Give an overview of the threats and vulnerabilities found in your organization. The vulnerabilities and related security issues should reflect incidents that could occur within your organization. Identify threats and vulnerabilities for the following 4 cl
Microsoft – Digital Forensics
Shirish Bhatnagar
Colorado Technical University
Digital Forensics CS631-2002B-01
May 27th, 2020
Abstract
Digital forensic and incident response plan (DFIR) is a significant component of an IT business. The philosophy is supported by technological advancements to provide comprehensive solutions for the security profession in IT. The team seeks to offer secure coverage of the internal systems of a corporation. The following is a DFIR plan for Microsoft Corporation.
Microsoft is a multinational corporation with a broad scope of operations. Its checklist will, therefore, prioritize the spontaneous response to the slightest data breach. Some of the components that will be included include:
· The time and date of the incident
· Activation and finalization of both the internal and external response team towards the breach
· Identification of secure perimeter around the systems and equipment are suspected to be breach targets
· Drawing the focus of the forensic team to secure the affected systems
· Initiating the repair efforts while monitoring for incidents of compromising
Table of Contents Abstract 2 Company Overview 4 Purpose of Digital Forensics 4 Overview of the Proposed Digital Forensics Plan 5 Vulnerabilities and the Root cause of the attacks 6 Digital Forensics Events 7 Forensics and Incident responses to be provided 7 Containment and Damage 8 Minimizing the Risks 8 Week 2: Threats and Vulnerabilities 9 Week 3: Computer System Incidents 10 Week 4: Network and Internet Incidents; Conclusion 11 Week 5: Risk Mitigation Techniques and Plans 12 References 13
Company Overview
Microsoft Company is a technology corporation that designs, supports, and gives licenses of various software products, devices, and services. The company's elements include personal computing, Intelligent Cloud, Business processes, and productivity. Operating systems like windows, server applications, desktop management tools, video games, application development tools, and business applications are among their products. Furthermore, it manufactures and sells computer devices. Microsoft is a corporation that has captured the global ecosystem making it an international company. Microsoft is located all over the globe. With this overview, it is clear to depict that Microsoft's sensitive data range from their customer's individual information, other businesses' information to their product information that includes product activation keys, among others (Bhanji, 2012). The fact that this sensitive information exists in Microsoft makes them prone to cyber-attacks and such threats. This brings the need for digital forensics, which refers to scientific preservation, identification, extraction, and reporting of computer evidence, which can be utilized to identify weak-points in a system to be patched and also used to report a crime.
Purpose of Digital Forensics
As the globe increases their dependence on cloud computing and other computerized systems, digital forensics becomes a critical element of strengthening a system and enforcing the law. Digital forensics is an essential element for both large corporations like Microsoft and small businesses. The purpose of digital forensics is to back up hypotheses about digital crimes in a civil or criminal court. Criminal cases include alleged law breakings and law enforcement systems and their digital forensic examiner. Civil cases include the right of protection of property and primarily intellectual property like unreleased software. Civil cases also involve contractual disputes among commercial entities where a type of digital forensics referred to as electronic discovery may be utilized. Experts in digital forensics, are also hired by private corporations like Microsoft, as a part of information security and cybersecurity teams for identification of the reason for data leaks, breaches, and cyber threats. Aside from identification purposes, digital forensics experts may also be part of the incident response team to identify and recover any personal identification information or sensitive data that may have been stolen or lost after a successful cyber-attack. Typically, digital forensics is a form of risk mitigation strategy utilized by corporations like Microsoft and other businesses to ease the damage and tension caused by cyber-attacks by discovering computers and individuals involved in cyber-attacks (Årnes, 2017). In the process of digital forensics, systems are made more resilient by discovering weak-spots in a system.
Overview of the Proposed Digital Forensics Plan
Anywhere IT systems are crucial Digital forensics and incident response plan is essential as the plan offers secure coverage of the internal systems of a corporation. In an overview of the proposed plan for Microsoft, five steps are involved including, preparation, containment, action item checklist, eradication, and recovery. The first phase, preparation, entails training the employees about responsibilities and roles in the incidence response plan. Preparation also examines funding of the plan as Microsoft management is boarded on the plan to ensure entailment of full support and teamwork. Ideally, this phase aims to eliminate the possibility of eras in case of a data breach. The second phase, containment, involves mitigating further damage to the business. Containment procedure involves isolation of the affected device from the whole, Microsoft network to avoid infection to other devices. The containment plan involves having a redundant back-up system to assure that Microsoft processes continue as containment continues. The third phase, Action Item Checklist, involving analysis of factors like time of the incident, activation of the response team, identification of safe perimeters, focusing on forensics team to secure the affected systems, initializing repair efforts, and monitoring for incidents of compromising. The fourth phase, eradication, entails eliminating the root source of the bleach. This phase involves removing all malware as the system is hardened through patch-ups. The fifth and the last phase, recovery, is utilized to restore and return the system's normalcy by returning the affected and cleaned devices to the Microsoft working environment. Note that the last phase is initiated after it is confirmed that the system is secure and ready to be operationalized.
Vulnerabilities and the Root cause of the attacks
For one to understand digital forensics, it is essential to examine vulnerabilities in a system and know the root causes of the attacks. The causes of attacks assist digital forensics experts in knowing when and where to look at in a system in case there is an attack. Some of the common causes of attacks include weak, stolen credentials. Illegally acquired weak passwords are a common cause of successful attacks; weak passwords mean that cybercriminals do not have to break a sweat gaining access to sensitive information that is protected through the weak passwords. For example, passwords like "password1", "password2", and "12345678" are easy combinations for a skilled cyber-criminal especially if they have a computer with high processing power (Watson & Dehghantanha, 2016). Furthermore, moderately secure passwords are easy to crack by the use of software like Johnny the Ripper that runs billions of the most popular passwords. There is even software that allows IT experts to create a dictionary with millions of passwords based on a person's information. For example, a company like Microsoft, a cyber-criminal, may generate passwords based on the corporation's top managers and the shareholder's information, which is easy to get through social media.
Another root cause of attacks is software vulnerabilities. All software or applications are deemed to have a particular vulnerability that criminals can exploit in various ways (Watson & Dehghantanha, 2016). For example, an attacker may utilize specific software stored in Microsoft's computer corporation to infect their network with malware, which can cause tremendous loss. Since hackers and crackers like to exploit every vulnerability they find, this is a major contribution to the attacks.
Another root cause of attacks is insider errors and malicious insiders. Insider error involves employees in an organization making an error like opening a malicious email in the corporation's computer. Malicious insiders, on the other hand, are employees with sensitive data and intentionally misuse it for personal gains (Watson & Dehghantanha, 2016).
Digital Forensics Events
Digital forensics events include investigators digging into devices of an alleged malicious insider to determine whether they were involved in an attack that may have occurred. A digital forensics event may also occur in real-time as experts try to trace the source of an attack to know who is attacking (Årnes, 2017).
Forensics and Incident responses to be provided
To meet the digital forensics purposes incident responses in critical. Incidence response with modern technology involves Intrusion Detection Systems or IDS and Intrusion prevention systems or IPS. IDS are utilized in forensics and incident response for detecting an ongoing attack and alerting the digital forensics team. IPS, on the other hand, is more active in that they isolate an attack and automatically initialize the process of incident response by maybe blocking malicious traffic. IDS and IPS integration are essential systems to be provided for any incident (Cusack & Mahmoud, 2018).
Containment and Damage
In case there is a virus, containment includes isolating infected computers to a separate virtual or physical space to avoid other computers from being infected. This involves disconnecting computers from a network and even from the power supply. If there is the identification of a malicious insider, containment involves separating him or her from the computer resources (Kävrestad, 2020). Taking these measures minimizes the damage done and gives a better space for the examination of the items.
Minimizing the Risks
Root causes of the attack, which are weak, stolen passwords and credentials, software vulnerabilities, insider errors, and Malicious insiders, require mitigation risk strategies. The mitigation strategies aim to minimize the risk. On the issue of Weak passwords, the corporation may prefer encrypting user credentials and storing them in an encrypted form. This minimizes the risk in that even if an attacker got the user credentials, he would have to decrypt them, which is a rare skill. It does not eliminate the risk, but it reduces the chances of successful infiltration. On software vulnerabilities, the corporation can minimize the risk by continually updating the software after it is patched. For an organization to minimize the risk of malicious insiders and errors, the corporation ought to ensure that sensitive information is accessed by few and trusted individuals (Bhuiyan et al., 2016). Training of employees on how to treat suspicious events will help reduce the risk of insider error.
Week 2: Threats and Vulnerabilities
Week 3: Computer System Incidents
Week 4: Network and Internet Incidents; Conclusion
Week 5: Risk Mitigation Techniques and Plans
References
Årnes, A. (Ed.). (2017). Digital forensics. John Wiley & Sons.
Bhanji, Z. (2012). Microsoft Corporation: A case study of corporate-led PPPs in education. Public private partnerships in education, 182.
Bhuiyan, T. H., Nandi, A. K., Medal, H., & Halappanavar, M. (2016, May). Minimizing expected maximum risk from cyber-attacks with probabilistic attack success. In 2016 IEEE Symposium on Technologies for Homeland Security (HST) (pp. 1-6). IEEE.
Cusack, B., & Mahmoud, A. (2018). Digital forensics investigative framework for control rooms in critical infrastructure.
Kävrestad, J. (2020). Incident Response. In Fundamentals of Digital Forensics (pp. 63-68). Springer, Cham.
Watson, S., & Dehghantanha, A. (2016). Digital forensics: the missing piece of the Internet of Things promise. Computer Fraud & Security, 2016(6), 5-8.