Research | Practice

Showing posts with label Infosec. Show all posts
Showing posts with label Infosec. Show all posts

2017-01-09

[How to] GPG and Signing Data

Monday, January 09, 2017 Posted by Unknown , , , , , No comments
GNU Privacy Guard (GPG) uses public and private keys to secure communications (public-key cryptography). Many people use it to encrypt their email or other documents. An email encrypted with a user's public key can then only be decrypted with the same user's private key. This provides end-to-end encryption of the message, meaning that it is impractical for anyone that is listening in on the conversation to get the message in transit.


This is, of course, good and bad. For example, Google and other email providers use email text to gain intelligence about the user, sell user information and do better ad targeting. This revenue stream keeps these services free, but users pay for it in terms of 'sold' privacy. Email using end-to-end encryption cannot be analyzed for useful marketing information. Because of this, these providers don't want to make it easy for mass encryption.

On the other hand, criminals also use Cloud-based email services. Making encryption somewhat difficult means that sloppy criminals are less likely to use encryption. If so, they may be easier to detect and catch.

Related Book: Lucas, Michael. PGP & GPG: Email for the Practical Paranoid. No Starch Press. 2006.

Whether you are paranoid and want all your emails encrypted (good luck), or you are trying to implement a personal or business data classification policy, GPG can help with encryption requirements.

Beyond encryption, GPG is useful for signing data. This is not exactly a signature that you would put on a document. Instead it is a signature that verifies that the data is correct. The video below describes how to sign data.



Signing data lets your contacts know that the data has not been modified from the time it left your possession. Signing is NOT encryption. Everyone could see the contents. Singing just allows your contact to know the data came from you, and it is in it's original state.

2017-01-02

2016-12-26

[How to] Installing and updating Linux in Virtualbox

Monday, December 26, 2016 Posted by Unknown , , No comments
Today we are going to install and update a Debian-based operating system in VirtualBox as a guest operating system.

The first video goes through creating a virtual machine in VirtualBox, and installing an operating system from an ISO disk image.



The next video uses apt-get to update the software in the system, as well as ifconfig and ping to check if the network is working.


The final video shows how to install VirtualBox Guest Additions to allow multiple features inside the guest operating system.


2016-12-09

What I'm Reading: A functional reference model of passive systems for tracing network traffic

Friday, December 09, 2016 Posted by Unknown , , , , No comments
What I'm Reading: Today we are talking about 'A functional reference model of passive systems for tracing network traffic' by Thomas E. Daniels. This paper deals with network traffic origin analysis using passive methods.

T. E. Daniels, “A functional reference model of passive systems for tracing network traffic,” Digit. Investig., vol. 1, no. 1, pp. 69–81, Feb. 2004.

Link: http://www.sciencedirect.com/science/article/pii/S1742287603000045


Audio only:

2016-11-17

No More Ransom - Detecting and unlocking ransomware without paying

Thursday, November 17, 2016 Posted by Unknown , , , No comments
Data is valuable. Ransomware takes advantage of the financial or sentimental value of our data, as well as the fact that most homes and organizations do not have adequate data backup solutions in place.

Once a computer is infected with ransomware, individual files are normally encrypted and users are asked to pay a ransom to unlock their data. If the victim pays, the data may or may not be unlocked. Ransomware started off like most viruses, targeting average computer users opportunistically. Ransomware groups, however, started targeting hospitals, police organizations and others.

Use nomoreransom.org to unlock your data

So what can you do if you are infected with ransomware? Internet vendors and law enforcement have come together to create No More Ransom. This website gives users information about current types of ransomware, download unlocking tools (for free), provides prevention information and even has a tool to analyze your encrypted files and recommends which unlocking tool to use.

The Problem
Ransomware is possible because people do not have backups in place.

The Solution
Backups.

If you have an extra hard-drive that you are not using, or even another computer that is often on, CrashPlan is a pretty straightforward backup solution that is free if you save data to your own computers.

Note: DropBox or similar are not good backup solutions because they constantly sync changes. If ransomware infects your systems, the changes may be synced to your cloud storage. With a backup solution like CrashPlan, 1) backup is not instantaneous and 2) CrashPlan keeps track of prior versions of data. So if encrypted files were backed up, you can still restore prior versions. Best of all, CrashPlan provides end-to-end encryption (if enabled).








2016-11-03

Paid Graduate Positions Available: Digital Investigations in Internet of Things

Thursday, November 03, 2016 Posted by Unknown , , , No comments
The Legal Informatics and Forensic Science (LIFS) Institute in the College of International Studies at Hallym University, South Korea, currently has openings for full-time researchers at the Masters, Ph.D. and Postdoctoral levels.

These positions deal with Internet of Things (IoT) digital forensic investigations. The following skills are necessary:
  • Programming skills (any language)
  • Ability to plan and carry out research
  • Ability to work with a team

The following skills are preferred but not required:
  • Knowledge of embedded systems
  • Embedded system programming experience
  • Computer / Network administration experience
  • Competency in Linux / Unix systems
  • Knowledge of Digital Forensic Investigation techniques (esp. acquisition)

These positions include a full scholarship as well as a monthly living stipend. Candidates should be willing to relocate to Chuncheon, South Korea.

To apply for the Master’s and Ph.D. positions, please do the following:
  1. Send an email with your CV and links to any research papers you have published to joshua.i.james@hallym.ac.kr with the subject “IoT Graduate Application”.
  2. Apply for a graduate position with Hallym University [http://bit.ly/20Fvvi4] by November 10th, 2016.
    • Download the application files [http://bit.ly/2eWHVSM]
    • Complete the basic application files
    • Mail the application files to grad@hallym.ac.kr and CC joshua.i.james@hallym.ac.kr
    • Other documents can be provided later (such as passport info, diploma, etc.)
    • No Visa will be issued until certified copies of supporting documents are provided.

To apply for a Post-doctorate in Digital Forensic Investigation of IoT Devices, please do the following:
  1. Send an email with your CV and links to any research papers you have published to joshua.i.james@hallym.ac.kr with the subject “IoT Postgraduate Application”.
    • Candidates must have already completed a PhD degree.

2016-11-01

사물인터넷(IoT) 디지털 수사 관련 전액장학금 지원 석/박사 직위 공모

Tuesday, November 01, 2016 Posted by Unknown , , , No comments
한림대학교 국제학부의 정보법과학전공에서는 현재 석사, 박사, 그리고 박사후과정생을 대상으로 정규직 연구원을 모집하고 있습니다.
해당 직위는 사물인터넷(IoT) 디지털 포렌식 수사에 관련된 연구를 담당하므로, 다음과 같은 자격을 요합니다.
  • 프로그래밍 실력 (언어 무관)
  • 연구설계 및 실행능력
  • 팀워크 능력

다음 사항은 필수 자격요건은 아니나 권장되는 능력입니다:
  • 임베디드 시스템에 대한 지식
  • 임베디드 시스템 프로그래밍 경험
  • 컴퓨터/네트워크 관리 경험
  • 리눅스/유닉스 시스템에 대한 이해
  • 디지털 포렌식 기법 (특히 획득기법)에 대한 지식


해당 직위는 전액 장학금 및 생활비가 제공됩니다. 후보자들은 거주지를 강원도 춘천시로 옮기는 것이 권장됩니다.


석사 및 박사과정생 직위에 응모하기 위해서는 다음과 같이 지원해주시기 바랍니다.
  1. 자신의 이력서 1, 출판된 연구결과물에 대한 링크를 “IoT Graduate Application”을 제목으로 하여 joshua.i.james@hallym.ac.kr 로 이메일을 보내주시기 바랍니다.
  2. 20161110일까지 다음 링크 [http://bit.ly/20Fvvi4]로 한림대학교 대학원에 지원해주시기 바랍니다.
    다음 링크 [http://bit.ly/2eWHVSM]를 통해 지원서 파일을 다운받은 후,
    기본 지원서 파일을 작성하시기 바랍니다.
    완성된 지원서 파일을 grad@hallym.ac.kr 로 발송하면서 joshua.i.james@hallym.ac.kr 로 참조를 걸어주시기 바랍니다.

    여권 및 신분증, 학위증명서 등 기타 다른 문서는 나중에 제출하셔도 됩니다.
박사후과정 직위에 응모하기 위해서는 다음과 같이 지원해주시기 바랍니다:

1. 자신의 이력서 1, 출판된 연구결과물에 대한 링크를 “IoT Graduate Application”을 제목으로 하여 joshua.i.james@hallym.ac.kr 로 이메일을 보내주시기 바랍니다.
후보자들은 반드시 박사학위를 취득하였어야 합니다

2016-07-16

[CFP] CLOUDFOR extended submission deadline

Saturday, July 16, 2016 Posted by Unknown , , No comments
CLOUDFOR 2016: Workshop on Cloud Forensics
In conjunction with the 9th IEEE/ACM International Conference on Utility and Cloud Computing (UCC), Tongji University, Shanghai, China.
6-9 December 2016

Scope and Purpose
=================
As a consequence of the sharp growth in the Cloud Computing market share, we can expect an increasing trend in illegal activities involving clouds, and the reliance on data stored in the clouds for legal proceedings. This reality poses many challenges related to digital forensic investigations, incident response and eDiscovery, calling for a rethink in traditional practices, methods and tools which have to be adapted to this new context. 
This workshop aims to bring researchers and practitioners together as a multi-disciplinary forum for discussion and dissemination of ideas towards advancing the field of Cloud Forensics. 

Topics of interest comprise, but are not limited to:
* Digital evidence search and seizure in the cloud
* Forensics soundness and the cloud
* Cybercrime investigation in the cloud 
* Incident handling in the cloud
* eDiscovery in the cloud
* Investigative methodologies for the cloud
* Forensics readiness in the cloud
* Challenges of cloud forensics
* Legal aspect of cloud investigations
* Tools and practices in cloud forensics
* Case studies related to cloud forensics
* Forensics-as-a-Service
* Criminal profiling and reconstruction in the cloud
* Data provenance in the cloud
* Law enforcement and the cloud
* Big data implications of cloud forensics
* Economics of cloud forensics
* Current and future trends in cloud forensics
* Grid forensics 

Important dates
===============
* Paper submission: 15 August 2016 (extended deadline)
* Notification of acceptance: 05 September 2016 
* Camera-ready submission:  21 September 2016

Workshop chairs
===============
Virginia N. L. Franqueira
University of Derby, UK
v.franqueira[at]derby.ac.uk

Kim-Kwang Raymond Choo
University of South Australia, AU

Tim Storer 
University of Glasgow, UK

Andrew Jones
University of Hertfordshire, UK 

Raul H. C. Lopes
Brunel University (GriPP & CMS/CERN), UK

Program Committee
=================
George Grispos, The Irish Software Research Centre (LERO), IE
Andrew Marrington, Zayed University, AE
Kiran-Kumar Muniswamy-Reddy, Amazon Web Services, US
Joshua I. James, Hallym University, KR
Geetha Geethakumari, BITS Pilani, IN
Shams Zawoad, Visa Inc., US
Olga Angelopoulou, University of Hertfordshire, UK
Vrizlynn Thing, Institute for Infocomm Research, SG
Theodoros Spyridopoulos, University of the West of England, UK
Vassil Roussev, University of New Orleans, US
Yijun Yu, Open University, UK
Ibrahim Baggili, University of New Haven, US
Martin Schmiedecker, SBA Research, AT
Ben Martini, University of South Australia, AU
Hein S. Venter, University of Pretoria, ZA
Ruy de Queiroz, Federal University of Pernambuco, BR
Martin Herman, National Institute of Standards and Technology, US 
Mark Scanlon, University College Dublin, IE

Submission 
==========
Authors are invited to submit original, unpublished work which will be reviewed by three committee members. Submission should be blind, i.e., with no stated authors, or self-references. Papers should comply with the IEEE format, and have a maximum of 6 pages; guidelines are available at: http://www.ieee.org/conferences_events/conferences/publishing/templates.html
All accepted papers will be published in the IEEE conference proceedings – provided they are presented at the workshop.
Submission will be handled through EasyChair: https://easychair.org/conferences/?conf=cloudfor2016

2016-05-13

Facebook Capture the Flag Platform Now Available

Friday, May 13, 2016 Posted by Unknown , , No comments
Facebook's hacking education platform and capture the flag is now available. See their release post here. Their goal is to educate about different types of web attacks by giving access to CTF infrastructure and letting more groups run hacking competitions. From their github repository:

  • Organize a competition. This can be with as few as two participants, all the way up to several hundred. The participants can be physically present, active online, or a combination of the two.
  • Follow setup instructions below to spin up platform infrastructure.
  • Enter challenges into admin page
  • Have participants register as teams
    • If running a closed competition:
      • In the admin page, generate and export tokens to be shared with approved teams, then point participants towards the registration page
    • If running an open competition:
      • Point participants towards the registration page
  • Enjoy!
I'm playing with it now, but it looks like it will be an amazing resource for students.

2016-04-29

Honeypot Fun

Friday, April 29, 2016 Posted by Unknown , No comments
At the Legal Informatics and Forensic Science Institute, we are preparing to do some research on IoT smart homes. Part of that is setting up a slightly-less-secure system. I run some honeypots on my home networks, but I was interested to see what is coming in to the known University IP range.

I had an extra Raspberry Pi laying around, and decided to run cowrie (kippo) SSH honeypot. Mostly because it is very fast to set up, gives you an idea of where attacks are coming from, and also gives a list of usernames and passwords that people are trying. More on the setup of cowrie later.

After putting cowrie online, it took 28 minutes before the first connection. This is actually longer than I expected. Possibly because the IP was up before, but port 22 was not open.

After 12 hours, login attempts from the following addresses:

Login Attempts IP Address Country
1 146.66.163.107 Russia
3 185.103.252.14 Russia
9 195.154.58.76 France
18 159.122.123.183 Germany
40 117.102.109.18 Indonesia
41 193.201.227.200 Ukraine
91 94.79.5.102 Russia
126 193.201.227.86 Ukraine
336 202.83.25.95 India

Remember that the country doesn't actually mean anything. These could be proxies, tor, hacked servers, etc.

The top usernames and passwords are not very surprising.

Tries Username / Password
21 [root/123456]
19 [root/default]
18 [admin/support]
18 [admin/default]
18 [admin/123123]
8 [root/admin]
6 [admin/admin]
5 [test/test]
5 [support/support]
5 [root/qwerty]

Probably the most interesting thing is that the first attack was that the first attack was trying some sort of buffer-overflow. Although they were connecting to SSH and sending (weird) user/pass combinations, after the connection was rejected they were sending really long strings. I suspect it is some sort of honeypot detection, or it exploits certain versions of SSH? Not sure.

Anyway, for a 1 hour project it is easy and interesting. Definitely something that students could do in an afternoon.

2016-04-28

2016-02-03

[CFP] JDFSL Special issue on Cyberharassment Investigation: Advances and Trends

Wednesday, February 03, 2016 Posted by Unknown , , , No comments

JDFSL Special issue on Cyberharassment Investigation: Advances and Trends.

Anecdotal evidence indicates that cyber harassment is becoming more prevalent as the use of social media becomes increasingly widespread, making geography and physical proximity irrelevant. Cyberharassment can take different forms (e.g., cyberbullying, cyberstalking, cybertrolling), and be motivated by the objectives of inflicting distress, exercising control, impersonation, and defamation. Investigation of these behaviours is particularly challenging because it involves digital evidence distributed across the digital devices of both alleged offenders and victims, as well as online service providers, sometimes over an extended period of time. As a result, little is currently known about the modus operandi of offenders.

This special issue invites original contributions from researchers and practitioners which focus on the state-of-the-art and state-of-the-practice of digital forensic investigation of cyberharassment of all kinds.  We particularly encourage multidisciplinary contributions that can help examiners to be more effective and efficient in cyberharassment investigations.
Topics of interest include, but are not limited to:
-Offender psychology and profiling
-Cyberharassment victimology
-Methodologies and process models specific to cyberharassment investigation
-Tools and techniques for dealing with the types of digital evidence encountered in cyberharassment investigation
-Cyberharassment indicators
-Challenges and particularities of different modalities of cyberharassment
-Trends and typologies of cyberharassment

Important dates:
-Paper Submission:                 1 June 2016
-Notification of Initial Decision: 30 June 2016
-Revision due:                     31 July 2016
-Notification of Final Decision:   31 August 2016
-Final Manuscript Due:             30 September 2016
-Publication Date:                 31 October 2016

Author instructions:
The submissions must be blind and original (i.e., must not have been published or be under review by any other publisher). Authors should refer to the following link for instructions: http://www.jdfsl.org/for-authors. The option “Cyberharassment Special Issue” must be selected as article type on JDFSL OJS Submission System.  Further queries can be directed to the guest editors.

Guest Editors:
Dr Joanne Bryce
School of Psychology
University of Central Lancashire

Dr Virginia Franqueira
College of Engineering and Technology
University of Derby

Dr Andrew Marrington
College of Technological Innovation
Zayed University

About JDFSL:

The Journal of Digital Forensics, Security and Law (JDFSL) is a peer-reviewed, multidisciplinary journal focussing on the advancement of the cyber forensics field through the publication of both basic and applied research. JDFSL is a no-fee open access publication, indexed in EBSCOhost, ProQuest, DOAJ, DBLP, arXiv, OAJI, ISI Web of Science, Google Scholar, and other databases. JDFSL is published by the Association of Digital Forensics, Security and Law.

2015-09-25

ICDF2C 2015 in Seoul, South Korea Final Program Now Available

Friday, September 25, 2015 Posted by Unknown , , , , , No comments
The 7th EAI International Conference on Digital Forensics & Cyber Crime will be held OCTOBER 6–8, 2015 in SEOUL, SOUTH KOREA.

The final program is now available at http://d-forensics.org/2015/show/program-final
Be sure to register so you don't miss the exiting talks and tutorials!

Keynote speakers include Max Goncharov from Trend Micro, Inc, and Dr. Dave Dampier from Mississippi State University:

Max Goncharov is a senior security Virus Analyst with Trend Micro Inc., and is responsible for cybercrime investigations, security consulting to business partners (internal, external), creation of security frameworks, designing technical security architecture, overseeing the build out of an enterprise incident response process, and creation of the enterprise risk management program. During his 15 years with Trend Micro Inc, he has participated as a speaker in various conferences and training seminars on the topic of cybercrime and related issues. He has especially focues on cyberterrorism, cybersecurity, underground economy; such as DeepSec, VB, APWG, etc.


Dr. Dave Dampier is a Professor of Computer Science & Engineering at Mississippi State University specializing in Digital Forensics and Information Security. He currently serves as Director of the Distributed Analytics and Security Institute, the university level research center charged with Cyber Security Research. In his current capacity, Dr. Dampier is the university lead for education and research in cyber security. Prior to joining MSU, Dr. Dampier spent 20 years active duty as an Army Automation Officer. He has a B.S. Degree in Mathematics from the University of Texas at El Paso, and M.S. and Ph.D. degrees in Computer Science from the Naval Postgraduate School. His research interests are in Cyber Security, Digital Forensics and Software Engineering.


There will also be three tutorials on investigation, open source hardware for digital investigations and setting up a research environment for mobile malware research:

  • Tutorial 1: DUZON – Desktop Exercise: Crafting Information from Data
  • Tutorial 2: Pavel Gladyshev – FIREBrick; an open forensic device
  • Tutorial 3: Nikolay Akatyev – Researching mobile malware
After the first day of the conference we are also holding a special discussion session with Seoul Tech Society called "Safe Cyberspace", with the panel consisting of the winners of the ICDF2C/STS essay contest. Everyone is welcome to join!

I hope to see you at ICDF2C in Seoul, South Korea! Don't miss this exciting opportunity.

2015-08-26

ICDF2C Revised Draft Program Released

Wednesday, August 26, 2015 Posted by Unknown , , No comments
7th International Conference on Digital Forensics and Cyber Crime (ICDF2C) updated program is now available here: http://bit.ly/1LsJpvM


The conference will be held in Seoul, South Korea from October 6 - 8, 2015. You can register for the conference here: http://d-forensics.org/2015/show/registration

We offer discounts for Law Enforcement and Students.

We are also working with Seoul Tech Society to run an information security essay contest and panel discussion. For more information, please see the call for essays.

2015-08-25

ICDF2C and SeoulTechSoc Call for Essays on Information Security

Tuesday, August 25, 2015 Posted by Unknown , , , No comments

ICDF2C and Seoul Tech Society Essay Contest

Have you ever surfed the Dark Web? Are you worried about the security of your virtual property? Technology is changing, and for every good side, there is a dark side. With these new technologies, how can the public protect themselves? Should the public rely on their government, or take security into their own hands? Let us know what you think with the ICDF2C and Seoul Tech Society Cyber Crime Essay Contest.



This year ICDF2C has two focus areas:

  • Usage, implications and investigation of the “Dark Web”
  • Preventing or investigating crimes using cryptocurrencies

Although these topics are recommended, essays are not limited to these topics. For the full list of conference topics, please see http://d-forensics.org/2015/show/cf-papers

Submission Instructions

  • Submissions should be in English
  • Submissions should be no longer than 3 pages (with references)
  • Submissions must be submitted as a PDF

Please send a PDF of your essay to Joshua at cybercrimetech.com

Important Dates

  • Submission Deadline: September 21, 2015 (any time zone)
  • Notification: October 1, 2015
  • ICDF2C/SeoulTech Discussion Session: October 6, 2015, 18:00 – 19:30

Rewards

  • The top 5 essays will present their ideas at the ICDF2C/SeoulTech Discussion Session
  • Selected essays will be published in discussion session proceedings, and made available on the Seoul Tech Society web page
See d-forensics.org for more information.

2015-08-23

Ashley Madison Data and Ethical Use

Sunday, August 23, 2015 Posted by Unknown , , No comments
On August 19th, the Impact Team released data of millions of alleged Ashley Madison users. Ashley Madison is a type of social networking website that promotes extra-marital affairs. After the main user data, the source code for the website, and emails from the founder were also released.

The data was initially released on the Dark Web, but has since been added to many clear web sites.

Impact Teams .onion site on Tor where the data can be downloaded
Impact Team's .onion site

The data contains information about users names, email addresses, locations, addresses, credit card numbers, credit card transactions, sexual preferences, and much, much more.

If you are thinking about looking up your friends and neighbors, think about the following first:

You cant trust most versions of the data

Many people are interested in this data. Hackers and criminals know that it will be very popular, so they will add viruses and other malware to the data. It is also possible that copied versions had records added specifically to frame people. If you are going to use any version, make sure it came from Impact Team.

You cant trust websites that let you search the data

Even before the data was released, some websites were created to be able to post the data if and when it was released. Some of these websites are created by trusted security researchers, some are created by hackers, some are created by people who just want to make money off of the situation. The result is that you should only use trusted websites when evaluating data like this. Other sites may have malware, and some sites may collect any email addresses, names, phone numbers that you enter to "check" and resell that information to advertising companies. Be careful with websites you don't know.

The original data could have been fake or tampered with

Data directly from Impact Team is the 'most reliable' version that we will get. However, this does not mean that it has not been tampered with. They may have added or modified entries.

Further, some accounts that exist in the system are likely to be fake anyway. The only accounts we can be reasonably sure of are attached to credit card transactions, and even those may possibly have been created by a stolen card.

Think about what you are doing

With data like this, there are a lot of things we can learn. I have a copy of the data, and I did not look up my friends or co-workers. Why? Because I don't care. Many websites are using the data to find who is cheating on who. That question is not interesting. What is interesting is, for example, why people are cheating. We might even ask is cheating a bad thing? For 39 million people, apparently it isn't. Other interesting questions include how to prevent an attack like this in the future? What are the most common passwords? Etc.

While the data is useful for information security to learn from its mistake, making the data easily accessible for the sake of gossip is not useful, and could potentially cause mental and physical damage. Consider this 'help' that a woman received from radio talk show hosts. As soon as the woman found out her husband was cheating, the host even admitted he felt like a jerk.



I completely agree with the approach from the people at haveibeenpwned.com who explain in their blog post that it is not the job of security researchers to out people. It is our job to protect people.

Every time there is a data leak, the information is used for all sorts of scams, and criminals are already using the AM data. The people involved in this breach could have their entire lives destroyed by releasing all of their information. Some people will say that they deserve it for being on such a site. Thats a matter of opinion. But as security researchers if we don't look for ways to use (and release) data responsibility, we may be hurting people to find the 'juicy bits' rather than improving security, privacy and freedom for everyone.