Digital Forensics Dr. Bhavani Thuraisingham The University of Texas at Dallas Network and Application Forensics September 26, 2014.

Slides:



Advertisements
Similar presentations
Guide to Computer Forensics and Investigations1 Network Forensics Overview Network forensics –Systematic tracking of incoming and outgoing traffic To ascertain.
Advertisements

1 Defining System Security Policies. 2 Module - Defining System Security Policies ♦ Overview An important aspect of Network management is to protect your.
1 Topic 1 – Lesson 3 Network Attacks Summary. 2 Questions ► Compare passive attacks and active attacks ► How do packet sniffers work? How to mitigate?
Building Your Own Firewall Chapter 10. Learning Objectives List and define the two categories of firewalls Explain why desktop firewalls are used Explain.
Intrusion Detection Systems and Practices
8.1 © 2007 by Prentice Hall 8 Chapter Securing Information Systems.
8.1 © 2007 by Prentice Hall 8 Chapter Securing Information Systems.
Handling Security Incidents
Security Awareness: Applying Practical Security in Your World, Second Edition Chapter 5 Network Security.
Lesson 11-Virtual Private Networks. Overview Define Virtual Private Networks (VPNs). Deploy User VPNs. Deploy Site VPNs. Understand standard VPN techniques.
© 2006 Cisco Systems, Inc. All rights reserved. Implementing Secure Converged Wide Area Networks (ISCW) Module 6: Cisco IOS Threat Defense Features.
Lesson 13-Intrusion Detection. Overview Define the types of Intrusion Detection Systems (IDS). Set up an IDS. Manage an IDS. Understand intrusion prevention.
Network Security. Network security starts from authenticating any user. Once authenticated, firewall enforces access policies such as what services are.
Lecture 11 Reliability and Security in IT infrastructure.
Guide to Computer Forensics and Investigations Third Edition Chapter 11 Network Forensics.
Lesson 19: Configuring Windows Firewall
Lesson 9-Securing a Network. Overview Identifying threats to the network security. Planning a secure network.
Host Intrusion Prevention Systems & Beyond
Computer Networks IGCSE ICT Section 4.
Network Infrastructure Security. LAN Security Local area networks facilitate the storage and retrieval of programs and data used by a group of people.
Digital Forensics Dr. Bhavani Thuraisingham
Lecture 11 Intrusion Detection (cont)
Lecture slides prepared for “Business Data Communications”, 7/e, by William Stallings and Tom Case, Chapter 8 “TCP/IP”.
FIREWALL TECHNOLOGIES Tahani al jehani. Firewall benefits  A firewall functions as a choke point – all traffic in and out must pass through this single.
Hands-on: Capturing an Image with AccessData FTK Imager
Guide to Computer Forensics and Investigations Fourth Edition Chapter 12 Investigations.
E-business Security Dana Vasiloaica Institute of Technology Sligo 22 April 2006.
Data Communications and Networks
1 Intrusion Detection Systems. 2 Intrusion Detection Intrusion is any use or attempted use of a system that exceeds authentication limits Intrusions are.
Information Systems CS-507 Lecture 40. Availability of tools and techniques on the Internet or as commercially available software that an intruder can.
Securing Information Systems
© 2007 Cisco Systems, Inc. All rights reserved.Cisco Public ITE PC v4.0 Chapter 1 1 Basic Security Networking for Home and Small Businesses – Chapter 8.
COEN 252 Computer Forensics
What is FORENSICS? Why do we need Network Forensics?
BUSINESS B1 Information Security.
Digital Forensics Dr. Bhavani Thuraisingham The University of Texas at Dallas Lecture #33 Information Warfare November 19, 2007.
Digital Forensics Dr. Bhavani Thuraisingham The University of Texas at Dallas Lecture #6 Forensics Services September 10, 2007.
COEN 252 Computer Forensics Collecting Network-based Evidence.
Honeypot and Intrusion Detection System
Environment for Information Security n Distributed computing n Decentralization of IS function n Outsourcing.
Digital Forensics Dr. Bhavani Thuraisingham The University of Texas at Dallas Lecture #17 Network Forensics October 19, 2008.
OV Copyright © 2013 Logical Operations, Inc. All rights reserved. Network Security  Network Perimeter Security  Intrusion Detection and Prevention.
Forensic and Investigative Accounting Chapter 14 Internet Forensics Analysis: Profiling the Cybercriminal © 2005, CCH INCORPORATED 4025 W. Peterson Ave.
Forensic and Investigative Accounting Chapter 14 Digital Forensics Analysis © 2011 CCH. All Rights Reserved W. Peterson Ave. Chicago, IL
FIREWALLS Vivek Srinivasan. Contents Introduction Need for firewalls Different types of firewalls Conclusion.
OV Copyright © 2011 Element K Content LLC. All rights reserved. Network Security  Network Perimeter Security  Intrusion Detection and Prevention.
Intrusion Detection Prepared by: Mohammed Hussein Supervised by: Dr. Lo’ai Tawalbeh NYIT- winter 2007.
Digital Forensics Dr. Bhavani Thuraisingham The University of Texas at Dallas Network and Application Forensics October 8, 2010.
CSCI 530 Lab Intrusion Detection Systems IDS. A collection of techniques and methodologies used to monitor suspicious activities both at the network and.
Linux Networking and Security
Digital Forensics Dr. Bhavani Thuraisingham The University of Texas at Dallas Lecture #14 Network Forensics September 26, 2007.
Digital Forensics Dr. Bhavani Thuraisingham The University of Texas at Dallas Application Forensics November 5, 2008.
Computer Networking From LANs to WANs: Hardware, Software, and Security Chapter 13 FTP and Telnet.
Digital Forensics Dr. Bhavani Thuraisingham The University of Texas at Dallas Application Forensics October 26, 2009.
CHAPTER 9 Sniffing.
Securing the Network Infrastructure. Firewalls Typically used to filter packets Designed to prevent malicious packets from entering the network or its.
Digital Forensics Dr. Bhavani Thuraisingham The University of Texas at Dallas Network Forensics - II October 29, 2008.
Topic 5: Basic Security.
1 Chapter 9 Intruders. 2 Outline Intruders –Intrusion Techniques –Password Protection –Password Selection Strategies –Intrusion Detection Statistical.
Digital Forensics Dr. Bhavani Thuraisingham The University of Texas at Dallas Network Forensics - III November 3, 2008.
Digital Forensics Dr. Bhavani Thuraisingham The University of Texas at Dallas Lecture #21 Network Forensics October 27, 2008.
Role Of Network IDS in Network Perimeter Defense.
Unit 2 Personal Cyber Security and Social Engineering Part 2.
Firewalls. Overview of Firewalls As the name implies, a firewall acts to provide secured access between two networks A firewall may be implemented as.
By: Brett Belin. Used to be only tackled by highly trained professionals As the internet grew, more and more people became familiar with securing a network.
CompTIA Security+ Study Guide (SY0-401)
Securing Information Systems
Security in Networking
CompTIA Security+ Study Guide (SY0-401)
Test 3 review FTP & Cybersecurity
Presentation transcript:

Digital Forensics Dr. Bhavani Thuraisingham The University of Texas at Dallas Network and Application Forensics September 26, 2014

Network Forensics l Network Forensics - Network Attacks - Security Measures - Network Forensics and Tools - Types of Networks - Other info l Summary/Conclusion and Links l Special presentation of network forensic l sics/network_primer.pdf sics/network_primer.pdf

Network Attacks l Denial of service Denial of service attacks cause the service or program to cease functioning or prevent others from making use of the service or program. l These may be performed at the network layer by sending carefully crafted and malicious datagrams that cause network connections to fail. l They may also be performed at the application layer, where carefully crafted application commands are given to a program that cause it to become extremely busy or stop functioning. l Preventing suspicious network traffic from reaching hosts and preventing suspicious program commands and requests are the best ways of minimizing the risk of a denial of service attack. l It is useful to know the details of the attack method, so you should educate yourself about each new attack as it gets publicized.

Network Attacks l Spoofing This type of attack causes a host or application to mimic the actions of another. l Typically the attacker pretends to be an innocent host by following IP addresses in network packets. l For example, a well-documented exploit of the BSD rlogin service can use this method to mimic a TCP connection from another host by guessing TCP sequence numbers. l To protect against this type of attack, verify the authenticity of datagrams and commands. l Prevent datagram routing with invalid source addresses. Introduce unpredictablility into connection control mechanisms, such as TCP sequence numbers and the allocation of dynamic port addresses.

Network Attacks l Eavesdropping This is the simplest type of attack. l A host is configured to "listen" to and capture data not belonging to it. Carefully written eavesdropping programs can take usernames and passwords from user login network connections. l Broadcast networks like Ethernet are especially vulnerable to this type of attack. l To protect against this type of threat, avoid use of broadcast network technologies and enforce the use of data encryption. l IP firewalling is very useful in preventing or reducing unauthorized access, network layer denial of service, and IP spoofing attacks. l It not very useful in avoiding exploitation of weaknesses in network services or programs and eavesdropping.

Securing a Network l Need measures to secure a network and prevent breaches l Apply patches; User a layered network defense strategy l NSA (National Security Agency) ahs developed DiD Defense in Depth) and has three models of protection - People, Technology, Operations - People: Employees are trained well - Technology: Strong network architecture and testing tools - Operations: applying security patches, anti-virus software, etc.

Network Security Mechanisms l Network security starts from authenticating any user, most likely a username and a password. l Once authenticated, a stateful firewall enforces access policies such as what services are allowed to be accessed by the network users l Though effective to prevent unauthorized access, this component fails to check potentially harmful contents such as computer worms being transmitted over the network. l An intrusion prevention system (IPS) helps detect and prevent such malware. IPS also monitors for suspicious network traffic for contents, volume and anomalies to protect the network from attacks such as denial of service. l Communication between two hosts using the network could be encrypted to maintain privacy. l Individual events occurring on the network could be tracked for audit purposes and for a later high level analysis.

Network Security Mechanisms l Honeypots, essentially decoy network-accessible resources, could be deployed in a network as surveillance and early- warning tools. Honeypots l Techniques used by the attackers that attempt to compromise these decoy resources are studied during and after an attack to keep an eye on new exploitation techniques. l Such analysis could be used to further tighten security of the actual network being protected by the honeypot l Some tools: Firewall, Antivirus software and Internet Security Software. For authentication, use strong passwords and change it on a bi-weekly/monthly basis. When using a wireless connection, use a robust password. Network analyzer to monitor and analyze the network.Antivirus softwareauthenticationNetwork analyzer

Network Forensics l What is Network Forensics? - gci859579,00.html gci859579,00.html l Network Forensics Analysis l Relationship to Honeynets/Honeypots l Policies for Networks Forensics l Example Prototype System l Some Popular Networks Forensics Analysis Tools (NFAT)

What is Network Forensics l Network forensics is the process of capturing information that moves over a network and trying to make sense of it in some kind of forensics capacity.network - Network forensics is the capture, recording, and analysis of network events in order to discover the source of security attacks or other problem incidents. l A network forensics appliance is a device that automates this process.network forensics appliance l Wireless forensics is the process of capturing information that moves over a wireless network and trying to make sense of it in some kind of forensics capacity.

What is Network Forensics? l Network forensics systems can be one of two kinds: - "Catch-it-as-you-can" systems, in which all packets passing through a certain traffic point are captured and written to storage with analysis being done subsequently in batch mode. This approach requires large amounts of storage, usually involving a RAID system.packetRAID - "Stop, look and listen" systems, in which each packet is analyzed in a rudimentary way in memory and only certain information saved for future analysis. This approach requires less storage but may require a faster processor to keep up with incoming traffic.

What is Network Forensics l Network Forensics is the process of collecting and analyzing raw network data and then tracking network traffic to determine how an attack took place l When intruders break into a network they leave a trail. Need to spot variations in network traffic; detect anomalies l Network forensics can usually help to determine whether network has been attacked or there is a user error l Examiners must establish standards procedures to carry out forensics

Network Analysis l Find analysis techniques developed for one type of network and apply it to another type of network l Types of networks - Computer and Communication Networks - Telecommunication Network - Transportation networks l Highways, Railroad, Air Traffic - Human networks l Terror networks, Relationship networks

Network Forensics Analysis Tools (NFAT): Relationships between IDS, Firewalls and NFAT l IDS attempts to detect activity that violates an organization’s security policy by implementing a set of rules describing preconfigures patterns of interest l Firewall allows or disallows traffic to or from specific networks, machine addresses and port numbers l NFAT synergizes with IDSs and Firewalls. - Preserves long term record of network traffic - Allows quick analysis of trouble spots identified by IDSs and Firewalls l NFATs must do the following: - Capture network traffic - Analyze network traffic according to user needs - Allow system users discover useful and interesting things about the analyzed traffic

NFAT Tasks l Traffic Capture - What is the policy? - What is the traffic of interest? - Intermal/Externasl? - Collect packets: tcpdump l Traffic Analysis - Sessionizing captured traffic (organize) - Protocol Parsing and analysis l Check for strings, use expert systems for analysis l Interacting with NFAT - Appropriate user interfaces, reports, examine large quantities of information and make it manageable

Network Forensics: NetworkMiner l NetworkMiner is a Network Forensic Analysis Tool (NFAT) for Windows. l NetworkMiner can be used as a passive network sniffer/packet capturing tool in order to detect operating systems, sessions, hostnames, open ports etc. without putting any traffic on the network. sniffer l The purpose of NetworkMiner is to collect data (such as forensic evidence) about hosts on the network rather than to collect data regarding the traffic on the network. l The main view is host centric (information grouped per host) rather than packet centric (information showed as a list of packets/frames).

Honeynets/Honeypots l Network Forensics and honeynet systems have the same features of collecting information about computer misuses l Honeynet system can lure attackers and gain information about new types of intrusions l Network forensics systems analyze and reconstruct he attack behaviors l These two systems integrated together build a active self learning and response system to profile the intrusion behavior features and investigate the original source of the attack.

Honeynet project l Honeynet project was established to make information about network attacks and solutions widely available l Objectives: Awareness, information, tools l Attacks: distributed Denial of Service, Zero day attacks l Honeypot is a computer set up to lure attackers l Honeywalls are computers set up to monitor what is happening to the honeypots in the network

Policies: Computer Attack Taxonomy l Probing - Attackers reconnaissance - Attackers create a profile of an organization's structure, network capabilities and content, security posture - Attacker finds the targets and devices plans to circumvent the security mechanism l Penetration - Exploit System Configuration errors and vulnerabilities - Install Trojans, record passwords, delete files, etc. l Cover tracks - Configure event logging to a previous state - Clear event logs and hide files

Policies to enhance forensics l Retaining information l Planning the response l Training l Accelerating the investigation l Preventing anonymous activities l Protect the evidence

Example Prototype System: Iowa State University l Network Forensics Analysis mechanisms should meet the following: - Short response times; User friendly interfaces l Questions addresses - How likely is a specific host relevant to the attack? What is the role the host played in the attack? How strong are two hosts connected to the attack? l Features of the prototype - Preprocessing mechanism to reduce redundancy in intrusion alerts - Graph model for presenting and interacting with th3 evidence - Hierarchical reasoning framework for automated inference of attack group identification

Example Prototype System: Modules l Evidence collection module l Evidence preprocessing module l Attack knowledge base l Assets knowledge base l Evidence graph generation module l Attack reasoning module l Analyst interface module l Reference l wang.pdf?key1= &key2= &coll=GUIDE&dl= GUIDE&CFID= &CFTOKEN= wang.pdf?key1= &key2= &coll=GUIDE&dl= GUIDE&CFID= &CFTOKEN= l hs.pdf hs.pdf

Network Tools l Network Forensics tools help in the monitoring of the network l Example: the records that Ps tools generate can prove that an employee ran a program without permission l Can also monitor machines/processes that may be harmful l Problem is the attacker can get administrator rights and start using the tools l Chapter 11 discusses tools for Windows and Linux

Some Popular Tools l Raytheon’s SilentRunner - Gives administrators help as they attempt to protect their company’s assets - Collector, Analyzer and Visualize Modules l Sandstorm Enterprise’s NetIntercept - Hardware appliance focused on capturing network traffic l Niksun’s NetDetector - Its an appliance like NetIntercept - Has an alerting mechanism - Integrates with Cicso IDS for a complete forensic analysis

Network Forensics: Open Source Tools l Open source tools - Wireshark Wireshark - Kismet Kismet - Snort Snort - OSSEC OSSEC - NetworkMiner is an open source Network Forensics Tool available at SourceForge. NetworkMineran open source Network Forensics Tool available at SourceForge - Xplico is an Internet/IP Traffic Decoder (NFAT). Protocols supported: HTTP, SIP, FTP, IMAP, POP, SMTP, TCP, UDP, IPv4, IPv6 XplicoHTTP, SIP, FTP, IMAP, POP, SMTP, TCP, UDP, IPv4, IPv6

Network Forensics: Commercial Tools l Deep Analysis Tools (data mining based tools) - E-Detective - ManTech International Corporation - Network Instruments - NIKSUN's NetDetectorNetDetector - PacketMotion - Sandstorm's NetInterceptNetIntercept - Mera Systems NetBeholderNetBeholder - InfoWatch Traffic Monitor InfoWatch Traffic Monitor

Network Forensics: Commercial Tools l Flow-Based Systems - Arbor Networks - GraniteEdge Networks - Lancope - Mazu Networks l Hybrid Systems - These systems combine flow analysis, deep analysis, and security event monitoring and reporting. - Q1 Labs

Performing Live Acquisitions l Insert bootable forensics CD in the suspect system l Keep a log of all the actions l Send collected information to a network drive l Copy the physical memory l Determine if root kit is present; access system’s firmware, - - l Get forensics hash value of all files

Performing Live Acquisitions: Windows l Setup NetCat listener to send the forensics data l Load Helix CD in the CD-ROM drive l Click appropriate buttons – System Information; Glad arrow etc l Click Acquire Live Image if Widows System l Connect to NetCat listener to send the collected data (e.g., enter IP address of NetCat listener) l Click Incidence Response Tools l Click on appropriate tools to collect data

Standard procedures l Standard installation image, hash schemes (e.g., MD5, SHA-1) l Fix vulnerabilities if intrusion is detected l Retrieve volatile data (RAM, processes) l Acquire compromised drive and make forensics image of it l Compare forensics image and standard image and determine if anything has changed

Network Logs l Network logs record traffic in and out of network l Network servers, routers, firewalls record activities and events that move through them l One ways is to run Tcpdump l When viewing network log, port information can give clues about suspicious activity l Use network analysis tool

Packet Sniffers l Devices or software to monitor (sniff) traffic l TCP/IP sniffers operate at the Packet level; in OSI operates at the Layer 2 or 3 level (e.g. Data link or Network layers) l Some sniffers perform packet captures, some perform analysis and some perform both l Tools exist for examining (i) packets with certain flags set (ii) headers (iii) IRC chats

Summary l Network Forensics is the process of collecting and analyzing raw network data and then tracking network traffic to determine how an attack took place l Layered defense strategies to the network architecture l Live acquisitions are needed to retrieve volatile items l Standard procedure are needed to establish how to proceed after a network attack occurs l By monitoring network traffic can establish normal operations; then determine if there is an anomaly l Network tools used to monitor networks; but intruders can get admin rights to attack from the inside l Tools are available for monitoring network traffic for both Windows and Linux systems l Honeynet project enables people to learn latest intrusion techniques

Links l l l ieee.pdf ieee.pdf l l work_primer.pdf work_primer.pdf l l ren.pdf?key1= &key2= &coll=GUIDE&dl=GUIDE&C FID= &CFTOKEN= ren.pdf?key1= &key2= &coll=GUIDE&dl=GUIDE&C FID= &CFTOKEN= l

Application Forensics l Forensics - Examining s - Mobile System Forensics - Note: Other Application/systems related forensics l Database forensics, Network forensics (already discussed) l Military Forensics Overview l Optional paper to read: -

Forensics l Investigations l Client/Server roles l crimes and violations l servers l forensics tools

Investigations l Types of investigations - s have worms and viruses – suspicious s - Checking s in a crime – homicide l Types of suspicious s - Phishing s i- they are in HTML format and redirect to suspicious web sites - Nigerian scam - Spoofing s

Client/Server Roles l Client-Server architecture l servers runs the server programs – example Microsoft Exchange Server l runs the client program – example Outlook l Identitication/authntictaion is used for client to access the server l Intranet/Internet servers - Intranet – local environment - Internet – public: example: yahoo, hotmail etc.

Crimes and Violations l Goal is to determine who is behind the crime such as who sent the l Steps to forensics - Examine message - Copy message – also forward - View and examine header: tools available for outlook and other clients - Examine additional files such as address books - Trace the message using various Internet tools - Examine network logs (netflow analysis) l Note: UTD Netflow tools SCRUB are in SourceForge

Servers l Need to work with the network administrator on how to retrieve messages from the server l Understand how the server records and handles the messages l How are the logs created and stored l How are deleted messages handled by the server? Are copies of the messages still kept? l Chapter 12 discussed servers by UNIX, Microsoft, Novell

Forensics Tools l Several tools for Outlook Express, Eudora Exchange, Lotus notes l Tools for log analysis, recovering deleted s, l Examples: - AccessData FTK - FINAL - EDBXtract - MailRecovery

Mobile Device/System Forensics l Mobile device forensics overview l Acquisition procedures l Summary

Mobile Device Forensics Overview l What is stored in cell phones - Incoming/outgoing/missed calls - Text messages - Short messages - Instant messaging logs - Web pages - Pictures - Calendars - Address books - Music files - Voice records

Mobile Phones l Multiple generations - Analog, Digital personal communications, Third generations (increased bandwidth and other features) l Digital networks - CDMA, GSM, TDMA, l Proprietary OSs l SIM Cards (Subscriber Identity Module) - Identifies the subscriber to the network - Stores personal information, addresses books, etc. l PDAs (Personal digital assistant) - Combines mobile phone and laptop technologies

Acquisition procedures l Mobile devices have volatile memory, so need to retrieve RAM before losing power l Isolate device from incoming signals - Store the device in a special bag - Need to carry out forensics in a special lab (e.g., SAIAL) l Examine the following - Internal memory, SIM card, other external memory cards, System server, also may need information from service provider to determine location of the person who made the call

Mobile Forensics Tools l Reads SIM Card files l Analyze file content (text messages etc.) l Recovers deleted messages l Manages PIN codes l Generates reports l Archives files with MD5, SHA-1 hash values l Exports data to files l Supports international character sets

Digital Forensics Dr. Bhavani Thuraisingham The University of Texas at Dallas Appendix Information Warfare and Military Forensics

Information Warfare l Information Warfare - Defensive Strategies for Government and Industry - Military Tactics - Terrorism and Information Warfare - Tactics of Private Corporations - Future IW strategies - Surveillance Tools - The Victims of Information Warfare l Military Forensics l Relevant Papers

What is Information Warfare? l Information warfare is the use and management of information in pursuit of a competitive advantage over an opponent. Information warfare may involve collection of tactical information, assurance that one's own information is valid, spreading of propaganda or disinformation to demoralize the enemy and the public, undermining the quality of opposing force information and denial of information collection opportunities to opposing forces.collectionassurancepropagandadisinformation demoralizeenemy l

Defensive Strategies for Government and Industry l Are US and Foreign governments prepared for Information Warfare - According to John Vacca, US will be most affected with 60% of the world’s computing power - Stealing sensitive information as well as critical, information to cripple an economy (e.g., financial information) l What have industry groups done - IT-SAC: Information Technology Information Sharing and Analysis l Will strategic diplomacy help with Information Warfare? l Educating the end user is critical according to John Vacca

Defensive Strategies for Government and Industry l What are International organizations? - Think Tanks and Research agencies - Book cites several countries from Belarus to Taiwan engaged in Economic Espionage and Information Warfare l Risk-based analysis l Military alliances - Coalition forces – US, UK, Canada, Australia have regular meetings on Information Warfare l Legal implications l Strong parallels between National Security and Cyber Security

Military Tactics l Supporting Technologies - Agents, XML, Human Computer Interaction l Military tactics - Planning, Security, Intelligence l Tools - Offensive Ruinous IW tools l Launching massive distributed denial of service attacks - Offensive Containment IW tools l Operations security, Military deception, Psychological operations, Electronic warfare (use electromagnetic energy), Targeting: Disable enemy's C2 (c0mmand and control) system and capability

Military Tactics l Tools (continued) - Defensive Preventive IW Tools l Monitor networks - Defensive Ruinous IW tools l Information operations - Defensive Responsive Containment IW tools l Handle hacking, viruses. l Other aspects - Dealing with sustained terrorist IW tactics, Dealing with random terrorist IW tactics

Terrorism and Information Warfare l Terrorists are using the web to carry out terrorism activities l What are the profiles of terrorists? Are they computer literate? l Hacker controlled tanks, planes and warships l Is there a Cyber underground network? l What are their tools? - Information weapons, HERF gun (high power radio energy at an electronic target), Electromagnetic pulse. Electric power disruptive technologies l Why are they hard to track down? - Need super forensics tools

Tactics of Private Corporations l Defensive tactics - Open course intelligence, Gather business intelligence l Offensive tactics - Packet sniffing, Trojan horse etc. l Prevention tactics - Security techniques such as encryption l Survival tactics - Forensics tools

Future IW Tactics l Electromagnetic bomb - Technology, targeting and delivery l Improved conventional method - Virus, worms, trap doors, Trojan horse l Global positioning systems l Nanotechnology developments - Nano bombs

Surveillance Tools l Data emanating from sensors: - Video data, surveillance data - Data has to be analyzed - Monitoring suspicious events l Data mining - Determining events/activities that are abnormal l Biometrics technologies l Privacy is a concern

Victims of Information Warfare l Loss of money and funds l Loss of shelter, food and water l Spread of disease l Identity theft l Privacy violations l Death and destruction l Note: Computers can be hacked to loose money and identity; computers can be used to commit a crime resulting in death and destruction

Military Forensics l CFX-2000: Computer Forencis Experiment Information Directorate (AFRL) partnership with NIJ/NLECTC - Hypothesis: possible to determine the motives, intent, targets, sophistication, identity and location of cyber terrorists by deploying an integrated forensics analysis framework - Tools included commercial products and research prototypes appb.pdf appb.pdf