Introduction to Computer and
Network Forensics
Phạm Văn Hậu, Ph.D.
Nghi Hoàng Khoa, [Link].
Giới thiệu đề cương môn học
• Tên tiếng Anh của môn học: Digital Forensics
• Giảng viên: TS. Phạm Văn Hậu, ThS. Nghi Hoàng Khoa
• Khoa: Bộ môn An toàn Thông tin – Khoa MTT&TT
• Email: khoanh@[Link]
• Số tín chỉ: 3 (2 tín chỉ lý thuyết và 1 tín chỉ thực hành).
• Hình thức đánh giá:
• Quá trình / đồ án: 30%
• Thực hành: 30%
• Cuối kỳ: 40%
Mục tiêu môn học
• Mục tiêu môn học nhằm cung cấp các kỹ thuật pháp chứng số trên mạng và máy
tính, các cách thức thu thập dữ liệu số và phân tích các bằng chứng số.
• Môn học cung cấp cái nhìn tổng quan về các lĩnh vực của pháp chứng số như:
• Pháp chứng máy tính
• Pháp chứng mạng
• Pháp chứng thiết bị di động
• Pháp chứng cơ sở dữ liệu
• Pháp chứng mạng xã hội
• [Link]
• Topics of Interest
• DFRWS welcomes new perspectives that push the envelope of what is currently possible in digital forensics. Potential topics (alphabetical) to be addressed by submissions include any digital forensic related topic, for example (but not limited to):
• Anti-forensics and anti-anti-forensics
• Case studies and trend reports
• Cloud and virtualized environments
• Covert channels (e.g., TOR, VPN)
• Digital evidence sharing and exchange
• Digital evidence and the law
• Digital forensic preparedness / readiness
• Digital investigation case management
• Digital forensic tool validation
• Digital forensic triage / survey
• Event reconstruction methods and tools
• Forensics analysis and visualization of Big Data
• Implanted medical devices
• Machine learning and data mining for digital evidence extraction/query
• Malware and targeted attacks (analysis and attribution)
• Mobile and embedded device forensics
• Network and distributed system forensics
• Non-traditional forensic scenarios / contexts
• SCADA / industrial control systems
• Smart power grid forensics
• Smart building forensics
• Vehicle forensics (e.g., drones, cars)
• Virtual currency
4
Contents
• In this chapter, we will cover the following topics:
• Defining digital forensics and goals
• Defining cybercrime and cybercrime sources
• Computers in cybercrimes
• Digital forensics categories
• Forensic data analysis
• Digital forensic users
• Investigation types
• Forensics readiness
• Digital evidence types
• Electronic evidence location
• Chain of custody
• Examination process
5
Defining digital forensics
• Digital forensics is a branch of forensic science that uses scientific
understanding to acquire, evaluate, record, and present digital evidence
related to computer crime in court.
• The main goal is to figure out what happened, when it happened, and who
did it.
• The term “digital forensics” is a catch-all word for computer forensics or,
more recently, “cyber forensics.”
• These investigations include user laptops, computers, mobile phones,
network devices, Webcams, tablets, camcorders, IoT and smart home
devices, and storage media such as USB drives, CD/DVD, SD cards, and
tapes, among other digital systems and devices that can send, receive,
and store digital data.
6
Defining digital forensics
• Objectives
7
Defining digital forensics
• Need for computer forensics
8
Defining digital forensics
• Digital forensics is a relatively new profession in the cybersecurity domain that
is becoming increasingly important as the number of crimes and unlawful
actions in cyberspace increases.
• In comparison to conventional forensic science (blood tests, DNA profiling,
or fingerprinting)
• digital forensics is a young science;
• the fact that it interacts with rapid changes in the computing ecosystem around us and
reaches other domains (such as the judicial process, law enforcement, management
consulting, information technology, and the borderless scope of the internet),
• makes it a difficult field that requires constant development of its foes.
9
Digital forensics goals
• The basic goal of digital forensics is to investigate crimes committed with
computer systems that store and processes digital data and to extract forensic’
digital evidence to present in court.
• This is achieved in the following ways using digital forensics.
• Locating and preserving legal evidence on computer devices in a way that is
acceptable in a court of law.
• Follow court-approved technological methods to preserve and recover evidence.
• Assigning responsibility for an activity to the person who initiated it.
• Determining data breaches inside a company.
• Identifying the extent of any damage that may occur as a result of a data breach.
• Compiling the findings into a formal report that may be submitted in court.
• Providing expert evidence in court as a guide.
10
Defining cybercrime
• Any illegal activity carried out on a computer or via a computer network,
such as the internet, is referred to as cybercrime.
• Cybercrime is defined as any unlawful behavior done against or with the use of
a computer or computer network.
• The fundamental motivation for cybercrime is financial gain (for example:
spreading malware to steal access codes to bank accounts).
• However, different motives drive a significant portion of cybercrime, including
disrupting service (for example, DDoS attacks to shut down a target
organization’s services), stealing confidential data (for example, consumer
data and medical information), cyber espionage (corporate trade and military
secrets), or illegally exchanging copyrighted materials.
11
Defining cybercrime
12
Defining cybercrime
• Security Attack
• any action that compromises the security of information owned by an organization
13
Defining cybercrime
• Hacking phases
14
Sources of cybercrime
• Insider threats and external attacks are the two primary sources of
cybercrime.
15
Computers in cybercrimes
• Cybercrime may be classified into three types based on how a computer was
used to commit a crime.
• The computer is used as a weapon in the commission of a crime. Launching denial-
of-service (DoS) attacks or delivering ransomware are two examples.
• Crime has been committed against a computing device. Obtaining illegal access to a
target computer, for example.
• The computer is used to aid in the commission of a crime. Using a computer to
keep incriminating data or communicate with other criminals online, for example.
16
Digital forensics categories
17
Digital forensics investigation types
• According to who is in charge of commencing the inquiry, digital forensic
investigations may be divided into two categories:
• Public investigation
• Private sector investigations
• Criminal cases leveraging investigations are handled according to the legal
guidelines set out by the appropriate authorities.
• Law enforcement agencies participate in public investigations, which are
conducted under national or state legislation.
• The three main phases of these investigations are complaint, investigation, and
prosecution.
• Private investigations are commonly conducted by businesses to investigate
policy violations, legal problems, unfair dismissal, or the leak of secret
information as industrial espionage
18
Type of digital evidence
• User-created data
• Previous backups (including both cloud storage backups and offline backups such as
CDs/DVDs and tapes)
• Account details (username, picture, and password)
• E-mail messages and attachments (both online and client e-mails as Outlook)
• Audio and video files
• Address book and calendar
• Webcam recordings (digital photos and videos)
• Content files (for example, MS Office documents, IM conversations, bookmarks),
spreadsheets, databases, and any other digitally stored text
• Hidden and encrypted files (including zipped folders) created by the computer user
• Machine and network-created data
19
Type of digital evidence
• User-created data
• Machine and network-created data
• Configuration files and audit trails, including third-party service providers (for example, Internet service providers(ISPs)
often retain customers’ accounts and browser history logs)
• Logs on the computer under Windows OS contain the following logs:
• Logs for application, security, setup, system, forward events, apps, and services
• GPS tracking information history
• Temporary files
• Information from the browser (browser history, cookies, and download history)
• In addition to the IP addresses associated with a LAN network and the broadcast settings, devices have Internet protocol (IP)
and MAC addresses
• Instant messenger history and buddy list (Skype and WhatsApp) (from devices with GPS capability)
• Application and Windows history (for example, a recently opened file in MS Office)
• Under Windows computers, restore points
• E-mail header information
• Registry files in Windows OS
• Hidden and conventional system files
• Printer spooler files
• Virtual machines
• Surveillance video recordings
• Paging and hibernation files and memory dump files
20
Locations of electronic evidence
• Systems: Desktops, Laptops, Tablets, Servers, and RAIDs
• Network devices: Hubs, switches, modems, routers, and wireless access points
• Internet-enabled home automation and IoT devices: Air conditioners and Smart refrigerators
• DVRs and surveillance systems
• MP3 players
• GPS devices
• Smartphones
• PDA
• Game stations—Xbox, PlayStation
• Digital cameras
• Smart cards
• Pagers
• Digital voice recorders
21
Chain of custody
• A chain of custody is required for any digital forensic investigation approach.
• A proper chain of custody should detail how digital evidence was discovered,
gathered, transported, researched (analyzed), stored, and maintained by
the various parties involved in the investigation.
• The ultimate goal is to protect the integrity of digital evidence by tracking down
everyone who had contact with it from the moment it was collected until it was
presented in court.
• If we fail to understand who made contact with the evidence at any time
throughout the investigation, the chain of custody will be jeopardized, and the
obtained evidence will be rendered useless in a court of law.
• To maintain a proper chain of custody that is acceptable in court, an audit
record for all acquired digital evidence that tracks the movements and
possessors of digital evidence at all times must be preserved
22
Chain of custody
• If the chain of custody is valid, investigators will be capable of answering
questions in a court of law:
• What is the definition of digital evidence? (For example, describe the digital proof that
was obtained.)
• Where did you find the digital evidence? (For example, a computer, tablet, or mobile
phone; furthermore, the status of the computing device
• when the digital evidence is acquired—ON or OFF?)
• How did the digital evidence come to be? (For example, tools employed; you
should also indicate the procedures done to protect evidence integrity throughout the
acquisition phase.)
• What methods were used to transfer, preserve, and handle digital evidence?
• What methods were used to assess the digital evidence? (For example, any tools and
procedures used.)
• When, by whom, and for what purpose was digital evidence accessed?
• What was the role of digital evidence in the investigation?
23
Examination process
• Although there is no globally agreed method or procedure for performing
digital forensic investigations, various approaches are in place, with varying
stages or phases. However, all strategies divide the job into four primary
phases.
• Search and seizure
• Acquiring
• Analyze
• Information gathering and reporting
24
• 1. Computer Forensics is also known as.
• a. Digital Forensic Science
• b. Computer Crime Stream
• c. Computer Forensic Science
• d. Computer Forensics Investigations
25
• 2. Computer Forensics can also be used in civil proceedings.
• a. True
• b. False
• c. Can be Yes or No
• d. Cannot say
26
• 3. You are supposed to maintain three types of records in Forensics, which of
these is not a record?
• a. Chain of Custody
• b. Documenting crime scene
• c. Searching crime scene
• d. Documenting actions
27
• 4. Volatile data resides in.
• a. Registries
• b. Cache
• c. RAM
• d. All the above
28
• 5. Forensic investigators should satisfy ….
• a. Contribute to society and human being
• b. Avoid harm to others
• c. Honest and trustworthy
• d. All Of the Above
29
• 6. Digital evidence is used to establish a credible link between……….
• a. Attacker and victim and the crime scene
• b. Attacker And information
• c. Either A or B
• d. Both A and B
30
• 7. The evidence and proof that can be obtained from the electronic
source is called the…….
• a. Digital Evidence
• b. Explainable evidence
• c. Either A or B
• d. Both A and B
31
• 8. Digital Evidence must follow the requirement of the …
• a. Ideal Evidence Rule
• b. Best Evidence Rule
• c. Exchange Rule
• d. All of the mentioned
32
• 9. A false positive can be defined as …
• a. An alert that indicates nefarious activity on a system that, upon further
inspection, turns out to represent legitimate network traffic or behavior
• b. An alert that indicates nefarious activity on a system that, upon further
inspection, turns out to truly be nefarious activity
• c. The lack of an alert for nefarious activity
• d. All of the above
33
• 10. A valid definition of digital evidence is:
• a. None of the below
• b. Data stored or transmitted using a computer
• c. Digital data of probative value
• d. Any digital evidence on a computer
34