Vista will force need for network forensics

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

Topics

Forensic, CA

COMMENT

It is an understandable yet curious characteristic of the information security space that the current 'big thing' relates not to the latest big threat, but to the newest threat.

The column inches dedicated to mobile malware bear little relation to the threat posed. All IT security personnel are aware of the reality of this situation, which is that the risk posed by internal threats has always outweighed the risk from external threats. Employee fraud, sloppy exposure of passwords and malicious damage from within the security perimeter cost businesses millions more every year than losses from viruses or spyware.

Most organisations have policies and processes in place to try and counter the internal threat, but two industry developments are making these threats — and the ability to investigate them — a timely and significant concern. First, it has become increasingly difficult for a company that has suffered a security breach to sweep the fact under the carpet. Not only have we witnessed numerous significant and public ID theft breaches, we also have legislation either in effect or being planned that will force companies to 'come clean' regarding their security failures, and to investigate the source of the failure.

Second, Microsoft will soon launch the Microsoft Vista platform, which will encrypt systems at the disk level by default. If successful investigation of a security breach relies on the data on a computer's drive being accessible to an investigator, then locking out that investigator by encrypting the data means all bets are off. While encryption has been a capability for years, most people doing bad things don't take the steps necessary to cover their tracks. Encryption by default means that without user credentials it will no longer be possible to investigate user behaviour at a disk level.

The result? Network forensics is rapidly becoming the next big thing in IT security.

Network forensics is the ability to investigate, at a network level, things taking place or that have taken place across an IT system. Network forensics software provides the tools to conduct this investigation in a correct, sound and thorough manner.

Network forensics overcomes the problem of disk-based encryption locking out the investigator by investigating at a network level. Material that is encrypted while sitting on the disk would be readable as text while passing over the network. Even if the user took the time to encrypt the document, evidence about where communications are coming from and going to, as well as information about the size of attachments and so on, could be enough to identify a sales manager sending confidential client information to a competitor, for example.

IT forensics is not a new invention. Some large organisations, particularly in the financial services sector, have had dedicated forensics departments for years, investigating activity such as employee fraud. Within the conventional law-enforcement community, the lack of expertise and resources for investigating computer crimes has meant private organisations have to take it upon themselves to investigate suspected cases of IT fraud or misuse, gathering the necessary evidence to take action against employees or hand over for prosecution.

While organisations should take all the proactive action they can to investigate employee fraud or security breaches, it is human nature to do only what we have to do, not what we ought to do. It has taken compliance requirements and Microsoft Vista to take network forensics from an 'ought to do' to a 'have to do'.

I'm not suggesting that every organisation will soon have its own forensics department and be running network forensics in-house. For many, there simply wouldn't be the daily requirement to warrant employing the people with the correct investigative skills to make use of the software. In most cases, services will be provided by companies that will use their software and expertise to conduct investigations on a client's network. However, persistent incidents such as security breaches, employee fraud and the exploitation of HR and security policies have led to the emergence of such services.

I anticipate that network forensics will be an area of significant investment and development for security vendors, and I wouldn't be surprised to see the few niche vendors in this area quickly acquired by larger players. The threat may be old but the reasons for dealing with it differently are new and that could be all it takes to make network forensics the 'next big thing'.

Biography: Simon Perry is vice president of security strategy for CA Europe

Talkback

An interesting article, and an interesting idea. Who knows, in fact, where the next "big thing" in IT is going to come from - you could be right. Or, it could be something entirely different.

One thing that this article suggests is that encryption in Vista is turned on "by default." Actually, it is not. In fact, it is not even available in most versions of Vista. Vista is available in five SKUs, only two of which support encryption (a feature known as "BitLocker", or "BitLocker Drive Encryption" - BDE). Vista Home Basic, Media Edition, and Business *do not* support BDE. Vista Enterprise and Ultimate - the two more expensive editions - do support BDE.

Also, encryption is not turned on by default. An important step during encryption involves defining the encryption and decryption keys. This cannot be done by default by someone other than the owner of the system. If it could, then that someone else would be able to gain access to the secure data - exactly what is trying to be controlled.

So - an interesting idea, that Network Forensics is the next big thing. We shall see.

Best,
Paul Yao
Utimaco Safeware, AG

1000112972 24 November, 2006 18:46
Reply

Of the 4 flavours of Vista currently released, only the Ultimate edition has the Bit Locker functionality enabled. This is an optional element, set up through the control panel and, upon doing so, will create 2 partitions on the hard disk; one for the OS the second for data.
The encryption key will reside on a trusted platform module built in to some motherboards or can be held on a removable USB storage device.

Simon is correct in advocation a network based approach to forensics as this is transparent to the user community and allows the forensic investigators to seize a system at the appropriate time; i.e when the system is live and logged on, thus affording the investigator the ability to seize all component parts of the system (including attached storage media).

Jim Griffiths
Digital Forensics Practitioner

1000202897 28 November, 2006 11:53
Reply

If the encrypted drives function like the Encrypted File System in Windows XP, then a network administrator can specify a third set of public keys as a data recovery key which all users have to import. This third set of keys then allow the third party owner to decrypt any of the data encrypted by their users.

nrlz 29 November, 2006 01:27
Reply

im already using windows Vista and i have to say i liek it, i liek it alot!!

however network forensics? ill use point to point tunnels if needs be :D

351668 8 December, 2006 19:01
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

Paul Smyth

Is this classic FUD? One thing I would definitely have notice is a Mozilla threat to stop supporting GNU/Linux.

32 minutes ago by Paul Smyth via Facebook on Firefox rapid release improves Fedora Linux
UnderINK

I agree with the previous commenter wholeheartedly. I couldn't say it better myself. This is very 'Big Brother'. And while I agree with protecting...

5 hours ago by UnderINK on European e-identity plan to be unveiled this month
Simon Bisson and Mary Branscombe

Nice to see that Turing's idea of a general purpose computer doing once-hardware-powered tasks in software is now universal ;-) Mary

10 hours ago by Simon Bisson and Mary Branscombe on Software with everything
Jason Burchell

seriously now. I've only bothered to read a small bit of the comments. do me and the rest of the world a favour. stop saying it does not work or...

14 hours ago by Jason Burchell via Facebook on Music industry negotiating over 24-bit downloads
Philip Charles Cohen

Read about it and weep, John Donahoe ... In addition to Visa’s V.me, there is now MasterCard’s PayPass digital wallet soon to arrive; another...

18 hours ago by Philip Charles Cohen via Facebook on PayPal takes phone-based payments to the high street
apexwm

Leslie Satenstein : Where have you ever seen Mozilla even mention this? Firefox is the most popular browser in the GNU/Linux OS, so I don't see...

19 hours ago by apexwm on Firefox rapid release improves Fedora Linux
songmaster

SHleG: Do you remember building a clockwork scorpion kit (I'm pretty sure I have a photo of it somewhere) — I think it was called something like...

20 hours ago by songmaster on Software with everything
Chris Wortman

Good I love Yahoo! Their search engine is getting better than Google as of late. I find more of what I want on the first page, and usually within...

21 hours ago by Chris Wortman via Facebook on Linux Mint 13 ramps up for KDE release
PatrickG

openhgs has made the point for Windows 8 multiple monitors without realising it! With Windows 7 you have to switch the mouse and so your focus...

23 hours ago by PatrickG on Windows 8 could speed multi-monitor uptake
Leslie Satenstein

Mozilla has threatened to stop supporting Linux. I guess that UBUNTU is going with another browser. I indicated that if Mozilla stops supporting...

1 day ago by Leslie Satenstein via Facebook on Firefox rapid release improves Fedora Linux
Andy Bolstridge

Much as I abhor Microsoft's licensing practices, this is almost certainly down to purchasing IT equipment via 3rd party consultants - you get the...

1 day ago by Andy Bolstridge via Facebook on 6 million wasted licences and £1,200 PCs: welcome to government IT
Jack Schofield

@openhgs Windows users have had multiple desktops since Linus started writing Linux. They just haven't shipped as standard because not enough...

2 days ago by Jack Schofield on Windows 8 could speed multi-monitor uptake
Jack Schofield

@Phil at Cloud4 What, Microsoft gets £1,200 per PC and £1,622 per server? Gosh, I'm amazed....

2 days ago by Jack Schofield on 6 million wasted licences and £1,200 PCs: welcome to government IT
craigsc

You guys have no idea what is going on at Autonomy. Autonomy could have been a much more profitable organization. The sales operations at Autonomy...

2 days ago by craigsc on HP cuts 27,000 staff as Autonomy chief Lynch leaves
Moley

How does this impact on dual or multi booting? Seems to me to more or less prohibit this, from Windows 8 anyway. Will Grub 2 recognise Windows 8,...

2 days ago by Moley on Windows 8 start-up speed forces USB boot workaround
apexwm

I don't understand why there cannot be a slight pause during the boot process so the user can press a key. Many operating systems do this, even if...

2 days ago by apexwm on Windows 8 start-up speed forces USB boot workaround
Gavin Goodman

You can now buy the Xi3 modular computer in the UK at http://www.ocdistribution.com . This can be bought with the Tand3m software, pricing and...

2 days ago by Gavin Goodman on CES 2012: Xi3 microSERV3R
Phil at Cloud4

I agree: Mike Lynch can clearly build a business and manage strategy. I suspect the exit of Mike is more likely the end of a planned handover...

2 days ago by Phil at Cloud4 on HP cuts 27,000 staff as Autonomy chief Lynch leaves
Phil at Cloud4

This is unbeleivable government wastage with only one winner... Microsoft 1 - Tax payer Nil!

2 days ago by Phil at Cloud4 on 6 million wasted licences and £1,200 PCs: welcome to government IT
Mispam

So what do you do when you can't boot into windows? Why can't I just hold Shift while I power up instead of having to boot into windows and click a...

2 days ago by Mispam on Windows 8 start-up speed forces USB boot workaround