Latest news
From the outset, I would like readers to note that when tasked (usually by the HR department) with conducting an investigation relating to computer equipment there are some key ‘rules’ to be followed:
Rule 1. An examination should never be performed on the original media.
Rule 2. A copy is made onto forensically sterile media. New media should always be used if available.
Rule 3. The copy of the evidence must be an exact, bit-by-bit copy. (Sometimes referred to as a bit-stream copy).
Rule 4. The computer and the data on it must be protected during the acquisition of the media to ensure that the data is not modified. (Use a write blocking device when possible)
Rule 5. The examination must be conducted in such a way as to prevent any modification of the evidence.
Rule 6. The chain of the custody of all evidence must be clearly maintained to provide an audit log of whom might have accessed the evidence and at what time.
All of the does not come without difficulties. There is an enhanced awareness amongst offenders of the nature of electronic evidence and the use of techniques to hide evidence. The skillful user makes the examiner’s job difficult, if not impossible. There is an increasing use of tools to hinder forensics - secure deletion tools, encryption tools, automated “scrubbing” tools, digital compression, steganography, remote storage, and audit disabling. Add to this the difficulty in placing a specific person at a specific computer without additional evidence, be it CCTV or Access Control Systems. Computer forensics is useful, but not always a silver bullet.
Not all incidents require of justify the full rigor of a forensic analysis. There are a number of factors affecting the decision to proceed, for instance, the seniority of staff. It is generally accepted that senior staff are more likely to appeal disciplinary procedures or otherwise respond. The background of staff is another important consideration. Staff with a legal, HR or union background may have other motivations. Obviously, if an investigation involves staff with a financial motive to appeal a disciplinary action, a forensic analysis that uncovers some compelling evidence may offer the organization a strong negotiation tool.
Spotlight

Cyber espionage campaign uses professionally-made malware
Posted on 20 May 2013. | A massive cyber espionage campaign has been hitting government ministries, IT companies, academic research institutions, and more.

Ransomware adds password stealing to its arsenal
Posted on 17 May 2013. | Microsoft researchers are warning about a new variant of the well-known Reveton ransomware doing rounds.

Application vulnerabilities still a top security concern
Posted on 16 May 2013. | Respondents to a new (ISC)2 study identified application vulnerabilities as their top security concern. A significant gap persists between software developers’ priorities and security professionals’ concerns.

IT security jobs: What's in demand and how to meet it
Posted on 15 May 2013. | Let's say you want a career in information security, where do you start? What credentials do you need? What are employers looking for? Read on to find some answers.

Hacking charge stations for electric cars
Posted on 15 May 2013. | Ofer Shezaf talks about what charge stations really are, why they have to be ‘smart’ and the potential risks created to the grid, to the car and most importantly to its owner’s privacy and safety.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.




