This document discusses issues related to acquiring forensic evidence from field devices. It begins with background on field devices and why they need to be considered from a forensic perspective. Problems that can be encountered are then outlined, including lack of interfaces, file system or OS compatibility issues, and risks to the integrity of the evidence. A case study is presented involving acquiring evidence from a SCADA system. Finally, discussion topics are proposed around what types of data are important to forensicators, how evidence can be preserved while maintaining a clear chain of custody, and challenges in acquiring different types of field devices for forensic analysis.
5. forensicinsight.org Page 5 / 21
Background
Why we need to care this?
Fxxk the mass-media
Have to cross check → Be trustworthy
For find the smoking-bit (specially, manipulate digital evidence)
no way without this
M a j o r t h r e a t
f o r e n s i c a t o r s
7. forensicinsight.org Page 7 / 21
Problems
Issues If
Interfaces It hasn’t usb, cdrom, display, keyboard, ethernet
FileSystem Mount Do not support NTFS? or trouble in recognize
OS Compatibility tools No excutable imaging tool, even DD
The risk of system failure We have no time for verification situation.
Capacity / Time Another headache factors
O f c o u r s e , w e h a v e t o k e e p i n t e g r i t y o f e v i d e n c e !
C a n y o u a c c o m p l i s h m e n t t h i s m i s s i o n ?
8. forensicinsight.org Page 8 / 21
Problems
Examples
Router / Switch
• Telnet, Console Connection
• But No Imaging tools
Home Router (Wire, Wireless)
• Telnet, Web Admin
• No Imaging tools (but It can be execute static DD binary)
Home SCADA
• Nothing !! Just opened stupid console
21. forensicinsight.org Page 21 / 21
Discussion topic
Case Studyk
What is the data for forensicators?
Disk / Memory Image? Log files?
How can we more preserve evidence?
• Imaging is very ideal option.
• FTP? / File copy?
How can we keep integrity for chain of custody?
• File Hash? / Documents(kind of agreements?) / Burning CD?
How can we acquire field device?
• Router, Gateway, Switch, Home network device, even SCADA?
• Forensic Acquisition tools? / DD? / file copy? / Cold imaging?