washington MBA, CISSP, CCE, CEH, - - PowerPoint PPT Presentation
Forensics for Managers x Ryan Washington MBA, CISSP, CCE, CEH, NSA/IAM 703-961-9456 Extension 128 Introduction US Marines, Special Intelligence Communicator Bachelors in Management Masters of Business Administration Solaris
Ryan Washington
MBA, CISSP, CCE, CEH, NSA/IAM
703-961-9456 Extension 128
2
◆ US Marines, Special Intelligence Communicator ◆ Bachelors in Management ◆ Masters of Business Administration ◆ Solaris Administrator ◆ Computer Nerd
3
◆ Awareness ◆ Knowledge ◆ Attributes ◆ Key Terminology
4
◆ “Computer Forensics is the application of the
scientific method to digital media in order to establish factual information for judicial
investigating computer systems to determine whether they are or have been used for illegal
forensics experts investigate data storage devices, either fixed like hard disks or removable like compact disks and solid state devices.
S
t h e a s t C
p u t e r F
e n s i c s a n d S e c u r i t y h t t p : / / s e c
p u t e r f
e n s i c s . c
/ i n d e x . p h p ?
t i
= c
_ c
t e n t & t a s k = v i e w & i d = 2 & I t e m i d = 4 8
5
◆ Identify sources of
documentary or
◆ Preserve the
evidence
◆ Analyze the evidence
Computer forensics experts:
6
◆ “Find Stuff” ◆ Deleted Files ◆ Corporate Theft
7
◆
Image
◆
E01
◆
.dd ◆
Unallocated Space
◆
Unused Space
◆
Carve
◆
Mount
◆
Logs
◆
Partition
◆
Root Kit
◆
Malware
◆
Steg
◆
Dongle
◆
Header
◆
Backdoor
◆
Hash
◆
Logical
◆
Physical
…sound like a pro
8
◆ You Don’t…
◆
Or…DO you?
◆ Different Skill Set ◆ Intrusions ◆ Employee Theft ◆ Corporate Malfeasance ◆ Human Resources Matters
9
◆ Governments ◆ Contractors ◆ Secrets ◆ Corporations ◆ Contractors ◆ Secrets ◆ Thieves ◆ Information ◆ MONEY
10
◆ Angry ◆ Make a Statement ◆ Random ◆ Weak Security ◆ Strong Security ◆ Paid
11
◆ Sleuthkit/Autopsy ◆ Wetstone Technologies ◆ ProDiscover ◆ Encase ◆ Forensic Toolkit (FTK) ◆ Paraben
12
Linux and Freeware
◆ PRO
◆
Free
◆
Open Source
◆
Distributed
◆ CON
◆
No Technical Assistance
◆
More Man-hours
◆
Deeper Trouble…
http://www.securityfocus.com/infocus/ 1503 http://www.tucofs.com/tucofs/tucofs.a sp?mode=mainmenu http://www.e-fense.com/helix/ http://fire.dmzs.com/ http://s-t-d.org/ http://www.opensourceforensics.org/t
13
◆ PRO
◆
Price
◆
Easy to Use
◆
Malware/Stego
◆ CON
◆
Hashing
◆
Basic
http://www.wetstonetech.com/f/index.htm
14
◆
PRO
◆
Price
◆
Perl * ◆
CON
◆
“Pay per filesystem”
◆
Pay for Perl ability
◆
Pay for More
http://www.techpathways.com/Desktop Default.aspx?tabindex=0&tabid=1
15
◆
PRO
◆
Robust
◆
Market Share
◆
Training ◆
CON
◆
Price
◆
Support
◆
Enscript
◆
Training
http://www.guidancesoftware.com/
16
◆ PRO
◆
Price
◆
Index
◆
“Dummy Proofing”
◆ CON
◆
False Sense of Completeness/Security
◆
Heavy Upfront
http://www.accessdata.com/
17
◆ PRO
◆
Distributed
◆
Price
◆ CON
◆
Distributed
◆
Training
http://www.paraben-forensics.com
18
◆ Cover Costs (of course…) ◆ Profit (of course…) ◆ Multi-Tasking ◆ Powerful ◆ “Easy to Use” ◆ Court Tested!!! ◆ Technical Assistance
19
◆ Junior
◆
$60,000 - $80,000
◆ Mid-Level
◆
$75,000 - $100,000
◆ Senior
◆
$90,000 - $150,000
◆ “Well Known” Senior
◆
$110,000 - $300,000
◆ Contractor/Independent/Hourly
◆
Over $200,000
20
◆ Experience
◆
Where? When?
◆
Commercial? Law Enforcement?
◆ Education
◆
University? Learning Center? Discovery Channel?
◆ Certifications
◆
CISSP, EnCE, ACE, GIAC, CCE, CFCE
◆ Personality
◆
?
◆
Integrity
◆
Honesty
21
◆ Hard Drive Size ◆ Expenses ◆ Level of Expertise ◆ Retainer ◆ Imaging Fee ◆ Admin Fee
$0 $10,000 $20,000 $30,000 $40,000 $50,000 $60,000 $70,000 $80,000 $90,000 One HD 5 HD 20 HD
Hours Junior Mid Senior
22
Full-Time? Full-Time? Contract? Contract? Part-Time? Part-Time?
23
“It wasn’t raining when Noah built the Ark.”
24
◆ How often are “Forensic Services” needed? ◆ Multi-tasked Person? ◆ Trusted Outsourced Company? ◆ Investigation Costs >, =, < Possible loss of
data?
◆ Remember…You Get What You Pay For….
25
Ryan Washington
rwashington@crucialsecurity.com Work 571-223-3426 Cell 571-437-3722