Presentation is loading. Please wait.

Presentation is loading. Please wait.

Computer Forensics: A 5 Minute Introduction Santa Clara University Department of Computer Engineering April 2007.

Similar presentations


Presentation on theme: "Computer Forensics: A 5 Minute Introduction Santa Clara University Department of Computer Engineering April 2007."— Presentation transcript:

1 Computer Forensics: A 5 Minute Introduction Santa Clara University Department of Computer Engineering April 2007

2 Information Assurance Continued need in the US for experts in Information Assurance. Legislative & Regulatory Pressure  Sarbanes Oxley  HIPPA  … Safe from Off-shoring

3 Computer Forensics Reconstructs events from digital traces on a device such as Computer Router Switch Cell-phone, SIM-card GPS system (car accident investigation) SCADA

4 Computer Forensics Goal of Forensics:  Reconstruction based on digital traces Criminal:  Apprehension and conviction of offenders  Computer is instrument of crime: Auction fraud, Check fraud, …  Computer is target of crime: intrusion, …  Computer contains evidence: emails, printings Commercial:  IP protection, Internet abuse, Security breaches, …  Prevention

5 Computer Forensics Computer Forensics Types:  Media Forensics Hard drive, USB, PDA, SIM, …  Network Forensics Router logs, IDS logs, network capture files, SMTP logs, email headers, …  Malware Analysis Given malware code (Assembly Language), reconstruct its functionality Code Red Worm: GET /default.ida?NNNNNNNNNNNNNNNNNNNNNNNNN NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN NNN NNNNNNNNNNNNNNNNNNN%u9090%u6858%ucbd 3%u7801%u9090%u6858%ucbd3%u7801%u9090%u 6858%ucbd3%u7801%u9090%u9090%u8190%u00c3 %u0003%u8b00%u531b%u53ff%u0078%u0000%u00

6 Activity Internet Explorer uses index.dat file to store past history.


Download ppt "Computer Forensics: A 5 Minute Introduction Santa Clara University Department of Computer Engineering April 2007."

Similar presentations


Ads by Google