Network Forensics Tracking Hackers 09-16-2017, 07:27 PM
#1
![[Image: 36afdd9a089543782263ebd9440d643e.png]](https://i.gyazo.com/36afdd9a089543782263ebd9440d643e.png)
Code:
Foreword xvii
Preface xix
0.1 The Changing Landscape xix
0.2 Organization xxi
0.2.1 Part I, “Foundation” xxi
0.2.2 Part II, “Traffic Analysis” xxii
0.2.3 Part III, “Network Devices and Servers” xxii
0.2.4 Part IV, “Advanced Topics” xxiii
0.3 Tools xxiii
0.4 Case Studies xxiii
0.5 Errata xxiv
0.6 Final Notes xxiv
Acknowledgments xxv
About the Authors xxvii
Part I Foundation 1
Chapter 1 Practical Investigative Strategies 3
1.1 Real-World Cases 3
1.1.1 Hospital Laptop Goes Missing 4
1.1.2 Catching a Corporate Pirate 6
1.1.3 Hacked Government Server 7
1.2 Footprints 8
1.3 Concepts in Digital Evidence 9
1.3.1 Real Evidence 10
1.3.2 Best Evidence 11
1.3.3 Direct Evidence 12
1.3.4 Circumstantial Evidence 12
1.3.5 Hearsay 13
1.3.6 Business Records 14
1.3.7 Digital Evidence 15
1.3.8 Network-Based Digital Evidence 15
vii
ptg8126969
viii Contents
1.4 Challenges Relating to Network Evidence 16
1.5 Network Forensics Investigative Methodology (OSCAR) 17
1.5.1 Obtain Information 17
1.5.2 Strategize 18
1.5.3 Collect Evidence 19
1.5.4 Analyze 20
1.5.5 Report 21
1.6 Conclusion 22
Chapter 2 Technical Fundamentals 23
2.1 Sources of Network-Based Evidence 23
2.1.1 On the Wire 24
2.1.2 In the Air 24
2.1.3 Switches 25
2.1.4 Routers 25
2.1.5 DHCP Servers 26
2.1.6 Name Servers 26
2.1.7 Authentication Servers 27
2.1.8 Network Intrusion Detection/Prevention Systems 27
2.1.9 Firewalls 27
2.1.10 Web Proxies 28
2.1.11 Application Servers 29
2.1.12 Central Log Servers 29
2.2 Principles of Internetworking 30
2.2.1 Protocols 30
2.2.2 Open Systems Interconnection Model 31
2.2.3 Example: Around the World ... and Back 33
2.3 Internet Protocol Suite 35
2.3.1 Early History and Development of the Internet Protocol Suite 36
2.3.2 Internet Protocol 37
2.3.3 Transmission Control Protocol 41
2.3.4 User Datagram Protocol 43
2.4 Conclusion 44
Chapter 3 Evidence Acquisition 45
3.1 Physical Interception 46
3.1.1 Cables 46
3.1.2 Radio Frequency 50
3.1.3 Hubs 51
3.1.4 Switches 52
3.2 Traffic Acquisition Software 54
3.2.1 libpcap and WinPcap 55
3.2.2 The Berkeley Packet Filter (BPF) Language 55
3.2.3 tcpdump 59
3.2.4 Wireshark 64
3.2.5 tshark 64
ptg8126969
Contents ix
3.2.6 dumpcap 64
3.3 Active Acquisition 65
3.3.1 Common Interfaces 66
3.3.2 Inspection Without Access 70
3.3.3 Strategy 71
3.4 Conclusion 72
Part II Traffic Analysis 73
Chapter 4 Packet Analysis 75
4.1 Protocol Analysis 76
4.1.1 Where to Get Information on Protocols 76
4.1.2 Protocol Analysis Tools 79
4.1.3 Protocol Analysis Techniques 82
4.2 Packet Analysis 95
4.2.1 Packet Analysis Tools 96
4.2.2 Packet Analysis Techniques 99
4.3 Flow Analysis 103
4.3.1 Flow Analysis Tools 105
4.3.2 Flow Analysis Techniques 109
4.4 Higher-Layer Traffic Analysis 120
4.4.1 A Few Common Higher-Layer Protocols 120
4.4.2 Higher-Layer Analysis Tools 129
4.4.3 Higher-Layer Analysis Techniques 131
4.5 Conclusion 133
4.6 Case Study: Ann’s Rendezvous 135
4.6.1 Analysis: Protocol Summary 135
4.6.2 DHCP Traffic 136
4.6.3 Keyword Search 138
4.6.4 SMTP Analysis—Wireshark 141
4.6.5 SMTP Analysis—TCPFlow 143
4.6.6 SMTP Analysis—Attachment File Carving 146
4.6.7 Viewing the Attachment 147
4.6.8 Finding Ann the Easy Way 150
4.6.9 Timeline 154
4.6.10 Theory of the Case 155
4.6.11 Response to Challenge Questions 155
4.6.12 Next Steps 157
Chapter 5 Statistical Flow Analysis 159
5.1 Process Overview 160
5.2 Sensors 161
5.2.1 Sensor Types 162
5.2.2 Sensor Software 163
5.2.3 Sensor Placement 164
ptg8126969
x Contents
5.2.4 Modifying the Environment 165
5.3 Flow Record Export Protocols 166
5.3.1 NetFlow 166
5.3.2 IPFIX 167
5.3.3 sFlow 167
5.4 Collection and Aggregation 168
5.4.1 Collector Placement and Architecture 169
5.4.2 Collection Systems 170
5.5 Analysis 172
5.5.1 Flow Record Analysis Techniques 172
5.5.2 Flow Record Analysis Tools 177
5.6 Conclusion 183
5.7 Case Study: The Curious Mr. X 184
5.7.1 Analysis: First Steps 185
5.7.2 External Attacker and Port 22 Traffic 186
5.7.3 The DMZ Victim—10.30.30.20 (aka 172.30.1.231) 189
5.7.4 The Internal Victim—192.30.1.101 193
5.7.5 Timeline 194
5.7.6 Theory of the Case 195
5.7.7 Response to Challenge Questions 196
5.7.8 Next Steps 196
Chapter 6 Wireless: Network Forensics Unplugged 199
6.1 The IEEE Layer 2 Protocol Series 201
6.1.1 Why So Many Layer 2 Protocols? 201
6.1.2 The 802.11 Protocol Suite 202
6.1.3 802.1X 212
6.2 Wireless Access Points (WAPs) 214
6.2.1 Why Investigate Wireless Access Points? 214
6.2.2 Types of Wireless Access Points 215
6.2.3 WAP Evidence 218
6.3 Wireless Traffic Capture and Analysis 219
6.3.1 Spectrum Analysis 220
6.3.2 Wireless Passive Evidence Acquisition 221
6.3.3 Analyzing 802.11 Efficiently 222
6.4 Common Attacks 224
6.4.1 Sniffing 224
6.4.2 Rogue Wireless Access Points 225
6.4.3 Evil Twin 227
6.4.4 WEP Cracking 228
6.5 Locating Wireless Devices 229
6.5.1 Gather Station Descriptors 229
6.5.2 Identify Nearby Wireless Access Points 229
6.5.3 Signal Strength 231
6.5.4 Commercial Enterprise Tools 233
ptg8126969
Contents xi
6.5.5 Skyhook 233
6.6 Conclusion 235
6.7 Case Study: HackMe, Inc. 236
6.7.1 Inspecting the WAP 236
6.7.2 Quick-and-Dirty Statistics 242
6.7.3 A Closer Look at the Management Frames 248
6.7.4 A Possible Bad Actor 250
6.7.5 Timeline 251
6.7.6 Theory of the Case 252
6.7.7 Response to Challenge Questions 253
6.7.8 Next Steps 255
Chapter 7 Network Intrusion Detection and Analysis 257
7.1 Why Investigate NIDS/NIPS? 258
7.2 Typical NIDS/NIPS Functionality 258
7.2.1 Sniffing 259
7.2.2 Higher-Layer Protocol Awareness 259
7.2.3 Alerting on Suspicious Bits 260
7.3 Modes of Detection 261
7.3.1 Signature-Based Analysis 261
7.3.2 Protocol Awareness 261
7.3.3 Behavioral Analysis 261
7.4 Types of NIDS/NIPSs 262
7.4.1 Commercial 262
7.4.2 Roll-Your-Own 263
7.5 NIDS/NIPS Evidence Acquisition 264
7.5.1 Types of Evidence 264
7.5.2 NIDS/NIPS Interfaces 266
7.6 Comprehensive Packet Logging 267
7.7 Snort 268
7.7.1 Basic Architecture 268
7.7.2 Configuration 269
7.7.3 Snort Rule Language 269
7.7.4 Examples 273
7.8 Conclusion 275
7.9 Case Study: Inter0ptic Saves the Planet (Part 1 of 2) 276
7.9.1 Analysis: Snort Alert 277
7.9.2 Initial Packet Analysis 278
7.9.3 Snort Rule Analysis 279
7.9.4 Carving a Suspicous File from Snort Capture 281
7.9.5 “INFO Web Bug” Alert 283
7.9.6 “Tcp Window Scale Option” Alert 284
7.9.7 Timeline 285
7.9.8 Theory of the Case 286
7.9.9 Next Steps 287
ptg8126969
xii Contents
Part III Network Devices and Servers 289
Chapter 8 Event Log Aggregation, Correlation, and Analysis 291
8.1 Sources of Logs 292
8.1.1 Operating System Logs 292
8.1.2 Application Logs 300
8.1.3 Physical Device Logs 302
8.1.4 Network Equipment Logs 305
8.2 Network Log Architecture 306
8.2.1 Three Types of Logging Architectures 306
8.2.2 Remote Logging: Common Pitfalls and Strategies 308
8.2.3 Log Aggregation and Analysis Tools 309
8.3 Collecting and Analyzing Evidence 311
8.3.1 Obtain Information 311
8.3.2 Strategize 313
8.3.3 Collect Evidence 314
8.3.4 Analyze 316
8.3.5 Report 317
8.4 Conclusion 317
8.5 Case Study: L0ne Sh4rk’s Revenge 318
8.5.1 Analysis: First Steps 319
8.5.2 Visualizing Failed Login Attempts 319
8.5.3 Targeted Accounts 322
8.5.4 Successful Logins 323
8.5.5 Activity Following Compromise 324
8.5.6 Firewall Logs 325
8.5.7 The Internal Victim—192.30.1.101 328
8.5.8 Timeline 330
8.5.9 Theory of the Case 332
8.5.10 Response to Challenge Questions 332
8.5.11 Next Steps 333
Chapter 9 Switches, Routers, and Firewalls 335
9.1 Storage Media 336
9.2 Switches 336
9.2.1 Why Investigate Switches? 337
9.2.2 Content-Addressable Memory Table 337
9.2.3 Address Resolution Protocol 338
9.2.4 Types of Switches 338
9.2.5 Switch Evidence 340
9.3 Routers 340
9.3.1 Why Investigate Routers? 341
9.3.2 Types of Routers 341
9.3.3 Router Evidence 343
9.4 Firewalls 344
ptg8126969
Contents xiii
9.4.1 Why Investigate Firewalls? 344
9.4.2 Types of Firewalls 344
9.4.3 Firewall Evidence 347
9.5 Interfaces 348
9.5.1 Web Interface 348
9.5.2 Console Command-Line Interface (CLI) 349
9.5.3 Remote Command-Line Interface 350
9.5.4 Simple Network Management Protocol (SNMP) 351
9.5.5 Proprietary Interface 351
9.6 Logging 352
9.6.1 Local Logging 352
9.6.2 Simple Network Management Protocol 353
9.6.3 syslog 354
9.6.4 Authentication, Authorization, and Accounting Logging 355
9.7 Conclusion 355
9.8 Case Study: Ann’s Coffee Ring 356
9.8.1 Firewall Diagnostic Commands 357
9.8.2 DHCP Server Logs 358
9.8.3 The Firewall ACLs 359
9.8.4 Firewall Log Analysis 360
9.8.5 Timeline 364
9.8.6 Theory of the Case 365
9.8.7 Responses to Challenge Questions 367
9.8.8 Next Steps 367
Chapter 10 Web Proxies 369
10.1 Why Investigate Web Proxies? 369
10.2 Web Proxy Functionality 371
10.2.1 Caching 371
10.2.2 URI Filtering 373
10.2.3 Content Filtering 373
10.2.4 Distributed Caching 374
10.3 Evidence 375
10.3.1 Types of Evidence 375
10.3.2 Obtaining Evidence 376
10.4 Squid 377
10.4.1 Squid Configuration 377
10.4.2 Squid Access Logfile 378
10.4.3 Squid Cache 379
10.5 Web Proxy Analysis 381
10.5.1 Web Proxy Log Analysis Tools 381
10.5.2 Example: Dissecting a Squid Disk Cache 384
10.6 Encrypted Web Traffic 392
10.6.1 Transport Layer Security (TLS) 394
10.6.2 Gaining Access to Encrypted Content 396
ptg8126969
xiv Contents
10.6.3 Commercial TLS/SSL Interception Tools 400
10.7 Conclusion 401
10.8 Case Study: Inter0ptic Saves the Planet (Part 2 of 2) 402
10.8.1 Analysis: pwny.jpg 403
10.8.2 Squid Cache Page Extraction 405
10.8.3 Squid Access.log File 408
10.8.4 Further Squid Cache Analysis 411
10.8.5 Timeline 415
10.8.6 Theory of the Case 417
10.8.7 Response to Challenge Questions 418
10.8.8 Next Steps 419
Part IV Advanced Topics 421
Chapter 11 Network Tunneling 423
11.1 Tunneling for Functionality 423
11.1.1 Background: VLAN Trunking 424
11.1.2 Inter-Switch Link (ISL) 424
11.1.3 Generic Routing Encapsulation (GRE) 425
11.1.4 IPv6 over IPv4 with Teredo 425
11.1.5 Implications for the Investigator 426
11.2 Tunneling for Confidentiality 427
11.2.1 Internet Protocol Security (IPsec) 427
11.2.2 Transport Layer Security (TLS) and Secure Socket Layer (SSL) 428
11.2.3 Implications for the Investigator 430
11.3 Covert Tunneling 430
11.3.1 Covert Tunneling Strategies 430
11.3.2 TCP Sequence Numbers 430
11.3.3 DNS Tunnels 431
11.3.4 ICMP Tunnels 432
11.3.5 Example: ICMP Tunnel Analysis 434
11.3.6 Implications for the Investigator 438
11.4 Conclusion 439
11.5 Case Study: Ann Tunnels Underground 441
11.5.1 Analysis: Protocol Statistics 442
11.5.2 DNS Analysis 443
11.5.3 Quest for Tunneled IP Packets 446
11.5.4 Tunneled IP Packet Analysis 451
11.5.5 Tunneled TCP Segment Analysis 454
11.5.6 Timeline 456
11.5.7 Theory of the Case 456
11.5.8 Response to Challenge Questions 458
11.5.9 Next Steps 459
ptg8126969
Contents xv
Chapter 12 Malware Forensics 461
12.1 Trends in Malware Evolution 462
12.1.1 Botnets 462
12.1.2 Encryption and Obfuscation 463
12.1.3 Distributed Command-and-Control Systems 465
12.1.4 Automatic Self-Updates 469
12.1.5 Metamorphic Network Behavior 472
12.1.6 Blending Network Activity 477
12.1.7 Fast-Flux DNS 479
12.1.8 Advanced Persistent Threat (APT) 480
12.2 Network Behavior of Malware 484
12.2.1 Propagation 485
12.2.2 Command-and-Control Communications 487
12.2.3 Payload Behavior 490
12.3 The Future of Malware and Network Forensics 491
12.4 Case Study: Ann’s Aurora 492
12.4.1 Analysis: Intrusion Detection 492
12.4.2 TCP Conversation: 10.10.10.10:4444–10.10.10.70:1036 495
12.4.3 TCP Conversations: 10.10.10.10:4445 502
12.4.4 TCP Conversation: 10.10.10.10:8080–10.10.10.70:1035 508
12.4.5 Timeline 513
12.4.6 Theory of the Case 514
12.4.7 Response to Challenge Questions 515
12.4.8 Next Steps 516![[Image: Vs4P58c.png]](https://i.imgur.com/Vs4P58c.png)






![[+]](https://sinister.li/images/modern/collapse_collapsed.png)