1 / 7100%
Running Head: ISE 640 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 1
Milestone One: Final Project
ISE 640 Investigation Digital Forensic
SNHU
ISE 640 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 2
Executive Summary
In ACME Construction Company, a major violation of the IT security is taking
place. Drew Patrick, a senior manager operating in the organization has been stealing
intellectual property form the firm which could adversely impact it. There are reports
that Drew is planning for leaving the organization. The director-level role helps him to
have access to sensitive corporate information. In the organizational context, he is
involved with the development of ACME’s excavators. Thus he has access to various
elements such as design documentation, support documents, schematics and other
technical references that are stored in the firm’s R&D databases. The forensic
investigation has revealed has Drew has been showcasing abnormal behavior as he has
been storing confidential data in his computer system. His actions could jeopardize the
organization, its clients and customers. e
Legal Concerns
The scenario that has been presented is extremely serious. The forensic
investigation is being carried out in a legal manner so that maximum possible evidence
can be captured against Drew Patrick. It is quite evident in the presented situation that
Drew has been making an attempt to steal sensitive data pertaining to the construction
company (Farshadkhah & Stafford, 2019). Due to the severity and complexity of the
situation, it is necessary to collect and analyze relevant information that can prove his
actions and behavior.
The pieces of evidence that are collected must be handled with utmost care so
that they could be presented in the court of law. It can have a major implication on
how the case is handled in the court and the decision that is taken by the judge. In
addition to this, it has to be ensured that the evidence that is collected is in sync with
the subject matter. e Ultimately, the reliability and the validity of the evidence have to be
ISE 640 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 3
given high priority so that it can act in favor of ACME Construction Company (Xia,
2017).
Relevant procedures
It is necessary to follow systematic practices and procedures before the investigation or
during the investigation process. A methodical approach can play a key role and help in
maintaining the integrity of the collected evidence.
Processes and Procedures
In the scenario of the organization, the investigation primarily focuses on the
communication that took place between Drew’s desktop computer and the Research and
Development database which comprises sensitive business data and information. The
objective is to ascertain whether the employee was involved in stealing the data or not.
The first and foremost thing that has to be done relates to the gathering of appropriate
evidence. Evidence could be in any form such as text, audio, video, physical evidence
or digital evidence. Since the issue has taken place in the IT ecosystem of the
organization, it is better to first find digital evidence and the move to other pieces of
evidence (Zhou, Wu & Jin, 2017). Log files can be checked as well to get an insight
into the activities that have been carried out by the user. The scenario indicates that
Drew has been saving data pertaining to the organization. So his hard disk or other
storage devices could be checked to gather evidence on his involvement.
Chain of Custody
The chain of custody would play an integral role as it would ensure that a
chronological sequence is followed for recording the sequence of analysis, control,
custody, and disposition of digital or physical evidence. Since sensitive evidence would
be gathered in the organizational setting against Drew, maintaining a robust chain of
custody would be extremely important (Xia, 2017). Accurate data and time would be
ISE 640 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 4
recorded when evidence is captured by the forensic team. Similarly, after the seizure of
Drew’s hard disk, no one could access it without sending a written request and getting it
approved by the management. e
Methodical steps would be of paramount importance throughout the investigation
process. They would play a key role to maintain the integrity of the digital evidence that
has been collected by the forensic team. It is necessary to assign suitable hash values to
the hard disk copies that are being created. Such a step would help to establish proper
control when any changes are made to the contents of the hard disk.
Details of investigation
It is necessary to give due importance to certain aspects of the forensic
investigation process such as the resources that would be needed, the methodologies and
methods that would be employed by the team and the ultimate findings that would be
arrived at the end of the investigation process (Farshadkhah & Stafford, 2019).
Resources needed
During the forensic investigation of ACME Construction Company, a number of
resources would be needed. These elements would basically help the investigating team
to capture necessary pieces of evidence in an effective and efficient manner. Resources
could involve both tangible as well as intangible elements such as knowledge of the
team members, skill set, and abilities (Zhou, Wu & Jin, 2017). In addition to this, it is
important to make sure that the investigation team has suitable tools and equipment with
itself to carry out the investigation in a smooth manner. e
One of the basic resources without which the investigation could not proceed is a
computer system. The forensic investigation team needs to ensure that it has a computer
system that would be strictly used to carry out the IT investigation. Secondly, the team
must have an extra hard disk which would be used for activities relating to the forensic
ISE 640 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 5
image. The software requirements also need to be fulfilled by the forensic investigation
team. A forensic disk imaging software would be necessary by the team to conduct the
investigation. Forensic Toolkit or FTK could be used by the team for the purpose of
creating a forensic image. e
In order to create hash values for the original image and the copied image, the
‘md5deep’ software package could be deployed. It would help by generating hash values
during the investigation process.
The professionals who would be responsible to carry out the investigation must
have adequate training so that the integrity, validity, and reliability of the collected
evidence would not get compromised. They need to possess an in-depth knowledge of
computer forensic analysis procedures. In addition to this, they must know the technique
of assessing the collected data in great detail.
Methods
A systematic method was employed for the purpose of effectively leveraging
available resources. The very first method that was employed by the team involved the
creation of the forensic image of Drew Patrick’s hard drive. The Forensic Toolkit was
used for doing this activity. It ensured that we could preserve the original evidence and
use a copy of the same for the investigation purpose (Xia, 2017). After the creation of
the copy, the team was involved in creating a hash value for both the images. Such a
step was taken to rest assure that both the images were similar in nature. In order to do
this, the md5deep software package was used by the team. It basically ensured that no
changes could be made to the images without the knowledge and awareness of the
forensic team.
The forensic image was thoroughly assessed by the team by making use of
Autopsy. Such a process ensured that no element of the forensic image was ignored by
ISE 640 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 6
the team during the investigation process. This method also helped to capture any piece
of information that could add value to the investigation and help in the court of law.
Then a baseline was established by the tea to get an insight into how the standard
operation would appear in the system. WFT was used for the purpose (Farshadkhah &
Stafford, 2019). It helped not just to create a baseline but it also helped to make a
comparison between the standard operations and the current operations that were taking
place in the system. The team also decided to evaluate the server logs to get an insight
into any malicious or unauthorized activity that could be taking place in the firm’s
system. It helped to get an insight into when connections were being established with
the firm’s database without its knowledge. Ultimately a sniffer was used for monitoring
the network traffic.
Findings
The findings that were arrived at after conducting the forensic investigation
process were of high relevance for the organization. One of the major findings was that
Drew’s hard disk contained the intellectual property of ACME Construction Company.
While reviewing the logs it was ascertained that a new account had been created and
unauthorized activities were being carried out by using the account. The thorough
assessment of the log files indicated that anonymous logins were being made from
Drew’s system even though his account was not being used directly (Farshadkhah &
Stafford, 2019). It was evident that Drew’s system was showcasing abnormal behavior
as numerous file transfers had taken place using the same system. In addition to this,
the files of the organization that were being transferred to the IP address were not
owned by the ACME Construction Company. This indicated that Drew was trying to
steal the intellectual property of the organization and use it after he would leave the
ISE 640 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 7
business entity. The in-depth assessment of the captured evidence indicates that Drew
was using his position to steal confidential data of the firm and sell it to its competitors.
References
Farshadkhah, S., & Stafford, T. (2019, January). The Role of “Eyes of Others” in
Security Violation Prevention: Measures and Constructs. In Proceedings of the
52nd Hawaii International Conference on System Sciences.
Xia, W. A. N. G. (2017). On the relationship between the psychological empowerment
and violation behavior of the airport security staff members. Journal of Safety and
Environment, (5), 45.
Zhou, S., Wu, L., & Jin, C. (2017). A privacy-based SLA violation detection model for
the security of cloud computing. China Communications, 14(9), 155-165.
Students also viewed