ENGLISH

Cyber And Digital Forensic Investigations: A Law Enforcement Practitioner’s Perspective

Book information

Publisher
Springer
Year
2020
ISBN
3030471306, 9783030471309, 9783030471316
Language
english
Format
PDF
Filesize
13 MB (13961089 bytes)
Series
Studies In Big Data Vol. 74
Edition
1st Edition
Pages
287\287
Time added
2020-07-26 13:54:33

Description

Understanding the latest capabilities in the cyber threat landscape as well as the cyber forensic challenges and approaches is the best way users and organizations can prepare for potential negative events. Adopting an experiential learning approach, this book describes how cyber forensics researchers, educators and practitioners can keep pace with technological advances, and acquire the essential knowledge and skills, ranging from IoT forensics, malware analysis, and CCTV and cloud forensics to network forensics and financial investigations. Given the growing importance of incident response and cyber forensics in our digitalized society, this book will be of interest and relevance to researchers, educators and practitioners in the field, as well as students wanting to learn about cyber forensics. Foreword by David A. “Dave” Dampier......Page 6 Foreword by Marcus K. Rogers......Page 8 Acknowledgements......Page 10 Contents......Page 11 Editors and Contributors......Page 13 1 Introduction......Page 16 2 Organisation of This Book......Page 17 Defending IoT Devices from Malware......Page 20 1 Introduction......Page 21 2 Related Work......Page 22 3.1 Mirai Malware Analysis......Page 23 3.2 Qbot Malware Analysis......Page 28 3.3 Comparison of Mirai and Qbot......Page 31 3.4 Conclusion of Mirai and Qbot Research......Page 34 4.1 Process......Page 36 5 Experiments and Discussion......Page 38 6 Conclusion and Future Work......Page 41 References......Page 42 1 Introduction......Page 45 2 Related Work......Page 46 4.1 Planning/Preparation......Page 48 4.3 Acquire Evidence and Preservation......Page 50 5.1 IoT Hardware......Page 51 5.2 Network Sniffing and Data Communication Acquiring......Page 52 6 Example Use Cases......Page 53 6.1 Scenario 1: Raspberry PI......Page 54 6.2 Scenario 2: Smart House......Page 58 7 Conclusion and Future Work......Page 60 References......Page 61 Forensic Investigation of Ransomware Activities—Part 1......Page 64 1 Introduction......Page 65 2.1 Evolution of Ransomware......Page 66 2.2 Stages of a Ransomware Attack......Page 67 3 SamSam Analysis......Page 68 3.2 The Ransomware Component......Page 69 3.4 Summary......Page 73 4.2 WannaCry Dropper Details......Page 74 4.3 The Worm Component......Page 76 4.4 Ransomware Component......Page 79 4.5 Encrypted DLL......Page 81 4.6 Summary......Page 84 5 Ransomworms in the Future......Page 85 5.1 Epidemiology......Page 86 6 Conclusion and Future Work......Page 87 References......Page 88 Forensic Investigation of Ransomware Activities—Part 2......Page 91 1.1 Evolution of Ransomware......Page 92 1.2 Types of Ransomware......Page 94 2.1 Crypto-Ransomware Behaviour and Activity......Page 96 2.2 Analysis and Detection of Ransomware......Page 98 3.1 Analysis of zCrypt......Page 102 3.2 Design of the Proposed Approach......Page 106 4.1 Evaluation Methodology......Page 111 4.2 Evaluation Results......Page 114 4.3 Discussion......Page 115 5 Conclusions......Page 116 References......Page 117 CCTV Forensics in the Big Data Era: Challenges and Approaches......Page 121 1 Introduction......Page 122 2 CCTV Forensics: A Literature Review......Page 123 3 CCTV Forensic Challenges Within the Context of Big Data......Page 124 4 Proposed CCTV Forensic Approach......Page 125 5.1 Case Study 1—GANZ DVR C-MPDVR-16......Page 131 5.2 Case Study 2—Swann DVR4-2500......Page 137 5.3 Case Study 3—Operation Baron......Page 144 6 Conclusion and Further Work......Page 146 References......Page 149 Forensic Investigation of PayPal Accounts......Page 152 2 Related Work......Page 153 4 Adopted Approach......Page 155 4.1 Web Browser Monitoring Approach......Page 156 4.2 Computer Forensics Approach......Page 157 4.3 Experimental Procedure......Page 158 5.1 Web Browser Monitoring......Page 159 5.2 Monitoring the Account Usage......Page 164 5.3 Computer Forensic Approach......Page 173 6 Conclusion......Page 182 References......Page 183 1 Introduction......Page 186 2 Related Work......Page 188 3 Methodology and Evaluation Criteria Catalogue......Page 190 4 Digital Forensics in IaaS......Page 191 5 Digital Forensics in PaaS......Page 200 6 Digital Forensics in SaaS......Page 201 7 Comparison of Digital Forensic Approaches......Page 203 8 Discussion and Conclusion......Page 204 9 Future Work......Page 207 References......Page 208 1 Introduction......Page 211 2 Related Work......Page 213 3 Problem Statement and Challenges......Page 214 4.2 Proposed Approach......Page 215 5.1 Testing Platforms......Page 216 5.3 Scenario 2: Unencrypted SMS Text Messaging......Page 218 5.4 Scenario 3: Basic Web Surfing......Page 220 5.5 Scenario 4: Skype......Page 222 5.6 Scenario 5: Leap Card Android Application......Page 223 6 Discussion......Page 225 References......Page 228 Towards an Automated Process to Categorise Tor’s Hidden Services......Page 231 2 Literature Survey......Page 232 3 Problem Statement......Page 237 4.1 Setting up the Hidden Service......Page 238 4.2 Web Scraping......Page 240 4.3 Categorisation......Page 245 4.4 Self-regulation......Page 246 5.2 Analysis of Hidden Services......Page 247 6 Conclusion and Future Works......Page 253 References......Page 255 The Bitcoin-Network Protocol from a Forensic Perspective......Page 257 1 Introduction......Page 258 2.1 Bitcoin Transaction Communication......Page 260 2.2 Bitcoin Network Protocol......Page 262 3.1 Current State of Network Forensic......Page 265 3.2 Current State of Bitcoin Network Research......Page 267 4 Methodology......Page 269 4.2 Collection......Page 270 4.4 Examination......Page 271 4.8 Limitation and Scope......Page 272 5 Experiment......Page 273 5.2 The Dataset......Page 274 5.3 Bitcoin Messages of Interests......Page 275 5.4 Discussion......Page 280 6 Conclusion and Future Work......Page 281 References......Page 283 1 Concluding Remarks......Page 286

Similar books