Cybercrime Investigations: A Comprehensive Resource For Everyone
Book information
Description
Cybercrime continues to skyrocket but we are not combatting it effectively yet. We need more cybercrime investigators from all backgrounds and working in every sector to conduct effective investigations. This book is a comprehensive resource for everyone who encounters and investigates cybercrime, no matter their title, including those working on behalf of law enforcement, private organizations, regulatory agencies, or individual victims. It provides helpful background material about cybercrime's technological and legal underpinnings, plus in-depth detail about the legal and practical aspects of conducting cybercrime investigations. Key features of this book include: • Understanding cybercrime, computers, forensics, and cybersecurity • Law for the cybercrime investigator, including cybercrime offenses; cyber evidence-gathering; criminal, private and regulatory law, and nation-state implications • Cybercrime investigation from three key perspectives: law enforcement, private sector, and regulatory • Financial investigation • Identification (attribution) of cyber-conduct • Apprehension • Litigation in the criminal and civil arenas. This far-reaching book is an essential reference for prosecutors and law enforcement officers, agents and analysts; as well as for private sector lawyers, consultants, information security professionals, digital forensic examiners, and more. It also functions as an excellent course book for educators and trainers. We need more investigators who know how to fight cybercrime, and this book was written to achieve that goal. Authored by two former cybercrime prosecutors with a diverse array of expertise in criminal justice and the private sector, this book is informative, practical, and readable, with innovative methods and fascinating anecdotes throughout. Cover......Page 1 Half Title......Page 2 Title Page......Page 4 Copyright Page......Page 5 Dedication......Page 6 Table of Contents......Page 8 About the Authors......Page 22 Acknowledgments......Page 24 PART I: Understanding Cybercrime, Computers, and Cybersecurity......Page 26 1.1 Why This Book......Page 28 1.2 Who Investigates Cybercrime?......Page 30 1.3 How This Book Is Organized......Page 31 1.4 Keeping It Fun: Anecdotes, Cases, Diagrams, and Cartoons......Page 32 1.5 Onward and Upward......Page 33 2.2 What Makes a “Cyber” Activity a Crime? A Quick Introduction to Cybercrime Offenses......Page 34 2.2.1 Computer and Network Intrusions......Page 35 2.2.4 Tampering with or Damaging a Network or System......Page 36 2.2.6 Theft of Funds and Fraud Schemes......Page 37 2.2.8 Money Laundering......Page 38 2.2.9 Harassment, Threats, Stalking, and Revenge Porn......Page 39 2.3 Cybercrime vs. Traditional Street Crime: The Differences......Page 40 2.3.2 Distance: The National and International Nexus......Page 41 2.3.4 Connection to a Broad Criminal Ecosystem......Page 42 2.4.3 Thrill and Bragging Rights......Page 43 2.4.6 Nation-State Objectives......Page 44 2.5 The Cybercrime-For-Profit Economy......Page 45 2.5.1 The Connection between Identity Theft and Cybercrime......Page 46 2.5.2 The Cybercrime Economy Earns Money and Requires Payments......Page 47 2.6 Digital Evidence: The Backbone of Any Cyber Investigation (and Traditional Investigations, Too)......Page 48 2.7 Conclusion......Page 49 3.1 Introduction......Page 51 3.2 How Computers Work......Page 52 3.3.1 Case......Page 54 3.3.3 Processors (CPUs)......Page 55 3.3.6 Communicating with the User: Interfaces for Input and Output......Page 56 3.3.10 External Storage, Servers and More......Page 57 3.4.2 Operating Systems......Page 59 3.5.1.1 NIC and MAC Addresses......Page 60 3.5.1.4 Router......Page 61 3.5.2 Networking Communication and Internet Protocol (IP) Addresses......Page 62 3.5.4 Domain Name System (DNS)......Page 64 3.5.5 Website Hosting......Page 65 3.6 Proxies, VPNs, and Tor......Page 66 3.7.2 Encryption at Rest......Page 68 3.8 Digital Forensics and Evidence Gathering......Page 69 3.8.1 Ensuring Integrity of Stored Data: Hashing......Page 70 3.8.2.2 Imaging......Page 71 3.8.2.3 Analysis......Page 72 3.8.5 Emails and Email Headers......Page 73 3.9 Conclusion......Page 74 4.2 Basic Information Security and Cybersecurity Principles......Page 75 4.2.1 CIA: The Three Information Security Objectives......Page 76 4.2.3 Authentication to Guard Access......Page 77 4.2.4 Principle of Least Privilege......Page 79 4.2.5 Incident Response......Page 80 4.3 Information Security Frameworks......Page 81 4.3.2 CIS Critical Security Controls......Page 82 4.3.4 NIST SP 800-53......Page 84 4.3.5 ISO/IEC 27000 Series......Page 85 4.3.7 Other Information Security Frameworks......Page 86 4.4 Conclusion......Page 87 PART II: Law for the Cybercrime Investigator......Page 88 5.2 Criminal Law and Procedure......Page 90 5.2.2 The Criminal Justice Process......Page 91 5.2.3 Criminal Justice Protections......Page 93 5.2.4 How Investigations and Prosecutions are Started......Page 94 5.2.5 Categories of Criminal Charges......Page 95 5.2.6 Charging the Defendant and Judicial Review: Complaints, Indictments, Grand Jury, Preliminary Hearings......Page 96 5.3.1 State/Local Enforcement and Federal Enforcement......Page 97 5.3.2 Jurisdiction and Venue......Page 98 5.4 What Constitutes a Crime and Its Elements......Page 99 5.4.2 Culpable Mental States (mens rea)......Page 100 5.4.3 Anticipatory Offenses (Such as Attempt and Conspiracy)......Page 101 5.6 The Fourth Amendment: Constitutional Rules for Search and Seizure......Page 102 5.6.1 Expectation of Privacy......Page 103 5.6.2 Consent......Page 104 5.6.4 Exceptions to the Search Warrant Requirement......Page 105 5.6.6 Private Searches versus Public Searches......Page 106 5.7.2 Other Forms of Evidence: Unlawful Arrests, Statements, and Witness Identifications......Page 107 5.7.3 Fruit of the Poisonous Tree Doctrine......Page 108 5.8.1 The Civil Litigation Process......Page 109 5.8.2.1 Intentional Torts......Page 110 5.8.2.2 Negligence Torts......Page 111 5.8.2.4 Cybercrime-Specific Causes of Action......Page 112 5.9 Licensing and Regulatory Law......Page 113 5.10 Conclusion......Page 114 6.2 Federal and State Law......Page 115 6.3.1 The Computer Fraud and Abuse Act (CFAA)......Page 116 6.3.2 The Wiretap Act......Page 117 6.3.4 The Controlling the Assault of Non-Solicited Pornography and Marketing Act (CAN-SPAM Act)......Page 119 6.4 State Cybercrime Law......Page 120 6.5 “Traditional” Federal and State Laws that Apply to Cybercrime......Page 121 6.5.1 Theft/Larceny......Page 122 6.5.2.1 Property: A Changing Concept in the Cyber Age......Page 123 6.5.3 Identity Theft......Page 124 6.5.4 Impersonation......Page 125 6.5.5 Credit/Debit Card Fraud......Page 126 6.5.8 Forgery......Page 127 6.5.9 Money Laundering......Page 128 6.5.10.1 First Amendment Considerations......Page 130 6.5.12 Vandalism......Page 131 6.5.14 Attempt and Conspiracy......Page 132 6.6 Conclusion......Page 133 7.1 Introduction......Page 135 7.2.1 Communications and Privacy......Page 136 7.2.2 Communications and Consent......Page 137 7.3 The Nine Tools for Gathering Evidence......Page 138 7.3.3 Subpoena Duces Tecum......Page 139 7.3.4 Section 2703(d) Order......Page 140 7.3.5 Search Warrant......Page 141 7.3.6 Pen Register and Trap-and-Trace Device......Page 142 7.3.8 Letter of Preservation......Page 143 7.4 The Electronic Communications Privacy Act (ECPA): Applying the Tools to Online Communications......Page 144 7.4.1 The Stored Communications Act: Records of Past Communications......Page 145 7.4.1.2 Services Covered by the SCA (ECS and RCS)......Page 146 7.4.1.5 Sensitive Non-Content Information......Page 148 7.4.1.7 Content Information......Page 149 7.4.1.8 SCA Rules for Letters of Preservation, Non-Disclosure,and Delayed Disclosure Orders......Page 151 7.4.3 The Wiretap Act: Live Monitoring of Content Information......Page 152 7.5 Obtaining Evidence Located in Another State......Page 153 7.5.2 State and Local Investigations......Page 154 7.5.3 Search Warrant Considerations for Out-of-State Devices and Physical Premises......Page 155 7.6 Obtaining Evidence Stored Overseas by U.S. Entities: The CLOUD Act......Page 156 7.7 Obtaining Evidence Located in Another Country......Page 157 7.7.3 Letters Rogatory......Page 158 7.7.6 Suspects Located in Other States and Foreign Countries (Preview)......Page 159 7.8 Conclusion......Page 160 8.1 Introduction......Page 161 8.2 Laws and Measures Relating to Nation-State and Terrorist Activity......Page 162 8.2.2 Civil Laws and the Foreign Sovereign Immunities Act (FSIA)......Page 163 8.2.3 International Treaties, Agreements, and Judicial Processes......Page 164 8.2.4 Laws and Principles of Sovereignty and Waging War......Page 165 8.2.5 Terrorism-Related Measures......Page 166 8.2.6 Espionage, Clandestine and Covert Operations, and Propaganda......Page 167 8.3.1 Generating Funds......Page 168 8.3.2 Nation-State Commercial Espionage......Page 170 8.3.3 Attacks on Infrastructure......Page 171 8.3.4 Attacks to Advance Strategic Interests......Page 172 8.4.1 Terrorist Funding......Page 175 8.4.4 Inciting Local Attacks......Page 176 8.6 Conclusion......Page 177 9.2 Attorney–Client Privilege......Page 178 9.3 Civil Lawsuits against Cybercriminals: Actions for Intentional Torts......Page 179 9.4 “Hacking Back”: Intentional Acts by Cybercrime Victims that Could Incur Liability......Page 180 9.5 Cybercrime Statutory Causes of Action......Page 181 9.6.1 Negligence that Directly Causes the Harm......Page 182 9.6.2 Negligence that Allows the Commission of a Crime by a Third PARTy......Page 183 9.6.2.3 Cybercrime Liability......Page 184 9.7 Actions under Contract Law......Page 185 9.8.1 Federal and State Laws......Page 187 9.8.3 Burden of Proof......Page 188 9.9 General Civil Laws and Regulations Regarding Cybersecurity and Privacy......Page 189 9.9.2 Information Security Laws......Page 190 9.9.4 Privacy Laws and Who Enforces Them......Page 191 9.9.4.2 GDPR......Page 192 9.10 Civil Laws and Regulations for Specific Sectors......Page 193 9.10.1.2 FFIEC and SEC Requirements......Page 194 9.11 Conclusion......Page 195 PART III: The Cybercrime Investigation......Page 196 10.2 Cybercrime Investigation from Three Perspectives: Private Sector, Law Enforcement, and Regulatory......Page 198 10.2.1 Private Sector......Page 199 10.2.3 Regulatory......Page 200 10.4.1 The End of Law Enforcement’s Investigation......Page 201 10.4.3 The End of the Regulatory Investigation......Page 202 10.5 Conclusion......Page 203 11.2 Cybercrime Investigation: The Cyclical Process of Building Evidence......Page 204 11.3.1 Proprietary Tools......Page 206 11.3.2 Readily Available Tools......Page 207 11.5 Writing for Cybercrime Investigations......Page 209 11.5.1 The Dangers of Automatic Hyperlinking......Page 210 11.6.1 Open Source Investigation Resources......Page 212 11.6.2 Viewing and Preserving Open Source Clues......Page 213 11.6.3 Practical Tips to Maximize the Admissibility of Open Source Data......Page 215 11.7 Records Evidence......Page 216 11.7.1 The Workflow for Records Evidence......Page 217 11.7.2 Tracking Records Requests......Page 218 11.7.4 Analyzing the Information in Records......Page 219 11.7.5 Admissibility of Records Evidence in Litigation......Page 220 11.8.1 Reading Email Headers......Page 221 11.8.2 Analyzing Large Sets of Emails......Page 222 11.9 The Importance of Cybercrime Intelligence......Page 223 11.10 Conclusion......Page 224 12.2 Incident Response (and Prevention)......Page 226 12.3 Discovery of Cybercrime Incidents by Private PARTies......Page 227 12.3.1 Is This a Crime the Private Entity Can and Should Investigate?......Page 228 12.4 Determining Investigation Goals and Scope......Page 230 12.5 Activating Necessary Personnel: In-House and External......Page 232 12.5.1 External Services to Consider......Page 233 12.6.1 Reporting to Law Enforcement......Page 234 12.6.2 Reporting to Regulators and Agencies Enforcing Similar Laws......Page 236 12.8 Collecting Evidence Available Internally......Page 237 12.8.2 Internal Records and Data......Page 238 12.8.3 Forensics on Internal Devices and Networks......Page 239 12.9.2 Requesting Data and Information from Third PARTies......Page 240 12.9.3 Civil Legal Process to Compel External PARTies to Produce Evidence: John Doe Lawsuits and Subpoenas......Page 241 12.9.4 Respecting the Rights of Third PARTies......Page 243 12.10 Conclusion......Page 244 13.2 How Cybercrime Comes to Law Enforcement’s Attention......Page 245 13.3 Was There a Crime?......Page 246 13.4.2 Nature of Initially Available Evidence......Page 247 13.4.5 Likelihood of Apprehending Suspects......Page 248 13.4.8 Advising the Victim......Page 249 13.5 Opening a Case......Page 250 13.7 Getting Ready to Investigate: A Recap of the Tools......Page 251 13.7.2 Consent......Page 252 13.7.5 Subpoena......Page 253 13.7.6 2703(d) Order......Page 254 13.7.8 Pen Register and Trap/Trace Device (Including with Location Data)......Page 255 13.7.9 Wiretap......Page 256 13.8 SIMPLE: The Six-Step Initial Mini-Plan for Law Enforcement......Page 257 13.9 The Records Phase: Digging for Clues and Connections......Page 258 13.10 The Data Search Phase: Zeroing in on Internet Accounts and the Criminals Using Them......Page 260 13.11 The Physical World Phase: Searching Spaces and Devices......Page 262 13.12 The Wiretap Phase: Special Cases Using Live Monitoring of Targets’ Communications......Page 265 13.14 Writing for Law Enforcement Investigations......Page 266 13.15 Working with the Private Sector......Page 267 13.17 Conclusion......Page 268 14.2 Regulatory Recap: Regulated Industries and Regulatory-Type Laws......Page 270 14.4 Investigating the Cybercrime: Sufficiency of Cybersecurity Measures and Accuracy of the Report......Page 272 14.5 Balancing the Roles of Compliance and Enforcement......Page 274 14.6 Confidentiality and Information Sharing......Page 275 14.7 Conclusion......Page 276 15.2 Money Laundering 101......Page 277 15.4 Virtual Currency and Cryptocurrency......Page 280 15.4.1 History of Virtual Currency and Its Evolving Terminology......Page 281 15.5 Getting Started on the Money Trail: How Financial Details Can Prove Crimes and the Criminal’s Identity......Page 284 15.6 Finding and Following the Money......Page 285 15.6.1 Where to Find Evidence of Financial Activity......Page 286 15.6.2 Investigating Virtual Currency Transactions: Specific Tools and Resources......Page 287 15.6.3 Cryptocurrency Transaction Records......Page 288 15.7 Conclusion......Page 289 16.2 Doing Illicit Business Online: Cyber Nicknames and Pseudonyms......Page 290 16.3 The Attribution Process and Developing a Suspect: Mapping Criminal Conduct to Cyber Pedigree and Physical Pedigree Information......Page 291 16.3.1 Two Kinds of Pedigree Information: Physical and Cyber......Page 292 16.3.2 The ID-PLUS Attribution Process: Six Steps to Link Criminal Conduct to Cyber Pedigree and Physical Pedigree......Page 293 16.3.3 Example: Using ID-PLUS to Build an Identification......Page 300 16.3.4 Example: A Sample Attribution Summary (Working from the Crime to a Suspect)......Page 302 16.3.5 The Attribution Process from Another Lens: Types of Evidence that Can Identify Cybercriminals......Page 304 16.4 Writing and Articulation Revisited: Clear and Effective Cyber Identification......Page 306 16.6 Apprehension: Confirming Pedigree through Statements and Forensics......Page 307 16.7 Conclusion......Page 309 17.2 Charging Decisions......Page 310 17.2.1 Methods for Charging a Suspect......Page 311 17.3 Interstate Procedures for Arresting and Extraditing Defendants......Page 312 17.4 International Procedures for Arresting and Extraditing Defendants......Page 314 17.5 Arrest Strategies and the Hunt for Evidence......Page 315 17.6 A Successful Arrest Does Not Mean “Case Closed”......Page 316 17.7 Conclusion......Page 317 PART IV: Litigation......Page 318 18.2 Goals of the Litigation......Page 320 18.3 Litigation Begins: Filing of an Accusatory Instrument......Page 321 18.4 The Defendant Enters the Litigation: Apprehension, Extradition, and Arraignment......Page 322 18.5 Guilty Pleas: Plea Position and Negotiation......Page 323 18.6 Discovery: Sharing the Investigation with the Defense......Page 324 18.7 Motion Practice, Hearings, and Pre-Trial Decisions: Testing the Investigation and Prosecution......Page 326 18.8 Trial: The Investigation Laid Bare......Page 327 18.8.2 Opening Statements......Page 328 18.8.3 Presenting the Evidence: Legal Admissibility and Jury Comprehension......Page 329 18.8.4.1 The “Baby Step” Technique and the Laptop Computer......Page 330 18.8.4.2 The “Baby Step” Technique and Financial Records......Page 333 Defense Cross-Examination during the People’s Case......Page 335 The Defense Case (If Presented)......Page 336 18.8.7 Jury Instructions......Page 337 18.8.9 Sentencing......Page 338 18.10 Conclusion......Page 339 19.2 Potential Litigation Scenarios Following a Cybercrime Investigation......Page 340 19.2.3 Civil Action against Cybercriminal under a Cybercrime Statutory Cause of Action......Page 341 19.2.5 Civil Action for Breach of Contract......Page 342 19.3 Goals and Expectations......Page 343 19.4 Experts......Page 344 19.6 The Civil Lawsuit and the Role of the Investigation......Page 345 19.7 Arbitration......Page 347 19.8 Conclusion......Page 348 Chapter 20. Conclusion......Page 349 Index......Page 351
Similar books
The Assassination of Robert F. Kennedy: Crime Conspiracy & Cover-Up: A new investigation
2020 · PDF
Lockpicking Forensics
2009 · PDF
Digital Forensics and Incident Response Incident response tools and techniques for effective cyber threat response
2022 · PDF
The mHealth Power Paradox Improving Data Protection in Health Apps through Self-Regulation in the European Union (in: Innovation and Protection: The Future of Medical Device Regulation, eds. I. Glenn Cohen; Timo Minssen; W. Nicholson Price II; Christopher T. Robertson; Carmel Shachar)
2022 · PDF
Unleashing the Art of Digital Forensics
2023 · PDF
How to Think on Your Feet
1994 · DJVU
Why Privacy Matters
2022 · PDF
Data Protection in the Practical Context: Strategies and Techniques
2017 · PDF