wtorek, 26 lutego 2013

SSD Drives Destroy Evidence


Today, posting a short abstract: the most important facts, researches summary , conclusions and links to great documentation and conducted experiments.   

Authors of tests claim that solid-state drives (SSDs) have the ability to destroy evidence under their own will.  While the acquisition of forensic data from standard magnetic disks is fairly good described, is seems that much remain to be done on the field of SSDs. Here I would like to introduce some terms, such as; self-contamination, garbage-collector, or wear-leveling.
The most important, we need to know how the SSD technology works. For this, check google and find any article for most important facts, just to know and understand the principles. During acquisition stage of investigation we need to follow some ‘sound’ methodology; what is obvious is the importance to do not destroy evidence. To minimize alteration to the system, the recovery/collection process should include prevention of overwriting.

Here, the phenomenon of solid-state drive (SSD) self-corrosion is proven to exist through experimentation using real world consumer hardware in an experimentally reproducible environment.

SSD technology uses wear-leveling schema, which means that driver of ssd disk is trying not to continually write on the same place. Then we have something called ‘translation layer’ (Flash Translation Layer_that keeps in mind where the computer thinks is writing (also check TRIM). For performance purposes SSDs manufactures have developed ‘garbage collector’ or ‘self healing’ technique to reset particular sectors of SSD disk to be prepared for incoming writing.For full test review and conclusions please follow Solid State Drives: The Beginning of the End for Current Practice in Digital Forensic Recovery? Graeme B. Bell and Richard Boddington http://www.jdfsl.org/subscriptions/JDFSL-V5N3-Bell.pdf.

Another awesome article reveals additional portion of information:
Today’s SSDs self-destroy court evidence through the process that can be called “self corrosion”. Garbage collection running as a background process in most modern SSDs will permanently erase data marked for deletion, making it gone forever in a matter of minutes after the data has been marked for deletion. It is not possible to prevent garbage collection by moving the disk to another PC or attaching it to a write blocking device. The only way to prevent self-corrosion is physically detaching the disk controller from flash memory chips storing the data, and then accessing the chips directly via custom hardware. 

Blocks of data processed by garbage collector are physically erased. Information from such blocks cannot be recovered even with the use of  hardware and blockers. . Forensic researchers named this process as “self-corrosion” (Q3 2012: State of the art in SSD forensics)

 Preventing the operation of internal garbage collection is only possible by physically disconnecting the built-in controller from actual flash chips, and accessing information stored in  the chips directly.

The digital investigation science is changing on almost daily basic, so we need to stay focused, watch  how the scene is evolving ,be proactive and do not lose the big picture !:)

sobota, 23 lutego 2013

Security information and event management (SIEM)


SIEM systems perform two main functions, according  to documentation:

Security information management (SIM) : This sub-system (historically), was designed for      compliance purposes(policy) and threat management. SIM was designed to collect, report and prematurely analyze logs (it was not created to provide sophisticated methods of correlation or any). Logs/flows can be taken from any network/security devices but also from servers, databases and applications. Additionally , more often SIEMs are supporting variety of network appliances making the connections more effective and flexible.

Security event management (SEM): SEM is – or was – responsible for aggregating, correlating and analyzing logs for real time needs. It is crucial for incident response, clear and wide visibility into infrastructure and reporting.

During some lectures I was trying to figure out which type of data warehouse SIEM is – if SIEM is a warehouse at all.  Looking for words combination ‘warehouse SIEM’ I found some articles:

…approaches SIEM as a data management issue. …solution is built atop an event data warehouse that leverages a columnar database uniquely designed for time-stamped, unstructured data to be correlated and analyzed,  either in real time or over months or even years. The solution runs on a platform employing massively parallel processing and commodity hardware and storage for  enhanced load and query throughput, very high data compression (…)  and  extremely large data retention (up to petabytes a year). It provides the ability to correlate events across multiple data  sources and systems, either in real-time or on a historical basis.

Taken from : http://www.sensage.comIt seems that SIEM can be some kind of hybrid between OLAP and OLTP warehouses or even a modification of mediatory system – easy access to real time data (structured, parsed and correlated) but also giving information about trends, statistics and other historical patterns (which are capabilities of standard database warehouses). But before moving forward, let look at what ‘standard’ features provide SIEM:

Log management : supports effective correlation (indexing), collection. There are deployed mechanism for fast and efficient searches.  System should also support reporting and capability to attach external data sources – not only those standard (for example syslog or more exclusive opsec).

Compliance/event managment : allows for signatures creation (behavioral anomalies rules also) . What is more, it supports incident handling and documentation.

Visibility and dashboarding : SIEM provides clear dashboards to view system availability and performance (ideal situation) . Alert notificatiosn and trends can be viewed in easy format.

Log source management: system allows for maintenance, tuning, editing and additional extensions (third party software as example).

External data sources/feed: SIEM should be accessible and aggregate also non-standard information taken from outside of infrastructure.


Moving back to warehouses. Basing on this article http://www.networkworld.com  ,we are finding the definition for Security Data Warehouse, which is:

(…)  making security decisions based on mining business intelligence and combining it with security-related event data from security devices.
Today, security analysis more typically relies on what's known as security information and event management (SIEM) tools which can aggregate security and other technical information for a birds-eve view of network activity or detect possible unauthorized actions. (…) but it's now possible to go further through correlation of business activities, based on feeds from other sources too.
 A SIEM may have trouble "dealing with massive amounts of historical data," (…) but by using the Hadoop framework with core components that can handle "terabytes, even petabytes of information," it's possible to achieve better analysis by combining business and security data. " A SIEM becomes one main feed into the Security Data Warehouse. Improved historical analysis is also resulting," (…)

 The conclusion may be: SIEM is the sub-system for bigger mechanism that can provide predictive analytics and possibly track anomalies. Basing on that hypothesis SIEM alone is not typical data warehouse as it provides real time information and trends (rrd), collects information for compliance regulatory but very limited in terms of post-factum response or data mining. To some point it is a hybrid warehouse giving ideas (and even limited capabilities) of big data approach (statistics, historical patterns, rrd dashboards .etc)  but possibly to weak to compete with the typical one. SIEM is a main component in Security data warehouse that is now in developmental and evolutionary status - Big data.

(…) Security Data Warehouse approach is making it more possible to detect phishing attempts by analyzing email and other events, "and that allows you to respond more quickly than in the past."

I would like to stop here, and strongly  encourage you to read following materials.

http://csrc.nist.gov/publications/nistpubs/800-92/SP800-92.pdf - Guide to Computer Security Log Management (Recommendations of the National Institute of Standards and Technology)

środa, 20 lutego 2013

Threats - announcement


Today, just a little bit about threats that we are facing today, and that are getting to be more serious in coming years. Short and kind a ‘high-level’ discussion to give the wide context and ideas.

Firstly, it should be said that apart from new sophisticated types of attacks (APT, AET, ... ), we should not forget about legacy infrastructure, which still is fundamental and crucial. Just to mention, firewalls (NGFW are awesome, but still),  IDS/IPS, NIDS/HIPS, AVs, policy, standards, end-user awareness, etc. When saying and listing these ‘standard’ and essential ways of protection (layers of security) I have SIEM infrastructure in mind. It is impossible to have it all, and understand and  have wide and clean visibility into company protection. Event management system and correlation is a must in bigger companies with big infrastructure .etc, somebody may ask what does mean ‘big’ or when company needs specific type of protection. I suppose this is all about risk management. Having those applied into our company we have context and visibility – very often we are able to shorten incident response, and filter out tons of – let say – unknown activity.
Recently, on one of webinars, lecturer mentioned and pointed out, that 24x7 coverage is major component of efficient incident response. Attackers are smart guys, and very often they know when the risk of being caught is the lowest – summer/vacation time, weekends ... etc. Now, I would like to go through several important aspects of ‘modern threats’. BYOD and popularity of social media. In my opinion the increasing popularity and ease of using internet communicators app, smart devices are lowering security (on the other hand comfort level is growing).  Very often people who are using this devices/apps are not technical educated persons – they are not aware of risk and threats waiting for them. Cloud technologies, easy access to global net and fast internet are also a problem for security. Here I should write several words about insider threat. IT espionage, IT sabotage or just spying are known to IT security; and this is a serious problem in field of DLP/DRM.
Moving forward, to have a robust picture of what happened we should have digital forensic on board. Awesome technologies such as E-Discovery or Triage will be great idea for hunting or just quickly checking what happened. In depth-analysis could be performed with tools for post-mortem analysis (X-Ways, Encase, FTK, .etc). On the other hand we have wide range of capture – package appliances, which is a great source of alerts (+SIEM).
Having said that, do not forget about apps (huge problem with application in companies and validations/ white listing .etc). Pentesting and audit should be considerated. Another field and great opportunity for security is vulnerability scanning, code analysis and whitelisting.

poniedziałek, 7 stycznia 2013

How to detect malicious process?


Any process that we execute during our session, is done at our own risk and responsibility. There is no security mechanism or barrier preventing any processes from being infected or altered. On the other hand we have Bell–LaPadula model and controlled access to specific information within given security level. There are also AVs and other tools used for alerting. Apart from theoretical stuff, let focus on methods of host inspection and finding suspicious malware hiding somewhere, behind processes.

What problems can we face during host inspection?

We start looking for malicious files and processes when other automated tools and AV failed. You know, tons of security layers, but still our host got infected. What now? Possibly this can be a rootkit trying to hide itself and other malware, trojan – behaving as a normal, standard process or job. Just to quickly look at simplified work flow:

        1.  Try to stop spreading.
        2.  Terminate suspicious process. (processes can cooperate).
        3.  Delete binaries and files, verify  auto-run. 
        4.   Restart machine and check what is going on.

Basic and at the same time very often sufficient list of helpful tools : procexp.exe, procmon.exe, movefile.exe, msconfig.exe, autoruns.exe. Please follow  sysinternals -  the  best reference in this subject.

Great knowledge and comprehensive tool description can be found in “Windows Sysinternals Administrator’s Reference” written by Mark Russinovich. Please note that tools can be downloaded directly to the infected host, brought by investigator or executed from the web. To run the program from Internet Explorer just type http://live.sysinternals.com/nameOfTool.exe or just map drive  \\live.sysinternals.com with net use utility. The last thing to mention is.. practice makes perfect. So, the more systems you analyze (infected and clean) the better you are. Spend some time with listed utilities and start training. 

sobota, 5 stycznia 2013

Hacker Lifestyle

Here, I would like just to quickly mention two really great novels about hackers and their lives. First of all, both stories present the history, how it all began, and how hacking  evolved. At the same level showing biography of famous guys, their vision, passion and troubles. Really good piece of entertainment, for those bored, exhausted or burned out( just for the moment! :) ) - to stay focused and see what is on 'the other side'. Enjoy reading.    

      


niedziela, 30 grudnia 2012

Malware Response with Mandiant Redline


Redline is MANDIANT’s non-commercial tool for investigating hosts for any intrusion activity, and malware. It analyzes files and memory, making a threat assessment profile at the same time.  In just a few words great tool for live incident response, and data analysis. Instead of manual live data acquisition (manual approach is a bad idea anyway), we can use Redline Collector for volatile + non-volatile information collection – possible adding IOC-  and then quick analyze on investigator machine also automatically (with support from white lists and MRI). At the same time, results can be confirmed using Memoryze or Volatility, for more ‘controlled’ study. Below just quick description of Redline’s modules or features.

Rapid Triage:
Without need for installation and alteration to the system state, one .bat script can be run on the subject host. It audits all processes, driver, network connection. What is more Redline Triage can be used for file structure capture and memory dump. Great for live response for volatile data.

Reveals Hidden Malware:
Collector is capable of memory imaging and deep study. It works on the level of kernel, so malware(rootkits, hidden processes) that are present in the memory (possibly not on the disk) can be seen and become obvious.  

Guided analysis:
Below description taken from guide, presents the ideology of Redline, and purposes. The statement  “takes the guesswork out of the task and time allocation” is so true, and perfectly shows that the memory inspection or intrusion detection process is not an easy task.

MANDIANT Redline streamlines memory analysis by providing a proven workflow for analyzing malware based on relative priority. This takes the guesswork out of task and time allocation, allowing investigators to provide a focused response to the threats that matter most. Redline calculates a “Malware Risk Index” that highlights processes more likely to be worth investigating, and encourages users to follow investigative steps that suggest how to start. As users review more audits from clean and compromised systems, they build up the experience to recognize malicious activity more quickly.

Investigative Steps:
Another great knowledge goes from Madiant. It is obvious, but I really like when developers and IT Security pros recommend training and learning.

Redline can collect a daunting amount of raw information. The key to becoming an effective investigator is to review Redline data from a variety of “clean” and “compromised” systems. As you gain experience, you will learn to quickly identify suspicious patterns.

Malware Risk Index Scoring and MD5 Whitelisting:
Redline during deep analyze uses its rules and techniques to calculate MRI for each task in the capture memory dump/ live data. That MRI uses different colors to demonstrate risk. Of course there will be some false positives or false negatives, but Redline gives also an easy way for tuning. Furthermore, majority of processes are legitimate and standard. MANDIANT has made MD5 hashes for multiple OS’es  and its components. Whitelisting allows to filter out tons of information that are known and unaltered – definitely not interesting during intrusion detection process.



Indicator of Compromise (IOCs):
mandiant_ioc_finder.exe can be used to look for IOCs in the subject system. MAndiant has developed an open standard(xml) for defining and then sharing threat information.

Going well beyond static signature analysis, IOCs combine over 500 types of forensic evidence with grouping and logical operators to provide advanced threat detection capability.

We have several methods of data collection: Standard Collector/Comprehensive Collector/ IOS search collector. Each of them can be modified and later provide fast and predefined options for incident response. Memory image acquisition can be applied in all of them. The ‘Analyze Data” section provide several options. Simple we choose what we want to analyze (investigator workstation!) and what ‘external’ feeds should be added: do we have IOC report, or whitelist imported?


Last interesting option, nicely done:
"Analyze this Computer" option is offered only for training and demonstration purposes. It performs a robust acquisition and analysis of the local system, with options for saving the results. This is an great way to gain experience using Redline but is not recommended for investigations. For real-world use on multiple systems, follow the workflow for Using a Collector. It is important that Redline analysis be carried out on a clean and protected workstation: this is easily accomplished using the Collector to bring captured data from potentially compromised systems to a secure Redline workstation. Do not risk compromising your collected evidence!

Workflow 
Process delivered by Mandiant is rather straightforward : collect, import and investigate. While collecting and importing are very easy … investigation is also simple. We have several options when it comes for collecting (do not forget about IOC finder). Here we need to create new ‘case’ and only launch RunRedlineAudit.bat. on the compromised system. Please, remember about place for acquired data!  Once data has been collected from the host it must be imported and automatically saved as .mans database file.



Investigation
Typical investigation steps contain reviewing: MRI Scores, Network connections/ports, Memory Sections/DLLs, Handles, Hooks and drivers. Here, it is worthy to mention, that when analyzing DLLs, Whitelists should be used. Here we have also set of filters. What is more, we have a bunch of tools for memory image study and acquisition. Furthermore we can acquire a driver. Another great feature is The Timeline, which provides a time-ordered list of events (use TimeWrinkle and Time Crunch for filtering). To sum up, we have a great tool with set of awesome features. For sure, I will spend days getting to know better the Redline - as it is complex solution (adding MIR) connecting incident response, malware response, intrusion detection and dead analysis. I strongly recommend reading the 'investigation' part from guide, also the appendix about best practises.  

Source for manuals, whitepapers and software (+whitelist):

For more information about the IOC standard and IOC Finder, visit http://openioc.org/ and http://www.mandiant.com/resources/download/ioc-finder/




sobota, 29 grudnia 2012

Live Response with WFT


    The Windows Forensic Toolchest™ (WFT) is designed to provide a structured and repeatable automated Live Forensic Response, Incident Response, or Audit on a Windows system while collecting security-relevant information from the system. WFT is essentially a forensically enhanced batch processing shell capable of running other security tools and producing HTML based reports in a forensically sound manner. 
   This description taken form http://www.foolmoon.net/security/wft/ wouldn’t be written better, and perfectly tell us what is the WFT. In another words, it is a light shell-program with config file that can run security tools and do it automatically and prepare html report. It supports Windows NT/2K/XP/2K3/VISTA/WIN7 and is commercial. Good presentation of this tools can be found here.


As we can read from support : The tools included in the default configuration file do not make any  significant alterations of the system they are being run on.
This tool is a great framework for incident response, and intrusion detection. On the other hand can be used by administrator for problem handling .etc. What I would like to mention, is the fact of automatization. Very often we know what information we want to collect -  it can be pslist, fport, handles .etc – and every time we want that data collected. So this part or incident response is repeatable and can be achieved with success – with WFT. What is more the output is great designed, we have it in html and  in .txt mode. Developers did not forget about documentation. Every step taken by this soft is logged and this can be seen also in the standard output. Additionally, we can track all changes made be tools, and we are prompted that some extraction can take more or less time, and what alteration is being made (which .exes/.dlls are needed). Of course all activities and scripting are with  a sound methodology, also computing MD5/SHA1 checksums.  


In another presentation this sentence can be found : WFT should be run from a CD (or USB memory stick) to ensure the forensic integrity of the evidence it collects. In addition to the WFT binary, users will also need to copy any external programs it will be invoking to the CD / memory stick. Okay.. but what about remote forensics ? I would like to end here, next I will focus on remote methods of data acquisition, and how to do it, to keep sound methodology of data collection.