Unit-V
Cyber Laws & Computer Forensics
Cyber Laws and Forensics
Introduction CS regulations
Introduction CS regulations
cybersecurity regulation- wiki definition
• A cybersecurity regulation comprises directives that
safeguard information technology and computer systems
with the purpose of forcing companies and organizations to
protect their systems and information from cyberattacks
like viruses, worms, Trojan horses, phishing,
denial of service (DOS) attacks,
unauthorized access (stealing intellectual property or confid
ential information)
and control system attacks.[1] While cybersecurity
regulations aim to minimize cyber risks and enhance
protection, the uncertainty arising from frequent changes
or new regulations can significantly impact organizational
response strategies
International law -Roles
Roles of International law
• Establishing Norms
• Addressing Cyber Crime
• Regulating State Behavior
• Protecting Human Rights(civil & Political
rights, Privacy , Expression )-context of
cybersecurity
• Ensuring accountability-cyber tribunals
The roles of International law in CS include
Establishing norms: Budapest Convention
Budapest-Capital of Hungary
• The Budapest Convention on Cybercrime is the first
international treaty to address cybercrime
• aim to harmonize national laws, improve investigative
techniques, and increase international cooperation.
• It was created by the Council of Europe and is legally binding
for member nations, establishing a legal framework for
dealing with offenses like illegal access, fraud, and child
pornography.
• The convention also includes provisions for evidence
gathering and has been supplemented by protocols to
address issues like racism.. Etc
• India though not member in 2018 , reconsidering since
increase in cyber crime..
Establishing norms: Tallinn Manual
• Tallinn Manual by experts in International Law-guidelines– in the
CONTEXT OF CYBERSPACE.
• Tallinn Manual is a non-binding, academic study that identifies
existing international law and applies it to cyber warfare and
cyber conflict.
• Drafted by an international group of experts at the invitation of
the NATO Cooperative Cyber Defence Centre of Excellence
• It presents "black-letter rules" and commentary on topics like
sovereignty, state responsibility, and international humanitarian
law
• It aims to provide clarity on how established international law
governs cyber operations and has become an influential resource
for states and legal experts.
• Second edition 2.0 released in 2017
The space and private sector in cyber space
The space and private sector in cyber space
The private sectors role in cyber security involves implementing
cybersecurity measures to protect their systems and networks.
They may implement CS standards and guide lines , such as ISO 27001
OR NIST CYBERSECURITY FRAME WORK , to ensure they are following best
practices for cybersecurity.
May hire CS experts to assess their security posture and recommend
improvements .
Role: State and Private sector in CS
State’s role in CS :
• ENFORCE LAWS AND REGULATIONS
• ESTABLISH STANDARDS AND GUIDELINES TO
PROTECT SYSTEMS AND NETWORKS
• INVEST IN Cyber Security R&D
• SUPPORT ORG TO ENHANCE CYSEC
CAPABILITIES
Role: Private sector in CS
• IMPLEMENT ISO 27001 OR NIST(US) CYSEC
FRAMEWORK
• HIRE EXPERTS –EVALUATE POSITION AND
IMPROVE STATE
• SHARE THREAT INTELLIGENCE
THE INDIAN CYBERSPACE –NATIONAL CYBER
SECURITY POLICY 2013
• India’s cyberspace has grown rapidly due to:
– Expanding internet connectivity (Digital India initiative, BharatNet
project),
– Increasing mobile and broadband penetration,
– Massive use of online banking, e-commerce, and social media
platforms.
• This growth, however, has made India vulnerable to cyber
threats such as:
– Cyber terrorism,
– Data breaches,
– Phishing, ransomware, and malware attacks,
– Attacks on government and critical infrastructure networks
THE INDIAN CYBER SPACE
• Cyberspace¹ is a complex environment consisting of
interactions between people, software and services,
supported by worldwide distribution of information and
communication technology (ICT) devices and networks.
• Owing to the numerous benefits brought about by
technological advancements, the cyberspace today is a
common pool used by citizens, businesses, critical
information infrastructure, military and governments in a
manner that makes it difficult to draw clear boundaries
among these different groups. The cyberspace is expected to
be more complex in the foreseeable future, with many fold
increase in networks and devices connected to it.
• Many initiatives have enabled increased IT adoption in
the country through sectoral reforms and National
programmes which have led to creation of large scale IT
infrastructure with corporate / private participation.
• providing right kind of focus for creating secure
computing environment and adequate trust &
confidence in electronic transactions, software, services,
devices and networks, has become one of the compelling
priorities for the country. Such a focus enables creation
of a suitable cyber security eco-system in the country, in
tune with globally networked environment.
Need for National Cyber Security Policy
• Cyberspace is vulnerable to a wide variety of
incidents, whether intentional or accidental,
manmade or natural, and the data exchanged
in the cyberspace can be exploited for
nefarious purposes by both nation- states and
non-state actors.
• Cyber attacks that target the infrastructure or underlying economic well-being of
a nation state can effectively reduce available state resources and undermine
confidence in their supporting structures.
• A cyber related incident of national significance may take any form;
– an organized cyber attack,
– an uncontrolled exploit such as computer virus or worms or
– any malicious software code,
– a national disaster with significant cyber consequences or
– other related incidents capable of causing extensive damage to the information
infrastructure or key assets.
• Large-scale cyber incidents may overwhelm the government, public and private
sector resources and services by disrupting functioning of critical information
systems.
• Complications from disruptions of such a magnitude may threaten lives,
economy and national security.
• Rapid identification, information exchange, investigation and
coordinated response and remediation can mitigate the damage
caused by malicious cyberspace activity.
• Some of the examples of cyber threats to individuals, businesses
and government are identity theft, phishing, social engineering,
hactivism, cyber terrorism, compound threats targeting mobile
devices and smart phone, compromised digital certificates,
advanced persistent threats, denial of service, bot nets, supply
chain attacks, data leakage, etc.
• The protection of information infrastructure and preservation of
the confidentiality, integrity and availability of information in
cyberspace is the essence of a secure cyber space.
Hence.,
• There are various ongoing activities and programs of
the Government to address the cyber security
challenges which have significantly contributed to the
creation of a platform that is now capable of supporting
and sustaining the efforts in securing the cyber space.
• Due to the dynamic nature of cyberspace, there is now
a need for these actions to be unified under a National
Cyber Security Policy, with an integrated vision and a
set of sustained & coordinated strategies for
implementation.
• The cyber security policy is an evolving task and it caters to the
whole spectrum of ICT users and providers including home
users and small, medium and large enterprises and Government
& nonGovernment entities. It serves as an umbrella framework
for defining and guiding the actions related to security of
cyberspace.
• It also enables the individual sectors and organizations in
designing appropriate cyber security policies to suit their needs.
• The policy provides an overview of what it takes to effectively
protect information, information systems & networks and also
gives an insight into the Government's approach and strategy
for protection of cyber space in the country.
• It also outlines some pointers to enable
collaborative working of all key players in
public & private to safeguard country's
information and information systems.
• This policy, therefore, aims to create a cyber
security framework, which leads to specific
actions and programmes to enhance the
security posture of country's cyber space.
Title: National Cyber Security Policy, 2013
Released by:
Department of Electronics and Information Technology
(DeitY), Ministry of Communications and Information
Technology
Date of Release: 2nd July 2013
FULL DOCUMENT:
[Link]
• OBJECTIVE:: This policy, therefore, aims to create a
cyber security framework, which leads to specific
actions and programmes to enhance the security
posture of country’s cyber space.
• VISION : To build a secure and resilient cyberspace
for citizens, businesses, and the Government
• MISSION : To protect information and information
infrastructure in cyberspace, build capabilities to
prevent and respond to cyber threats, and minimize
damage from cyber incidents.
Key Goals
• To create a secure cyber ecosystem.
• To develop 500,000 skilled cybersecurity
professionals over five years.
• To encourage open standards and strengthen
regulatory frameworks.
• To enable collaboration between public and
private sectors.
• To enhance the protection of critical
infrastructure.
Strategies
• Designation of a National Nodal Agency to coordinate
all cyber security activities.
• Setting up Sectoral CERTs (Computer Emergency
Response Teams).
• Creation of national and sectoral level crisis
management plans.
• Promote R&D in cyber security.
• Develop public-private partnerships.
• Establish a legal framework and cybercrime laws.
• Encourage international cooperation.
Focus Areas
• Critical Information Infrastructure Protection
(CIIP)
• Security Threat Early Warning & Response
• Security Audits & Compliance
• Cybercrime prevention, detection, and
prosecution
• Education, awareness, and training
• Cybersecurity awareness programs
. Institutional Framework
• Strengthening of CERT-In (Indian Computer
Emergency Response Team)
• Promotion of National Critical Information
Infrastructure Protection Centre (NCIIPC)
• Involvement of law enforcement and
judiciary
Implementation
• Policy implementation through
– public-private partnerships,
– collaboration with academia,
– international cooperation, and
– capacity building.
Importance of Securing Indian Cyberspace
•Cyber threats can affect:
• National Security – cyber warfare, espionage.
• Economic Security – banking frauds, intellectual
property theft.
• Social Security – misinformation, online
radicalization.
Need for the National Cyber Security
Policy (2013)
•Rising Cyber Attacks
•Rapid digitalization increased India’s exposure to global cyber threats.
•Example: attacks on government websites, defacement, and DDoS
incidents.
•Protection of Critical Information Infrastructure (CII)
•Infrastructure such as power grids, banking systems, telecom,
and transport require high protection levels.
•Growing Dependence on ICT
•Businesses, governance, and citizens rely heavily on ICT →
any cyber disruption impacts productivity and national stability.
•Global Commitments
•India, as a member of global cyber organizations (like ITU),
needed to align with international best practices for cyber resilience.
Objectives of the National Cyber Security Policy (2013)
• The main goal of NCSP 2013 is:
“To build a secure and resilient cyberspace for citizens,
businesses, and the Government.”
• Specific Objectives:
• To create a secure computing environment and adequate trust
& confidence in electronic transactions.
• To strengthen regulatory frameworks for cybercrime
prevention and investigation.
• To promote research and development (R&D) in cyber security
technologies.
• To encourage indigenous security solutions.
• To create awareness and capacity building among all users —
government, corporate, and citizens.
Strategies under NCSP 2013
Multiple strategic areas addressed by the policy:
• 1. Creating a Secure Cyber Ecosystem
Promoting cooperation between government, private sector, and academia.
Establishing a National Nodal Agency for cyber security coordination (later realized as NCIIPC under NTRO).
• 2. Strengthening Regulatory Framework
Enhancing the IT Act, 2000 and its Amendments (2008) for addressing cybercrimes.
Encouraging organizations to comply with cyber security standards like ISO 27001.
• 3. Assurance Framework
Developing frameworks for auditing and certifying IT products and systems.
Promoting testing facilities to ensure trust in ICT products.
• 4. Encouraging Open Standards
Adoption of open standards to ensure interoperability and security.
• 5. Strengthening the Workforce
Building a pool of 500,000 trained cyber security professionals over five years.
Training law enforcement and judiciary in cybercrime handling.
• 6. R&D and Innovation
Promoting indigenous research and innovation in encryption, digital forensics, and cyber threat intelligence.
• 7. Public–Private Partnerships-Engaging private enterprises in national cyber defense initiatives.
• 8. Cybercrime Prevention
Establishment of cybercrime cells and forensic labs in all states.
Encouraging reporting mechanisms for cyber incidents.
• 9. Information Sharing and Early Warning
Setting up Cyber Crisis Management Plan (CCMP) and CERT-In as the nodal agency for incident response.
INSTITUTIONAL MECHANISMS
Agency/Organization Task
CERT-In (Indian Computer Emergency National nodal agency for responding to
Response Team) cyber incidents.
NCIIPC (National Critical Information Protects critical sectors like energy,
Infrastructure Protection Centre) banking, telecom.
Responsible for implementing policy
DeitY (Now MeitY) MINISTRY
initiatives.
Cyber Coordination Centre (CyCord)- Coordinates multiple agencies during
I4C national-level incidents.
State CERTs Handle regional-level cyber incidents.
Challenges in Implementation
Several practical challenges:
• Lack of coordination among multiple cyber agencies.
• Insufficient awareness among small and medium
enterprises (SMEs).
• Shortage of skilled cyber security manpower.
• Limited indigenous R&D and reliance on foreign
technology.
• Evolving nature of cyber threats — requiring
continuous policy updates.
Recent Developments (Beyond 2013)
• Although the NCSP 2013 laid the foundation,
subsequent steps have expanded its vision:
• National Cyber Security Strategy 2020 (draft) –
focuses on resilience, deterrence, and
collaboration.
• Launch of Cyber Surakshit Bharat and National
Cyber Coordination Centre (NCCC).
• Introduction of Data Protection Bill (2023) to
safeguard personal information.
CYBER FORENSICS
Cyberforensics
Provides digital evidence of a specific or general activity
Key role in investigation of cybercrime
“Evidence” in the case of “cyberoffenses”
Handling of the digital forensics evidence
Computer is either the subject or the object of cybercrimes or is used as a tool to commit a
cybercrime
Computer Forensics (or Digital Forensics)
Digital evidence is required
A fast growing profession as well as business
Computer security and computer forensics are different from each other.
The use of scientifically derived and proven methods toward the preservation, collection,
validation, identification, analysis, interpretation, documentation and presentation of digital
evidence derived from digital sources for the purpose of facilitating or furthering the
reconstruction of events found to be criminal, or helping to anticipate unauthorized actions
shown to be disruptive to planned operations.
Cyber Security by Nina Godbole/Sunit Belapure
Copyright 2011 Wiley India Pvt. Ltd. All rights reserved.
Digital Forensics Science
Application of analyses techniques to the reliable and unbiased collection, analysis,
interpretation and presentation of digital evidence.
The use of scientifically derived and proven methods toward the preservation,
collection, validation, identification, analysis, interpretation,
documentation and presentation of digital evidence derived from digital sources
for the purpose of facilitation or furthering the reconstruction of events found to be criminal, or
helping to anticipate unauthorized actions shown to be disruptive to planned operations.
Computer Forensics
Related to the use of analytical and investigative techniques to identify,
collect, examine and preserve evidence/information which is magnetically
stored or encoded.
The lawful and ethical seizure, acquisition, analysis, reporting and safeguarding of data and
metadata derived from digital devices which may contain information that is notable and
perhaps of evidentiary value to the trier of fact in managerial, administrative, civil and criminal
investigations. In other words, it is the collection of techniques and tools used to find evidence
in a computer.
Cyber Security by Nina Godbole/Sunit Belapure
Copyright 2011 Wiley India Pvt. Ltd. All rights reserved.
Need for Computer Forensics
Convergence of ICT advances and the pervasive use of computers worldwide
High technical capacity of modern computers/computing devices
New risks for computer users
Widespread use of computer forensics is the result of:
Increasing dependence of law enforcement on digital evidence
Ubiquity of computers that followed from the microcomputer revolution
Evidence
Everything that is used to determine or demonstrate the truth of an assertion.
Can be used in court to convict people who are believed to have committed crimes.
Handle carefully.
Cyberforensics and Digital Evidence
1. Computer forensics
2. Network forensics
Computer forensics experts know the techniques to retrieve the data from files listed in standard
directory search, hidden files, deleted files, deleted E-Mail and passwords, login IDs, encrypted
files, hidden partitions, etc. Typically, the evidences reside on computer systems, user created files,
user protected files, computer created files and on computer networks.
Cyber Security by Nina Godbole/Sunit Belapure
Copyright 2011 Wiley India Pvt. Ltd. All rights reserved.
The path taken by digital evidence can be conceptually depicted as shown in Fig. 2.
The Rules of Evidence
According to the “Indian Evidence Act 1872,” “Evidence” means and includes:
[Link] statements which the court permits or requires to be made before it by
witnesses, in relation to matters of fact under inquiry, are called oral
evidence.
[Link] documents that are produced for the inspection of the court are called
documentary evidence.
Cyber Security by Nina Godbole/Sunit Belapure
Copyright 2011 Wiley India Pvt. Ltd. All rights reserved.
Digital evidence consistently reveals that :
• Metadata is crucial --(timestamps, logs, headers)
• Logs reconstruct events -- (server logs, mail logs)
• Deleted data can be recovered --(file carving, imaging)
• Chain of custody is essential- process validate how many evidences gathered,
tracked and protected on the way to court of law
• Forensic imaging --prevents contamination of evidence
• Correlation of multiple sources --gives accurate reconstruction
The London Subway Bombings – Mobile Phone Evidence
Incident
Terrorist attacks in London (2005). Investigators recovered damaged mobile phones from blast sites.
Digital Evidence
•Recovered SIM data
•SMS logs
•Contact lists
•Photos and travel patterns
Outcome
Helped reconstruct:
•Suspects’ movements
•Communication networks
•Planning stages
Forensic Lesson
•Even severely damaged devices can yield data.
•Mobile forensics can rebuild entire timelines.
Silk Road Dark Web Marketplace – Server Misconfiguration
Incident
Silk Road was a large darknet marketplace.
Digital Evidence
FBI discovered:
•The hidden Tor server leaked its real IP address once due to a configuration error.
•Server logs were obtained from that IP.
Outcome
Identified Ross Ulbricht (“Dread Pirate Roberts”), leading to his arrest.
Forensic Lesson
•Cybercriminals make operational mistakes.
•Log files and network traces are essential evidence.
Various case studies –used Digital Evidence that led to the Forensic Conclusion
Outcome / Forensic
Case Study Description Digital Evidence Used
Conclusion
E-mail headers, Proved origin of e-mail and
1. E-mail Spoofing & Forged business e-mail sent to originating IP, identified sender;
Forgery cause defamation/complaint. mail server logs, established authenticity of
timestamp correlation. evidence.
Web server logs,
FTP logs, Confirmed unauthorized
2. Website Corporate website homepage
file modification login and traced attacker’s
Defacement altered by attacker.
timestamps, access IP access path.
traces.
Transaction logs,
Unauthorized credit card Linked fraudulent purchases
customer access logs,
3. Credit Card Fraud transactions on an e-commerce to specific systems and
device/browser history,
platform. misuse of card details.
IP traces.
Victim received E-mail trace routes, Identified stalker and
4. Cyber Stalking threatening/harassing emails and IP logs from ISPs, established communication
messages. login timestamps. chain for prosecution.
Traffic dumps, packet
Server overwhelmed with Showed attack originated
5. Denial of Service headers,
malicious traffic causing from compromised systems
(DoS) Attack server logs,
downtime. controlled by botnet.
botnet C2 traces.
Outcome / Forensic
Case Study Description Digital Evidence Used Conclusion
Hard disk images,
6. Intellectual Employee leaked
USB usage logs, Proved unauthorized copying
Property Theft / Data confidential company
e-mail attachments, and leaking of corporate data.
Leakage documents.
file-transfer timestamps.
Browser history,
malware artifacts Established presence of
Victim’s credentials stolen
7. Identity Theft (keyloggers), spyware and traced misuse of
and used on multiple sites.
login IPs, credentials.
password dump files.
Disk image,
Provided conclusive evidence
8. Child Pornography Illegal content found on browsing logs,
of possession/distribution of
Possession suspect’s computer. image metadata (EXIF),
illegal content.
recovered deleted files.
Installation logs,
Demonstrated deliberate
9. Software Piracy Company systems found registry entries,
installation and use of pirated
(Corporate) using unlicensed software. license keys,
software.
file access records.
Phishing email headers,
Users received fraudulent Identified phishing servers and
URLs,
10. Phishing Attack banking emails leading to linked victim credential theft to
server logs,
credential theft. the campaign.
browser cache data.
Number of contexts involved in actually identifying a piece of digital evidence
The path taken by digital evidence can be conceptually depicted shown in Fig. 2.
Cyber Security by Nina Godbole/Sunit Belapure
Copyright 2011 Wiley India Pvt. Ltd. All rights reserved.
Forensics Analysis of E-Mail
It helps establish the authenticity of an E-Mail when suspected.
E-Mails -- the most common means of communication.
The subject of forensics analysis for “digital evidence.”
E-Mail System
The hardware and software that controls the flow of E-Mail.
Components
1. E-Mail server
2. E-Mail gateway
RFC 2822
Internet Message Format
Several formats of valid E-Mail addresses: joshi@[Link], john@[[Link]], “Joshi
Ganesh”@[Link] or “Joshi Ganesh”@[[Link]]
Many E-Mail address validators on the Web fail to recognize some of those valid E-Mail addresses
RFC2822 standard applies only to the Internet Message Format
Some of the semantics of message contents contains no specification of the information in the
envelope
Digital Forensics Life Cycle
and Process
Cyber Security by Nina
Godbole/Sunit Belapure
Copyright 2011 Wiley India Pvt.
Ltd. All rights reserved.
E-Mail System
The hardware and software that controls the flow of E-Mail.
Components
1.E-Mail server
2.E-Mail gateway
Cyber Security by Nina Godbole/Sunit Belapure
Copyright 2011 Wiley India Pvt. Ltd. All rights reserved.
RFC2822
Internet Message Format
Several formats of valid E-Mail addresses: joshi@[Link], john@[[Link]], “Joshi
Ganesh”@[Link] or “Joshi Ganesh”@[[Link]]
Many E-Mail address validators on the Web fail to recognize some of those valid E-Mail
addresses
RFC2822 standard applies only to the Internet Message Format
Some of the semantics of message contents contains no specification of the information in
the envelope
Digital Forensics Life Cycle
As per FBI’s (Federal Bureau of Investigation) view, digital evidence is present in nearly every crime scene.
That is why law enforcement must know how to recognize, seize, transport and store
original digital evidence to preserve it for forensics examination.
Digital Forensics Life Cycle –phases
1. Preparation and identification
2. Collection and recording
3. Storing and transporting
4. Examination/investigation
5. Analysis interpretation and attribution
6. Reporting
7. testifying
LIVE FORENSICS Vs DEAD FORENSICS
Live forensics analyzes a running system to capture volatile data like active
processes and network connections,
Dead forensics powers down the system to analyze a static image of the
storage drive, preserving the data at rest but losing all volatile
information.
Live forensics is useful for active incidents where volatile
data is crucial but risks altering evidence,
Whereas
dead forensics provides a more stable, untouched copy for
later analysis.
LIVE FORENSICS DEAD FORENSICS
Analyzing a computer or device while it is still Powering down the system and creating
turned on and running. a forensic image of the storage drive for
Key advantage: Captures volatile data, such as offline analysis.
information in RAM like encryption keys, active Key advantage: Creates a stable,
processes, and network connections, which untouched copy of the data, reducing
would be lost if the system were shut down. It the risk of alteration during the imaging
is essential for real-time incident response and process. This makes the data more
cases where systems cannot be powered off. legally defensible.
Key disadvantage: The process of collecting Key disadvantage: It fails to capture
data can alter evidence, and it is difficult to volatile data from RAM that is lost when
ensure that data is not modified by the the power is cut.
system's normal operation. It may also face Best for: Analyzing a suspect's device
challenges with advanced encryption. after the incident has concluded and
Best for: Active intrusions, incident response, volatile data is not a priority, or when a
and when critical systems cannot be taken complete, non-altered copy of the hard
offline. drive is needed
•DIFFERS
CHOOSING THE RIGHT METHOD
WITH SITUATIONS:
•In a live incident, an investigator might start
with live forensics to gather crucial, real-time
information, then use dead forensics to perform
a deeper analysis of the storage drive.
•If a system cannot be taken offline without
major disruption, live forensics is often the
only option.
•If the system is already offline or a thorough,
stable copy is the priority, dead forensics is
the preferred method
Digital forensics :
Digital forensics evidence consists of exhibits.
The exhibits are introduced as evidence by either
side.
Testimony is presented to establish the process.
The party must show the evidence.
Digital forensics evidence can be challenged.
Forensics experts formulate a cost proposal.
Proposed timeline of activities, lists of anticipated
deliverables and a plan for production and turnover
of evidence.
Submission of a preliminary risk analysis for the
forensics service being proposed.
Cyber Security by Nina Godbole/Sunit Belapure
Copyright 2011 Wiley India Pvt. Ltd. All rights reserved.
Digital Forensics Process-Involves the following activities:
1. Prepare : case briefings, engagement terms, interrogatories, spoliation
prevention, disclosure and discovery planning, discovery requests
2. Record : Drive Imaging,indexing profiling, search plans,cost estimates, risk
analysis
3. Investigate: Triage images,daTa recovery, key word searches, hidden data review,
communicate , iterate
4. Report: Oral [Link], relevant document production , search statistic reports,
chain of custody reporting, case log reporting
5. Testify: testimony preparation, presentation preparation, testimony
Cyber Security by Nina Godbole/Sunit Belapure
Copyright 2011 Wiley India Pvt. Ltd. All rights reserved.
DIGITAL EVIDENCE DOCUMENTATION
Collecting and Recording Digital Evidence
Sources
1. Computers
2. Cell phones
3. Digital cameras
4. Hard drives
5. CD-ROM
6. USB memory devices
7. Digital thermometers
8. Black boxes inside automobiles
9. RFID tags and webpages
Storing and Transporting Digital Evidence
1. Image computer media using a write-blocking tool to ensure that no data is added to the suspect
device
2. Establish and maintain the chain of custody
3. Document everything that has been done
4. Only use tools and methods that have been tested and evaluated to validate their accuracy and
reliability.
5. Care must be taken in transportation to prevent spoliation (in a hot car, digital media tends to lose
bits).
6. Care must be taken to preserve chain of custody and assure that a witness can testify accurately
about what took place.
Cyber Security by Nina Godbole/Sunit Belapure
Copyright 2011 Wiley India Pvt. Ltd. All rights reserved.
Examining/Investigating Digital Evidence
Special care must be taken to ensure that the forensics specialist has the legal authority to
seize, copy and examine the data.
Sometimes authority stems from a search warrant.
As a general rule, one should not examine digital information unless one has the legal
authority to do so.
Amateur forensics examiners should keep this in mind before starting any unauthorized
investigation.
Analysis, Interpretation and Attribution
Analysis, interpretation and attribution of evidence are the most difficult aspects encountered
by most forensics analysts.
Analysis, interpretation and attribution of digital forensics evidence can be reconciled with
non-digital evidence.
Digital forensics evidence can be externally stipulated.
Open-source tools are available to conduct analysis of open ports, mapped drives on the live
computer system.
Holding unpowered RAM below −60°C will help preserve the residual data by an order of
magnitude, thus improving the chances of successful recovery. However, it is impractical to do
this during a field examination.
Cyber Security by Nina Godbole/Sunit Belapure
Copyright 2011 Wiley India Pvt. Ltd. All rights reserved.
Reporting
A report is generated.
The report may be in a written form or an oral testimony (or combination of the two).
Evidence, analysis, interpretation and attribution to be presented in the form of expert
reports, depositions and testimony.
Presentation of the report (a complex and tricky process)
Broad-Level Elements of the Report
1. Identity of the reporting agency
2. Case identifier or submission number
3. Case investigator
4. Identity of the submitter
5. Date of receipt
6. Date of report
7. Serial number, make and model
8. Identity and signature of the examiner
9. Steps taken during examination
10. Results/conclusions
Cyber Security by Nina Godbole/Sunit Belapure
Copyright 2011 Wiley India Pvt. Ltd. All rights reserved.
Principles to maintain the integrity of digital evidence
1. Principle 1: No action taken by law enforcement agencies or their agents should change
data held on a computer or storage media, which may subsequently be relied upon in court.
2. Principle 2: In exceptional circumstances, where a person finds it necessary to access
original data held on a computer or on storage media that person must be competent to do so
and be able to give evidence explaining the relevance and the implications of his/her actions.
3. Principle 3: An audit trail or other record of all processes applied to computer-based
electronic evidence should be created and preserved. An independent third party should be
able to examine those processes and achieve the same result.
4. Principle 4: The person in-charge of the investigation (the case officer) has overall
responsibility for ensuring that the law and these principles are adhered to.
Cyber Security by Nina Godbole/Sunit Belapure
Copyright 2011 Wiley India Pvt. Ltd. All rights reserved.
Chain of Custody Concept
It is the central concept in cyberforensics/digital forensics investigation.
It is the process of validating how many kinds of evidences have been gathered,
tracked and protected on the way to a court of law.
It is essential to get in the habit of protecting all evidences equally so that they
will hold up in court.
The purpose is that the proponent of a piece of evidence must demonstrate that
it is what it purports to be.
The chain of custody is a chronological written record of those individuals who
have had custody of the evidence from its initial acquisition until its final
disposition.
A chain of custody begins when an item of relevant evidence is collected, and
the chain is maintained until the evidence is disposed off.
The chain of custody assumes continuous accountability.
Cyber Security by Nina Godbole/Sunit Belapure
Copyright 2011 Wiley India Pvt. Ltd. All rights reserved.
Chain of Custody Concept
Network Forensics
This discipline is included within the computer forensics science.
The goal is to provide the methodology and tools required to collect and analyze (wireless)
network traffic.
It involves capturing all data moving over Wi-Fi network and analyzing network events.
The security analyst must follow the same general principles that apply to computer
forensics.
Cyber Security by Nina Godbole/Sunit Belapure
Copyright 2011 Wiley India Pvt. Ltd. All rights reserved.
Typical Elements in a Forensics Investigation Engagement Contract
1. Authorization
2. Confidentiality
3. Payment
4. Consent and acknowledgment
5. Limitation of liability
Steganography
Hiding messages in image data (used by criminals and by noncriminals).
The threat raised by steganography is very real.
Its use is not easy to detect or intercept, as the information does not need to be broadcast
across the Internet.
The hidden message can reside unsuspectingly on a website, for example, and can be
viewed from around the world.
Steganalysis is of increasing importance to cybersecurity.
Rootkits
A “rootkit” is a set of tools used after cracking a computer operating system that hides
logins, processes, password, etc., which would carefully hide any trace that those
commands normally display.
The mechanisms and techniques whereby malware including viruses, Spyware and Trojans
attempt to hide their presence from Spyware blockers, antivirus and system management
utilities.
Cyber Security by Nina Godbole/Sunit Belapure
Copyright 2011 Wiley India Pvt. Ltd. All rights reserved.
Rootkits can be classified as – persistent rootkits, memory-based rootkits, user-mode rootkits
and kernel-mode rootkits.
Rootkits are installed after an attacker has exploited a system vulnerability and gained root
access.
Rootkits by themselves do not give an attacker root access; they only work after a system
compromise. Rootkits consist of tools that generally have three functions: (a) maintain root
access to the system, (b) hide the presence of the attacker and (c) attack (or accelerate
attacks) against other systems.
o Binary rootkits take administrative utilities and modify them to hide specific connections,
processes and activities of specific users.
o Binary rootkits can be defeated through the use of file integrity scanners.
o Binary rootkits can also be detected by system integrity tools.
Information Hiding
1. Three common approaches of hiding information in digital images
2. Least significant bit insertion
3. Masking and filtering
4. Algorithms and transformations
Cyber Security by Nina Godbole/Sunit Belapure
Copyright 2011 Wiley India Pvt. Ltd. All rights reserved.
A Partial Volume Image in Cyber Forensics refers to the forensic capture of only a portion of a storage
device, rather than the entire disk or volume. This may include only:
• Selected files or folders
• Specific partitions or logical drives
• System areas (e.g., MFT-Master file Tables, registry hives, or logs)
This approach is typically used when time, storage, or operational constraints make full disk imaging
impractical.
Why Is Partial Volume Imaging Used?
Reason Explanation
Full imaging can take hours—partial imaging targets only relevant
Time Constraints
evidence.
In enterprise systems with terabytes of data, it's inefficient to
Large Storage Volumes
copy everything.
Full physical access may not be available—so partial logical
Cloud or Remote Systems
acquisitions are made.
Sometimes investigators are legally allowed to collect only specific
Legal/Privacy Restrictions
content.
For live systems, minimal disruption is preferred—so only critical
Volatile or Active Environments
data is collected.
Examples of Partial Volume Imaging in Practice
[Link] Incident Response:
Only user-specific directories, browser history, or chat logs are imaged.
[Link] Fraud Investigation:
Only the mail storage folders (e.g., .pst files or mail servers) are imaged.
[Link] Forensics:
Only the Program Files, AppData, and memory dumps are collected.
[Link] Forensics:
When imaging cloud drives (e.g., Google Drive, OneDrive), only synced folders
are acquired.
Tools That Support Partial Imaging
Tool Features
FTK Imager Allows selection of individual
files/folders to image.
Autopsy/SleuthKit Supports targeted extraction from
logical drives.
X-Ways Forensics Advanced partial volume control
and filtering.
Magnet AXIOM Facilitates targeted imaging based
on case type.
Key Steps of Crime Scene Management
Digital Forensics Life Cycle
As per FBI’s (Federal Bureau of Investigation) view, digital evidence is present in nearly every
crime scene. That is why law enforcement must know how to recognize, seize, transport and store
original digital evidence to preserve it for forensics examination.
Digital Forensics Process
Digital forensics evidence consists of exhibits.
The exhibits are introduced as evidence by either side.
Testimony is presented to establish the process.
The party must show the evidence.
Digital forensics evidence can be challenged.
Forensics experts formulate a cost proposal.
Proposed timeline of activities, lists of anticipated deliverables and a plan for production and
turnover of evidence.
Submission of a preliminary risk analysis for the forensics service being proposed.
Cyber Security by Nina Godbole/Sunit Belapure
Copyright 2011 Wiley India Pvt. Ltd. All rights reserved.
Need of Cyber Forensics
needed , Because of the rapid growth of cyber crimes: data theft,
hacking, malware, identity fraud.
•Helps in legal proceedings: by providing admissible digital
evidence.
•Enables organizations to detect, respond, and recover from
incidents effectively.
•Supports root-cause analysis and helps strengthen security
posture
•Example: A corporate network breach where forensic analysis
uncovered how the attacker entered and what data was
exfiltrated.
Phases in Computer Forensics/Digital Forensics
1. Preparation and identification
2. Collection and recording
3. Storing and transporting
4. Examination/investigation
5. Analysis, interpretation and attribution
6. Reporting
7. Testifying
Cyber Security by Nina Godbole/Sunit Belapure
Copyright 2011 Wiley India Pvt. Ltd. All rights reserved.
Cyber Evidence
•What is digital/cyber evidence: information of probative value stored or transmitted in
digital form.
•Types: computer files, logs, network captures, email, mobile device data, cloud data.
•Characteristics: integrity, authenticity, chain of custody.
•How cyber evidence differs from traditional evidence: volume, volatility, distributed nature,
encryption, anti-forensic tactics.
•Example: Log entries showing unauthorized access, forensic image of a hard drive.
•Diagram suggestion: “Chain of custody” flow.
Cyberforensics steps
Collecting and Recording Digital Evidence-
Sources
Computers
Cell phones
Digital cameras
Hard drives
CD-ROM
USB memory devices
Digital thermometers
Black boxes inside automobiles
RFID tags and webpages
Cyber Security by Nina Godbole/Sunit Belapure
Copyright 2011 Wiley India Pvt. Ltd. All rights reserved.
Documentation and Management of Crime Scene
•Importance of proper documentation: ensures admissibility,
reproducibility, audit trail.
•Crime scene management: securing the scene, preventing
contamination, logging everything (who, when, what).
•Steps: initial response, scene survey, evidence collection, scene closure.
•For digital crime scene: securing devices, making forensic images,
preserving volatile data (RAM, network sessions).
•Best practices: photographs, sketches, annotated logs, witness
statements.
•Example: Forensics team arriving at corporate server room after breach;
documenting each device, videoing the scene.
Image Capturing and its Importance
•What is image capturing in digital forensics: creating bit-by-bit copy (forensic
image) of storage devices (hard drives, SSDs, USBs), memory dumps, network
captures.
•Importance: preserves original evidence in unaltered form; allows analysis
while keeping original intact.
•Types: logical image vs physical image (bit-stream).
•Why record everything: timestamps, metadata, device states, logs.
•Example: Capturing RAM of a live system before shutdown to preserve volatile
evidence such as active network connections or encryption keys.
•“Forensic image vs original device”
Image acquisition phase
Internet Crime Investigations
•What is Internet crime: any crime where the Internet is a significant element –
e.g., fraud, identity theft, phishing, malware-distribution, child exploitation,
cyber-espionage.
•Forensic scope: attacker devices, network logs, email/message records, browser
history, cloud storage, mobile devices.
•Challenges: jurisdiction, cross-border evidence, encryption, anonymisation
services.
•Example: Phishing campaign targeting bank customers; forensic team tracks
phishing domain, email headers, compromised server, stolen credentials.
Internet Forensics
•Define Internet forensics: subset of digital forensics focused on the Internet – including
network forensics (traffic capture and analysis), web forensics (web server, browsers),
email forensics, social media forensics.
•Key elements: packet capture (PCAP), netflow, DNS logs, proxy logs, SSL/TLS artefacts,
web-browser cache, cookies, browser history.
•Tools & techniques: Wireshark, tcpdump, Bro/Zeek, log-analysis tools.
•Example: Investigation of data exfiltration via SSL tunnel; network forensic capture
reveals unusual outbound connection
Steps for Investigating Internet Crime
•Step 1: Initial Response & Identification – secure systems, isolate
networks, preserve volatile data.
•Step 2: Planning and Scoping – define investigation scope, resources,
legal/intel issues.
•Step 3: Collection – capture disk images, network traffic, logs,
browser data, emails.
•Step 4: Preservation – maintain chain of custody, use write-blockers,
hash data.
•Step 5: Analysis – examine data, correlate logs, reconstruct
timelines, use forensic tools.
•Step 6: Presentation & Reporting – prepare forensic report, present
evidence in court if needed.
•Step 7: Review & Lessons Learned – identify root causes,
recommend controls, update policies.
•Example: Walk through of a hypothetical case of data exfiltration via web application,
showing timeline from detection→response→investigation→report.
Investigating Internet Crime
Email Crime Investigations
•What constitutes email crime: phishing, spoofing, spamming, business email compromise
(BEC), malware attachments.
•Forensic tasks: analyse email headers (sender, path, IPs), content, attachments, links;
identify origin; check server logs (SMTP, webmail), spam filters, DNS records (SPF, DKIM,
DMARC).
•Challenges: forged headers, anonymisers, encrypted attachments, deleted emails, cloud-
mail.
•Example: A BEC case where attacker impersonates CFO and requests funds transfer;
forensic analysis finds spoofed email, origin IP, compromised account.
•Diagram suggestion: “Email header analysis flow” (mail server → header fields → forensic
extraction).
Partial Volume Image
•Define partial volume image: capturing a specific portion of a
storage device (e.g., a partition, a volume) rather than the entire
disk.
•When it may be used: when time/resource constraints or only
one volume is suspect.
•Pros and cons: faster, smaller size vs risk of missing relevant data
outside the volume.
•Best practice: document the decision and ensure the scope is
appropriate.
•Example: A USB drive with multiple partitions; only the user data
partition is imaged for investigation.
•Diagram suggestion: “Volume partitions of a disk” showing full
disk vs partial volume capture.
Web Attack Investigations
•Define web attacks: attacks targeting web applications, servers or users via web technologies
(e.g., SQL injection, cross-site scripting, defacement, malware delivered via websites).
•Role of forensics: identify attack vector, compromised web server, malicious scripts, injection
points, logs (web server, application, database), map attacker path.
•Typical steps: collect web server logs, access logs, database logs; image the server if needed;
examine web application code; identify malicious payload.
•Example: A SQL injection attack on an e-commerce site; forensic analysis reveals injected SQL
commands, exfiltrated customer data.
•Diagram suggestion: “Web application attack flow” (user→webserver→database) annotated
with attack injection
Denial of Service Investigations
•Define Denial of Service (DoS) / Distributed Denial of Service
(DDoS): flooding a target with traffic to exhaust resources and make
service unavailable.
•Forensic challenge: high volume, distributed sources, ephemeral
connections.
•Role of forensics: collect network logs, firewall records, ISP logs,
packet captures; identify attack sources; determine type of attack
(UDP flood, SYN flood, application layer).
•Example: DDoS against a retail website during sale period; forensic
team uses netflow logs, identifies botnet sources.
•Diagram suggestion: “DDoS attack diagram” showing many
bots→target server.
Storing and Transporting Digital Evidence
1. Image computer media using a write-blocking tool to ensure that no data is added to the suspect
device
2. Establish and maintain the chain of custody
3. Document everything that has been done
4. Only use tools and methods that have been tested and evaluated to validate their accuracy and
reliability.
5. Care must be taken in transportation to prevent spoliation (in a hot car, digital media tends to lose
bits).
6. Care must be taken to preserve chain of custody and assure that a witness can testify accurately
about what took place.
Cyber Security by Nina Godbole/Sunit Belapure
Copyright 2011 Wiley India Pvt. Ltd. All rights reserved.
Examining/Investigating Digital Evidence
Special care must be taken to ensure that the forensics specialist has the legal authority to
seize, copy and examine the data.
Sometimes authority stems from a search warrant.
As a general rule, one should not examine digital information unless one has the legal authority
to do so.
Amateur forensics examiners should keep this in mind before starting any unauthorized
investigation.
Analysis, Interpretation and Attribution
Analysis, interpretation and attribution of evidence are the most difficult aspects encountered
by most forensics analysts.
Analysis, interpretation and attribution of digital forensics evidence can be reconciled with non-
digital evidence.
Digital forensics evidence can be externally stipulated.
Open-source tools are available to conduct analysis of open ports, mapped drives on the live
computer system.
Holding unpowered RAM below −60°C will help preserve the residual data by an order of
magnitude, thus improving the chances of successful recovery. However, it is impractical to do
this during a field examination.
Cyber Security by Nina Godbole/Sunit Belapure
Copyright 2011 Wiley India Pvt. Ltd. All rights reserved.
Reporting
A report is generated.
The report may be in a written form or an oral testimony (or combination of the two).
Evidence, analysis, interpretation and attribution to be presented in the form of expert reports,
depositions and testimony.
Presentation of the report (a complex and tricky process)
Broad-Level Elements of the Report
1. Identity of the reporting agency
2. Case identifier or submission number
3. Case investigator
4. Identity of the submitter
5. Date of receipt
6. Date of report
7. Serial number, make and model
8. Identity and signature of the examiner
9. Steps taken during examination
10. Results/conclusions
Cyber Security by Nina Godbole/Sunit Belapure
Copyright 2011 Wiley India Pvt. Ltd. All rights reserved.
Principles to maintain the integrity of digital evidence
1. Principle 1: No action taken by law enforcement agencies or their agents should change data
held on a computer or storage media, which may subsequently be relied upon in court.
2. Principle 2: In exceptional circumstances, where a person finds it necessary to access original
data held on a computer or on storage media that person must be competent to do so and be
able to give evidence explaining the relevance and the implications of his/her actions.
3. Principle 3: An audit trail or other record of all processes applied to computer-based
electronic evidence should be created and preserved. An independent third party should be
able to examine those processes and achieve the same result.
4. Principle 4: The person in-charge of the investigation (the case officer) has overall
responsibility for ensuring that the law and these principles are adhered to.
Cyber Security by Nina Godbole/Sunit Belapure
Copyright 2011 Wiley India Pvt. Ltd. All rights reserved.
Chain of Custody Concept
It is the central concept in cyberforensics/digital forensics investigation.
It is the process of validating how many kinds of evidences have been gathered, tracked and
protected on the way to a court of law.
It is essential to get in the habit of protecting all evidences equally so that they will hold up in
court.
The purpose is that the proponent of a piece of evidence must demonstrate that it is what it
purports to be.
The chain of custody is a chronological written record of those individuals who have had
custody of the evidence from its initial acquisition until its final disposition.
A chain of custody begins when an item of relevant evidence is collected, and the chain is
maintained until the evidence is disposed off.
The chain of custody assumes continuous accountability.
Network Forensics
This discipline is included within the computer forensics science.
The goal is to provide the methodology and tools required to collect and analyze (wireless)
network traffic.
It involves capturing all data moving over Wi-Fi network and analyzing network events.
The security analyst must follow the same general principles that apply to computer forensics.
Cyber Security by Nina Godbole/Sunit Belapure
Copyright 2011 Wiley India Pvt. Ltd. All rights reserved.
Typical Elements in a Forensics Investigation Engagement Contract
1. Authorization
2. Confidentiality
3. Payment
4. Consent and acknowledgment
5. Limitation of liability
Steganography
Hiding messages in image data (used by criminals and by noncriminals).
The threat raised by steganography is very real.
Its use is not easy to detect or intercept, as the information does not need to be broadcast
across the Internet.
The hidden message can reside unsuspectingly on a website, for example, and can be viewed
from around the world.
Steganalysis is of increasing importance to cybersecurity.
Rootkits
A “rootkit” is a set of tools used after cracking a computer operating system that hides logins,
processes, password, etc., which would carefully hide any trace that those commands
normally display.
The mechanisms and techniques whereby malware including viruses, Spyware and Trojans
attempt to hide their presence from Spyware blockers, antivirus and system management
utilities.
Cyber Security by Nina Godbole/Sunit Belapure
Copyright 2011 Wiley India Pvt. Ltd. All rights reserved.
Rootkits can be classified as – persistent rootkits, memory-based rootkits, user-mode rootkits
and kernel-mode rootkits.
Rootkits are installed after an attacker has exploited a system vulnerability and gained root
access.
Rootkits by themselves do not give an attacker root access; they only work after a system
compromise. Rootkits consist of tools that generally have three functions: (a) maintain root
access to the system, (b) hide the presence of the attacker and (c) attack (or accelerate
attacks) against other systems.
o Binary rootkits take administrative utilities and modify them to hide specific connections,
processes and activities of specific users.
o Binary rootkits can be defeated through the use of file integrity scanners.
o Binary rootkits can also be detected by system integrity tools.
Information Hiding
1. Three common approaches of hiding information in digital images
2. Least significant bit insertion
3. Masking and filtering
4. Algorithms and transformations
Cyber Security by Nina Godbole/Sunit Belapure
Copyright 2011 Wiley India Pvt. Ltd. All rights reserved.
WEB-ATTACK INVESTIGATION
Detailed Presentation
WEB-ATTACK-INVESTIGATION
It is the systematic process of identifying, analyzing, and
reconstructing how an attacker exploited a web application, web
server, or online service, with the goal of:
• Determining entry point and attack vector
• Assessing impact and compromised assets
• Preserving and analyzing digital evidence
• Containing the attack to prevent further damage
• Supporting legal action and reporting
COMMON WEB-ATTACK TYPES:
Injection-based, client-side attacks,authentication and session
attacks, server side attacks,network or availability attacks
UNIT-5\cyber-forensics-Case studies -web attack investigation-d
etailed [Link]
Introduction
• • Investigation focuses on identifying
unauthorized web compromise
• • Involves analysis, evidence preservation, and
reconstruction
• • Supports containment, recovery, and legal
reporting
• • Ensures integrity and admissibility of
collected digital evidence
Types of Web Attacks
• • SQL Injection
• • Cross-Site Scripting (XSS)
• • Session Hijacking
• • Directory Traversal
• • File Upload Exploitation
• • Web Shell Deployment
Initial Response & Preservation
• • Do not shut down the affected system
• • Begin chain of custody documentation
• • Capture volatile data (RAM, connections,
processes)
• • Isolate without powering off or altering
evidence
Sources of Evidence
• • Web server access and error logs
• • Application logs and authentication records
• • Database audit trails
• • Uploaded or modified web files
• • Network captures and traffic patterns
• • System artifacts and timestamps
Investigation Process
• 1. Identification – confirm incident and scope
• 2. Collection – gather logs, images, and
memory
• 3. Examination – filter and extract relevant
data
• 4. Analysis – reconstruct sequence of events
• 5. Reporting – document findings and
evidence
Analysis Techniques
• • Log correlation and anomaly detection
• • Parameter inspection in HTTP requests
• • File system and timestamp analysis
• • Detection of web shells and malicious
uploads
• • Database query reconstruction
• • Timeline building using event sequencing
Challenges
• • Log tampering or deletion
• • Encrypted HTTPS traffic inspection
• • Shared hosting limitations
• • Cloud-based access constraints
• • Real-time modification of dynamic content
Preventive Controls
• • Input validation and sanitization
• • Parameterized database queries
• • Strong authentication and session security
• • Web Application Firewall (WAF)
• • Regular patching and configuration reviews
• • Least privilege principle
Case Study Example
• • University portal defaced and redirected
users
• • SQL injection exploited login page
• • Web shell uploaded through file upload flaw
• • Homepage altered using unauthorized
access
• • Root cause: lack of input validation and
upload restrictions
Investigation Checklist
• ✔ Preserve system without shutdown
• ✔ Record all actions with timestamps
• ✔ Collect logs, memory, and file snapshots
• ✔ Identify attack vector and payload
• ✔ Reconstruct timeline accurately
• ✔ Assess scope and affected components
• ✔ Report findings with evidence references
WEB-ATTACK-INVESTIGATION –TOOLS USED
Email crime investigation
[Link]
b33_email_en.pdf
WEB ATTACKS INVESTIGATION:
UNIT-5\Web_Attack_Investigation.pdf
Email crime investigation : example ppt-US cybercrime -
UNIT-5\EMAIL-CRIME -INVESTIGATION US-CRIME-GOV
Email-crime –investigation
UNIT-5\Email_Crime_Investigation.pdf
Internet crime investigation
UNIT-5\Internet_Crime_Investigation_Forensics_CaseStudy.p
df
Dos attack investigation
UNIT-5\Denial_of_Service_Investigation.pdf
Web-Attack Internet Crime DoS Email Crime
Feature / Focus
Investigation Investigation Investigation Investigation
Any crime using
Web apps & Service Email systems &
Primary Target internet
servers availability communication
medium
Find exploit Identify traffic
Reconstruct Verify sender
path & source &
Main Goal offender actions authenticity &
compromised restore
& identity trace message
components availability
Multi-platform
HTTP logs, DB Email headers,
logs, Network traffic,
Key Evidence traces, web server logs,
cloud/mobile firewall/IDS logs
artifacts attachments
data
Fraud,
Data theft / Financial gain,
Typical Attacker deception,
unauthorized harassment, Disruption
Objective malware
access exploitation
delivery
Complexity Application- Broad + multi- Communication
Network-layer
Level layer jurisdiction -layer
Dynamic Anonymous or
Primary Attribution & Spoofed traffic
content & log spoofed email
Challenge legal scope & botnets
tampering sources
Relevance of the OSI 7 Layer Model to Computer Forensics
The steps taken by attackers who hack networks are:
Step 1: Foot Printing
Step 2: Scanning and Probing
Step 3: Gaining Access
Step 4: Privilege
Step 5: Exploit
Step 6: Retracting
Step 7: Installing Backdoors
Forensics and Social Networking Sites: The Security/Privacy Threats
Sites: Orkut, Facebook, MySpace, Bebo, “Bigadda”, etc.
It enables people to reach out to their old/long lost friends and classmates, relatives, etc.
Social networking sites help connect like-minded people, people with the same professions or
collaboration and discussion of ideas.
Social networking, thus, makes people part of a worldwide community and so the sites are
getting popular. The usage of social network sites has increased rapidly in recent years.
Kids, teenagers are the ones who are known to be making the maximum use of social
networking sites. LinkedIn: Professional networking site
Security threats emerging through careless use of social networking sites.
Cyber Security by Nina Godbole/Sunit Belapure
Copyright 2011 Wiley India Pvt. Ltd. All rights reserved.
Forensics and Social Networking Sites: The Security/Privacy Threats
Sites: Orkut, Facebook, MySpace, Bebo, “Bigadda”, etc.
It enables people to reach out to their old/long lost friends and classmates, relatives, etc.
Social networking sites help connect like-minded people, people with the same professions or
collaboration and discussion of ideas.
Social networking, thus, makes people part of a worldwide community and so the sites are
getting popular. The usage of social network sites has increased rapidly in recent years.
Kids, teenagers are the ones who are known to be making the maximum use of social
networking sites. LinkedIn: Professional networking site
Security threats emerging through careless use of social networking sites.
Security issues that are associated with social networking sites:
1. Corporate espionage.
2. Cross-site scripting.
3. Viruses and worms.
4. Social networking site aggregators.
5. Spear Phishing and social networking specific Phishing.
6. Infiltration of networks leading to data leakage.
7. ID theft
Cyber Security by Nina Godbole/Sunit Belapure
Copyright 2011 Wiley India Pvt. Ltd. All rights reserved.
The Regulatory Perspective for Forensics at the International Level
Internationally, there are a few laws and regulations that indicate the need for digital
investigations: Sarbanes Oxley (the SOX), California SB 1386, Gramm Leach Bliley Act (the GLBA)
and Health Insurance Portability and Accountability Act (HIPAA) of 1996.
Features of GLBA
1. Financial Privacy Rule (collection and dissemination of customers’ information)
2. Safeguards Rule (governs the processes and controls in an organization to protect customers’
financial data)
The Safeguards Rule of GLB calls for financial institutions to:
3. Ensure the security and confidentiality of customer information.
2. Protect against any anticipated threats or hazards to the security or integrity of such
information.
3. Protect against unauthorized access to or use of such information that could result in
substantial harm or inconvenience to any customer.
HIPAA (Health Insurance Portability and Accountability Act of 1996) has the primary goal for
healthcare providers to improve the privacy and security of their clients’ medical information.
Cyber Security by Nina Godbole/Sunit Belapure
Copyright 2011 Wiley India Pvt. Ltd. All rights reserved.
Computer Forensics Expertise Status in India
There is a rise in cybercrimes and in India, computer forensics is a much-needed expertise. At
present, there seems to be a shortage of these skills.
Two-fold problem in India
1. Lack of availability of cyberforensics expertise as well as lack of awareness about
cyberforensics/digital forensics/computer forensics
2. Involvement of cyberforensics in the day-to-day activities of individuals as well as
corporations is going to increase due to the rising rate of cybercrimes in India.
The reach of computer forensics must be enterprise-wide and ideally, the response time
should be immediate in order to demonstrate that the organizations are utilizing best
practices in managing and controlling their information security compliance.
Organizations need to have a combination of in-house capability supplemented with external
expert services.
Cyberlaws of India need to be supported by sound cybersecurity and effective cyberforensics.
A good team of techno-legal experts is needed who to help in the drafting of good laws and in
its amendments and enforcement.
Cyber Security by Nina Godbole/Sunit Belapure
Copyright 2011 Wiley India Pvt. Ltd. All rights reserved.
Challenges in Computer Forensics
A microcomputer may have 200 GB or more storage capacity.
There are more than 5.2 billion messages expected to be sent and received in the US alone per day.
There are more than 3 billion indexed webpages worldwide.
There are more than 550 billion documents online.
Terabytes of data are stored on tape or hard drives.
Most of existing tools and methods allow anyone to alter any attribute associated with digital data.
Encryption is a major antiforensics technique and key word search can be defeated by renaming file
names.
Technical Challenges: Understanding the Raw Data and its Structure
“Complexity” problem
“Quantity” problem
Non-file system layers of abstraction
1. ASCII
2. HTML Files
3. Windows Registry
4. Network Packets
5. Source Code
Digital forensics is also challenged by the “quantity problem” – it involves the hugeness of digital
forensics to analyze. It is inefficient to analyze every single piece of it. Data reduction techniques need
to be used to solve this. Data reduction is done by grouping data into one larger event or by removing
known data.
Cyber Security by Nina Godbole/Sunit Belapure
Copyright 2011 Wiley India Pvt. Ltd. All rights reserved.
The Legal Challenges in Computer Forensics and Data Privacy Issues
Evidence, to be admissible in court, must be relevant, material and competent, and its
probative value must outweigh any prejudicial effect.
Digital evidence can be easily duplicated and modified; often it can be without even leaving any
traces; it can present special problems related to competency.
Digital evidence needs to satisfy the legal admissibility requirements.
Modern computers have enormous data storage facilities. Gigabyte disk drives are common and
a single computer may contain several such drives.
Seizing and freezing of digital evidence can no longer be accomplished just by burning a single
CD-ROM.
Failure to freeze the evidence prior to opening the files can invalidate critical evidence.
There is also the problem of locating the relevant evidence within massive amounts of data.
Artificial limitations imposed by constitutional, statutory and procedural issues.
Various personnel involved in digital forensics/computer forensics:
1. Technicians
2. Policy makers
3. Professionals
Cyber Security by Nina Godbole/Sunit Belapure
Copyright 2011 Wiley India Pvt. Ltd. All rights reserved.
Special Tools and Techniques
Most tools have the same underlying principles:
1. Creating forensics quality or sector-by-sector images of media;
2. Locating deleted/old partitions;
3. Ascertaining date/time stamp information;
4. Obtaining data from slack space;
5. Recovering or “undeleting” files and directories, “carving” or recovering data based on file
headers/file footers;
6. Performing keyword searches;
7. Recovering Internet history information.
Special Technique: Data Mining used in Cyberforensics
Depending on the type of cybercrimes, the impact and the impacted parties can vary.
Some impact and impacted parties
1. National security and government
2. Financial impacts and individuals
3. Brand image and organizations
Cyber Security by Nina Godbole/Sunit Belapure
Copyright 2011 Wiley India Pvt. Ltd. All rights reserved.
Techniques of Data Mining
1. Entity extraction
2. Clustering techniques
3. Association rule mining
Automated techniques to analyze different types of crimes need a unifying framework
describing how to apply them.
There is a need for understanding the relationship between analysis capability and crime type
characteristics. This understanding can help investigators more effectively to use those
techniques to identify trends and patterns, address problem areas and even predict crimes.
Forensics Auditing
1. It is also known as “forensics accounting.”
2. It is a specialized form of accounting.
3. It includes the steps needed to detect and deter fraud.
4. Forensics auditors make use of the latest technology to examine financial documents and
investigate white-collar crimes.
5. Uses accounting, auditing and investigative techniques.
6. Forensics accounting professionals are assigned specialty tasks.
7. Forensics auditors are responsible for detecting fraud, identifying individuals involved,
collecting evidence, presenting the evidence in criminal proceedings, etc.
Cyber Security by Nina Godbole/Sunit Belapure
Copyright 2011 Wiley India Pvt. Ltd. All rights reserved.
Antiforensics
It is the application of scientific method to digital media to invalidate factual information for
judicial review. Moreover, it is a combination of people, process and tools.
Four categories of antiforensics
1. Data destruction
2. Data hiding
3. Data encryption
4. Data contraception
Some well-known tools with “counter-forensics features”
1. Windows Washer
2. Windows and Internet Cleaner
3. CyberScrub Pro
4. Evidence Eliminator
5. Acronis Privacy Expert
6. SecureClean
Metasploit antiforensics investigation arsenal includes following tools
5. Timestomp
6. Slacker
7. Transmogrify
8. Sam Juicer
Cyber Security by Nina Godbole/Sunit Belapure
Copyright 2011 Wiley India Pvt. Ltd. All rights reserved.