Anti-computer forensics (sometimes counter forensics) is a general term for a set of techniques used as countermeasures to forensic analysis.
- Dr. Marcus Rogers
Anti-forensics are the counter-measures taken to frustrate forensic investigation and evade from it. The main aim of anti- forensic technique is to prevent any crime evidence from getting caught. Once a crime surfaces, then a defense is developed, then a new crime counters the new defense. Hence along with continuous developments in forensics, a thorough study and knowledge of developments in anti-forensics is equally important.
PURPOSE OF USING ANTI-FORENSICS TECHNIQUES
•Avoiding detection that some kind of event has taken place.
•Disrupting the collection of information.
• Increasing the time that an examiner needs to spend on a case.
• Casting doubt on a forensic report or testimony (Liu and Brown, 2006).
Other goals might include:
•Forcing the forensic tool to reveal its presence.
• Subverting the forensic tool (e.g., using the forensic tool itself to attack the organization in which it is running).
• Mounting a direct attack against the forensic examiner (e.g., discovering and disconnecting the examiner’s network, or bombing the building in which the examiner is working).
• Leaving no evidence that an anti-forensic tool has been run.
ANTI-FORENSICS TECHNIQUES BROADLY CATEGORIZED
Anti forensic technique can be divided into four categories such as destruction, evidence source elimination, evidence hiding, and evidence counterfeiting.
ANTI-FORENSICS TECHNIQUES
There are various anti-forensics techniques that can/are used to hamper the evidences for forensics analysis. Some of them are as follows:
•Traditional Anti-Forensics Techniques
Tools that overwrite information
that might be the subject of an investigation are the oldest and most common
forms of anti-forensic tools available today. Such tools are easy to write and
validate, require little training to run, and are distributed with most
operating systems.
Modes of operations:
•The program can overwrite the entire media.
• The program can attempt to overwrite individual files. This task is complicated by journaling file systems: the file itself may be overwritten, but portions may be left in the journal.
•The program can attempt to overwrite files that were previously “deleted” but left on the drive. Programs typically do this by creating one or more files on the media and then writing to these files until no free space remains, taking special measures to erase small files.
Methodologies Used :
- Over Writing Data & MetaData
- Cryptography, Steganography and other data hiding approaches
Information can be stored in the Host Protected Area (HPA) and the Device Configuration Overlay (DCO)
areas of modern ATA hard drives. Data in the HPA and DCO is not visible to the BIOS or operating system,
although it can be extracted with special tools.
•Anti-Forensics techniques that minimize footprint
Another approach is to minimize the “footprint,” or data that the attacker has left behind. In this way, there is less data for the CFT to analyze.
•Anti-Forensics techniques that exploit CFT bugs
If an attacker has access to a CFT or knowledge of how that tool works, the attacker can craft data that will manifest bugs within the CFT. Properly triggered, these bugs can accomplish many anti-forensic goals.
•Anti-Forensics techniques that detect CFTs
AFTs can change their behavior if they can detect that a CFT is in use. For example, a packer might not decrypt its payload if it realizes that it is running on a disk that has been imaged.
COUNTERMEASURES FOR ANTI-FORENSICS
To counter measuring the anti forensic, some approachment can be made. Focusing in these issues such as human element, the dependence of the tool and physical to logical limitation.
- Human element is the most difficult problem to be solved. Human elements include investigator experience, alertness, and educational level. We can avoid this by increasing experience from training for example, increasing educational level , and keep increasing awareness during investigation.
- Dependence of the tools means that investigator should not rely on one specific tools in the computer forensic investigation. It is because the tools itself are not immune to attack. >se variety of tools can be better choice.
- Save data where the attacker can’t get at it:
— Log hosts
— CD-Rs
- Develop new tools:
— Defeat encrypted file systems with keyloggers.
— Augment network sniffers with traffic analysis
CONCLUSION
Any methodologies that used to incriminating computer forensic process can be considered as a anti forensic. Detection for anti forensic activities can be done by increasing awareness of investigator during computer forensic investigation. Circumvention tools are widely available.
New approaches:
•Minimizing or eliminating memory footprints
•Virtual machines
•Direct attacks against computer forensic tools
Because law enforcement resources are limited, it seems reasonable to hypothesize that, other things being equal; attackers employing anti-forensic technology are less likely to be apprehended than those who do not.
In preparation and completion of this presentation, I took help from the following resources :

Informative ...... Keep posting such articles
ReplyDeleteThanks Bhanu
Delete