Want help with copying the entire project to own words.
Project 1: Forensic Memory Analysis
Your name
School Name
Forensic Memory Analysis
Instructor’s name
Due date
INCIDENT RESPONSE PLAN
Introduction
The <Program Name> <System Name> Incident Response Plan (IRP) documents the strategies, personnel, procedures, and resources required to respond to any incident affecting the system.
Scope
This IRP has been developed for <System Name> which is classified as a <moderate-low-low> impact system for the three security objectives: confidentiality, integrity, and availability.
Roles and Responsibilities
The <System Name> roles and responsibilities for various task assignments and deliverables throughout the incident response process are depicted in the table below.
|
Roles |
Responsibilities |
|
INFORMATION SYSTEM OWNER/PROGRAM MANAGER (ISO/PM) – Incident Occurs |
The responsibilities of the ISO/PM when an incident occurs are listed but not limited to the following: <enter responsibilities> |
|
SYSTEM ADMINISTRATOR (SA) |
The responsibilities of the SA are listed but not limited to the following: <enter responsibilities> |
|
PROGRAM SECURTY OFFICER (PSO) |
The responsibilities of the PSO are listed but not limited to the following: <enter responsibilities> |
|
INFORMATION SYSTEM SECURITY MANAGER/INFORMATION SYSTEM SECURITY OFFICER (ISSM/ISSO) |
The responsibilities of the ISSM/ISSO are listed but not limited to the following: <enter responsibilities> |
Definitions
Event
An event is an occurrence not yet assessed that may affect the performance of an information system and/or network. Examples of events include an unplanned system reboot, a system crash, and packet flooding within a network. Events sometimes provide indication that an incident is occurring or has occurred.
Incident
An incident is an assessed occurrence having potential or actual adverse effects on the information system. A security incident is an incident or series of incidents that violate the security policy. Security incidents include penetration of computer systems, spillages, exploitation of technical or administrative vulnerabilities, and introduction of computer viruses or other forms of malicious code.
Types of Incidents
The term “incident” encompasses the following general categories of adverse events:
Data Destruction or Corruption: The loss of data integrity can take many forms including changing permissions on files so that they are writable by non-privileged users, deleting data files and or programs, changing audit files to cover-up an intrusion, changing configuration files that determine how and what data is stored and ingesting information from other sources that may be corrupt.
Data Compromise and Data Spills: Data compromise is the exposure of information to a person not authorized to access that information either through clearance level or formal authorization. This could happen when a person accesses a system he is not authorized to access or through a data spill. Data spill is the release of information to another system or person not authorized to access that information, even though the person is authorized to access the system on which the data was released. This can occur through the loss of control, improper storage, improper classification, or improper escorting of media, computer equipment (with memory), and computer generated output.
Malicious Code: Malicious code attacks include attacks by programs such as viruses, Trojan horse programs, worms, and scripts used by crackers/hackers to gain privileges, capture passwords, and/or modify audit logs to exclude unauthorized activity. Malicious code is particularly troublesome in that it is typically written to masquerade its presence and, thus, is often difficult to detect. Self-replicating malicious code such as viruses and worms can replicate rapidly, thereby making containment an especially difficult problem.
Virus Attack: A virus is a variation of a Trojan horse. It is propagated via a triggering mechanism (e.g., event time) with a mission (e.g., delete files, corrupt data, send data). Often self-replicating, the malicious program segment may be stand-alone or may attach itself to an application program or other executable system component in an attempt to leave no obvious signs of its presence.
Worm Attack: A computer worm is an unwanted, self-replicating autonomous process (or set of processes) that penetrates computers using automated hacking techniques. A worm spreads using communication channels between hosts. It is an independent program that replicates from machine to machine across network connections often clogging networks and computer systems.
Trojan Horse Attack: A Trojan horse is a useful and innocent program containing additional hidden code that allows unauthorized Computer Network Exploitation (CNE), falsification, or destruction of data.
System Contamination: Contamination is defined as inappropriate introduction of data into a system not approved for the subject data (i.e., data of a higher classification or of an unauthorized formal category).
Privileged User Misuse: Privileged user misuse occurs when a trusted user or operator attempts to damage the system or compromise the information it contains.
Security Support Structure Configuration Modification: Software, hardware and system configurations contributing to the Security Support Structure (SSS) are controlled since they are essential to maintaining the security policies of the system. Unauthorized modifications to these configurations can increase the risk to the system.
Note: These categories of incidents are not necessarily mutually exclusive.
Incident Response
<Program Name> shall follow the incident response and reporting procedures specified in the security plan. Upon learning of an incident or a data spillage, the ISSM will take immediate steps intended to minimize further damage and/or regain custody of the information, material or mitigate damage to program security.
Instruction: Provide an overview of your facility's incident response and reporting procedures.
Incident response will follow the following six steps:
1. Preparation – one of the most important facilities to a response plan is to know how to use it once it is in place. Knowing how to respond to an incident BEFORE it occurs can save valuable time and effort in the long run.
2. Identification – identify whether or not an incident has occurred. If one has occurred, the response team can take the appropriate actions.
3. Containment – involves limiting the scope and magnitude of an incident. Because so many incidents observed currently involve malicious code, incidents can spread rapidly. This can cause massive destruction and loss of information. As soon as an incident is recognized, immediately begin working on containment.
4. Eradication – removing the cause of the incident can be a difficult process. It can involve virus removal, conviction of perpetrators, or dismissing employees.
5. Recovery – restoring a system to its normal business status is essential. Once a restore has been performed, it is also important to verify that the restore operation was successful and that the system is back to its normal condition.
6. Follow-up – some incidents require considerable time and effort. It is little wonder, then, that once the incident appears to be terminated there is little interest in devoting any more effort to the incident. Performing follow-up activity is, however, one of the most critical activities in the response procedure. This follow- up can support any efforts to prosecute those who have broken the law. This includes changing any company policies that may need to be narrowed down or be changed altogether.
Incident Response Training
All Program personnel will receive incident response training at least annually and a record of the training will be maintained. This training can be integrated into the overall program specific annual security awareness training.
Overview:
For each of the Project 1 sections, complete the appropriate filling in with lab results and answers to specific questions.
Processed Evidence Search:
1. Using the Hex tab in the evidence window, what are the first four hex values displayed?
2. Using the Permissions tab in the evidence window, what are the unique Names listed? (e.g Administrators…)
3. Using the Attributes tab in the evidence window, what is the Full Serial Number?
Time zone of Image
1. What is the time zone listed for the image?
Image Search Results:
1. What type (e.g. Guns, Knifes, Rocket Launchers…) of weapons do you immediately see when you browse the 9RD3Y03V folder.
2. Which folder contains a Mastercard image?
3. Which folder contains a Login with Facebook image?
4. Which folder contains at least two images of people?
Keyword Search Results:
1. Go to the first hit of the Guns-> Items. This is most likely named search[1].htm. Review the transcript. What does the central theme of this search seem to be? Provide some specific text examples of the transcript that align with this central theme.
2. Go to Password-> Items and find search[2].htm file. Look at the transcript of this resource. Review the transcript. What does the central theme of this search seem to be? Provide some specific text examples of the transcript that align with this central theme.
Data Hiding Lab
1. Using OpenStego
For your lab report, experiment with two (2) images of your own. Show screenshots of you hiding the messages and then extracting them. Be sure to review and describe the size and format differences.
2. Using HxD
For your lab report, use the javainuse.com site to create a secret message. Use your own secret key and initialization vector. Encrypt the message, and then add it to the HiddenTextPlay file. Provide screenshots of the resulting file in the Hex Editor and then extract the message and decrypt it using the javainuse.com site. Discuss trades off associated with this technique for hiding a message. For example, will the size of the file change? Will the original purpose of the file be the same?
Introduction to Memory Forensic Lab
HxD experiment
For your report, create your own secret message using notepad and use the HxD tool to uncover the results. Document your results with screenshots and a brief description of the process you performed. Use the Project 1 Reporting Template to record your results.
Run the imageinfo command
For your lab report answer the following questions related to this process:
1. What suggested Profile was Instantiated?
2. How many processors were on this image?
3. What date was the image created?
4. Describe the main purpose of this Volatility command. (Hint: see the command reference documentation)
Run the pslist command
For your lab report answer the following questions related to this process:
1. Of the many processes running, do any look suspicious? Hint: you can google the .exe to see what pops up.
2. Why do you think the dd.exe command was listed? What does it do?
3. What is the Process ID (PID) associated with the TaskSwitch.exe process?
Run the pstree command
For your lab report answer the following questions related to this process:
1. Which processes listed are not child processes?
2. What is the time associated with the System process?
3. How many threads (Thds) are associated with the explore.exe process?
Run the psscan command
For your lab report answer the following questions related to this process:
1. What value over running similar commands does psscan provided?
2. What is the offset and PID values of the Pluckupdater.exe processes? How is the offset value used in Memory analysis?
3. What does the Fast.exe process do?
Run the getsids command
For your lab report answer the following questions related to this process:
1. How could the getsids report be used to support a Forensic Memory analysis report?
2. How many unique users are found in the output? A unique user are the users found in parenthesis at the end of the line -Local System Administrators, Everyone …). Hint: you can pipe the output to file and then analyze using a text editor or excel spreadsheet.
3. Which processes does Sarah have access to use?
Run the cmdscan command
For your lab report answer the following questions related to this process:
1. Why is the cmdscan a user command to run in Volatility
2. Look at the results from the command and conduct some research on the results. What was primarily happening in the results reported? For examples, why was dd.exe being executed?
Run the modules command
For your lab report answer the following questions related to this process:
1. Does the system appear to have an Anti-virus program running? How did you determine this?
2. What is the size of pt.sys file in bytes. (Hint: convert the hex to decimal)
3. What is the offset of the NAVAPEL.SYS file in Hex.
Run the modscan command
For your lab report answer the following questions related to this process:
1. What value does running the modscan provide in Forensic memory analysis?
2. You will most likely see a null.sys and navap.sys modules among many others. Conduct some research and explain their purpose.
Run the connscan command
For your lab report answer the following questions related to this process:
1. What URL is associated with 66.161.12.81. Hint: You can use nslookup IP at the command prompt to answer this.
2. Conduct searches on 3 additional Remote IP addresses on the list. List the name of the site listed. Did you see any sites that were of a questionable nature? Explain.
Run the mutantscan --silent command
For your lab report answer the following questions related to this process:
1. What is the #PTR value associated with the c:!documents and settings!sarah!cookies! Mutant
2. Conduct some research on the RAS_MO_02. Based on your research, is this something you should be concerned about and report in your analysis? Explain.
3. Conduct some research and explain how the mutantscan be used to help identify remote outside communications or virus activity. (Consider this resource as one case study: https://apps.dtic.mil/sti/pdfs/AD1004194.pdf)
Run the psxview command
For your lab report answer the following questions related to this process:
1. Conduct some research on psxview. What type of detections can psxview provide? What would be an indicator of an issue such as a virus?
2. Are there any hidden processes? Hint: A hidden process is typically associated with False, False in the first two columns.