📱

Get Our Mobile App

Take your business learning on the go!

Download on the App StoreGet it on Google Play

CYBERSECURITY MASTERCLASS || SESSION 17 || Introduction to Digital Forensics

LOVE EMPIRE INTERNATIONAL40:38

Transcription

Okay, so, um, so this night, or tonight, we are discussing digital forensics. Okay. Uh, this is a, a very important aspect of, um, cyber security. So far, we have looked at different aspects of cyber security. We looked at the first thing we started with was networking, which is, um, the foundation. Uh, then we went, uh, we did a little bit of, uh, CLI, command line interface on C.E. and we did, um, uh, what again? Cryptography. Uh, what else have we done? Um, I think that should be all we have done so far. Okay.

So, um, today I'll look at digital forensics and what it is all about. So, um, digital forensics, the definition is very simple. It is a process of collecting, resulting, obtaining, analyzing, and presenting, um, um, digital evidence for investigations. Please take note of that definition, it is very key. Like the way the statement is arranged, that is how, um, it should be. First of all, you collect digital evidence. Uh, you are also mandated to preserve those digital evidence. You are to analyze those digital evidence, and at the end of the day, you make a presentation of what you have gained, what you deduced from, um, the digital evidence that you got. That's okay. So that they can use it for investigations. If you are very good with digital forensics, you can work with police. You can work with a lot, um, agencies. Okay. Like, um, in fact, currently there's a plane crash that happened in Virginia in the US that they are trying to investigate, uh, what actually happened to the plane. So as a digital forensics expert, you have a job in that place as well. Okay.

Um, apart from digital forensics, we also have other aspects of forensics. Like, uh, maybe, uh, those who do biology, they also, uh, also have aspects of forensics that they do. All these things, like, um, what do you call it? Uh, like trying to use chemicals to try to determine the age of maybe a particular bone, particular rock. All those kinds of things, that's also forensics. So, uh, what is the purpose of digital forensics? Uh, number one is to support criminal, civil, or corporate investigations. You know, there are different types of investigations. There are, um, we have seen criminal, we have civil, and we have corporate investigations. So, um, the purpose of digital forensics is to support these types of investigations. Secondly, is to recover and preserve critical data after a cyber security incident. So, um, like I said, in the US, there was a plane that crashed. So right now, they're trying to recover, uh, some bodies. They are also trying to recover the black box. I think they, they were able to recover that already. So from there, they will do some analysis to know what actually happened to, um, what happened that the plane collided with the helicopter. Okay.

So, um, the importance of digital forensics is one, to identify causes, um, of breaches. Like if your system or your network was breached, uh, by the time you carry out a digital forensics, you know what actually happened, how, uh, were they able to succeed, what method did they use, so that in the future, you can, uh, prevent such from happening. Another importance is that it provides evidence, uh, that can be used in court. Against, maybe you were able to arrest the person that committed the crime. So through digital invest, digital forensics, you can gather evidence that will, um, help in, uh, prosecuting the person in court. Okay. This, um, I know this very well because from time to time, my, one of my brothers works with EFCC. I also have a brother that works with ICPC. So from time to time, I help them to do one or two digital forensics for them. You know, most of these politicians, once they catch them, they normally, uh, seize their phones or maybe their computers. So they, if your phone is locked, or maybe your computer is locked, or there are ways you can go through the phone to check the information, whether it's locked or unlocked. Okay. So you can check the, maybe like their call history, check what they have shared, all those kinds of things. It, it also helps in, um, investigations. Okay.

So the last, uh, importance is that it helps organizations in improving security. So from time to time, as you are conducting digital forensics, it will be helping your organization because when you, as you are conducting your digital forensics, you are discovering, uh, loopholes. You're discovering, like, um, places where, uh, an enemy can easily attack, where a breach can happen. So you take care of those places. You know, it's just like in your house now, if you know a thief, if a thief wants to come into your house, he can follow this particular place. Uh, you would not wait for the thief to come before, uh, you start looking for how to block that place. You block it before, uh, the thief thinks of coming following them. Okay.

So in digital, um, forensics, there are processes that we follow when you're conducting your investigation. Okay. There are processes you follow. So the first process is identification, that is recognizing, uh, potential sources of evidence. So when you get, if a place was attacked, when you get there, um, I mind you, digital forensics mostly is, is after an attack has happened. Okay. Mostly, mostly is when an attack has happened that, uh, digital forensics take place. Okay. That's when the incident has taken place already. Okay. So when you get to the scene or wherever the incident took place, so the first thing you are looking at, you have to, uh, try to recognize potential sources of evidence. What are the things that you can gather as evidence from this place? Maybe there are things like, uh, flash drives, hard drives. Is there a computer? Is there, like, anything at all that can help your, um, investigation? Okay.

So when you have gathered all these things, the next thing that you are supposed to do is to preserve it, ensuring, uh, data integrity. You know, when we talk about cyber security, we talk about the, um, CIA triad. The CIA triad. So you ensure data integrity by creating backups and securing original evidence. Okay. Maybe you got, let's say, one of the evidence you got was a hard drive. So the first thing you do is to create a backup of, uh, that hard drive. If you have watched crime movies a lot, you see they always do that. Like when somebody recovers, maybe like a flash drive that contains very sensitive information, the first thing they do is to back it up, create a backup somewhere, so that if eventually, maybe another attacker comes and tries to steal that flash drive, they will still have a backup somewhere. Okay. So preservation.

Then the third, uh, uh, process is analysis. So this is where you now start extracting data, trying to interpret the data for, like, data that maybe have, uh, data that is broken. You try to reconstruct it. Okay. Now, before we continue, I want to let you know that for those of you that maybe, um, you normally have some sensitive stuff on your phone, those, especially maybe some ladies, you share your, uh, note pictures or not videos with anybody, then you delete it from your phone and you're feeling happy, like maybe you think you have gotten rid of it. Know that anything that you delete from your phone or your computer can still be recovered. So anything at all that you have deleted from your phone, as long as it is a digital file, if you have deleted it, it can still be recovered. So in fact, avoid creating such, such videos or pictures at all. Avoid, uh, be careful with anything you are putting online because once it goes online, even though you delete it, let's say you posted something and you later discover that I don't want this stuff, you deleted it. Know that somehow it can still be recovered. Okay. So to be safe, don't even post it at all for your own, uh, security. Okay.

So the third point, analysis, which is extracting, interpreting, then trying to reconstruct digital artifacts, like the ones that have broken, okay, maybe or maybe some that have been deleted, you try to recover them. Then, um, when you're done with this, you document it. That's recording the findings. What did you discover? Uh, what method did you use? What are the tools that, um, you use during your analysis to, uh, conduct this, uh, um, forensics? Then at the end of the day, you now do your presentation, maybe to your boss or to your team, and from there, uh, other people who need the information can take it from there. So you are done with your own, uh, aspect. If they need more questions, they can always come and ask you. Okay.

So we have, um, types of digital forensics. So one, we have the digital, uh, Dix forensics, rather. We have Dix forensics, and this, uh, is examining hard drives for deleted files. Just like I said earlier, anything you have deleted, as long as it is a, it is a digital file, there are ways these things can be recovered. So to be safe, don't even try creating it in the first place if you know, uh, you don't want it to exist. Okay. You know, like some people, uh, if, like most crime movies, you see somebody will quickly go and delete something from their system if they know that they're going to investigate and the investigation might catch up with them, they might get some evidence. They'll quickly go and delete such files. They can always be recovered. There are softwares you can use, um, to recover them. Then we have partitions, metadata. Okay. Metadata is like, metadata is like the information about a digital file. Let's say like a video now, when you create a video, there, that video comes with information. There's a metadata about that video, and there's a way to check it. Okay. I'm going to show you by tomorrow. I'll give you some commands there, the way you can check metadata of any digital file. Digital data will tell you when the file was created, where it was created. If it is like a picture now, they will tell you what kind of camera they used in snapping the picture, the location where they took the picture, you get? It will give you information. That's what they mean by metadata. It will give you like a breakdown of what is the size of the picture. It will give you a breakdown of that, um, information. If it's video, the same thing. It will tell you information about the video. Okay. What kind of device they used to create the video.

Then the second type of digital forensics is, uh, memory forensics, which is analyzing, uh, volatile memory like RAM, uh, for malware traces or running, uh, processes. Okay. Then we have network forensics. That's capturing and analyzing network traffic for suspicious activities. This is what we did when we were doing, uh, networking. Uh, all those pcap files that we captured and we were using Nmap and Wireshark to analyze them. Okay.

Okay, um, that's recovering data from smartphones. Is my network breaking? That's, I feel like the network is kind of breaking. Uh, we also have mobile forensics, which is, uh, this involves recovering data from smartphones and, uh, tablets. Any, uh, thing that looks like a phone at all. Anything that looks like a mobile phone. So you can recover data from smartphones as well. So if, like I told you before, organizations like ICPC, EFCC, when they arrest you, I know some of you used to wonder how they were able to determine that so-and-so person stole so-and-so amount of money or so-and-so person committed so-and-so crime. It's through analyzing their digital, uh, files. Okay. That's why you see most of these politicians, when they want to do their, uh, magomago or their wicked stuffs, you see that most of them, they don't use, for those of them that are a little bit wise, they prefer to use raw cash, like physical cash. They don't do bank transfers or anything that can be traced. Okay.

So, um, so we have mobile forensics. You can, anything at all that you have deleted from your phone, you can recover it. And we have cloud, um, cloud forensics, investigating data that are hosted on cloud services. Uh, this one is, uh, mostly maybe for like, yo boys, all those boys that do online, you know, some of them can host like a website and be using it to deceive people. So you can also do, uh, cloud forensics for such, um, yeah, even them too, you can do mobile forensics for them with their phone. You can know what they were, what they have been doing with their phone for. You can get logs of what they have been doing with their phones for the past one year, the past two months, past. You can see every chat, every phone call, everything they have done with their phone, who and who, amount they receive into their phones. You can get all those things just by having access to their mobile phones. So, um.

So we have some tools for digital forensics. Most of these tools are already on your C. Okay. So you can always go online and look for videos on how to use these tools. And but that should be at your own risk. You should be careful whatever you're doing. Make sure it is legal. Okay. For this forensics, we have what we call Autopsy. I know it sounds like that autopsy that they used to, um, perform on a dead body, but that's not it. This one is a software. It's like an application. They call it Autopsy that you can use to perform, um, big forensics. You can use it to recover, uh, information from like a hard drive, flash, and all of that. We have FTK Imager, EnCase. Then for memory forensics, we have Volatility and Rekall. For network forensics, we have Wireshark, TCPdump, and we have Zeek. I think we have used Wireshark somehow, though at that point, I believe what we were doing didn't look like interesting. For mobile forensics, we have what they call Cellebrite. This CBR is a very powerful tool, like very, very powerful. But unfortunately, it is, um, not free. You have to pay to get some assets into it. But with this tool, you can recover, uh, uh, mobile phone logs, whatever someone has done with your phone in the past few months, past, uh, two months, depending on what you want to get. You can use it to get information on somebody's mobile phone, whether the phone is locked or unlocked, it's none of your business. You can, with this tool, you can access the mobile phone. And we have, uh, this Magnet AXIOM. This Magnet AXIOM, I've not used it, but I know it's also a good tool. The one I'm very familiar with is right. For cloud forensics, we have, um, AWS CloudTrail. We have Google Workspace Investigation. You can check this Google Workspace Investigation. I think it's free.

So in digital forensics, there's something they call chain of, uh, custody. Okay. And what is chain of custody? It's a record of evidence handling from discovery to presentation. Like who and who have touched this evidence. Okay. Because at times, people can manipulate evidence. Yes, people can manipulate evidence. Like I was telling you guys earlier about, um, EFCC and ICPC, once at times, you just hear that they took so-so politician to court and at the end of the day, the case will just disappear. You'll be wondering what happened. The person paid somebody who is working in EFCC to make the evidence disappear. So anyway, this is Nigeria. So most of these things, they really, most of the time, don't really hold water like that. So outside the country, there's something, this chain of custody is very important. Like if there's any evidence missing, who, they have to trace who and who were handling this evidence, how did this disappear, what happened to it? Okay.

So, um, the importance of this is to ensure that evidence is, uh, admissible in court. Track who accessed the evidence, when, and why. Okay. So if you have access to the evidence, when and why they accessed the evidence. Are you part of the investigation team? Or are you also a digital forensics expert? And even if you're a digital forensic person, are you on the team that is working with the data, the evidence that has been gathered? Okay. So you label them. Once you get your evidence, you label the evidence. Like this is evidence number one, maybe it's a phone that you got from the person. If it's a, if you get a disk, you label it. This is evidence number two, hard drive, evidence number three, like that, depending on how many evidence you are able to, um, gather. Okay. And then you have to ensure that the evidence are secure, like maintain a secure storage environment that nobody can have access to. Okay. Like organizations like EFCC, ICPC, maybe even police, they have like a safe. I don't know if you all know what a safe is. They have like a safe, uh, where they keep, uh, all this evidence, and only some certain people have access to that safe. So if something is missing from that safe, they know, they know the person that they are going to hold. So they have like a safe, and only a few people will have the key to that safe or the code, or the safe that they are using code. Okay. And you have to record, like, every interaction with the evidence. Anybody that is coming in contact with the evidence, record. If somebody says, okay, I want to check this phone, and maybe the phone is part of the evidence that was recovered, you write the person's name, the time the person is taking the phone, what the person wants to do with it, when the person is done and returning it, write the time he's returning it, and if the phone is returning the way, uh, he took it, or something has changed. So all these things help in, uh, if there are discrepancies at the end of the day, maybe something is missing, they know what to do. Okay.

So what are some of the challenges in digital forensics? Um, data encryption. So some of the challenges you could face will be accessing encrypted files and drives. I believe you already know what encryption is. When, when we talk about encryption, we are simply saying files that have passwords. Okay. So encryption should not be a big word again. We did, um, um, cryptography already, so you should know what encryption is. So this is one of the usually one of the challenges. Um, and like I said, there are tools that you can always use for this to bypass, uh, such processes, depending on the type of encryption. Anyway, there are some encryption that, like, there are some phones that they are making now, if the phone is encrypted, if you try to, if you try to bypass the, the phone, the, the encryption, the phone will like self-destruct. I, what is the English I use? Like the phone will destroy itself so that you will not recover anything from the phone. So there are, phones like that. Even flash drives. In fact, even some computers, you can program your computer in such a way that if you, if somebody tries to enter the password, maybe the person enters the wrong password, maybe two, three, four times, the computer will just fry. It will burn. Okay. If you, if you watch some of these investigative movies, you'll see all of these things. It happens. Okay. Like a flash drive, you can program your flash drive in such a way that when you plug it into a particular computer, it copies everything that you want it to copy from that computer, and it will do it very fast and swift. Or maybe at times, you can even program a virus into that flash drive in such a way that when you plug it into a computer, it will just mess up the entire computer. Okay.

Another challenge is usually the volume of data. Okay. So let's say you recovered, maybe, uh, a hard disk, and the hard disk contains information, maybe like up to 2 terabytes. Imagine sitting down and trying to analyze all this, uh, data one after the other. So it could be another, uh, it could be a very big challenge. Right. The volume of the data. Then we have emerging technologies, like keeping up with cloud services, IoT devices, and advanced malware. You know, as you are discovering, uh, as people are looking for how to solve problems, more problems are also being created. So there are new technologies that are emerging that, um, we don't yet know how to crack through those, um, technologies, how to access those technologies. Okay. Then legal complexities, like navigating international laws and jurisdiction. You know, you could have somebody's phone. Let's say you arrested somebody and you got their phone. If another question you ask yourself now is, is it actually legal to access this person's phone? Okay. Because first of all, you have not convicted the person. You are not sure yet. So is it legal to access the person's phone? Is it legal to access the person's computer? If the person refuses to give you access to their computer or to their phone? Okay. Is it illegal? So depending on, um, the law, laws of that jurisdiction or the country where you are, or the state where you are. So this could also be like a challenge because if you access somebody's phone or computer without their knowledge, at the end of the day, they could sue you, and it will become another problem. Okay.

Um, so what are the applications of, um, digital forensics? Like we earlier said, um, digital forensics is used in criminal investigation, that for solving cyber crimes like fraud, hacking, and identity theft. Okay. So digital forensics is also, uh, used for corporate investigation, internal, uh, investigation for data leaks or compliance. Let's say a sensitive information, you know, like at times when, um, the president is planning to do something, at times you just hear that there's something leaked, or maybe APC is planning something wicked or one bad thing, and before you know it, you just hear that there's something leaked and PDP was able to know what is happening, and before you know it, the thing goes viral, and you'll be wondering how this information keeps leaking. So there are ways to investigate to know who, uh, leaked the commission, who compromised. So that's why they are referring to as corporate investigation. Then we have incident response, uh, supporting post-breach recovery by identifying the root cause. That's similar to like corporate investigation, and then followed by, uh, legal proceedings. You know, like, um, the last election that they did where, uh, Labour Party and PDP claimed that the elections were rigged. Right. In fact, right now, there's also another legal, um, battle in Edo state where the PDP are claiming that elections were rigged. So if you have a very good, um, digital forensic expert that can analyze those BIVRs and know how they really work, and if people were, uh, people actually voted for who and who people actually voted for. Okay. With that BIVR, you can be able to, um, analyze your information. But like I said, our country, we are still coming up. We don't really have, uh, some of these things yet. But these are things that are very, very possible to work with. And in fact, that is even the essence of using that BIVR in the first place, so that in cases of, uh, conflict like this, they can go through it and be able to, uh, sort out what actually happened. Okay.

So, uh, reward cases, case studies. We have case study one, investigating a ransomware attack on a healthcare organization. Okay. Let's say somebody attacked a database of, uh, healthcare, uh, organization using a ransomware. This is what is ransomware before we continue, because these are some of the things we started with. What is a ransomware? Just drop your answer in the comment. What is a ransomware? And if you can explain how it works. Okay. So, uh, the tools that you can use for such, for this kind of, uh, an attack. Okay. The tools for this is memory forensics or malware, um, analysis. And what will be the outcome? Identification of the attack vector and then recovery strategy. Nobody has dropped an answer yet. Then we have case study two, which is analyzing insider threat in a financial institution. When we talk about financial institution, it could be a like microfinance bank or central bank or a normal commercial bank. Okay. So, uh, what are some of the tools that we use here? We use network and Dix forensics. And then what will be the outcome? Uh, preventing further, uh, data exfiltration. Thank you. That's a good, um, definition. Holding someone that are hostage. Yes, Fred. I like your definition. It's, uh, straightforward. Okay. So, uh, a type of malware that encrypts data. Ransom is then demanded for. Yeah. So you guys are giving correct definitions. I believe you went to check somewhere because it took you time. Don't mind me. Okay. So, uh, let's look at careers in digital forensics. So what are some of the roles that you could play as a digital forensics expert? You could become a digital forensics analyst. If you are very good with this, okay. If you are very good with, uh, this stuff, you could become a digital forensics, uh, analyst. You could become like a cyber crime investigator. So these are some of the careers that you can follow if you want to be in this part of digital forensics. You could become an incident response specialist, and you could also become a forensic consultant. If you are able to get those. In fact, most, um, the most important thing with digital forensics is having the tools. Okay. Once you have the tools and you understand the processes, you are good to go. Okay. Because those tools are usually very expensive, and they are not very common. The tools are very expensive to access, to get access to. Okay.

A ransomware attack is a cybercrime where malicious actors gain victim computer system. Thank you. Thank you. For me, I don't know who is this 101. I've told you guys to change to your real name. Somebody is still using 101. What is 101? Okay. Uh, so what are the skills needed if you want to become a digital forensics expert? You need strong knowledge of operating systems and networks. With it, networks, we have not really taken time to deal with operating systems, but this is a knowledge that you need if you want to do, uh, digital forensics. You need very strong knowledge of operating systems, both Windows, Kali, whatever type of operating system, MacBook. You need to understand how those operating systems work. Okay. Then you need expertise in forensic tools and methodology. Uh, like I said before, one of the most important things in digital forensics is understanding the tools, having the tools, and understanding them. Okay. Then you also need to understand the legal and, um, you need to have the understanding of both the legal and ethical aspects of digital forensics so that you don't fall into, uh, trap, you don't find yourself, um, doing something illegal. Okay.

Um, so in conclusion, digital forensics is a cornerstone of, uh, modern cyber security. Its roles extend from preventing crimes to aiding legal processes. A career in digital forensics offers exciting opportunities to combat cyber threats and protect valuable information. Okay. So this is the end of our slide. By tomorrow, we go straight to CyberTalent and solve, uh, some challenges so that you also have, uh, it will help you get more understanding of how, what all these, uh, things we are talking about that look very strange. So be on CyberTalent tomorrow to, um, solve some, some challenges. Then after that, we are going to have, uh, assignment. After that, we have, uh, assignment.