ppb forensics – may 2010 ip theft it forensic solutions chris hatfield senior manager, it...

19
PPB Forensics May 2010 IP Theft IT Forensic Solutions Chris Hatfield Senior Manager, IT Forensics

Upload: theodora-woods

Post on 16-Dec-2015

222 views

Category:

Documents


2 download

TRANSCRIPT

Page 1: PPB Forensics – May 2010 IP Theft IT Forensic Solutions Chris Hatfield Senior Manager, IT Forensics

PPB Forensics – May 2010

IP TheftIT Forensic Solutions

Chris HatfieldSenior Manager, IT Forensics

Page 2: PPB Forensics – May 2010 IP Theft IT Forensic Solutions Chris Hatfield Senior Manager, IT Forensics

Risk Management

The process of determining the maximum acceptable level of overall risk to and from a proposed activity, then using risk assessment techniques to determine the initial level of risk and, if this is excessive, developing a strategy to ameliorate appropriate individual risks until the overall level of risk is reduced to an acceptable level.

http://en.wiktionary.org/wiki/risk_management

Page 3: PPB Forensics – May 2010 IP Theft IT Forensic Solutions Chris Hatfield Senior Manager, IT Forensics

Security Triad

Page 4: PPB Forensics – May 2010 IP Theft IT Forensic Solutions Chris Hatfield Senior Manager, IT Forensics

Security Triad

Page 5: PPB Forensics – May 2010 IP Theft IT Forensic Solutions Chris Hatfield Senior Manager, IT Forensics

Authentication

Page 6: PPB Forensics – May 2010 IP Theft IT Forensic Solutions Chris Hatfield Senior Manager, IT Forensics

Layer 1

Page 7: PPB Forensics – May 2010 IP Theft IT Forensic Solutions Chris Hatfield Senior Manager, IT Forensics

Layer 2

Page 8: PPB Forensics – May 2010 IP Theft IT Forensic Solutions Chris Hatfield Senior Manager, IT Forensics

Layer 3

Page 9: PPB Forensics – May 2010 IP Theft IT Forensic Solutions Chris Hatfield Senior Manager, IT Forensics

Sources

A CB

Page 10: PPB Forensics – May 2010 IP Theft IT Forensic Solutions Chris Hatfield Senior Manager, IT Forensics

Mobile Devices

A E

G I

C

M ON

B

F H J

K L

D

Page 11: PPB Forensics – May 2010 IP Theft IT Forensic Solutions Chris Hatfield Senior Manager, IT Forensics

Hard Copy

BA C

Page 12: PPB Forensics – May 2010 IP Theft IT Forensic Solutions Chris Hatfield Senior Manager, IT Forensics

Web mail, mail clients and mail servers.

Email Communication

B CA

Page 13: PPB Forensics – May 2010 IP Theft IT Forensic Solutions Chris Hatfield Senior Manager, IT Forensics

Local, Remote and Hosted.

Data Locations

BA C

Page 14: PPB Forensics – May 2010 IP Theft IT Forensic Solutions Chris Hatfield Senior Manager, IT Forensics

Pro-Active Solutions

Page 15: PPB Forensics – May 2010 IP Theft IT Forensic Solutions Chris Hatfield Senior Manager, IT Forensics

Pro-Active Solutions

• Data transfer restrictions• Internet Logging• Personal email restrictions• Disable unnecessary media connections (USB/CD)• Monitor USB connections• Restrict working hours on IT equipment• Monitor/log printing habits• Monitor customer relationship software• Restrict access to only data they require access to• Log user activity• Keep reliable backups• Multi user authentication

Page 16: PPB Forensics – May 2010 IP Theft IT Forensic Solutions Chris Hatfield Senior Manager, IT Forensics

Re-Active Solutions

POLICE POLICE POLICE POLICE POLICE POLICE POLICE POLICE POLICE

Page 17: PPB Forensics – May 2010 IP Theft IT Forensic Solutions Chris Hatfield Senior Manager, IT Forensics

Re-Active Solutions

• Control crime scene• Equipment• Locations• People

• Contain evidence• Forensic image• Backup tapes• Physical segregation

• Evidence continuity• Do not touch original• Document all actions

Page 18: PPB Forensics – May 2010 IP Theft IT Forensic Solutions Chris Hatfield Senior Manager, IT Forensics

Re-Active Solutions

• Conduct Forensic Analysis• Time of compromise• Extent of compromise• Threat assessment• USB access lists• Internet activity• Events timeline• Personal email activity• Business email activity• Printing activity• File access

Page 19: PPB Forensics – May 2010 IP Theft IT Forensic Solutions Chris Hatfield Senior Manager, IT Forensics

Questions

PPB Forensics – May 2010

Joe DicksPartner, Melbourne

03 9269 4209 [email protected]

Phillip RussoDirector, Perth08 9216 7634

[email protected]

Andrew McLeishSenior Manager, Melbourne

03 9269 4276 [email protected]

Chris HatfieldSenior Manager, Sydney

02 8116 [email protected]