0% found this document useful (0 votes)
15 views12 pages

Investigating Computer Intrusions

The document discusses computer intrusions, which involve unauthorized access to systems leading to data theft and financial losses. It outlines various types of intrusions, indicators of compromise, consequences, prevention strategies, and the evidence collection process in digital forensics. Additionally, it highlights challenges in evidence collection and lists tools used for intrusion investigation.

Uploaded by

gargikaushik1711
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
15 views12 pages

Investigating Computer Intrusions

The document discusses computer intrusions, which involve unauthorized access to systems leading to data theft and financial losses. It outlines various types of intrusions, indicators of compromise, consequences, prevention strategies, and the evidence collection process in digital forensics. Additionally, it highlights challenges in evidence collection and lists tools used for intrusion investigation.

Uploaded by

gargikaushik1711
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Investigating Computer Intrusions

Kavya Gupta
Department of CSE(AI&ML)
KIET Group of Institutions

Kavya Gupta,
[Link]
508443105
Introduction to Computer Intrusions
• Computer intrusions refer to unauthorized
access or breaches into computer systems,
networks, or digital assets. These intrusions
can result in data theft, system disruptions,
financial losses, and reputational damage.
Attackers exploit vulnerabilities in software,
hardware, or human behavior to gain access.

Kavya Gupta,
[Link]
508443105
Types of Computer Intrusions
• Malware Attacks – Involves malicious software like
viruses, worms, Trojans, and ransomware.
• Phishing Attacks – Social engineering techniques to
deceive users into revealing credentials.
• Denial-of-Service (DoS) Attacks – Overloading a
system to make it unavailable.
• SQL Injection – Exploiting database vulnerabilities to
access sensitive data.
• Zero-Day Exploits – Attacks targeting unknown or
unpatched vulnerabilities.
Kavya Gupta,
[Link]
508443105
Indicators of Compromise (IoCs)
• Unusual Network Traffic
• Unauthorized System Access
• Modification of Log Files and System Files

Kavya Gupta,
[Link]
508443105
Consequences of Computer Intrusions
• Data loss or theft
• Financial fraud
• Identity theft
• Operational disruption
• Legal consequences

Kavya Gupta,
[Link]
508443105
Prevention and Mitigation

•Implement strong authentication mechanisms


•Regular software updates and patching
•Network monitoring and intrusion detection systems
•Security awareness training for users
•Data encryption and backup strategies

Kavya Gupta,
[Link]
508443105
Evidence Collection in Computer
Intrusions
• Evidence collection in computer intrusions is a
critical process in digital forensics, ensuring
that data related to an attack is properly
gathered, preserved, and analyzed for
investigation and legal proceedings. The
process follows a structured approach to
maintain the integrity and admissibility of
evidence.

Kavya Gupta,
[Link]
508443105
Types of Digital Evidence in Computer
Intrusions
• Volatile Data – Information stored in RAM, such as active
network connections, running processes, and system
logs.
• Non-Volatile Data – Files, logs, emails, databases, and
disk images stored on hard drives and removable media.
• Network Traffic Data – Captured packets, firewall logs,
and intrusion detection system (IDS) alerts.
• System and Application Logs – Operating system logs,
security logs, and application logs that record user
activities and system events.
Kavya Gupta,
[Link]
508443105
Steps in Evidence Collection
• Identification – Recognizing sources of evidence, such as compromised
systems, logs, or user accounts.
• Preservation – Ensuring evidence is not altered or lost by isolating affected
systems and using write-blocking techniques.
• Acquisition – Making forensic copies of storage devices, capturing memory
dumps, and collecting network logs.
• Analysis – Examining collected data for signs of unauthorized access, malware,
or attacker footprints.
• Documentation – Recording timestamps, system details, and chain of custody
for legal compliance.
• Presentation – Summarizing findings in a structured report for law
enforcement, legal teams, or security analysts.

Kavya Gupta,
[Link]
508443105
Challenges in Evidence Collection
•Data Volatility – Critical evidence in RAM can be lost if not
captured immediately.
•Encryption and Anti-Forensic Techniques – Attackers may use
encryption or data-wiping tools to evade detection.
•Legal and Privacy Issues – Adhering to laws like GDPR and
cybercrime regulations while collecting data.
•Complexity of Attacks – Advanced persistent threats (APTs) can
leave minimal traces, requiring deep forensic analysis.

Kavya Gupta,
[Link]
508443105
Tools for Intrusion Investigation
1. Memory Forensics Tools
• Volatility – Extracts and analyzes volatile memory data (RAM).
• Rekall – Advanced memory forensics and analysis.
2. Disk Forensics Tools
• Autopsy – Open-source digital forensic platform.
• EnCase – Industry-standard tool for disk imaging and analysis.
• FTK (Forensic Toolkit) – Comprehensive forensic investigation suite.
3. Network Forensics Tools
• Wireshark – Captures and analyzes network traffic.
• Zeek (formerly Bro) – Network security monitoring tool.
• Tcpdump – Command-line network packet analyzer.
4. Log Analysis Tools
• Splunk – Searches and analyzes security logs.
• Graylog – Centralized log management tool.
• ELK Stack (Elasticsearch, Logstash, Kibana) – Real-time log processing and visualization.

Kavya Gupta,
[Link]
508443105
Tools for Intrusion Investigation
5. Intrusion Detection & Response Tools
• Snort – Open-source intrusion detection and prevention system (IDS/IPS).
• Suricata – High-performance IDS/IPS for network security monitoring.
• OSSEC – Host-based intrusion detection system (HIDS).
6. Malware Analysis Tools
• Cuckoo Sandbox – Automated malware analysis.
• YARA – Identifies malware patterns in files.
• IDA Pro – Reverse engineering and disassembly tool.
7. Cloud Forensics Tools
• AWS CloudTrail – Monitors AWS cloud activity.
• Google Cloud Security Command Center – Detects threats in Google Cloud.
• Azure Sentinel – Cloud-native SIEM for security monitoring.

Kavya Gupta,
[Link]
508443105

You might also like