Successfully reported this slideshow.
We use your LinkedIn profile and activity data to personalize ads and to show you more relevant ads. You can change your ad preferences anytime.
Dark DataHiding in your RecordsOpportunity or Danger?<br />Rob Zirnstein<br />President<br />Forensic Innovations<br />Jan...
Darth Vader?<br />No, “Dark Data”, but they both<br />Are often associated with evil<br />Keep secrets (“Luke, I’m your fa...
Dark Matter?<br />No, “Dark Data”!  But they both<br />Go undetected<br />Are surrounded by<br />    detectable stuff<br /...
What is Dark Data?<br />Dark Data in our digital devices<br />Everyone creates it (unintentionally)<br />Criminals may hid...
Where is Dark Data?<br />DCO & HPA<br />Unformatted Disk Space<br />Deleted Files<br />Unknown Files<br />Between Files<br...
Hard Drive Layout<br />Device Configuration<br />   Overlay (DCO)<br />http://www.forensicswiki.org/wiki/SAFE_Block_XP<br ...
Deleted Files<br />Deleted Files aren’t really gone?<br />Unused Disk Space (in a volume)<br />Disk Caches / Swap Files<br...
Unknown Files (1)<br />500 types of files handled by eDiscovery, Document Management & Computer Forensics Tools<br />50,00...
Unknown Files (2)<br /> Typical ToolsFI Tools<br /> (23 wrong files)	   (26 Correct Files)<br />
Between Files<br />Alternate Data Streams (ADS)<br />Files hiding behind files (on NTFS)<br />RAM Slack<br />Padding betwe...
Inside Common Files<br />Deleted Objects<br />Ex: Adobe PDF & MS Office 2003 (OLE)<br />	not removing deleted data (change...
Smuggled Objects<br />Some formats ignore<br />	foreign objects<br />MS Office 2007 (Zip)<br />MS Wave (RIFF)<br />This ex...
Deleted Data in Slack<br />  Deleted Data that evades Redaction<br />
Steganography<br />Intentional Data Hiding<br />
Dark Data Can Be Fragile<br />Deleting Files without using the Recycle Bin.<br />SHIFT + DEL<br />Defragmenting a hard dri...
Dangers<br />You may loose a law suit if the other side finds what you missed.<br />Corporate Digital Assets may be walkin...
Opportunities<br />Protect your company by being Aware of your Digital Assets.<br />Illegal content may be hidden accident...
What Does FI Do?<br />Create Technologies to Capture Dark Data<br />File Investigator<br />File Expander<br />File Harvest...
FI Technologies<br />File Investigator<br />Discovers Files Masquerading as Other Types<br />Identifies 3,953+ File Types<...
Thank you<br />Contact<br />Rob Zirnstein<br />Rob.Zirnstein@ForensicInnovations.com<br />www.ForensicInnovations.com<br /...
Upcoming SlideShare
Loading in …5
×

Dark Data Hiding in your Records: Opportunity or Danger?

1,698 views

Published on

There is Dark Data hiding in every document that we create. Does this Dark Data represent an opportunity or danger to us and our business?

Published in: Technology
  • Be the first to like this

Dark Data Hiding in your Records: Opportunity or Danger?

  1. 1. Dark DataHiding in your RecordsOpportunity or Danger?<br />Rob Zirnstein<br />President<br />Forensic Innovations<br />January 19th, 2011<br />
  2. 2. Darth Vader?<br />No, “Dark Data”, but they both<br />Are often associated with evil<br />Keep secrets (“Luke, I’m your father”)<br />Are potentially harmful<br />
  3. 3. Dark Matter?<br />No, “Dark Data”! But they both<br />Go undetected<br />Are surrounded by<br /> detectable stuff<br />Affect things around them<br />
  4. 4. What is Dark Data?<br />Dark Data in our digital devices<br />Everyone creates it (unintentionally)<br />Criminals may hide it (Anti-Forensics)<br />Forensic tools can’t see it<br />But it is there!<br />Data that we can’t see<br />On our hard drives<br />On out flash drives<br />In our computer files<br />
  5. 5. Where is Dark Data?<br />DCO & HPA<br />Unformatted Disk Space<br />Deleted Files<br />Unknown Files<br />Between Files<br />Inside Common Files<br />Deleted Data Objects<br />
  6. 6. Hard Drive Layout<br />Device Configuration<br /> Overlay (DCO)<br />http://www.forensicswiki.org/wiki/SAFE_Block_XP<br />Data Cleaner+ http://www.mp3cdsoftware.com/blancco---data-cleaner--download-16317.htm<br />http://www.utica.edu/academic/institutes/ecii/publications/articles/EFE36584-D13F-2962-67BEB146864A2671.pdf<br />Host Protected<br /> Area (HPA)<br />http://www.thinkwiki.org/wiki/Hidden_Protected_Area<br />Forensic Duplicator<br />http://www.tableau.com/pdf/en/Tableau_TD1_Product_Brief.pdf<br />HDD Capacity Restore Tool http://hddguru.com/software/2007.07.20-HDD-Capacity-Restore-Tool/<br />Unformatted Disk Space<br />
  7. 7. Deleted Files<br />Deleted Files aren’t really gone?<br />Unused Disk Space (in a volume)<br />Disk Caches / Swap Files<br />Windows Recycle Bin<br />Are they hard to recover?<br />Fragmentation is deadly<br />Large databases tend to be<br /> heavily fragmented<br />Even DFRWS Researchers find<br /> that fragmentation can make<br /> some file types impossible to<br /> recover (http://www.dfrws.org/2007/challenge/results.shtml)<br />
  8. 8. Unknown Files (1)<br />500 types of files handled by eDiscovery, Document Management & Computer Forensics Tools<br />50,000+* types of files in the world<br />5,000 types of files typically in use<br />*http://filext.com<br />
  9. 9. Unknown Files (2)<br /> Typical ToolsFI Tools<br /> (23 wrong files) (26 Correct Files)<br />
  10. 10. Between Files<br />Alternate Data Streams (ADS)<br />Files hiding behind files (on NTFS)<br />RAM Slack<br />Padding between the end of a file and the end of the current sector<br />Typically zeros, sometimes random content<br />File/Cluster/Residual/Drive Slack<br />Padding between sectors used<br /> & the end of the current cluster<br />Previous sector content that<br /> should be used in File Carving<br />http://www.forensics-intl.com/def6.html<br />
  11. 11. Inside Common Files<br />Deleted Objects<br />Ex: Adobe PDF & MS Office 2003 (OLE)<br /> not removing deleted data (change tracking)<br />Smuggled Objects<br />Ex: MS Office 2007 (Zip) and MS Wave<br /> (RIFF) formats ignore foreign objects<br />Object / Stream Slack<br />Ex: OLE objects have sector size issues,<br /> just like with disk sectors<br />Field Slack<br />Ex: Image files that don’t use the whole<br /> palette, and/or less than 8/16/32/48 bpp<br />Steganography<br />
  12. 12. Smuggled Objects<br />Some formats ignore<br /> foreign objects<br />MS Office 2007 (Zip)<br />MS Wave (RIFF)<br />This example<br />I added a file to a<br /> Word 2007 document.<br />The document opens<br /> without any error.<br />
  13. 13. Deleted Data in Slack<br /> Deleted Data that evades Redaction<br />
  14. 14. Steganography<br />Intentional Data Hiding<br />
  15. 15. Dark Data Can Be Fragile<br />Deleting Files without using the Recycle Bin.<br />SHIFT + DEL<br />Defragmenting a hard drive.<br />Installing Applications.<br />Turning off “Track Changes” & “Fast Save” options.<br />Using Redaction Tools.<br />MS Word - http://redaction.codeplex.com<br />PDF - http://www.appligent.com/redax<br />PDF - http://www.rapidredact.com<br />Using Data Wipers.<br />SafeErase - http://www.oo-software.com<br />CyberScrub - http://www.cyberscrub.com<br />
  16. 16. Dangers<br />You may loose a law suit if the other side finds what you missed.<br />Corporate Digital Assets may be walking out the door.<br />Intellectual Property theft<br /> can put a company out of business.<br />
  17. 17. Opportunities<br />Protect your company by being Aware of your Digital Assets.<br />Illegal content may be hidden accidentally or intentionally.<br />Recover lost Digital Assets by knowing where to look.<br />Employee misconduct is tracked by the hidden trail of improper acts.<br />Catch Intellectual Property theft before it walks out the door.<br />Identify in-house criminals by detecting their smuggling methods.<br />
  18. 18. What Does FI Do?<br />Create Technologies to Capture Dark Data<br />File Investigator<br />File Expander<br />File Harvester<br />Equip Law Enforcement with Tools<br />FI TOOLS<br />FI Object Explorer<br />FI Data Profiler Portable<br />
  19. 19. FI Technologies<br />File Investigator<br />Discovers Files Masquerading as Other Types<br />Identifies 3,953+ File Types<br />High Accuracy & Speed<br />File Expander<br />Discovers Hidden Data within files<br />Data missed by all forensic tools<br /><ul><li>File Harvester (Under Development)</li></ul>Recovers deleted/lost files the<br /> rest of the industry can’t<br />Will eventually rebuild partial files<br />
  20. 20. Thank you<br />Contact<br />Rob Zirnstein<br />Rob.Zirnstein@ForensicInnovations.com<br />www.ForensicInnovations.com<br />(317) 430-6891<br />

×