1 / 7100%
Running Head: ISE 640 ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab a ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab
ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab 1
Milestone One: Final Project
ISE 640 Investigation Digital Forensic
SNHU
ISE 640 ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab
ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab a ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab a ab ab ab ab ab ab ab ab ab ab 2
Executive Summary
In ACME Construction Company, a major violation of the IT security is
taking place. Drew Patrick, a senior manager operating in the organization has been
stealing intellectual property form the firm which could adversely impact it. There
are reports that Drew is planning for leaving the organization. The director-level role
helps him to have access to sensitive corporate information. In the organizational
context, he is involved with the development of ACME’s excavators. Thus he has
access to various elements such as design documentation, support documents,
schematics and other technical references that are stored in the firm’s R&D
databases. The forensic investigation has revealed has Drew has been showcasing
abnormal behavior as he has been storing confidential data in his computer system.
His actions could jeopardize the organization, its clients and customers. ab
Legal Concerns
The scenario that has been presented is extremely serious. The forensic
investigation is being carried out in a legal manner so that maximum possible
evidence can be captured against Drew Patrick. It is quite evident in the presented
situation that Drew has been making an attempt to steal sensitive data pertaining to
the construction company (Farshadkhah & Stafford, 2019). Due to the severity and
complexity of the situation, it is necessary to collect and analyze relevant information
that can prove his actions and behavior.
The pieces of evidence that are collected must be handled with utmost care
so that they could be presented in the court of law. It can have a major implication
on how the case is handled in the court and the decision that is taken by the judge.
In addition to this, it has to be ensured that the evidence that is collected is in sync
with the subject matter. Ultimately, the reliability and the validity of the evidence
ISE 640 ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab
ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab a ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab a ab ab ab ab ab ab ab ab ab ab 3
have to be given high priority so that it can act in favor of ACME Construction
Company (Xia, 2017).
Relevant procedures
It is necessary to follow systematic practices and procedures before the investigation
or during the investigation process. A methodical approach can play a key role and help in
maintaining the integrity of the collected evidence.
Processes and Procedures
In the scenario of the organization, the investigation primarily focuses on the
communication that took place between Drew’s desktop computer and the Research
and Development database which comprises sensitive business data and information.
The objective is to ascertain whether the employee was involved in stealing the data
or not. The first and foremost thing that has to be done relates to the gathering of
appropriate evidence. Evidence could be in any form such as text, audio, video,
physical evidence or digital evidence. Since the issue has taken place in the IT
ecosystem of the organization, it is better to first find digital evidence and the move
to other pieces of evidence (Zhou, Wu & Jin, 2017). Log files can be checked as
well to get an insight into the activities that have been carried out by the user. The
scenario indicates that Drew has been saving data pertaining to the organization. So
his hard disk or other storage devices could be checked to gather evidence on his
involvement.
Chain of Custody
The chain of custody would play an integral role as it would ensure that a
chronological sequence is followed for recording the sequence of analysis, control,
custody, and disposition of digital or physical evidence. Since sensitive evidence
would be gathered in the organizational setting against Drew, maintaining a robust
ISE 640 ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab
ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab a ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab a ab ab ab ab ab ab ab ab ab ab 4
chain of custody would be extremely important (Xia, 2017). Accurate data and time
would be recorded when evidence is captured by the forensic team. Similarly, after
the seizure of Drew’s hard disk, no one could access it without sending a written
request and getting it approved by the management. ab
Methodical steps would be of paramount importance throughout the
investigation process. They would play a key role to maintain the integrity of the
digital evidence that has been collected by the forensic team. It is necessary to
assign suitable hash values to the hard disk copies that are being created. Such a
step would help to establish proper control when any changes are made to the
contents of the hard disk.
Details of investigation
It is necessary to give due importance to certain aspects of the forensic
investigation process such as the resources that would be needed, the methodologies
and methods that would be employed by the team and the ultimate findings that
would be arrived at the end of the investigation process (Farshadkhah & Stafford,
2019).
Resources needed
During the forensic investigation of ACME Construction Company, a number
of resources would be needed. These elements would basically help the investigating
team to capture necessary pieces of evidence in an effective and efficient manner.
Resources could involve both tangible as well as intangible elements such as
knowledge of the team members, skill set, and abilities (Zhou, Wu & Jin, 2017). In
addition to this, it is important to make sure that the investigation team has suitable
tools and equipment with itself to carry out the investigation in a smooth manner. ab
ISE 640 ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab
ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab a ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab a ab ab ab ab ab ab ab ab ab ab 5
One of the basic resources without which the investigation could not proceed
is a computer system. The forensic investigation team needs to ensure that it has a
computer system that would be strictly used to carry out the IT investigation.
Secondly, the team must have an extra hard disk which would be used for activities
relating to the forensic image. The software requirements also need to be fulfilled by
the forensic investigation team. A forensic disk imaging software would be necessary
by the team to conduct the investigation. Forensic Toolkit or FTK could be used by
the team for the purpose of creating a forensic image.
In order to create hash values for the original image and the copied image,
the ‘md5deep’ software package could be deployed. It would help by generating hash
values during the investigation process.
The professionals who would be responsible to carry out the investigation
must have adequate training so that the integrity, validity, and reliability of the
collected evidence would not get compromised. They need to possess an in-depth
knowledge of computer forensic analysis procedures. In addition to this, they must
know the technique of assessing the collected data in great detail.
Methods
A systematic method was employed for the purpose of effectively leveraging
available resources. The very first method that was employed by the team involved
the creation of the forensic image of Drew Patrick’s hard drive. The Forensic
Toolkit was used for doing this activity. It ensured that we could preserve the
original evidence and use a copy of the same for the investigation purpose (Xia,
2017). After the creation of the copy, the team was involved in creating a hash
value for both the images. Such a step was taken to rest assure that both the images
were similar in nature. In order to do this, the md5deep software package was used
ISE 640 ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab
ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab a ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab a ab ab ab ab ab ab ab ab ab ab 6
by the team. It basically ensured that no changes could be made to the images
without the knowledge and awareness of the forensic team.
The forensic image was thoroughly assessed by the team by making use of
Autopsy. Such a process ensured that no element of the forensic image was ignored
by the team during the investigation process. This method also helped to capture any
piece of information that could add value to the investigation and help in the court
of law. Then a baseline was established by the tea to get an insight into how the
standard operation would appear in the system. WFT was used for the purpose
(Farshadkhah & Stafford, 2019). It helped not just to create a baseline but it also
helped to make a comparison between the standard operations and the current
operations that were taking place in the system. The team also decided to evaluate
the server logs to get an insight into any malicious or unauthorized activity that
could be taking place in the firm’s system. It helped to get an insight into when
connections were being established with the firm’s database without its knowledge.
Ultimately a sniffer was used for monitoring the network traffic.
Findings
The findings that were arrived at after conducting the forensic investigation
process were of high relevance for the organization. One of the major findings was
that Drew’s hard disk contained the intellectual property of ACME Construction
Company. While reviewing the logs it was ascertained that a new account had been
created and unauthorized activities were being carried out by using the account. The
thorough assessment of the log files indicated that anonymous logins were being
made from Drew’s system even though his account was not being used directly
(Farshadkhah & Stafford, 2019). It was evident that Drew’s system was showcasing
abnormal behavior as numerous file transfers had taken place using the same system.
ISE 640 ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab
ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab a ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab a ab ab ab ab ab ab ab ab ab ab 7
In addition to this, the files of the organization that were being transferred to the IP
address were not owned by the ACME Construction Company. This indicated that
Drew was trying to steal the intellectual property of the organization and use it after
he would leave the business entity. The in-depth assessment of the captured evidence
indicates that Drew was using his position to steal confidential data of the firm and
sell it to its competitors.
References
Farshadkhah, S., & Stafford, T. (2019, January). The Role of “Eyes of Others” in
Security Violation Prevention: Measures and Constructs. In Proceedings of the
52nd Hawaii International Conference on System Sciences.
Xia, W. A. N. G. (2017). On the relationship between the psychological
empowerment and violation behavior of the airport security staff members.
Journal of Safety and Environment, (5), 45.
Zhou, S., Wu, L., & Jin, C. (2017). A privacy-based SLA violation detection model
for the security of cloud computing. China Communications, 14(9), 155-165.
Students also viewed