business continuity plan and disaster recovery plan ( i need this in 1 hr 20 mints ASAP)and exactly how the professor is asking
Principles of Incident Response and
Disaster Recovery, 2nd Edition
Chapter 8 Incident Response: Recovery and
Maintenance
Objectives
• Describe how an organization plans for and executes the recovery process when an incident occurs
• Explain the need for and steps involved in the ongoing maintenance of the IR plan
• List the steps involved in collecting digital evidence • Discuss the process used to analyze evidence • Explain how encryption can thwart digital forensic
analysis
Principles of Incident Response and Disaster Recovery, 2nd Edition 2
Introduction
• Incident recovery can begin – Once the incident has been contained and system
control has been regained • First task
– Inform the appropriate human resources • CSIRT
– Must assess the full extent of the damage to determine what must be done to restore the systems
Principles of Incident Response and Disaster Recovery, 2nd Edition 3
Recovery
• Incident damage assessment – Initial determination of the scope of the breach of
confidentiality, integrity, and availability of information and information assets
– Can take days or weeks, depending on the extent of the damage
– Damage can range from minor to severe
Principles of Incident Response and Disaster Recovery, 2nd Edition 4
Identify and Resolve Vulnerabilities
• Forensics – Used for intrusion analysis and as part of evidence
collection and analysis – Also used to assess how the incident occurred and
what vulnerabilities were exploited to cause the assessed damage
• After any incident – The organization should address the safeguards that
failed to stop or limit the incident
Principles of Incident Response and Disaster Recovery, 2nd Edition 5
Restore Data
• The IR team must: – Understand the backup strategy used by the
organization – Restore the data contained in backups – Use the appropriate recovery processes from
incremental backups or database journals to recreate any data that was created or modified since the last backup
Principles of Incident Response and Disaster Recovery, 2nd Edition 6
Restore Services and Processes
• Compromised services and processes must be examined, verified, and then restored
• If services or processes were interrupted in the course of regaining control of the systems, they need to be brought back online
• An organization should continuously monitor its system
Principles of Incident Response and Disaster Recovery, 2nd Edition 7
Restore Confidence Across the Organization
• The IR team may wish to: – Issue a short memorandum outlining the incident
and assuring everyone that the incident was handled and the damage was controlled
• Objective of this communication – To prevent panic or confusion from causing
additional disruption to the operations of the organization
Principles of Incident Response and Disaster Recovery, 2nd Edition 8
Maintenance
• Maintenance of the IR plan includes: – Procedures to complete effective after-action review
meetings – A process to complete comprehensive periodic plan
review and maintenance – Efforts to continue the training of staff members who
will be involved in IR
Principles of Incident Response and Disaster Recovery, 2nd Edition 9
After-Action Review
• This is a detailed examination of the events that occurred, from first detection to final recovery
• Should be completed immediately after the events in question have been completed
• The entire AAR should be recorded for use as a training case for future staff
Principles of Incident Response and Disaster Recovery, 2nd Edition 10
After-Action Review (cont’d.)
• Use AAR to document lessons learned and generate IR plan improvements – Examining the documentation of the incident should
reveal • The point at which the incident was first detected • The point in time that the IR plan was enacted • How the first responders and CSIRT reacted
Principles of Incident Response and Disaster Recovery, 2nd Edition 11
After-Action Review (cont’d.)
• AAR as historical record of events – This may or may not be a requirement for legal
proceedings • AAR as a case training tool
– Even in defeat, the organization must continue to rebuild its defenses to fight another day
• AAR as closure – The AAR serves as closure to an incident
Principles of Incident Response and Disaster Recovery, 2nd Edition 12
Plan Review and Maintenance
• Questions that might be useful in this review – Has there been any use of this plan in the past
review period? – Were any AAR meetings held, and have the minutes
of any such meetings been reviewed to note deficiencies that may need attention?
– Have any other notices of deficiency been submitted to the plan owner, and have they been addressed yet?
Principles of Incident Response and Disaster Recovery, 2nd Edition 13
Training
• A systematic approach to training is needed to support the IR plan
• Cross-training – Is needed to be assured that enough staff members
with the proper skills are available for all realistic scenarios
Principles of Incident Response and Disaster Recovery, 2nd Edition 14
Rehearsal
• Plans should be rehearsed until those responding are prepared for the actions they are expected to perform
• Rehearsal adds value by: – Exercising the procedures – Identifying any shortcomings – Providing the opportunity to improve the plan before
it is needed
Principles of Incident Response and Disaster Recovery, 2nd Edition 15
Law Enforcement Involvement
• When an incident violates civil or criminal law – It is the organization’s responsibility to notify the
proper authorities • Law enforcement agencies
– Usually better equipped at processing evidence than a business organization
• Disadvantage of law enforcement involvement – Possible loss of control of the chain of events
following an incident
Principles of Incident Response and Disaster Recovery, 2nd Edition 16
Reporting to Upper Management
• After preliminary assessment, the CSIRT leader should: – Make a report to upper management, typically the
CISO and CIO • Upper management
– Usually requests assistance in drafting a press release to notify the general public and a specific notification to any stakeholders affected by the event
Principles of Incident Response and Disaster Recovery, 2nd Edition 17
Loss Analysis
• In determining the costs associated with an incident, consider: – Cost associated with the number of person-hours
diverted from normal operations to react to the incident
– Cost associated with the number of person-hours needed to recover data
– Opportunity costs associated with the number of person-hours that could have been devoted to working on more productive tasks
Principles of Incident Response and Disaster Recovery, 2nd Edition 18
Loss Analysis (cont’d.)
• In determining the costs associated with an incident, consider (cont’d.) – Cost associated with reproducing lost data (if
possible) – Legal cost associated with prosecuting offenders (if
possible) – Cost associated with loss of market advantage or
share due to disclosure of proprietary information – Cost associated with acquisition of additional
security mechanisms ahead of budget cycle
Principles of Incident Response and Disaster Recovery, 2nd Edition 19
Incident Forensics
• Forensics – The use of methodical technical investigation and
analysis techniques to identify, collect, preserve, and analyze objects and information of potential evidentiary value
• Computer forensics – The use of forensics techniques when the source of
evidence is a computer system • Digital forensics
– The use of forensic techniques when the source of evidence is a digital electronic device
Principles of Incident Response and Disaster Recovery, 2nd Edition 20
Legal Issues in Digital Forensics
• Private organizations should employ the following procedure when searching an employee’s computer – Verify that organizational policy allows such a search
to occur – Verify that the search is “justified at its inception” – Verify that the search is “permissible in its scope” – Verify that the organization has clear ownership over
the container the material was discovered in – Verify that the search has been authorized by a
manager or administrator in the appropriate chain of command
Principles of Incident Response and Disaster Recovery, 2nd Edition 21
Digital Forensics Team
• When planning a forensics operation, an organization should consider: – Cost – Response time – Data sensitivity
• Division of forensic functions – First response – Analysis and presentation
Principles of Incident Response and Disaster Recovery, 2nd Edition 22
Digital Forensics Team (cont’d.)
• First response team – Incident manager, scribe, and imager
• Analysis team – Forensic analysis function: examination and analysis – Forensic examiners
• Skilled in the operations of particular tools – Forensic analysts
• Know about operating systems and networks
Principles of Incident Response and Disaster Recovery, 2nd Edition 23
Digital Forensics Team (cont’d.)
• Some of the contents of a forensic field kit – Forensic laptops that have multiple operating systems – Call list with subject-matter experts in various IT
technologies – Cell phones with extra batteries and chargers – Hard drives, blank CDs, blank DVDs, and USB flash
drives – Imaging software or hardware with write blockers – Forensic software and tools – Cables, extension cords, and power strips – Evidence bags, seals, and permanent markers
Principles of Incident Response and Disaster Recovery, 2nd Edition 24
Principles of Incident Response and Disaster Recovery, 2nd Edition 25
Digital Forensics Methodology
• A digital investigation usually begins with some allegation of wrongdoing
• Assessing the scene involves: – Interviewing the key contacts who are present and
documenting the scene – Methods used include photography and field notes
Principles of Incident Response and Disaster Recovery, 2nd Edition 26
Principles of Incident Response and Disaster Recovery, 2nd Edition 27
Principles of Incident Response and Disaster Recovery, 2nd Edition 28
Principles of Incident Response and Disaster Recovery, 2nd Edition 29
Digital Forensics Methodology (cont’d.)
• Acquiring the evidence – An organization’s IR policy must spell out the
procedures for initiating the investigative process – Digital evidence collection follows a simple four-step
methodology • Identify sources of evidentiary material • Authenticate the evidentiary material • Collect the evidentiary material • Maintain a documented chain of custody
Principles of Incident Response and Disaster Recovery, 2nd Edition 30
Digital Forensics Methodology (cont’d.)
• Identifying sources – Information may reside on:
• Disks in a desktop and/or laptop computer • Disks in external storage enclosures • Memory sticks or cards • PDA • Cellular phone • Storage devices, such as MP3 players • Optical storage, such as CDs and DVDs • Networked storage
Principles of Incident Response and Disaster Recovery, 2nd Edition 31
Digital Forensics Methodology (cont’d.)
• Authenticating evidence – Cryptography
• One way to identify a particular digital item – When a piece of digital evidence is collected, its
hash value is calculated and recorded – Hashes are acceptable for demonstrating the
integrity of digital evidence – NIST is developing new hash algorithms that will be
more resistant to attack
Principles of Incident Response and Disaster Recovery, 2nd Edition 32
Digital Forensics Methodology (cont’d.)
• Collecting evidence – The investigator must make no changes to the
evidence – Evidence labels and seals are crucial to prevent
doubts on evidence handling – All sterilization procedures must be codified – All media sterilization processes must be
documented
Principles of Incident Response and Disaster Recovery, 2nd Edition 33
Principles of Incident Response and Disaster Recovery, 2nd Edition 34
Principles of Incident Response and Disaster Recovery, 2nd Edition 35
Digital Forensics Methodology (cont’d.)
• Collecting evidence (cont’d.) – In a dead acquisition
• The computer is typically powered off so that its disk drives can be removed for imaging
• An investigator seeks to obtain a forensic image of the disk or device
– When making a forensic image of a device • Forensic investigators use bitstream copying
– Write blockers • Devices that allow acquisition of information on a drive
without creating the possibility of accidentally damaging the contents
Principles of Incident Response and Disaster Recovery, 2nd Edition 36
Principles of Incident Response and Disaster Recovery, 2nd Edition 37
Digital Forensics Methodology (cont’d.)
• Maintaining a documented chain of custody – Chain of custody
• A legal record of where the evidence was at each point in its lifetime and documentation of each and every access to it
– The storage facility requires • Controlled temperature and humidity • Freedom from strong electrical and magnetic fields
that might damage the items • Protection from fire and other physical hazards
Principles of Incident Response and Disaster Recovery, 2nd Edition 38
Principles of Incident Response and Disaster Recovery, 2nd Edition 39
Digital Forensics Methodology (cont’d.)
• Analyzing evidence – First step is to obtain the evidence from the storage
area and perform physical authentication – Disk images must be loaded into the particular
forensic tool used by the organization – Two common tools used in forensic analysis
• Forensic Toolkit (FTK) from AccessData • EnCase from Guidance Software
Principles of Incident Response and Disaster Recovery, 2nd Edition 40
Digital Forensics Methodology (cont’d.)
Principles of Incident Response and Disaster Recovery, 2nd Edition 41
Digital Forensics Methodology (cont’d.)
• Analyzing evidence (cont’d.) – FTK
• Performs extensive pre-processing of evidence items • Organizes the various items into a tabbed display • Constructs an index of terms found in the image as
part of preprocessing – EnCase forensic edition
• Presents an extensible forensic platform that makes it easy for trained investigators to carry out their tasks
• Supports EnScripts
Principles of Incident Response and Disaster Recovery, 2nd Edition 42
Principles of Incident Response and Disaster Recovery, 2nd Edition 43
Principles of Incident Response and Disaster Recovery, 2nd Edition 44
Digital Forensics Methodology (cont’d.)
• Reporting the findings – Once the analysis is complete, the findings must be
reported in written and often verbal form – People who will use the report
• Upper management • Forensic expert retained by the opposition • Attorneys, judges, and juries • Other professionals (auditors, heads of human
resources departments, and others)
Principles of Incident Response and Disaster Recovery, 2nd Edition 45
eDiscovery and Anti-Forensics
• Discovery – One party can obtain evidence from the opposing
party through specific requests for information • eDiscovery
– The search for, collection, and review of items stored in electronic format that are of potential evidentiary value based on criteria specified by a legal team
• Anti-forensics – An attempt made by those who may become subject
to digital forensic techniques to hide items of evidentiary value
Principles of Incident Response and Disaster Recovery, 2nd Edition 46
eDiscovery and Anti-Forensics (cont’d.)
• Organizations must be aware that: – Forensic tools are not just in the hands of honest
professionals, they are available to everyone • Encrypted information
– Poses significant challenges to forensic investigators because, by its nature, encryption conceals the content of digital material
• Some forensic products – Offer brute force attacks against the encrypted
information, using dictionaries of common pass phrases
Principles of Incident Response and Disaster Recovery, 2nd Edition 47
Principles of Incident Response and Disaster Recovery, 2nd Edition 48
Summary
• IR begins once an incident has been contained and system control has been regained
• After any incident, address the safeguards that failed to stop or limit the incident
• Compromised services and processes must be examined, verified, and then restored
• Ongoing maintenance includes – After-action review (AAR) meetings – Planning review and maintenance – Training of staff members
Summary (cont’d.)
• When plan shortcomings are noted, the plan should be reviewed and revised
• A systematic approach to training is needed to support the IR plan
• A digital investigation begins with an allegation of wrongdoing
• First-response digital forensic team – Secures and collects the devices, media, or media
images that are potentially evidentiary
Principles of Incident Response and Disaster Recovery, 2nd Edition 49
Summary (cont’d.)
• Forensic tools – Can be used by investigators even to obtain
information that has been deleted from digital media • eDiscovery
– The search for, collection, and review of items stored in electronic format that are of potential evidentiary value
• Anti-forensics – The attempt by those who may become subject to
digital forensics techniques to hide items of evidentiary value
Principles of Incident Response and Disaster Recovery, 2nd Edition 50
- Principles of �Incident Response and Disaster Recovery, 2nd Edition
- Objectives
- Introduction
- Recovery
- Identify and Resolve Vulnerabilities
- Restore Data
- Restore Services and Processes
- Restore Confidence Across the Organization
- Maintenance
- After-Action Review
- After-Action Review (cont’d.)
- After-Action Review (cont’d.)
- Plan Review and Maintenance
- Training
- Rehearsal
- Law Enforcement Involvement
- Reporting to Upper Management
- Loss Analysis
- Loss Analysis (cont’d.)
- Incident Forensics
- Legal Issues in Digital Forensics
- Digital Forensics Team
- Digital Forensics Team (cont’d.)
- Digital Forensics Team (cont’d.)
- Slide Number 25
- Digital Forensics Methodology
- Slide Number 27
- Slide Number 28
- Slide Number 29
- Digital Forensics Methodology (cont’d.)
- Digital Forensics Methodology (cont’d.)
- Digital Forensics Methodology (cont’d.)
- Digital Forensics Methodology (cont’d.)
- Slide Number 34
- Slide Number 35
- Digital Forensics Methodology (cont’d.)
- Slide Number 37
- Digital Forensics Methodology (cont’d.)
- Slide Number 39
- Digital Forensics Methodology (cont’d.)
- Digital Forensics Methodology (cont’d.)
- Digital Forensics Methodology (cont’d.)
- Slide Number 43
- Slide Number 44
- Digital Forensics Methodology (cont’d.)
- eDiscovery and Anti-Forensics
- eDiscovery and Anti-Forensics (cont’d.)
- Summary
- Summary (cont’d.)
- Summary (cont’d.)