MEMO
DATE: 12/08/2018
TO: Non-expert Stakeholder
FROM: (Cybersecurity Practitioner)
SUBJECT: DIGITAL FORENSIC INVESTIGATION MEMO
Over a period of years digital forensic investigation has out grown into a body that in need of details digital forensic model. Different academic researchers have suggested over a hundred different types of investigation procedural models. In addition to this proposed model over the years, there has been a challenged whereby the model lack experimental testing to ascertain the truth about the investigation. More so there is a need of evaluating the same model to complement the process of investigation progression in support to the entire scientific community (Learner, D. E. (2009). Electronic crime scene investigation. New York: Nova Science).
Based on the experienced encountered in ACME Company on digital forensic investigation on Patrick Drew, there was suspicions activities from HR department. The suspicion was not proven. The information is handed over to IT department to take a further analysis on the act and gather more details that will give a clear and precise picture what the Company might be facing. With the level of clearance that Patrick Drew has with the Company operation, schematics, file and other technical references maintenance, it was clear that he might be plotting to tamper or steal information from the company to auction it to a competitor. ACME company databases is preserve and reinforced by security operation center (SOC). The center uses Snort as an essential component of their security information and event management (SIEM). Upon the suspicion, there was an alert from SIEM to SOC of an existence of peer-to-peer movement emanating from an internet protocol registered to Drew’s computer. Realizing that there was transfer of files from the same internet protocol, center for security enacted a two-factor authorization to prevent sharing of files from one end to another. This incident call for further action where the legal team and Human Resource department decided to conduct further digital forensic investigation on the matter.
There was a call to investigate the incident and the task was handed over to digital forensic investigation team. For any investigation to be conducted there must be due process that should be followed to prevent any suspicion from the investigated subject and to maintain a legal order that calls for the same action. This process includes:
IDENTIFICATION
This is a process of identifying an incident from indicators and defining the type of intrusion in the company. In this context identification happens when SOC was alerted by SIEM of a peer-to-peer files transfers which raised suspicion after (HR) department reported the same suspicion from an internal worker plotting to still the information.
PREPARATION
Digital forensic investigation should be ready to conduct the process by gathering the required tools, methods, law suit warrants, and overseeing authorizations and administration support. Preparation in this scenario is understanding and acknowledging the presents of SOC and SIEM and more so HR department by monitoring and identifying the threats and taking an initiate to investigate the matter. Presence of Snort and Intrusion Prevention System contributed a lot to investigation and gathering of facts.
METHODOLOGY PLAN
Formulating a plan based on possible witnesses and the specified system in questions is also an essential strategy that ease the entire investigation process. The core value for this methodology is to collect proof of untainted facts in addition to maximizing the effect on victim. The purpose of the process in this scenario was to avoid the entire digital forensic investigation from second guessing from the entire ACME Company and the legal department on their initiate the investigation on Patrick Drew suspicion and alleged data stolen. Formulating a plan is give a clear picture and step to be followed other than just rushing into the process without a proper plan.
PROTECTION
All the evidence gathering from the crime scene were isolated, fortified and the condition of physical and digital facts. The entire process includes limiting the entire staff from using any electromagnetic devices or digital devices in the scene. The greater purpose of these process is avoiding any alteration to the content that is under investigation by any part with the same motive. Protecting evidence by digital forensic investigation team is of important when conducting investigation of such nature. Subject under investigation is presumed to have the knowledge of the process and hence he/she might end up tampering with the evidence.
ASSEMBLY
On identifying the physical scene all data should be recorded and replicated with a standardized procedure which is legal and follows due Company procedure.
SCRUTINY
There should be a deep search for facts involving the suspected crime. The entire process involves focusing on recognizing the pinning the essential evidence that are within unusual sites. After collecting the facts, a detailed documentation analysis is constructed.
BREAKDOWN
After gathering all the potential evidence, we determine the importance, regenerate the pieces of information and come up with a conclusion that lie entirely on the facts discovered on the scene. The process might take long enough to come up with actual and enough evidence to support the crime theory.
EXHIBITING
Final purpose for this entire process is to issue out exhibits that will support crime theory. The reason behind presenting the exhibit is to evaluate and relate whether the data collected and analyzed matches with what the entire suspicion or allegation was. Issuing out or presenting collected information to the company by digital forensic investigation agency means that they are in their full satisfactory state of what they have gathered, and it is up to the Company to take further law suit disciplinary process to the subject under investigation.
IMPACTS ON SECURITY
Respectively, there is a rise in the number of digital crimes in each year in the entire world. With the changes in technology and software users digitally savvy. The lawbreaking they commit become refined. Legal suit is in a continuous race with these criminals minded to make sure that the playing ground remains leveled. Part of the process is coming up with appropriate tools that will gap with the rise of the same crimes. ACME Company should embrace the idea of developing a constant team assigned to conducting investigation and auditing every activity in the company. The impact to security in this scenario is so sensitive that the company was in a position of losing the entire company production under Patrick Drew management.
With the information collected from the scene and the attempt of stealing, company realized that every staff should be put under monitoring process to avoid further of information. Information collected prove beyond doubt the accuracy and validity of the crime theory and call for further action. ACME Company will take further action to the subject under investigation and establishes defensibility against the Patrick Drew action (Erickson, E. (2015). Criminalistics laboratory manual: The basics of forensic investigation).
REFERENCES
Erickson, E. (2015). Criminalistics laboratory manual: The basics of forensic investigation.
Muda, A. K., Choo, Y.-H, Abraham, A., & N, S. S. (2014). Computational Intelligence in Digital Forensics: Forensic Investigation and Applications. Cham: Springer International Publishing.
Learner, D. E. (2009). Electronic crime scene investigation. New York: Nova Science.
Erickson, E. (2015). Criminalistics laboratory manual: The basics of forensic investigation