Expert undermines hacking suspect's defence

NEWS
An expert witness in the case of a teenager accused of accidentally launching a distributed denial of service (DDoS) attack on a major US port said on Thursday there was no indication that evidence had been planted on the suspect's hard drive.

The defence counsel for Aaron Caffrey, who is on trial at Southwark Crown Court, had said that his client's computer could have been compromised by a hacker who had altered the system's log files -- which record how the machine is being used -- and staged an attack from the teenager's computer.

But Professor Neil Barrett, technical director at Information Risk Management and an expert witness at the trial, told the court that after examining the physical location of data blocks on Caffrey's computer, there was no evidence that the log files had been altered at a later date.

"If you edit a file after you finish writing it to disk, it results in block fractures. The block that corresponds to the edited text would be written elsewhere. The disk blocks that correspond to this file show no evidence of fracturing and were sandwiched between files that were created before and after it," Barrett told the court.

Barrett conceded that a hacker could, in theory, have planted a different log file on Caffrey's computer, but said it would be obvious that it was inserted later because of the physical position of the file's data blocks. "There is obviously a way of introducing (the file) on the computer, but not in the correct place," he said.

Caffrey's counsel questioned the validity of Barrett's evidence because the witness had not physically examined the actual hard disk from Caffrey's computer, but an image of it that was sent to him on CD-ROM. Barrett argued that this did not make a difference because the image was "forensically sound".

The case continues.

Talkback

Fire this expert.
THe log file would not be fractured if
1) the log file got shorter, or
2) the device file was edited.

Besides, windows protects its event logger.
The log file can only be modified by
editing the disk, there would be no trace.

via Facebook 10 October, 2003 03:23
Reply

Windows doesn't do nearly enough to "protect" syslogs, assuming that logging has been enabled and properly configured to begin with.

Best Practices call for active, ongoing archival of individual system syslogs to at least one known-to-be-secure repository system that is not the generator of the original logfiles. You then test for tampering by comparing the (various) archived copies, as a time series of data, against one another. That's where you look for and perhaps find syslog discrepancies.

Given syslogs residing on the very same system that generated them, any number of things could happen to those log files... not the least of which could be filesystem defragmentation, which can and does fully defrag syslogs (provided that the event logging service is taken offline and/or redirected to write to a different set of target files and/or that the defrag occurs before GUI boot).

More compelling evidence would be the presence/absence of significant time gaps in syslog entries (indicating rather inept syslog deletions) and/or syslog entry forgeries (attempting to cover the deletions of legitimate entries).

This "expert"'s so-called block/sector-level analysis of the disk blocks/sectors on which the log files were eventually found to reside, at least as described and (probably) summarized in the article, leaves too much to be desired. It make this expert sound too "block-headed" to be believed, let alone to convict on.

Direct editing of a so-called file, using a disk-level binary editor, would not necessarily "fracture" unfractured blocks, but it would require artful and precise forgeries to cover time gaps created by deleted entries.

via Facebook 10 October, 2003 05:03
Reply

Surely any image taken from a hard drive would be subject to defragmentation as part of the imaging process? Is the actual drive still available for examination?

via Facebook 10 October, 2003 12:02
Reply

A true sector-level disk image, with no "dead-space" skipping and no "image compression" should almost preserve the exact sector-level state of the original drive, as long as the orignal drive was properly mounted for forensic analysis (absolutely no external write capabilities).

But there are possible, and potentially serious exceptions...

I do not know how hardware-level bad sector sparing would be copied and/or missed by COTS sector-level disk imaging tools.

I believe most COTS tools simply skip already mapped "bad sectors" and also slip-stream in any on-the-fly "spare sectors," swapped in (by hardware), for bad/failing sectors .

via Facebook 11 October, 2003 02:24
Reply

Did the examiners:

 - mount the original disk on a *hardware* disk duplicating device, with read-only capability

 - temporarily disable all error correction on the original disk prior to taking a duplicate image TO A ZERO-MEDIA-DEFECT DUPLICATE of the original disk (make, model, factory & firmware revision)

 - duplicate the internal sector-sparing tables from the original disk

 - then manually reconstruct the same sector-sparing tables on the zero-defect duplicate disk

???...

I can't think of any other way to identically duplicate the original disk, if one is going to convict over arguments of contiguous and/or non-contiguous disk blocks/sectors.

An image recorded to CDROM or DVD could not possibly be an exact sector-level duplicate of the original disk, unless the original disk, itself was also a CDROM or DVD.

via Facebook 11 October, 2003 02:41
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

Freebies202

Duplicate comments are not made intentionally. Its very good to know that now you are keeping check on this problem because sometimes a commenter...

7 hours ago by Freebies202 on Microsoft fixes blog comments, speeds up blogs with open source
kevinmchapman

"the very significant number of users" and "many (most) of us" - you have no evidence for these statements. It is a fact that most users are saying...

15 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
Marg Menzies Harrison

Another grammar faux pas is the improper use of "you". When sitting down down in a restaurant, for example, I get cringe when the waitress...

17 hours ago by Marg Menzies Harrison via Facebook on 10 flagrant grammar mistakes that make you look stupid
zdnetukuser

And NOW, folks, for Canonical's next trick... Kubuntu is late. Here's a pencil. Draw your own conclusions. cf.:...

17 hours ago by zdnetukuser on Linux Minterface
Moley

@kevinmchapman. The discussion here reflects the very significant number of users who really do like the traditional menu system and who wish to...

19 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

21 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

22 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

23 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

23 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

24 hours ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

1 day ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

1 day ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

1 day ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

1 day ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

1 day ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

1 day ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

2 days ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

2 days ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

2 days ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

2 days ago by Moley on A tale of two distros: Ubuntu and Linux Mint