The Experts below are selected from a list of 57 Experts worldwide ranked by ideXlab platform
Brian Hay - One of the best experts on this subject based on the ideXlab platform.
-
teaching digital forensics techniques within linux environments
Hawaii International Conference on System Sciences, 2014Co-Authors: Lucas Mcdaniel, Brian HayAbstract:Appropriately motivating digital forensics topics in an educational environment is a challenging task for a lecturer. Not only will the skill levels of the students vary widely, but designing a lab exercise that introduces a single concept runs the risk of requiring too much additional knowledge to appropriately describe the task or may easily devolve into a contrived example that does not allow the student to fully grasp the extent of the topic at hand. In some cases, this difficulty is compounded by the sheer amount of misinformation that results from years of common knowledge and research becoming invalid after changes to kernels and operating systems. Last year, the Honeynet Project Challenge 12 - "Hiding in Plan Sight" - and a computer security workshop sought to introduce some concepts regarding information and process hiding and disguising through a series of digital forensics labs. This paper will describe the components of these labs that were successful at motivating a core concept, as well as those that were not as successful and have been subsequently modified based upon feedback. These findings will be presented through a suggested lecture-lab format, and a series of scoped topics that can be used in other educational environments to motivate digital forensics and anti-forensics concepts. Scripts used to build each lab have also been provided to serve as a point of reference.
-
Securing e-government assets through automating deployment of Honeynets for IDS support
Proceedings of the Annual Hawaii International Conference on System Sciences, 2010Co-Authors: Christopher Hecker, Brian HayAbstract:One of the challenges facing system e-government security professionals is the laborious task of sifting through numerous log files in an attempt to identify malicious traffic and conduct a forensics analysis to determine an appropriate course of action. This process is complicated significantly by the volume of traffic that can be associated with a production system environment. A Honeynet can provide a mechanism to identify much of the forensically interesting traffic by creating a representative system to collect traffic data. However, it is challenging to maintain an accurate representation of a dynamic system in order to consistently collect the appropriate data of interest. This research effort addresses a current challenge identified by researchers at the Honeynet Project by describing a methodology for automatically creating and dynamically updating a Honeynet in order to facilitate IDS support.
Dowling Anthony - One of the best experts on this subject based on the ideXlab platform.
-
Digital Forensics: A Demonstration of the Effectiveness of The Sleuth Kit and Autopsy Forensic Browser
'University of Otago Library', 2010Co-Authors: Dowling AnthonyAbstract:The Sleuth Kit is a collection of Linux tools that perform different aspects of a file system analysis. The Autopsy Forensic Browser is a graphical user interface that provides a user friendly interface to the command line tools contained within The Sleuth Kit. This research Project investigates the use of The Sleuth Kit and Autopsy Forensic Browser as forensic investigation tools, with the aim of demonstrating the effectiveness of these tools in real world case studies as digital forensic tools. The research found that The Sleuth Kit and Autopsy Forensic Browser provide an effective file system analysis toolset. The flexibility of the tools contained within The Sleuth Kit often lead to complex command line strings, the complexity of which is overcome by the automation provided by the Autopsy Forensic Browser. Not only do The Sleuth Kit and Autopsy Forensic browser provide an effective toolset, they also offer an affordable alternative to expensive commercial or proprietary based toolsets. Digital Forensics is an area of increasing importance with an expanding field of coverage requiring many different tools to help perform varying functions. It is with this in mind that the focus of this research Project is three case studies that are utilised to demonstrate the effectiveness of The Sleuth Kit and Autopsy Forensic Browser. The demonstration of The Sleuth Kit and Autopsy Forensic Browser contained within the case studies could serve as an introductory overview of a new toolset for investigators looking for an alternative or complementary Digital Forensics toolset.NIJ, Solicitation for Concept Papers - Electronic Crime Research and Development. 2005. p. 1-13. Carrier, B., Open Source Digital Forensic Tools: The Legal Argument. 2002. Farmer, D. and W. Venema. The Coroners Toolkit Project Page. 2004 [cited; Available from: httpi//wwwporcupine.org/forensics/tct.html. Vacca, J.R., Computer Forensics: Computer Crime Scene Investigation. 2002, Hingham, Massachusetts: David F. Pallai. 731. Casio Computer Company Ltd. Casio E-Data Bank Watches. 2005 [cited; Available from: http://world.casio.com/pacific/wat/e_data/. MacSema Inc. Contact Memory Button (CMB'S). 2001 [cited; Available from: http://www.macsema.com/buttonmemory.htrn. Wikimedia Foundation. Wikipedia - Data Recovery Definition. 2005 [cited; Available from: http://en.wikipedia.org/wiki/Data recovery. Lee, H., T. Palmbach, and M. Miller, Henry Lee's Crime Scene Handbook. 2001, London: Academic Press. Ltd, C.F.N. Data Recovery & Computer Investigations. 2005 [cited; Available from: http://www.datarecovery.co.nz/datarecovery/ index.html?source=adwords-datarecov. New Zealand Police E-crime Lab. Fighting e-crime in New Zealand. 2002 [cited; Available from: http://www.police.govt.nz/service/ecrime/. Wikimedia Foundation. Wikipedia - Sulphonylurea Definition. 2005 [cited; Available from: http://en.wikipedia.org/wiki/Sulphonylurea. NZHerald.co.nz. Jury quick to convict doctor of murder. 2001 [cited; Available from: http://www.nzherald.co.nz/index.cfm?Ob'ectiD=229152. Police, N.Z. New Zealand Police Youth Education Service. 2005 [cited; Available from: http://www.police.govt.nz/service/yes/. Police, N.Z. Keeping Ourselves Safe. 2005 [cited; Available from: http://www.police. ovt.nz/service/yes/resources/violence/kos.html. Farmer, D. and W. Venema, Forensic Discovery. 2004: Addison-Wesley. Office of e-Government. Forensic Plan. 2004 [cited; Available from: http://www.egov.dpc.wa.gov.au/. Gutmann, P., Secure Deletion of Data from Magnetic and Solid-State Memory, in Sixth USENIX Security Symposium Proceedings. 1996, University of Auckland. Gutmann, P. Data Remanence in Semiconductor Devices. 2001 [cited. Carrier, B., File System Forensic Analysis. 2005: Addison-Wesley. Optical Storage Technology Association. Understanding CD-R CD-RW Disc Longevity. 2001 [cited; Available from: http://www.osta.org/technolo /cda13.htm. Instruments, V. Veeco Instruments Web Site. 2005 [cited; Available from: http://www.veeco.com/. Garfinkel, S.L. and A. Shelat, Remembrance of Data Passed: A Study of Disk Sanitization Practices. 2003, Massachusetts Institute of Technology. American Institute of Physics. Heisenberg - Quantum Mechanics, 1925 - 1927: The Uncertainty Principle. 2005 [cited; Available from: http://www.aip.org/history/heisenberg/p08.htm. Seagate. Seagate Barracuda 7200.8 ST3400832A Specs. 2005 [cited; Available from: http://www.seagate.com/cda/products/discsales/marketing/detail/0.html. ACPO. ALPO Good Practice Guide to Computer Based Evidence. 2003 [cited; Version 3.0:[Available from: http://www.acpo.police.uk/asp/policies/Data/gpg_computer_based_evidence_v3.pdf. New Technologies Inc. File Slack Defined. 2004 [cited; Available from: http://www.forensics-intl.com/def6.html. PCTechGuide. Hard Disks. 2003 [cited; Available from: http://www.pctechguide.com/04disks.htm. Wikimedia Foundation. Wikipedia - Endianness. 2005 [cited; Available from: http://en.wiki edia.or /wiki/Biendian. 29. www.lookuptables.com. ASCII Table and Description. 2005 [cited; Available from: http://www.lookuptables.com/. Inc, U. Unicode Home Page. 2005 [cited; Available from: http://www .unicode.org/ Inc, U. Unicode v4.1.0. 2005 [cited; Available from: http://www.unicode.org/versions/Unicode4.1.0/. Microsoft. FAT32 File System Specification. 2000 [cited; Available from: http://www.microsoft ..oiT!/vvlidc/system/platform/fin-nware/fa en.ms x: Carrier, B. The Sleuth Kit and Autopsy Project Page. 2004 [cited; Available from: http://www.sleuthkit.org. Brzitwa, M. gpart - Guess PC-type hard disk partitions. 2001 [cited; Available from: http://www.stud.uni-hannover.de/user/76201/gpart/. cgSecurity. TestDisk - Tool to check and undelete partition. 2005 [cited; Available from: htt.://www.c_ security.org/index.html?testdisk.html. PJRC. Understanding FAT32 Filesystems. 2005 [cited; Available from: http://www.pjrc.com/tech/8051/ide/fat32.html. Brouwer, A. Partition Types. 2005 [cited; Available from: http://www.win.tue.n1/~aeb/partitions/partition_types.html. Microsoft. Encrypting File System Overview. 2005 [cited; Available from: http://www.microsoft.com/resources/documentation/windows/x /all/proddocs/ en-us/encrypt_overview.mspx. PGP Corporation. PGP Corporation Website. 2005 [cited; Available from: http://www.com/. Devine, C. Encrypted Root Filesystem HOWTO. 2005 [cited; Available from: http://linuxfromscratch.org/~devine/erfs-howto.html Wolfe, H., Penetrating Encrypted Evidence. Journal of Digital Investigation, 2004. 1(2). "@stake". "gstake.com". 2004 [cited; Available from: http://www.atstake.com/. NIST. National Software Reference Library. [Project Web Site] 2004 [cited; Available from: http://www.nsrl.nist.gov/index.html. The Honeynet Project. The Honeynet Project Website. The Honeynet Project 2004 [cited; Available from: http://www.Honeynet.org/misc/Project.html. The Honeynet Project. The Honeynet Project Scan of the Month 24. The Honeynet Project 2001 [cited; Available from: http://www.Honeynet.org/scans/scan24/. The Honeynet Project. The Honeynet Project Scan of the Month 26. The Honeynet Project 2002 [cited; Available from: http://www.Honeynet.org/scans/scan26/. The Honeynet Project. The Honeynet Project Forensic Challenge. The Honeynet Project 2001 [cited; Available from: http://www.Honeynet.org/challenge/index.html. Digital Forensic Research Workshop. Digital Forensic Research Workshop website. 2005 [cited; Available from: http://www.dfrws.org/. 49. Hamilton, E. JPEG File Interchange Format v1.02. 1992 [cited; Available from: http://www.w3.org/Graphics/JPEG/. Kessler, G. File Signature Table. 2005 [cited; Available from: http//www.garykessler.net/library/file_sigs.html. United States Air Force Office of Special Investigation. Foremost - Webpage. 2005 [cited; Available from: http://foremost.sourceforge.net/. Provos, N. Stegdetect - Webpage. 2005 [cited; Available from: http//www.outguess.org/. NeoByte Solutions. Invisible Secrets - Webpage. 2005 [cited; Available from: http://www.invisiblesecrets.com/. Roesch, M. SNORT. 2005 [cited; Available from: http://www.snort.org/. Roesller, T. Lastlog File Analyser Source File. 2000 [cited; Available from: http://www.Honeynet.org/challenge/results/submissions/roessler/files/lastlog.c. CERT/CC. CERT® Coordination Center (CERT/CC). 2005 [cited; Available from: http://www.cert.org/nav/index_main.html. CERT/CC. CERT® Advisory CA-2000-17 Input Validation Problem in rpc.statd. 2000 [cited; Available from: http://www.cert.org/advisories/CA- 2000-17.html. Red Hat Network. Revised advisory: Updated package for nfs-utils available. 2000 [cited; Available from: https://rhn.redhat.com/errata/RHSA-2000- 043.html
-
Digital forensics: A demonstration of the effectiveness of the sleuth kit and autopsy forensic browser
2006Co-Authors: Dowling AnthonyAbstract:The Sleuth Kit is a collection of Linux tools that perform different aspects of a file system analysis. The Autopsy Forensic Browser is a graphical user interface that provides a user friendly interface to the command line tools contained within The Sleuth Kit. This research Project investigates the use of The Sleuth Kit and Autopsy Forensic Browser as forensic investigation tools, with the aim of demonstrating the effectiveness of these tools in real world case studies as digital forensic tools. The research found that The Sleuth Kit and Autopsy Forensic Browser provide an effective file system analysis toolset. The flexibility of the tools contained within The Sleuth Kit often lead to complex command line strings, the complexity of which is overcome by the automation provided by the Autopsy Forensic Browser. Not only do The Sleuth Kit and Autopsy Forensic browser provide an effective toolset, they also offer an affordable alternative to expensive commercial or proprietary based toolsets. Digital Forensics is an area of increasing importance with an expanding field of coverage requiring many different tools to help perform varying functions. It is with this in mind that the focus of this research Project is three case studies that are utilised to demonstrate the effectiveness of The Sleuth Kit and Autopsy Forensic Browser. The demonstration of The Sleuth Kit and Autopsy Forensic Browser contained within the case studies could serve as an introductory overview of a new toolset for investigators looking for an alternative or complementary Digital Forensics toolset.UnpublishedNIJ, Solicitation for Concept Papers - Electronic Crime Research and Development. 2005. p. 1-13. Carrier, B., Open Source Digital Forensic Tools: The Legal Argument. 2002. Farmer, D. and W. Venema. The Coroners Toolkit Project Page. 2004 [cited; Available from: httpi//wwwporcupine.org/forensics/tct.html. Vacca, J.R., Computer Forensics: Computer Crime Scene Investigation. 2002, Hingham, Massachusetts: David F. Pallai. 731. Casio Computer Company Ltd. Casio E-Data Bank Watches. 2005 [cited; Available from: http://world.casio.com/pacific/wat/e_data/. MacSema Inc. Contact Memory Button (CMB'S). 2001 [cited; Available from: http://www.macsema.com/buttonmemory.htrn. Wikimedia Foundation. Wikipedia - Data Recovery Definition. 2005 [cited; Available from: http://en.wikipedia.org/wiki/Data recovery. Lee, H., T. Palmbach, and M. Miller, Henry Lee's Crime Scene Handbook. 2001, London: Academic Press. Ltd, C.F.N. Data Recovery & Computer Investigations. 2005 [cited; Available from: http://www.datarecovery.co.nz/datarecovery/ index.html?source=adwords-datarecov. New Zealand Police E-crime Lab. Fighting e-crime in New Zealand. 2002 [cited; Available from: http://www.police.govt.nz/service/ecrime/. Wikimedia Foundation. Wikipedia - Sulphonylurea Definition. 2005 [cited; Available from: http://en.wikipedia.org/wiki/Sulphonylurea. NZHerald.co.nz. Jury quick to convict doctor of murder. 2001 [cited; Available from: http://www.nzherald.co.nz/index.cfm?Ob'ectiD=229152. Police, N.Z. New Zealand Police Youth Education Service. 2005 [cited; Available from: http://www.police.govt.nz/service/yes/. Police, N.Z. Keeping Ourselves Safe. 2005 [cited; Available from: http://www.police. ovt.nz/service/yes/resources/violence/kos.html. Farmer, D. and W. Venema, Forensic Discovery. 2004: Addison-Wesley. Office of e-Government. Forensic Plan. 2004 [cited; Available from: http://www.egov.dpc.wa.gov.au/. Gutmann, P., Secure Deletion of Data from Magnetic and Solid-State Memory, in Sixth USENIX Security Symposium Proceedings. 1996, University of Auckland. Gutmann, P. Data Remanence in Semiconductor Devices. 2001 [cited. Carrier, B., File System Forensic Analysis. 2005: Addison-Wesley. Optical Storage Technology Association. Understanding CD-R CD-RW Disc Longevity. 2001 [cited; Available from: http://www.osta.org/technolo /cda13.htm. Instruments, V. Veeco Instruments Web Site. 2005 [cited; Available from: http://www.veeco.com/. Garfinkel, S.L. and A. Shelat, Remembrance of Data Passed: A Study of Disk Sanitization Practices. 2003, Massachusetts Institute of Technology. American Institute of Physics. Heisenberg - Quantum Mechanics, 1925 - 1927: The Uncertainty Principle. 2005 [cited; Available from: http://www.aip.org/history/heisenberg/p08.htm. Seagate. Seagate Barracuda 7200.8 ST3400832A Specs. 2005 [cited; Available from: http://www.seagate.com/cda/products/discsales/marketing/detail/0.html. ACPO. ALPO Good Practice Guide to Computer Based Evidence. 2003 [cited; Version 3.0:[Available from: http://www.acpo.police.uk/asp/policies/Data/gpg_computer_based_evidence_v3.pdf. New Technologies Inc. File Slack Defined. 2004 [cited; Available from: http://www.forensics-intl.com/def6.html. PCTechGuide. Hard Disks. 2003 [cited; Available from: http://www.pctechguide.com/04disks.htm. Wikimedia Foundation. Wikipedia - Endianness. 2005 [cited; Available from: http://en.wiki edia.or /wiki/Biendian. 29. www.lookuptables.com. ASCII Table and Description. 2005 [cited; Available from: http://www.lookuptables.com/. Inc, U. Unicode Home Page. 2005 [cited; Available from: http://www .unicode.org/ Inc, U. Unicode v4.1.0. 2005 [cited; Available from: http://www.unicode.org/versions/Unicode4.1.0/. Microsoft. FAT32 File System Specification. 2000 [cited; Available from: http://www.microsoft ..oiT!/vvlidc/system/platform/fin-nware/fa en.ms x: Carrier, B. The Sleuth Kit and Autopsy Project Page. 2004 [cited; Available from: http://www.sleuthkit.org. Brzitwa, M. gpart - Guess PC-type hard disk partitions. 2001 [cited; Available from: http://www.stud.uni-hannover.de/user/76201/gpart/. cgSecurity. TestDisk - Tool to check and undelete partition. 2005 [cited; Available from: htt.://www.c_ security.org/index.html?testdisk.html. PJRC. Understanding FAT32 Filesystems. 2005 [cited; Available from: http://www.pjrc.com/tech/8051/ide/fat32.html. Brouwer, A. Partition Types. 2005 [cited; Available from: http://www.win.tue.n1/~aeb/partitions/partition_types.html. Microsoft. Encrypting File System Overview. 2005 [cited; Available from: http://www.microsoft.com/resources/documentation/windows/x /all/proddocs/ en-us/encrypt_overview.mspx. PGP Corporation. PGP Corporation Website. 2005 [cited; Available from: http://www.com/. Devine, C. Encrypted Root Filesystem HOWTO. 2005 [cited; Available from: http://linuxfromscratch.org/~devine/erfs-howto.html Wolfe, H., Penetrating Encrypted Evidence. Journal of Digital Investigation, 2004. 1(2). "@stake". "gstake.com". 2004 [cited; Available from: http://www.atstake.com/. NIST. National Software Reference Library. [Project Web Site] 2004 [cited; Available from: http://www.nsrl.nist.gov/index.html. The Honeynet Project. The Honeynet Project Website. The Honeynet Project 2004 [cited; Available from: http://www.Honeynet.org/misc/Project.html. The Honeynet Project. The Honeynet Project Scan of the Month 24. The Honeynet Project 2001 [cited; Available from: http://www.Honeynet.org/scans/scan24/. The Honeynet Project. The Honeynet Project Scan of the Month 26. The Honeynet Project 2002 [cited; Available from: http://www.Honeynet.org/scans/scan26/. The Honeynet Project. The Honeynet Project Forensic Challenge. The Honeynet Project 2001 [cited; Available from: http://www.Honeynet.org/challenge/index.html. Digital Forensic Research Workshop. Digital Forensic Research Workshop website. 2005 [cited; Available from: http://www.dfrws.org/. 49. Hamilton, E. JPEG File Interchange Format v1.02. 1992 [cited; Available from: http://www.w3.org/Graphics/JPEG/. Kessler, G. File Signature Table. 2005 [cited; Available from: http//www.garykessler.net/library/file_sigs.html. United States Air Force Office of Special Investigation. Foremost - Webpage. 2005 [cited; Available from: http://foremost.sourceforge.net/. Provos, N. Stegdetect - Webpage. 2005 [cited; Available from: http//www.outguess.org/. NeoByte Solutions. Invisible Secrets - Webpage. 2005 [cited; Available from: http://www.invisiblesecrets.com/. Roesch, M. SNORT. 2005 [cited; Available from: http://www.snort.org/. Roesller, T. Lastlog File Analyser Source File. 2000 [cited; Available from: http://www.Honeynet.org/challenge/results/submissions/roessler/files/lastlog.c. CERT/CC. CERT® Coordination Center (CERT/CC). 2005 [cited; Available from: http://www.cert.org/nav/index_main.html. CERT/CC. CERT® Advisory CA-2000-17 Input Validation Problem in rpc.statd. 2000 [cited; Available from: http://www.cert.org/advisories/CA- 2000-17.html. Red Hat Network. Revised advisory: Updated package for nfs-utils available. 2000 [cited; Available from: https://rhn.redhat.com/errata/RHSA-2000- 043.html
Lucas Mcdaniel - One of the best experts on this subject based on the ideXlab platform.
-
teaching digital forensics techniques within linux environments
Hawaii International Conference on System Sciences, 2014Co-Authors: Lucas Mcdaniel, Brian HayAbstract:Appropriately motivating digital forensics topics in an educational environment is a challenging task for a lecturer. Not only will the skill levels of the students vary widely, but designing a lab exercise that introduces a single concept runs the risk of requiring too much additional knowledge to appropriately describe the task or may easily devolve into a contrived example that does not allow the student to fully grasp the extent of the topic at hand. In some cases, this difficulty is compounded by the sheer amount of misinformation that results from years of common knowledge and research becoming invalid after changes to kernels and operating systems. Last year, the Honeynet Project Challenge 12 - "Hiding in Plan Sight" - and a computer security workshop sought to introduce some concepts regarding information and process hiding and disguising through a series of digital forensics labs. This paper will describe the components of these labs that were successful at motivating a core concept, as well as those that were not as successful and have been subsequently modified based upon feedback. These findings will be presented through a suggested lecture-lab format, and a series of scoped topics that can be used in other educational environments to motivate digital forensics and anti-forensics concepts. Scripts used to build each lab have also been provided to serve as a point of reference.
Manavi Sina - One of the best experts on this subject based on the ideXlab platform.
-
Digital forensics investigation framework for Raspberry Pi
2015Co-Authors: Manavi SinaAbstract:Raspberry Pi is a Linux based embedded computer device in a palm hand size, with 512MB of RAM, 700MHz of ARM CPU and GPU Integrated in a single chipset with HDMI output, providing USB ports and Network plugs. In addition, this tiny computer device has a low price in the market and easily accessible for public. Different Linux distribution has been developed for Raspberry Pi from Media Center OS, Penetration Testing OSes such as W3afi Pi ('\v3af," 2013), ARM Kali Linux (Ofensive-Security, 2012) and PWNPI ("PwnPI," 2012) and web application security scanners such as Glasptopf Pi ("Honeypot Project," 2012) and Kippo Pi ("SSH Honeypot," 2009) as web application honeypot Projects. Due to its open source characteristics, scientific industry people can easily develop application to use in robotics Projects and smart home technologies. Since Raspberry is new in the market, the unknown data structure and lack of digital forensics methods for Raspberry Pi put digital forensics examiner in difficulties for data acquisition and analysis. This study focuses on developing a digital forensics framework to bypass the security mechanism, collect stored data of the SD card and volatile memory and then analyze and extracted the evidence from the captured data. This study has two main objectives. The first objective is to propose and develop a new method to bypass the security mechanism and gain privileged access for data acquisition. And the second objective is to propose and develop a tool to extract and analyze evidence from volatile memory. The scope of this research is bypassing the security mechanism of the Linux kernel, data collection of the volatile memory and SD card, and finally analyzing the dumped volatile memory. To perform this research, available data collection and analysis methods of ARM Linux based embedded devices has been studied and applied on the Raspberry Pi to find the best approach. Raspberry Pi Digital Forensics Investigation Framework (RPiDFIF) is proposed and development framework that has two major components. Data collection component bypasses the Security mechanism of the Linux kernel, dumps the volatile memory and SD card with minimum interaction and changing the integrity of the live Raspberry Pi. Second component analyzes the SD card content and volatile memory of the RAM. While there are available tools to extract and analyze the SD card data, the developed component with interaction of the Volatility framework extract the running process, established network connections, log files, encryption keys and many more. Forensics investigator by using these two independent automated components of RPiDFIF can easily investigate remotely or by having physical access of the Raspberry Pi in the crime scene. To evaluate RPiDFIF, three evaluations have been conducted. In the first evaluation experiment, data collection has been done separately to ensure if data collection works properly and independently and capture the whole data stored on the SD card and volatile memory. Then in the second evaluation, volatile memory investigation has been performed to extract evidence from captured volatile memory. Finally, in the last evaluation, we performed a real world attack case study based on one of the challenges of the Honeynet Project has been selected. In this scenario, we compromised the Raspberry Pi as a Linux web server and using the RPiDFIF we bypassed the security mechanism and acquired data from both SD card and volatile memory, and using the Autopsy for SD card investigation and developed plugins and profile for Volatility framework. Based on the developed RPiDFIF framework, digital forensics investigator can easily examine the Raspberry Pi remotely or by having physical access to the device automatically and without learning new commands
L Spitzner - One of the best experts on this subject based on the ideXlab platform.
-
The Honeynet Project: Trapping the hackers
IEEE Security and Privacy, 2003Co-Authors: L SpitznerAbstract:What specific threats do computer networks face from hackers? Who's perpetrating these threats and how? The Honeynet Project is an organization dedicated to answering these questions. It studies the bad guys and shares the lessons learned. The group gathers information by deploying networks (called Honeynets) that are designed to be compromised.