652 pages, all free. You do not need to give out your personal information or subscribe to anything..."
The original link to get the publication is no longer current. However, a copy can still be downloaded using the following link: http://web.archive.org/
Investigations, Practices and Procedures: Seizure-Forensic Examination-Evidence. Cellular and Satellite Telephones, Call Records-Billing Data, Cell Site Analysis. Telecomms. Computer and Network Analysis. GPS devices & Jammers, Cyber, IoT forensics.
Showing posts with label computer forensics. Show all posts
Showing posts with label computer forensics. Show all posts
Thursday, October 09, 2014
Sunday, February 17, 2013
Cyber Wrapping
Susan Brenner has had published her article 'Cyber-threats and the
Limits of Bureaucratic Control' published in MINN. J. L. SCI. &
TECH. [Vol. 14:1] and downloadable from the link below. Susan's brief
synopsis is available here: http://cyb3rcrim3.blogspot.co.uk/2013/02/fyi-maybe-new-article-on-cyberthreats.html. A further link to material for review is here: University of Minnesota http://conservancy.umn.edu/handle/144222.
This is a very useful and informative article from Susan and sets out challenges about understanding the impact of 'cyber-' and how a "State" copes with control of such threats.
The marketplace is burgeoning with 'cyber courses' e.g. with content such as: "cyber attack and defense, digital analysis, computer forensics, security policies and strategies, risk analysis, ethical and legal issues, operational processes, cyber crime, and more" (http://www.excelsior.edu/web/news/college-news/-/blogs/five-cybersecurity-programs-certified-to-meet-the-nsa%E2%80%99s-committee-on-national-security-systems-cnss-training-standards) which appears to suggest cyber people have been unable to distinguish cyber as a platform of its own without subsuming e.g. computer forensics and therefore dismantling this job title and work in an attempt to top it.
My original thinking when getting to grips to understand what the cyber-people wanted to show when the approach started back in 2000 was that, irrespective of the technology, it is the fundamental messages/signals, instructions or information included and transmitted through electrical impulses, analogue/digital signalling and so on would complement existing investigatory, examination and forensics programmes and employment and tools. Instead, cyber appears to want to cast a veil over all of these mature approaches to make everything science/technology neutral and claim they are subsets of cyber.
Fundamentally, cyber is a subset to all forms of communication mediums, transmitters and receivers and the technology that interprets communications and signalling. Moreoever cyber-attack/crime/etc is a 50/50 proposition and a subset of "intention" (pragmatically and legally) and must be judged in that context when compared to a "mistake" where the person had no intention to generate an attack but an unwanted outcome occurs anyway.
Download: http://conservancy.umn.edu/bitstream/144222/1/Cyber-Threats-by-Susan-Brenner-MN-Journal-Law-Science-Tech-Issue-14-1.pdf
This is a very useful and informative article from Susan and sets out challenges about understanding the impact of 'cyber-' and how a "State" copes with control of such threats.
The marketplace is burgeoning with 'cyber courses' e.g. with content such as: "cyber attack and defense, digital analysis, computer forensics, security policies and strategies, risk analysis, ethical and legal issues, operational processes, cyber crime, and more" (http://www.excelsior.edu/web/news/college-news/-/blogs/five-cybersecurity-programs-certified-to-meet-the-nsa%E2%80%99s-committee-on-national-security-systems-cnss-training-standards) which appears to suggest cyber people have been unable to distinguish cyber as a platform of its own without subsuming e.g. computer forensics and therefore dismantling this job title and work in an attempt to top it.
My original thinking when getting to grips to understand what the cyber-people wanted to show when the approach started back in 2000 was that, irrespective of the technology, it is the fundamental messages/signals, instructions or information included and transmitted through electrical impulses, analogue/digital signalling and so on would complement existing investigatory, examination and forensics programmes and employment and tools. Instead, cyber appears to want to cast a veil over all of these mature approaches to make everything science/technology neutral and claim they are subsets of cyber.
Fundamentally, cyber is a subset to all forms of communication mediums, transmitters and receivers and the technology that interprets communications and signalling. Moreoever cyber-attack/crime/etc is a 50/50 proposition and a subset of "intention" (pragmatically and legally) and must be judged in that context when compared to a "mistake" where the person had no intention to generate an attack but an unwanted outcome occurs anyway.
Download: http://conservancy.umn.edu/bitstream/144222/1/Cyber-Threats-by-Susan-Brenner-MN-Journal-Law-Science-Tech-Issue-14-1.pdf
Monday, June 25, 2012
Hidden data battery investigations
Hidden data battery investigations
Due to a common embedded controller found in Lithium Ion (Li-Ion) and Lithium
Polymer batteries and used in a large number of MacBook, MacBook Pro, and MacBook Air laptop computers it is possible when the battery is 'unsealed' to conceal data in its memory.
To avoid data being lost at the next boot up of the laptop, by setting the unsealed battery's embedded contoller into Boot ROM mode (factory setting stage) charging cannot function and pass information to the flash and overwrite the hidden data.
A perpetrator could therefore transport hidden data and/or pass data in the battery to another person/laptop. If the laptop/battery are seized before the hidden data has been extracted and the examiner switches on the laptop, the battery's memory can be re-written causing loss of the hidden data - a cross between a trojan horse and dead-man's trap.
It is possible to brick the battery giving the impression the battery is a dud. An examiner may not think to consider the battery as memory storage and disregard the battery during investigation.
Polymer batteries and used in a large number of MacBook, MacBook Pro, and MacBook Air laptop computers it is possible when the battery is 'unsealed' to conceal data in its memory.
To avoid data being lost at the next boot up of the laptop, by setting the unsealed battery's embedded contoller into Boot ROM mode (factory setting stage) charging cannot function and pass information to the flash and overwrite the hidden data.
A perpetrator could therefore transport hidden data and/or pass data in the battery to another person/laptop. If the laptop/battery are seized before the hidden data has been extracted and the examiner switches on the laptop, the battery's memory can be re-written causing loss of the hidden data - a cross between a trojan horse and dead-man's trap.
It is possible to brick the battery giving the impression the battery is a dud. An examiner may not think to consider the battery as memory storage and disregard the battery during investigation.
Friday, November 18, 2011
Taping Business Mobile Phone Calls - Part 2
Taping Business Mobile Phone Calls - Part 2
Last year the FSA (Financial Services Authority) published its consultation document concerned with recording mobile communications within the finanical services industry http://trewmte.blogspot.com/2010/04/taping-business-mobile-phone-calls.html. I also produced a list of additional statutory and regulatory links to materials about call recording.
The FSA has now concluded their consultation and published CP10/17 which can be downloaded here:
http://www.fsa.gov.uk/pubs/policy/ps10_17.pdf
"2.28 What constitutes ‘reasonable steps’ is fundamentally principles-based, meaning that we are not prescriptive about what we expect from firms to be compliant. Each firm must decide what it deems necessary and reasonable to comply with the taping provisions."
Last year the FSA (Financial Services Authority) published its consultation document concerned with recording mobile communications within the finanical services industry http://trewmte.blogspot.com/2010/04/taping-business-mobile-phone-calls.html. I also produced a list of additional statutory and regulatory links to materials about call recording.
The FSA has now concluded their consultation and published CP10/17 which can be downloaded here:
http://www.fsa.gov.uk/pubs/policy/ps10_17.pdf
"2.28 What constitutes ‘reasonable steps’ is fundamentally principles-based, meaning that we are not prescriptive about what we expect from firms to be compliant. Each firm must decide what it deems necessary and reasonable to comply with the taping provisions."
Thursday, December 30, 2010
Apple sued over iPad and iPhone app 'data leaks'
Apple sued over iPad and iPhone app 'data leaks'
The BBC article doesn't mention it, but it would be helpful to know what personal data is being captured by web-based companies etc. In the wrong hands captured personal data for MSISDN could be used, by pinging from the internet, to cache polled MSISDNs for their IMSIs etc. The equipment is out there to do it and has been for many years.
With credit card details being included within suggested secure apps for UICC cards, it is not difficult to imagine a rogue poll and de-tanking event occuring that goes unnoticed because it appears like the modern unobtrusive location updating procedure or another procedure and the user may only know about it after the data is missing.
Should that event happen it is what is termed as a "Mobile Cybercrime". The relevance being, making use of the singular term cybercrime as a title is highly misleading because you need a science and an operable technology in which the event needs to activate and commission. Mobile communications is a science and a technology (a damned fine science and technology they are, too).
http://www.bbc.co.uk/news/technology-12089225
Tuesday, March 23, 2010
Linux - out-of-memory (L-OOM)
Linux - out-of-memory (L-OOM)
Whilst researching on mobile phones using Linux OS I came across a report on guidelines for creating robust embedded systems (published in 2009). The report's discussion arrived at the topic out-of-memory (OOM) and perceived flaws with Linux overbooking the kernel. The report calls this 'OOM Killer'
The report noted:
"One Linux detractor says this about the feature:
"Linux on the other hand is seriously broken. It will by default answer "yes" to most requests for memory, in the hope that programs ask for more than they actually need. If the hope is fulfilled Linux can run more programs in the same memory, or can run a program that requires more virtual memory than is available. And if not then very bad things happen."
The report then goes on to record this gem of an analogy as to what might happen when Linux over commits.
"One comedian has described this feature of Linux as follows:
"An aircraft company discovered that it was cheaper to fly its planes with less fuel on board. The planes would be lighter and use less fuel and money was saved. On rare occasions however the amount of fuel was insufficient, and the plane would crash. This problem was solved by the engineers of the company by the development of a special OOF (out-of-fuel) mechanism. In emergency cases a passenger was selected and thrown out of the plane. (When necessary, the procedure was repeated.) A large body of theory was developed and many publications were devoted to the problem of properly selecting the victim to be ejected. Should the victim be chosen at random? Or should one choose the heaviest person? Or the oldest? Should passengers pay in order not to be ejected, so that the victim would be the poorest on board? And if for example the heaviest person was chosen, should there be a special exception in case that was the pilot? Should first class passengers be exempted? Now that the OOF mechanism existed, it would be activated every now and then, and eject passengers even when there was no fuel shortage. The engineers are still studying precisely how this malfunction is caused."
Monday, November 16, 2009
Solid State Drives will Ruin Forensics
Solid State Drives will Ruin Forensics
Part 5/5 presentation on YouTube from the series about Solid State Drives (SDD) -v- Hard Disc Drives (HDD) is worth viewing if you haven't seen it yet. At the same time you can catch up with the other parts if you have missed those too!
http://www.youtube.com/watch?v=2Xn-f7tmsOU&feature=youtube_gdata
Monday, August 31, 2009
Forensic Focus Interviews
Forensic Focus Interviews
.
Forensic Focus regularly interviews well known personalities from the world of computer and mobile phone forensics.
.
This month it was my turn:
.
Mobile Telephone Expert Witness, 29/08/09
.
Readers of trewmte.blogspot may also want to read the Interviews of past personalities, available at the link below:
.
- Sean McLinden, Outcome Technology Associates, Inc. - 21/07/09
- Graham Brown-Martin, Digital Safety Conference - 12/06/09
- Lee Whitfield, Forensic 4cast - 10/06/09
- Robert Botchek, President & Founder – Tableau, LLC - 09/06/09
- Dr Chris Pamplin, Editor – UK Register of Expert Witnesses - 31/05/09
- Ben Levitan, US Telecommunications Expert Witness - 08/05/09
- Nick Furneaux, MD CSITech & Director, Bright Forensics - 07/05/09
- Jan Collie, The Digital Detective - 24/04/09
- Professor Tony Sammes, Cranfield University - 31/03/09
- Simon Biles, Thinking Security - 27/11/08
- Gene Spafford, CERIAS - 12/09/08
- Paul Wright, City of London Police - 05/09/08
- Jonathan Krause, Forensic Control - 27/08/08
- Ian Kennedy, Forensic Consultant & Open University Lecturer - 14/07/08
- Matt Shannon, Founder and Chief Software Architect F-Response - 19/06/08
- David Sullivan, Appointments-UK - 28/04/08
- Stefan Fleischmann, CEO X-Ways Software Technology AG - 27/02/08
- John Patzakis, Guidance Software - 28/06/07
- Harlan Carvey - 07/03/07
Subscribe to:
Posts (Atom)