Threat Hunting for Digital Forensic Using GRR Rapid Response with NIST Framework
Chalerm Klinkhamhom, Pongsarun Boonyopakorn · 2022
There are presently a huge number of internet users. Conventional security systems such as Firewall and IDS/IPS might not be enough to secure the system so far as those cannot detect the cyber-attack timely. Moreover, the attacker has more complicated tools and methods resulting in continuously growth in cyber criminality. This paper presents the use of a digital forensic process on a computer system following standards of NIST framework SP800-86 to analyze, track, and inspect incidents caused by the cyber-attack systematically and effectively. It demonstrated a use of a forensic tool called GRR rapid response framework which is a remote live forensic, convenient, and fast tool for digital forensic investigation. It works based on client-server which collects and analyzes digital evidence via web interface. The paper validated efficiency to detect cyber-attack of the framework in different network environments. Three types of attacks were imitated in this paper including DDos, Memory, and Target application in 3 different network environments which covered server zone, user zone and wireless zone. The result revealed that the GRR rapid response framework showed the highest percentage of incident response to DDos at 100% when the attack took place on all three network zones. Whereas Memory attack showed second-most significant incident response followed by Target Application attack.