Computer Security Fundamentals by Chuck Easttom Chapter 13 Cyber Detective
Chapter 13 Objectives Find contact information on the web Locate court records on the web Locate criminal records on the web Use Usenet newsgroups to gather information We no longer live all our lives in the small towns where we were born. People move into and out of our lives constantly. Corporate moves, job losses, educational opportunities, and many other reasons cause a constant shifting in our neighbors and co-workers. Our busy lives do not allow us to know people as well as we used to. Information gathering is a way to protect ourselves, both personally and on the job. © 2016 Pearson, Inc. Chapter 13 Cyber Detective
Introduction Preceding chapters have examined these topics: Identity theft Hacking Investigating potential employees © 2016 Pearson, Inc. Chapter 13 Cyber Detective
Introduction (cont.) Identity theft Criminals use a small amount of information to garner more. Look at Internet techniques for finding additional information. Security personnel need to know how this is done to defend against it. Any small bit of information about you can be turned into another bit that, combined with another, can result in a social engineering coup! Each of these steps is just one brick at a time in the wall. © 2016 Pearson, Inc. Chapter 13 Cyber Detective
Introduction (cont.) Hacking Investigating potential employees Obtain information to social engineer or to guess passwords. Investigating potential employees Calling references may not be enough. Hiring a private detective may be impractical. © 2016 Pearson, Inc. Chapter 13 Cyber Detective
Introduction (cont.) Network administrators in particular must be investigated. The network cannot keep out the person who set it up. Information about his past from a source other than supplied references may affect the hiring decision. Remember that 80% of security policy violations are perpetrated by network techs. © 2016 Pearson, Inc. Chapter 13 Cyber Detective
Introduction (cont.) The Internet is a valuable investigative tool. Useful for finding out about potential employees, babysitters, and so forth. Much of the information is free. States have court records online. © 2016 Pearson, Inc. Chapter 13 Cyber Detective
Introduction (cont.) Information is a two-edged sword. An innocent person may use it for legitimate investigations. A less scrupulous person may use it for identity theft or stalking. Invasion of privacy has ethical, moral, and legal ramifications. Practice searches on your own name unless you have written consent. Be careful. Have consent before you search a potential hire, business partner, babysitter, and so forth. Their refusal will tell you something! © 2016 Pearson, Inc. Chapter 13 Cyber Detective
General Searches Search to find addresses, phone numbers, or e-mail addresses www.yahoo.com www.infobel.com www.smartpages.com www.theultimates.com/white www.bigfoot.com www.whowhere.com www.switchboard.com © 2016 Pearson, Inc. Chapter 13 Cyber Detective
Court Records and Criminal Checks Sex offender registries www.fbi.gov/hq/cid/cac/registry.htm You may not be able to base employment decisions on certain information. Check with an attorney first. © 2016 Pearson, Inc. Chapter 13 Cyber Detective
Court Records and Criminal Checks (cont.) Civil court records Civil issues, as well as crimes, may make a person unsuitable for a particular job. No centralized Web site for these issues. Many states and Federal courts offer online records, for example: www.oscn.net/applications/oscn/casesearch.asp © 2016 Pearson, Inc. Chapter 13 Cyber Detective
Court Records and Criminal Checks (cont.) Other resources The National Center for State Courts www.ncsconline.org/ The Law School at Emory University www.law.emory.edu/FEDCTS/ Public record finder www.freeprf.com/ © 2016 Pearson, Inc. Chapter 13 Cyber Detective
Court Records and Criminal Checks (cont.) Other resources Pacer www.pacer.psc.uscourts.gov/ The Boost www.theboost.net/court_records/ State public access ctl.ncsc.dni.us/publicaccess/ © 2016 Pearson, Inc. Chapter 13 Cyber Detective
Court Records and Criminal Checks (cont.) Other resources Prison searches www.ancestorhunt.com/prison_search.htm Federal prison records www.bop.gov Public records www.searchsystems.net/ United Kingdom public records www.pro.gov.uk © 2016 Pearson, Inc. Chapter 13 Cyber Detective
Usenet Newsgroups on many subjects. Use Google “Groups” option. Anyone can post anything . Search for potential employees. Can be an important investigative tool. Information must be verified elsewhere. Be careful. Take what you find with a grain of salt. Use it to verify other information you may have, or look for more information to verify what you find here. Anyone can say anything on Usenet, whether true or false. Also, keep in mind that many people post to Usenet under pseudonyms—you may be more successful gathering information about companies than data about individuals. © 2016 Pearson, Inc. Chapter 13 Cyber Detective
Summary The Internet is a valuable investigative resource To hackers and identity thieves To employers of network administrators as well as babysitters Periodically check your own identity to see what information is available. Keep on top of your own identity in this way. © 2016 Pearson, Inc. Chapter 13 Cyber Detective