天极Yesky
  • 笔记本电脑
    笔记本
  • 台式电脑
    台式机
  • 手机
    手机
  • 电脑硬件DIY
    DIY硬件
  • CPU
    主板
    音箱
  • 硬盘
    显卡
    键鼠
  • 内存光驱
    显示器
    机箱电源

  • 数码相机DC
    数码相机
  • MP3播放器
    MP3/MP4
  • 数码摄像机DV
    摄像机
  • 电脑外设
    外设
  • 网络
    网络
  • 服务器
    服务器
  • 数字家庭
    数字家庭
  • 群乐
    群乐
  • 产品报价 行情 商家 新闻 评测 | 软件 设计 网页 开发 安全 论坛 E时代 游戏 图片 壁纸 下载 网摘 博客 索尼专区 Vista 科技奥运
    天极网
    Forensic specialists of the IT world
    作者: Mark Edmead
    出处:
    责任编辑:
    [ 2004-06-17 18:23 ]




    My favorite TV shows and books are detective mysteries. When I started in the information security business, I was immediately exposed to the "investigative" side of IT security. In my last article, I wrote about incident handling -- what you should do if there's a security breach. In many instances, part of that process involves collecting and preserving the evidence found during an incident. But the exciting part (at least for me) is when I'm asked to investigate the incident to try to determine the extent of the damage and trace the incident back to the source.

    A computer forensic investigation is the term used to describe the detailed examination of the event. If the security incident in question is, for instance, a hacker attack (and subsequent unauthorized access to your network), it might be part of your incident handling response to collect all of the evidence possible on this break-in so that it can be used to prosecute the intruder. Many organizations use a data forensics specialist. That person's job is to review the case by first identifying, processing, analyzing and finally reporting the findings to management or the authorities.

    The following steps are involved in the data forensics investigation process:

    1. Acquiring the evidence -- The first step is to determine the appropriate evidence to collect, which could be in the form of data on hard drives or perhaps hard-copy evidence. Because evidence can be subject to modification, it must be handled and controlled carefully. The term "chain of evidence" is used to describe the steps taken when handling evidence. You must document the following:

      a. The location of the evidence
      b. The time it was obtained
      c. The names of those who discovered the evidence
      d. The names of those who secured the evidence
      e. The names of those who controlled or possessed the evidence
    2. Examining the evidence -- This involves examining the computer media. One important point is that the integrity of the media must be maintained at all times. Any output generated from the examination must be clearly marked and controlled.
    3. Presenting evidence -- Present the relevant findings to be used by prosecutors.

    When using evidence in a prosecution, the evidence must meet the following requirements:

    • It must be relevant -- The evidence must clearly show that it is related to the crime committed.
    • It must be permissible by law -- The evidence was obtained in a lawful manner.
    • The evidence must be reliable -- The evidence must not have been tampered or altered in any way. (That's why we need the chain of evidence.)
    • The evidence must be identified without changing or damaging it.
    • The evidence must be preserved without possibility of damage or destruction.

    The bottom line when conducting a forensic investigation: document, document, document. And be sure to follow the legal procedures for collecting evidence. If the proper steps aren't followed, it is possible for the attacker to go free on a legal technicality. Before conducting an investigation, consult with management and/or legal authorities to make sure you are in compliance with the rules and regulations.

    About the author
    Mark Edmead CISSP, SSCP, is president of MTE Software, Inc. and has more than 22 years of experience in software development, product development and network systems security. He is also co-author of the book Windows NT: Performance, Monitoring and Tuning published by McMillan Press. In addition, he has written numerous articles for technical publications and is currently writing a book on Internet security certifications.

    笔名:
    请您注意:

     遵守国家有关法律、法规,尊重网上道德,承担一切因您的行为而直接或间接引起的法律责任。

     天极网拥有管理笔名和留言的一切权利。
    相关内容