Skip to main content

ANTI-FORENSICS TECHNIQUES

 INTRODUCTION 


Anti-computer forensics (sometimes counter forensics) is a general term for a set of techniques used as countermeasures to forensic analysis.

                                                                                                      - Dr. Marcus Rogers


Anti-forensics are the counter-measures taken to frustrate forensic investigation and evade from it. The main aim of anti- forensic technique is to prevent any crime evidence from getting caught. Once a crime surfaces, then a defense is developed, then a new crime counters the new defense. Hence along with continuous developments in forensics, a thorough study and knowledge of developments in anti-forensics is equally important. 


PURPOSE OF USING ANTI-FORENSICS TECHNIQUES

•Avoiding detection that some kind of event has taken place.

•Disrupting the collection of information.

• Increasing the time that an examiner needs to spend on a case.

• Casting doubt on a forensic report or testimony (Liu and Brown, 2006).


Other goals might include:

•Forcing the forensic tool to reveal its presence.

• Subverting the forensic tool (e.g., using the forensic tool itself to attack the organization in which it is running).

• Mounting a direct attack against the forensic examiner (e.g., discovering and disconnecting the examiner’s network, or bombing the building in which the examiner is working).

• Leaving no evidence that an anti-forensic tool has been run.

ANTI-FORENSICS TECHNIQUES BROADLY CATEGORIZED

Anti forensic technique can be divided into four categories such as destruction, evidence source elimination, evidence hiding, and evidence counterfeiting.

ANTI-FORENSICS TECHNIQUES

There are various anti-forensics techniques that can/are used to hamper the evidences for forensics analysis. Some of them are as follows:

•Traditional Anti-Forensics Techniques

Tools that overwrite information that might be the subject of an investigation are the oldest and most common forms of anti-forensic tools available today. Such tools are easy to write and validate, require little training to run, and are distributed with most operating systems.

Modes of operations:

•The program can overwrite the entire media.

• The program can attempt to overwrite individual files. This task is complicated by journaling file systems: the file itself may be overwritten, but portions may be left in the journal.

•The program can attempt to overwrite files that were previously “deleted” but left on the drive. Programs typically do this by creating one or more files on the media and then writing to these files until no free space remains, taking special measures to erase small files.

Methodologies Used : 

  •        Over Writing Data & MetaData
       - Some CFTs can prepare “timeline” of the attacker’s actions by sorting all of the computer’s timestamps in chronological order.
- Instead of wiping the  contents of the media, the attacker might hide her tracks by overwriting the access times themselves so that the timeline could not be reliably constructed to avoid getting attention.
  •        Cryptography, Steganography and other data hiding approaches   
 - Cryptography is very effective at hiding information, encrypted data itself is easy to detect: encrypted data has exceptionally high entropy, and many products embed specific flags, headers or other signatures in their encrypted data. Some forensic tools can decrypt encrypted data if the key is obtained—for example, through spyware or other covert channels. Even if the original plaintext data cannot be recovered, the mere fact that encryption has been used may attract unwanted attention to the attacker.
- Cryptographic file systems
 - Encrypted Network Protocol
- Program Packers
- Steganography
 - Generic data hiding

•Cryptographic file systems –
•Cryptographic file systems transparently encrypt data when it is written to the disk and decrypt data when it is read back, making the data opaque to any attacker (or CFT) that does not have the key.
•Even if the cryptographic system lacks an intentional sanitization command or “self-destruct,” cryptography   can still be a potent barrier to forensic analysis if the cryptographic key is unknown to the examiner.
     •Encrypted Network Protocol –
•Network traffic can likewise be encrypted to protect its content from forensic analysis.
•Cryptographic encapsulation protocols such as SSL and SSH only protect the content of the traffic. Protecting against traffic analysis requires the use of intermediaries. Onion Routing combines both approaches with multiple layers ends of the communication and the plaintext content.
    •Program Packers –
•Packers are commonly used by attackers so that attack tools will not be subject to reverse engineering or detection by scanning.
•Packers such as PECompact and Burneye will take a second program, compress and/or encrypt it, and wrap it with a suitable extractor

   •Steganography - Steganography can be used to embed encrypted data in a cover text to avoid detection. Steghide embeds text in JPEG, MBP, MP3, WAV and AU files.

  •Generic data hiding – Data can also be hidden in unallocated or otherwise unreachable locations that are ignored by the current generation of forensic tools.
•Metasploit’s Slacker will hide data within the slack space of FAT or NTFS file system.
•FragFS hides data within the NTFS Master File Table.
•RuneFS stores data in bad blocks.
•Waffen FS stores data in the ext3 journal file.
•KY FS stores data in directories.
•Data Mule FS stores data in inode reserved space.
•It is also possible to store information in the unallocated pages of Microsoft Office files.

Information can be stored in the Host Protected Area (HPA) and the Device Configuration Overlay (DCO)

areas of modern ATA hard drives. Data in the HPA and DCO is not visible to the BIOS or operating system,

although it can be extracted with special tools.

•Anti-Forensics techniques that minimize footprint

Another approach is to minimize the “footprint,” or data that the attacker has left behind. In this way, there is less data for the CFT to analyze.


•Memory injection & syscall proxying -
•Buffer overflow exploits allow an attacker to inject and run code in the address space of a running program, effectively changing the victim program’s behavior. Traditionally buffer overflows have just been used as a point-of-entry to a remote system, after which the attacker uploads tools that are then saved on the target machine’s hard drive.
•The “Userland Execve” technique allows programs on the victim computer to be loaded and run without the use of the Unix execve() kernel call, allowing the attacker to overcome kernel-based security systems that may deny access to execve() or log its use to a secure logging service.
•Live CDs, bootable USB tokens & virtual machines –
•Live CDs are an operating system distribution that boots and runs from a read-only device. Live CDs typically have a window system, web browser and SSH client, and run with virtual memory disabled.
•Bootable USB tokens are similar to a Live CD except that the operating system is contained within an attachable USB device. These tokens can typically store more information that CDs and allow information to be saved, generally via encryption.
•Virtual Mare “client” operating systems run inside a virtualization program such as VMWare Player, Parallels, or Microsoft Virtual PC. These systems typically store all of the states associated with the client operating system within a small set of files on the host computer.
          •Anonymous identities & storage –
Attackers have long protected their actual identity by making use of anonymous accounts available at Hotmail, Yahoo and Gmail. Recently the amount of storage associated with these accounts has been dramatically increased. Attackers can utilize this storage to avoid the risk of storing attack tools and captured information on their own computers.

•Anti-Forensics techniques that exploit CFT bugs

If an attacker has access to a CFT or knowledge of how that tool works, the attacker can craft data that will manifest bugs within the CFT. Properly triggered, these bugs can accomplish many anti-forensic goals.

•Anti-Forensics techniques that detect CFTs

AFTs can change their behavior if they can detect that a CFT is in use. For example, a packer might not decrypt its payload if it realizes that it is running on a disk that has been imaged.

COUNTERMEASURES FOR ANTI-FORENSICS


To counter measuring the anti forensic, some approachment can be made. Focusing in these issues such as human element, the dependence of the tool and physical to logical limitation.

  •         Human element is the most difficult problem to be solved. Human elements include investigator experience, alertness, and educational level. We can avoid this by increasing experience from training for example, increasing educational level , and keep increasing awareness during investigation.
  •         Dependence of the tools means that investigator should not rely on one specific tools in the computer forensic investigation. It is because the tools itself are not immune to attack. >se variety of tools can be better choice.
  •         Save data where the attacker can’t get at it:

— Log hosts

— CD-Rs

  •         Develop new tools:

— Defeat encrypted file systems with keyloggers.

— Augment network sniffers with traffic analysis



CONCLUSION

Any methodologies that used to incriminating computer forensic process can be considered as a anti forensic. Detection for anti forensic activities can be done by increasing awareness of investigator during computer forensic investigation. Circumvention tools are widely available.


New approaches:

•Minimizing or eliminating memory footprints

•Virtual machines

•Direct attacks against computer forensic tools


Because law enforcement resources are limited, it seems reasonable to hypothesize that, other things being equal; attackers employing anti-forensic technology are less likely to be apprehended than those who do not.


Thanks for scrolling!

Comments

Post a Comment