Network forensics and the inside job

Simon A Perry · Network Security · 2006

Internal threats cost millions more every year than losses from viruses or spyware. Regulatory requirements usually involve demonstrating strong capabilities around incident investigation and remediation of internal threats. Enter network forensics. Investigating attacks and incidents is by no means entirely ‘new news’ to the IT security industry. What is new is that more companies are now taking a more detailed and disciplined approach to security investigations to the extent that they may be more accurately termed ‘forensics investigations’. But barriers routinely pop up. For instance, Microsoft Vista adds a new dimension by encrypting the disk by default. Mirroring a computer disk is often the most obvious way to conduct a forensics investigation, but encryption of disk content will make this approach very difficult with Vista. Furthermore, the skills required to conduct investigations have until now been lacking. According to recent studies undertaken by the FBI and Computer Security Institute, 80% of network attacks are instigated by authorised users and not by an external hacker. How can network forensics help uncover the inside job?

Read the paper · More papers on PaperTik