20
Trusted Signal: A·tem·po·ral Time and Place: Hunting Evil with Atemporal Time Line Analysis Doing it Weird

Atemporal Time Line Analysis - SecTor · Atemporal Time Line Analysis Author: davehull Created Date: 10/20/2011 12:21:49 PM

  • Upload
    others

  • View
    3

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Atemporal Time Line Analysis - SecTor · Atemporal Time Line Analysis Author: davehull Created Date: 10/20/2011 12:21:49 PM

Trusted Signal: A·tem·po·ral

Time and Place: Hunting Evil with Atemporal Time Line Analysis

Doing it Weird

Page 2: Atemporal Time Line Analysis - SecTor · Atemporal Time Line Analysis Author: davehull Created Date: 10/20/2011 12:21:49 PM

Trusted Signal: A·tem·po·ral

Ob bio

Page 3: Atemporal Time Line Analysis - SecTor · Atemporal Time Line Analysis Author: davehull Created Date: 10/20/2011 12:21:49 PM

Trusted Signal: A·tem·po·ral

time lines

brief intro by way of a case study…

– case background:

• Discovered in Q1 2011

• irc bot <- yeah, old skool

Page 4: Atemporal Time Line Analysis - SecTor · Atemporal Time Line Analysis Author: davehull Created Date: 10/20/2011 12:21:49 PM

Trusted Signal: A·tem·po·ral

find it

Photo source - http://www.flickr.com/photos/theplanetdotcom

Page 5: Atemporal Time Line Analysis - SecTor · Atemporal Time Line Analysis Author: davehull Created Date: 10/20/2011 12:21:49 PM

Trusted Signal: A·tem·po·ral

reality

Photo source - http://www.flickr.com/photos/zeevveez/

Page 6: Atemporal Time Line Analysis - SecTor · Atemporal Time Line Analysis Author: davehull Created Date: 10/20/2011 12:21:49 PM

Trusted Signal: A·tem·po·ral

investigative plan

where’s the attacker’s code?

how’d they get in?

what did they do/take?

Page 7: Atemporal Time Line Analysis - SecTor · Atemporal Time Line Analysis Author: davehull Created Date: 10/20/2011 12:21:49 PM

Trusted Signal: A·tem·po·ral

investigative methodology

String or Byte Search

Data Recovery

Timeline Analysis

Media Analysis

Reporting Results

Incident Response And Evidence Acquisition

Investigation and Analysis

Source – SANS Forensics 508: Advanced Computer Forensic Analysis and Incident Response

Timeline Analysis

Page 8: Atemporal Time Line Analysis - SecTor · Atemporal Time Line Analysis Author: davehull Created Date: 10/20/2011 12:21:49 PM

Trusted Signal: A·tem·po·ral

traditional time lines

taunting the demo gods

Photo source - internets

Page 9: Atemporal Time Line Analysis - SecTor · Atemporal Time Line Analysis Author: davehull Created Date: 10/20/2011 12:21:49 PM

Trusted Signal: A·tem·po·ral

new school time lines

Source – http://log2timeline.net

Page 10: Atemporal Time Line Analysis - SecTor · Atemporal Time Line Analysis Author: davehull Created Date: 10/20/2011 12:21:49 PM

Trusted Signal: A·tem·po·ral

a·tem·po·ral

“considered without relation to time”

Page 11: Atemporal Time Line Analysis - SecTor · Atemporal Time Line Analysis Author: davehull Created Date: 10/20/2011 12:21:49 PM

Trusted Signal: A·tem·po·ral

file systems: how do they work?

Photo source - http://www.flickr.com/photos/alexwatkins123

Page 12: Atemporal Time Line Analysis - SecTor · Atemporal Time Line Analysis Author: davehull Created Date: 10/20/2011 12:21:49 PM

Trusted Signal: A·tem·po·ral

metadata

Photo source - http://www.flickr.com/photos/deborahfitchett

Page 13: Atemporal Time Line Analysis - SecTor · Atemporal Time Line Analysis Author: davehull Created Date: 10/20/2011 12:21:49 PM

Trusted Signal: A·tem·po·ral

metadata demo

Page 14: Atemporal Time Line Analysis - SecTor · Atemporal Time Line Analysis Author: davehull Created Date: 10/20/2011 12:21:49 PM

Trusted Signal: A·tem·po·ral

towards automation

https://github.com/davehull/body-outliers

Page 15: Atemporal Time Line Analysis - SecTor · Atemporal Time Line Analysis Author: davehull Created Date: 10/20/2011 12:21:49 PM

Trusted Signal: A·tem·po·ral

standing on Carrier’s toes

Souce - http://www.dfrws.org/2005/proceedings/carrier_targetdefn.pdf

Page 16: Atemporal Time Line Analysis - SecTor · Atemporal Time Line Analysis Author: davehull Created Date: 10/20/2011 12:21:49 PM

Trusted Signal: A·tem·po·ral

meta attributes as spatial pts

http://en.wikipedia.org/wiki/File:Scatter_diagram_for_quality_characteristic_XXX.svg

Page 17: Atemporal Time Line Analysis - SecTor · Atemporal Time Line Analysis Author: davehull Created Date: 10/20/2011 12:21:49 PM

Trusted Signal: A·tem·po·ral

false positives are high

Souce - http://www.dfrws.org/2005/proceedings/carrier_targetdefn.pdf

Page 18: Atemporal Time Line Analysis - SecTor · Atemporal Time Line Analysis Author: davehull Created Date: 10/20/2011 12:21:49 PM

Trusted Signal: A·tem·po·ral

future dev

• Find outliers for meta element within the set of another meta element, i.e.

– for files created on a given day, what is the average metadata address, what are the outliers?

– for files in a given metadata address range, what are the date outliers?

Page 19: Atemporal Time Line Analysis - SecTor · Atemporal Time Line Analysis Author: davehull Created Date: 10/20/2011 12:21:49 PM

Trusted Signal: A·tem·po·ral

future dev

• combine with external data sources, i.e.

– are outliers packed?

– correlate with autoruns

• graphing, i.e.

– scatterplot metadata as spatial points per Carrier

• …

Page 20: Atemporal Time Line Analysis - SecTor · Atemporal Time Line Analysis Author: davehull Created Date: 10/20/2011 12:21:49 PM

Trusted Signal: A·tem·po·ral

questions?

contact:

trustedsignal.com

twitter.com/trustedsignal

Thank you