Showing posts with label forensics. Show all posts
Showing posts with label forensics. Show all posts

Thursday, November 12, 2009

Don't cry over spilled COFEE

This morning I was looking at my Information Technology daily news feed from Infragard, which is supposed to be sensitive information but only ever contains links to public web sites and a brief discussion of the link. Anyway, in this morning's edition there was some discussion about Microsoft's COFEE being leaked into the wild and a link to this article:http://www.darkreading.com/security/vulnerabilities/showArticle.jhtml?articleID=221600872. Generally there seems to be terror surrounding the release of this tool. Here are the two money quotes:
"the danger is that a detection tool will be written for COFEE so that the bad guys can cover their tracks."

and
"One researcher who got a copy of COFEE online says bad guys could abuse the tool by taking one of its Dynamic Link Libraries (DLL) and loading it into a compromised machine’s memory, where it then dumps stored clear-text passwords to a file."

I believe these feelings are being expressed by people who probably don't know much of the fundamentals of forensics or information security. I could see this being very disturbing news for a law enforcemet agent that doesn't know anything other than "insert this magic USB stick into a computer and magic happens and you get the stuff you need."

Sure, somebody could write a rootkit that watches for COFEE and starts trashing evidence, and it probably will happen before too long. So what? Many of us use DD to image the memory on a computer and the same threat has existed for us, and we're not freaking out about it. If malware writers started to do that, they would just end up on the same hamster wheel that anti-virus writers are on. Today your malware can detect COFEE so we pack the code differently. Now your malware has to detect two signatures for COFEE. And so on, and so on, and so on.
And so I find myself in agreement with Microsoft's Richard Boscovich, an attorney in the Internet Safety Enforcement Team.
"we do not anticipate the possible availability of COFEE for cybercriminals to download and find ways to 'build around' to be a significant concern..."
Unfortunately, that quote didn't make it into the Infragard summary of the article, which is too bad because I think that is the money quote. Here is the next best quote from the article:
"COFEE was designed and provided for use by law enforcement with proper legal authority, but is essentially a collection of digital forensic tools already commonly used around the world. Its value for law enforcement is not in secret functionality unknown to cybercriminals -- its value is in the way COFEE brings those tools together in a simple and customizable format for law enforcement use in the field."

The second quote from above is what really steamed my broccoli; the one about dumping clear text passwords by loadingg a DLL into memory. Obviously there are the security problems about any program that is keeping passwords in clear text, and users should be purging themselves of such software. Mainly thought, I feel like that functionality is actually exploiting a vulnerability in Microsoft's code and should be patched. Seriously, if such functionality exists (and I'm not positive that it does) this should be considered a major security flaw. Unfortunately I can't give you an educated opinion on this because I'm not a law enforcement agent and so I can't see the secret program. Here is a decent write up of what it can do: http://praetorianprefect.com/archives/2009/11/more-cofee-please-on-second-thought/

Verdict: everybody chill out. No big deal. Nothing to see here. Move on.

Thursday, July 9, 2009

Sometimes a burden is worth it.

I just read this legal opinion from Voom about a recent Supreme Court decision. http://www.prweb.com/releases/Justice_Scalia/cybercrime/prweb2620114.htm This quote sums up article fairly well.
In a U.S. Supreme Court ruling handed down last month in the case of Melendez-Diaz v. Massachusetts, the Court held that "certificates" of forensic findings were admitted in error. In a controversial 5 to 4 vote that reversed the judgment of the Massachusetts Appeals Court, the Supreme Court held that admission of notarized forensic analysts' reports violated the defendant's 6th Amendment right to confront witnesses against him under the Confrontation Clause. In the absence of live testimony by forensic analysts, such evidence was precluded.
The Voom analysis indicates that there is a likelihood that this decision will add an undue burden to forensic analysts around the country. The ruling was not limited to "conventional" forensics like what you see on CSI either, it also includes digital forensics. So it is possible that whenever a lab produces a report of its findings, an analyst may have to show up in court to defend it. I would like to go on record saying that I support this decision, and I think that in the long run it may work to REDUCE burden on forensic workers.

A while back I was commenting on whether people should sue PCI QSA's that report incorrect findings, and I said that I think that is a good thing too. The reason is because it protects the integrity of our field. If a QSA has subpar practices they would hopefully be sued out of business and the whole field would be better off. If QSAs ever gained a repution for being expensive people that you can pay to say anything then you would have a couple bad things happen. First a "race to the bottom" with other people coming in and agreeing to say anything for a little less than the last new entry in the QSA field. Followed up quickly with PCI moving away from QSAs in favor of some other group that doesn't have a bad reputation. So while it is burdensome for QSAs to face litigation over their decisions, it is less burdensome than going through a few years of declining profits followed by searching for a new job.

Some of these principles apply in the case of digital forensic work too. I don't think there is anyone in the digital forensics field that would argue with me when I say that the integrity of the profession and the public perception of that integrity is one of the top five most important things to the continued success of the field. How do you gain integrity? By withstanding scrutiny time and time again. Now as it stands today, there isn't a great deal of competition in the digital forensics field. It would be difficult to call up the FBI lab at Quantico, Virginia and pressure them to find evidence that supports your case with the threat that you'll take your business elsewhere. There aren't many other places that you can take your case, but that is quickly changing as the availability of education increases and demand continues to stay high. If we were to bless all of our forensic professionals with the ability to write a report and not have to face cross examination then you would invite less honest people into the field, and eventually for a price you could get someone to say anything. Finally we would reach a place where prosecutors and defendants each show up to court with their notarized certificates from the lab of their choice and both would be worthless. Even if the prosecutor got his certificate from an honest lab, it would be cancelled out by the dishonest report issued by some other lab. The way we deal with that now is through cross examination and if this Supreme Court decision had gone the other way we might have lost that valuable check on our field. And before we get to that place we have people that will be sent to jail because of a report from someone that doesn't have to come to court and face cross examination.

Does this decision add more work for forensics professionals? Yes it does, but probably not as much as you might think at first glance. Quantico deals with a million cases every year, but the vast majority of them do not make it to trial because of plea bargaining. Most of the time, the crime lab will submit a written report and that will be presented to the defense and they will say "let's make a deal." Sure, if even 10% of those cases go to trial you end up with 500 employees having to deal with 100,000 trials. But I think it is less burdensome than allowing the integrity of the profession to rot and then having to deal with the consequences of that. Also, by placing more work on our forensic professionals we will increase demand for more of them, which will lead to higher salaries and more job security. That is also good for the field.

So maybe I'm wrong about this, but I'm not terribly upset with the Supreme Courts decision. If you think I'm wrong, feel free to leave a comment and set me straight.

Wednesday, April 15, 2009

PI License for Forensic Work in Texas Revisited

I've talked about the ongoing debate about requiring Private Investigator licenses for people doing computer forensic work before.  I've also talked specifically about the requirements in Texas because of the unintended consequences that came of it.  See Texas screws the pooch even harder for more details.


The SANS Forensic blog is reporting on some changes to the Texas Requirements that people performing computer forensics get private investigator licenses.  A bill has been introduced in Texas to amend the Business & Commerce Code to define what a "Computer data recovery specialist", "Computer forensic analyst", and a "Computer technician" is.  The bill also makes changes to the Occupations code and changes the licensing requirements for some computer work based on the definitions that were added to the Business & Commerce Code.  You can find the bill here: http://www.legis.state.tx.us/tlodocs/81R/billtext/pdf/HB02564I.pdf and the law currently in place here: http://tlo2.tlc.state.tx.us/statutes/docs/OC/content/pdf/oc.010.00.001702.00.pdf


I am not a lawyer, but I can read fairly well so here is what I think is going on.  Don't take any legal advise from me though.  Let's start with those definitions.  


Computer data recovery specialist: dude that recovers data, but not for evidentiary purposes.


Computer forensic analyst: dude that acquires data, or dude that analyzes data acquired by someone else for the purpose of providing evidence in actual or potential civil or criminal proceedings.


Computer technician: dude that repairs computers, including the software.


The first change in the way we do business also comes in the Business and Commerce Code.  Section 107.002 of the proposed amendment requires all three of those people defined above to get a statement before they perform any work on a computer.  That statement basically would say that the facts presented in the work order are true and that the computer being analyzed has been legally obtained.  In other words, it is being presented for work by the owner or it has been authorized by a court of law (think search warrant).  Forensic analysts and computers technicians do not need this if they are working on their employers computer.


OK.  So far things seem fair.  I know that lawyers are able to take straight forward sentences and make them mean something else, but I would say that I agree with the spirit of the changes so far.  I don't think it is terribly burdensome to make people sign off that they own or have legally acquired the data they are asking someone to analyze.  Under the proposed changes, not getting these statements is a class C misdemeanor.  Under Texas penal code, Title 3, Chapter 12, Subchapter A Section 12.03 (c) "Conviction of a Class C misdemeanor does not impose any legal disability or disadvantage."  Section 12. 23 states that "An individual adjudged guilty of a Class C misdemeanor shall be punished by a fine not to exceed $500."  http://tlo2.tlc.state.tx.us/statutes/docs/PE/content/htm/pe.003.00.000012.00.htm


Next we should look at the changes being made to the Occupations code.  First, we should look at the easy to understand stuff.  Section 1702.104 is getting a subsection C and D added onto it, and some changes to subsection B.  Subsection D is really easy to understand.  The repair or maintenance of a computer does not constitute and investigation for purposes of this section ad doesn't require a license as long as the technician isn't gathering evidence.  The change to subsection B is pretty easy to grasp too.  It says "all the language that is in here now stays, but we're making exceptions for the stuff written in subsection C and D.


So that leaves us with the change to subsection C.  So now we need to look at the current law on the books and kind of understand what section 1702.104 says.  The whole chapter talks about the licensing requirements of various people, include investigations companies.  According to section 1702.104 a person acts as an investigations company if they are engaged in the business of obtaining information related to crimes, or locations of stolen property, or the general information about a person.  Subsection B of 1702.104 specifically calls out computer forensic.  It says that doing any of that investigating I talked about above includes investigation of computer-based data not available to the public.    Remember that the bill introduced leaves subsection B as it is but says that there are two exceptions which are listed in section C and D (computer repair man).  Section C says that obtaining and furnishing information does not include obtaining for furnishing computer data by a forensic analyst as defined up above in the Business & Commerce Code.  That kind of work does not require a license under this chapter.  Chapter 1702 of the Occupations code relates to private security and the licensing necessary to act in those job roles.  So the proposed bill makes it so that forensic analysts and computer repair people are not being lumped into the same requirements as private investigators, people that install security alarm systems, armored car drivers, etc.


The definitions that are applied here are pretty specific to computer forensics though.  I wonder if a forensic accountant would be required to get a private investigators license to do business in Texas.  Overall, I am happy with the changes if I am reading them correctly.  It removes the requirement that you have to qualify as a private investigator before you can analyze a hard drive which I think is asinine.  It puts some very reasonable restrictions on the practice of forensics (requiring a signed statement of ownership) and it leaves the door open for other requirements to be imposed on digital forensic analysts that actually pertain to the work they do.  


I want to be clear that I am not opposed to having some licensing requirements for forensic analysts.  I think that requiring someone to have some number of hours of experience before they can work unsupervised or present their findings in court is reasonable.  Requiring 6000 hours of experience as a highway patrolman pulling over speeders shouldn't be sufficient to be licensed as a digital forensic expert...just like 6000 hours of being a digital forensic expert shouldn't qualify you to be a private investigator.  I'm not opposed to background checks or requiring analysts to carry errors and omissions insurance.  All I want to see is that if states are going to impose some licensing requirements on digital forensic analysts those licensing requirements should be relevant to the work they do. 

Wednesday, January 14, 2009

Forensics: Live memory analysis

I just saw a link to this video on the Volatility blog and I wanted to share it here. Normally I try not to retread stuff that was just said somewhere else, but I also really want to hype up this video. If you've been wondering why the forensic community is putting more focus on live system analysis and specifically memory analysis then you should definitely watch this video.
http://vimeo.com/2810702

In the video, the presenter touches on some of the stickier points of live system analysis...namely that some of the forensic hardliners disapprove. The main point of disapproval is that these tools will make changes to the system, and we try to avoid doing that. That is true and valid, but I've come to find that RAM contains artifacts so valuable that only a fool would throw it away.

Mike Murr, who taught a forensics class that I took a couple years ago talked about it briefly. I remember that he compared memory analysis to holding the shutter open on a camera. The resulting picture will be blurred in some places because things were changing while the film was being exposed. However, that doesn't mean that you can't get useful data from it. Image a court room, for example, where you've placed a camera in the back with the shutter open. When you develop the photo you're still going to be able to make out features of the room. You would know if there was an open window in the front for example. You probably couldn't make out the faces of the jurors, but you could probably tell if there weren't 12 of them. So while you don't get an exact copy, and you've made some changes to the system, it is still a worthwhile effort.

So for my bretheren in Higher Ed especially, please consider working memory analysis into your incident response plans. Even if you don't have the expertise to examine the image yourself, you can easily gather vital evidence that may be useful to law enforcement agencies if you ever need their help. Check out the video above, and then practice using tools like Win32DD to gather memory images.

Thursday, January 8, 2009

Fear and Terror! All your data are being stolen!

Wow, this is just asinine, with emphasis on the ass part. http://news.bbc.co.uk/2/hi/technology/7816446.stm

This article is telling everyone that if you really want your data to be safe when you throw away your computer, you need to beat the thing to a pulp with a hammer.
The most straightforward solution, according to Which?, is complete destruction - and it recommends using a hammer.

If you're that worried, get rid of it properly: burn it or put it in acid.
Frankly, I think that this article is irresponsible. In a nutshell, the article is saying that yes, you can find software out there that will erase your data securely, but the only way to be completely positive is if you beat your hard drive with a hammer. This, I believe, does a disservice to the non-computer experts of the world. Consider a case of two identical hard drives, one beaten to pieces and the other overwritten a single time with random data. Which one would be easier to retrieve data from?

The answer is the broken one. Now I wouldn't want to be the guy to have to do it, but you can piece together all those broken platters and recover data from them. I was watching Forensic Files a few months ago and they had a case where someone had cut up a 5 1/4 inch floppy drive with scissors and the Department of Defense was able to piece it back together and get the data. On the other hand, recovering data that has been overwritten with other data is as close to impossible as I would say you can get...and it becomes less possible as hard drive densities increase.

Once upon a time there was a man named Peter Gutmann who suggested that with the use of an electron microscope you might be able to figure out what was once written to a part of a hard drive that had been overwritten. That lead people to come up with policies like "you have to overwrite 7 times before it is safe to dispose of." However, despite all the assurances I've heard that it can be done, nobody knows anyone that has actually done it. A couple years back I took a forensic class with Mike Murr from the SANS institute and he was talking about this very thing. Everyone knows someone that has done it, but nobody has done it themself.

I should be clear that I'm talking about data that has been deleted and overwritten by the operating system or some other software. Here is a great quote from the Wikipedia entry on the subject:
Daniel Feenberg, an economist at the private National Bureau of Economic Research, claims that the chances of overwritten data being recovered from a modern hard drive amount to "urban legend".[3] Daniel Feensberg also points to the interesting fact, that the "18 minute gap" Rosemary Woods created on the tape of Nixon discussing the Watergate break-in, has not been recovered. An easy task compared to recovery of a modern high density digital signal.
I'm worried about people like my dad. He's going to read something like this and instead of looking for some free software to clear his old hard drive, he's going to take it out to the garage and hit it with a hammer. He's going to go through all that work and possibly give himself a heart attack when he could have sat in his living room chair, watching TV and actually had better protection. Poor dad. Please don't let this happen to your dad. Spread the word that overwriting or encrypting your data is more effective than pulverizing it.

Monday, January 5, 2009

Pointsec for PC: Master Boot Record Analysis

Occasionally when people are thinking about dual booting computers with Pointsec I get asked about what changes Pointsec makes to the Master Boot Record. The short answer is, none. Pointsec installs its boot code to the Volume Boot Sector. At least that is the stock answer from Checkpoint. Last night I decided to check it out for myself. The following is a harrowing tale of forensics and Pointsecery, but if you don't feel like reading it all, then you can take my word for it. Pointsec doesn't make any changes to the Master Boot Record when it is installed.

So the first step is to establish my hypothesis. Here they are:
H1: Installation of Pointsec does not result in changes to the Master Boot Record.
H2: Installation of Pointsec does result in changes to the Volume Boot Sector.
To test my hypothesis, I created a virtual machine using VirtualBox and loaded Windows XP onto the machine. Then I booted to a Helix disk which allows me to do forensic analysis of the disk.

Once inside helix, I opened up a command prompt so that I could gather the Master Boot Record of my Windows machine. For those of you that are not familiar with File System Forensics, the MBR consists of the first 512 bytes on the hard drive for DOS based systems. I wanted to capture the MBR from this virtual machine on my Mac, so I also opened a command prompt on my Macbook and set up a netcat listener with this command: nc -l 8000 > mbr1.txt. Back in the virtual machine I used dd to gather the MBR and copy it over the network to my Mac: dd if=/dev/hda bs=512 count=1 | nc ip_address_of_mac 8000. To sum up, on the Mac, netcat set up a listener on port 8000 and any data sent to that listener was copied to a file called mbr1.txt. On the Virtual machine dd will copy from the hard drive (/dev/hda). The block size is 512 and we are going to copy one block. The output of dd will be piped into netcat which will set up a connection and transmit the data.

Now that I have my MBR copied, I want to create an MD5 hash of it so that I can quickly detect any changes. On the Mac I typed md5 mbr1.txt and got b8ce0ea32fdf9706ff7b17eac93d7ea4.

Now let's take a look at that Master Boot Record. I opened up the MBR with a hex editor, in this case xxd, xxd
mbr1.txt | less. There are two important things to look at in the MBR, the boot code and the partition table. The boot code consists of the first 446 bytes of the MBR. After that you've got the partition table. Here is a photo of the one I copied from the virtual machine. Notice that at the very end you'll find the hex 55aa, which is the signature for the end of the MBR on little-endian systems like mine. The line labelled 00001b0: is the line where the partition table begins and the last set of four is the specifc place where it starts. It begins with the code 80 which means that this partition is bootable. On the next line, in the second grouping of four we see the code 07, which means that this is an NTFS partition. This partition entry ends where all the zeros begin which tells us that there is only one partition on this system.

The next thing I wanted to do was get a copy of the Volume Boot Sector, which is also known as the Partition Boot Record. (PBR). So from my virtual machine that had been booted into Helix, I opened a command prompt. I typed the command fdisk -lu /dev/hda to get a list of partitions, and as expected it came back with one. The partition starts at sector 63, and since my sectors are 512 bytes in size, that means that it begins 32256 bytes into the drive. So I set up my netcat listener again and used the following command on Helix to copy the PBR: dd if=/dev/hda bs=1 count=512 skip 32256 | nc ip_address_of_mac 8000. Once the PBR was copied, I ran an md5 hash of it and got 46223945ddf87f223fc8850483b99cf0. The picture on the left is the Volume Boot Sector from my virtual machine. Notice the first three bytes, 0xEB5290. This is a jump instruction that tells the computer where to go for its next instruction.

Alright, so we've established our baselines. The next step in my experiment was to install Pointsec on my virtual machine. I went through the installation, rebooted, logged in and waited for the disk t
o start encrypting. Then I shutdown and booted back into Helix.

So I ba
sically repeated the same process as above. I opened a command prompt and copied the Master Boot Record to my Macbook. Then I ran the md5 hash on the second MBR and found that the hashes are the same. Pointsec made no changes to the Master Boot Record on the virtual machine. However, when I checked out the Volume Boot Sector the hashes did not match, which is what I expected. Further inspection of the Volume Boot Sector showed that the jump instruction at the begining had changed to something else. This supports my previous knowledge on the subject of how Pointsec boots. The computer boots the MBR and the MBR sends the computer to the active partition where the Volume Boot Sector contains additional code. Pointsec changes the jump instruction so that instead of running the Windows code, the Pointsec code is run first.

So let's follow up on my hypothesis:
H1: Proven true in this case by the MD5 hashes. No changes to the MBR.
H2: Proven true in this case by the MD5 hashes. Changes to the jump instructions and possibly other changes.

Tuesday, December 23, 2008

PI licenses for forensics: Texas screws the pooch even harder.

I just read this blog posting from Benjamin Wright talking about some decisions made by the Texas Private Security Bureau. Benjamin has been keeping a close watch on this issue in Texas and his input on the subject has been very valuable.

In previous articles, Benjamin has talked about the law in Texas requiring Private Investigator licenses for persons performing digital forensic work and how that law was being used to challenge tickets issued by red-light cameras.

Now the Texas Private Security Bureau has issued a decision that makes it OK for the red-light cameras to operate, but I'm afraid that it muddies the water about who can and cannot perform digital forensics without a PI license. And I have to disagree with Benjamin's conclusion that this is probably a step in the right direction. I have been very clear about my opinion that the whole notion is completely bunk, and this new decision doesn't help the digital forensic field because it allows the government in the state of Texas to sidestep the B.S. that comes with this law, but everyone else still has to shovel it.

I also think that my reading of the decision left me with a different conclusion about the rational that the Bureau used to justify their decision than what Benjamin reported on. The main reason that the Bureau does not see a problem with the red-light cameras is that they are operated by municipalities, and the government is exempt under the Texas law. The Bureau felt that the contractors are only providing ministerial work for the municipalities.

I feel that this decision skirts the intent of the law as it was passed. In theory, the reason this law was passed was to ensure that people's rights were not violated when an untrained, unlicensed person undertook an investigation. If we accept for a brief moment that having a PI license does make you more qualified to perform the investigation then this decision is in essence allowing the government to use unqualified persons to perform digital investigations. I mean, I understand that a police officer is trained in how to gather evidence while protecting people's rights, but these cameras are probably operated by some dude in the IT department. That dude, by the way, has no more forensic qualification than I do. So when a private organization wants to investigate something they need to hire someone with a PI license to protect everyone's rights. But when the government wants to investigate something they don't need to hire someone that has special training on the matter. The libertarian in me is screaming that the people need just as much protection from their government as they do from corporations. The government in Texas can use unlicensed investigators to gather evidence against you, but you need to hire a licensed investigator to counter that evidence.

This decision by the Bureau also leaves us scratching our heads as to how much work an unlicensed investigator can do for the government and still fit the definition of ministerial acts. For example, the red light cameras are simply gathering evidence. Does that mean that acquiring a hard drive image is also simply a ministerial act? What if the investigator takes special steps to gather data from a Host Protected Area or Device Configuration Overlay? Where does it stop?

So I am very disappointed with this decision. By allowing the State government of Texas to avoid the pain of this law, there is a reduced probability that sensibility will prevail and the law will be changed. People in Texas are going to be hiring Sam Spade to do their forensic work and talented IT people who have a passion for technology will be kept out of the business.

Sunday, December 7, 2008

More on PI Licenses for Digital Forensic Work.

There has been a little more chatter on the subject of private investigator licenses for people performing digital forensic work, or in other cases perform digital investigations.

Here is a short piece by Ben Wright (who commented on my blog the other day) about unintended consequences in Texas from their law requiring PI licenses for computer investigations. Hint: People are challenging tickets issues by red light cameras.

I also found a posting where the State of Michigan has defined what it would take for you to be a private investigator working on computer forensic cases. I have to actually say that I'm not up in arms about what Michigan has done as much as what I've seen in Texas. The Michigan law requires you to be a private investigator, but you can become a private investigator by getting certified as a computer forensic specialist and they had defined what exactly they expect from a certification program. So rather than tell me that I have to spend 10,000 hours working for someone peeking in peoples windows to catch cheating spouses before I can do computer forensic work, I have been given the option to complete a reasonable amount of study in areas that make sense for what I would want to do. Kudos to you Michigan.

There is still the problem of defining what an investigation is. Many times system administrators have to figure out what is causing a problem on their systems...and sometimes that problem turns out to be people. At what point would you say that their work has become an investigation? Is it an investigation if you set out from the start to catch a criminal as is the case for the red light cameras in Texas? What if a student comes to the help desk with a computer that is acting funny and I start to investigate? During the investigation I might go through log files, and I might run tools like Seccheck and rootkit revelaer. Maybe I'll even take a snapshot of the ram and look for running processes or open ports that are hidden. What if during this process I figure out that someone intentionally installed bad software on the computer and I figure out who did it? Has all the evidence been spoiled because I am not a private investigator and I didn't know that in helping this student out I was going to find evidence of misuse?

I'm also still not a big fan of the whole private investigator license anyway. Even though Michigan has done something to make it easier to swallow, I still don't want to be a private investigator. I am a computer security professional, and I don't want to be lumped in with a group of people 95% of whom do not do what I do. I can't show up to a industry meeting of private investigators and start talking about extracting strings from a hard drive image to find useful files that are hidden in slack space on a hard drive. If it is so important that we forensic types prove our worth then come up with some other licensing for us. Most state legislators recognize that even though coroners do investigative work, they are completely different from private investigators and have different licensing requirements. If there are any states where you can be a county coroner just by getting your PI license then let me know so I don't visit. I don't want Sam Spade performing an autopsy on me.

Saturday, September 6, 2008

Private investigator licenses for digital forensics

A few days ago I posted about the growing trend to exclude people from the digital forensics field if they are not members of a law enforcement agency. I guess that I'm not the only person that feels that way since the American Bar Association has passed a resolution urging all the states to avoid the folly of requiring private investigator licenses for people practicing digital forensics. I quote:
RESOLVED, That the American Bar Association urges State, local and territorial legislatures, State regulatory agencies, and other relevant government agencies or entities, to refrain from requiring private investigator licenses for persons engaged in:
computer or digital forensic services or in the acquisition, review, or analysis of digital or computer-based information...

The traditional role of private investigators is significantly different from that of a computer forensic or network testing professional and may licensed private investigators have little or no training in these areas.

The public and courts will be negatively impacted...because not all licensed private investigators are qualified to perform computer forensic services and many qualified computer forensic professionals would be excluded because they are not licensed.
There was also a great breakdown about states which require a license, and states where there is some ambiguity about requiring a license. Here are the states the most definitely require a private investigator license for digital forensic work: Illinois, Texas, Michigan, Georgia, Rhode Island, South Carolina, and coming soon North Carolina.

In these states a license may be required: Massachusetts, Nevada, New York, Arizona, Arkansas, California, Connecticut, Hawaii, Iowa, Kansas, Maine, Maryland, Minnesota, Montana, New Hampshire, New Jersey, New Mexico, Ohio, Oklahoma, Oregon, Tennessee, Utah, Vermont, West Virginia, and Wisconsin.

So already in 64% of states it is either illegal to perform digital forensic work without a private investigator license, or there is some ambiguity and doing so might open you up to trouble down the road. I fear that the trend has already gone too far.

I can only guess what the arguments are in favor of licenses. I honestly can't find a website where someone has claimed that this is a good idea. There seems to be almost universal agreement that this is a bad idea, except in the state legislatures of our country.

Monday, September 1, 2008

Digital Forensics: Nerds need not apply

When I first got my job as an information security professional, I took a great interest in digital forensics. I felt that there was a lot of science in digital forensics, and I felt that it was an area where there were still a lot of discoveries to be made. So I took a couple classes on forensics, and I started reading a lot of books. I started running experiments of my own and developing the procedures that I would use to respond to incidents on my network.

This was all very valuable to me, and I do believe that my information is more protected now that we have documented procedures in place to respond to incidents. But I was hungry for more. I wanted to learn more about forensics, I wanted to be involved in more investigations, mysteries, and experiments. It takes a lot of work to keep up on the various digital forensics techniques, but I was willing to do the work because I really liked what I was doing. A few months ago I gave my first presentation at a national IT conference and it was on computer forensics for universities.

But it seems like things are getting harder. It is a lot of work, but I can keep up with the new developments in registry analysis, memory acquisition, and network forensics. What I can't get past is the forces in the industry that seemed determined to shut me out. For example, there are some great forensic conferences each year where outstanding new information is presented, but you can only show up if you're connected to a law enforcement agency. In April Microsoft released COFEE, a USB thumb drive that dramatically cuts the time necessary to gather evidence from a Windows machine. That's all I know about it though, because it was only released to law enforcement agencies. Sure, you can find it on the Internet, but I shouldn't have to steal knowledge. Last month I read about this on the Windows Incident Response blog:
I received an email from AccessData the other day in my work inbox, advertising something called the National Repository for Digital Forensic Intelligence, or NRDFI. ... The AccessData email said that NRDFI is a "knowledge management platform for collecting and sharing digital forensic information." The email goes on to say that the repository has been seeded with over 1000 documents - examiner tips and tricks, whitepapers, digital forensic tool collections, etc.

Sound interesting. Too bad it's completely off-limits to non-LE such as myself, those who have an interest and desire to contribute, but are not sworn officers.
There is also the trend of states making it so that you have to have a Private Investigators license to perform digital forensic work. In my state, that means that I have to have 6000 hours of work experience with a government investigative service or law enforcement agency. EDIT: I should point out that my state hasn't passed such legislation as other states have done. But if my state should go that route then I would need the 6000 hours with an investigative agency.

So I'm starting to feel like I should just give the whole forensic community the finger. Clearly they don't want any of us non-law-enforcement nerds gaining any of their sacred knowledge. You have to be chosen to join their forensics priesthood and everyone else is a dirty protestant. Am I wrong about all of this? Am I blowing the problem out of proportion?