With this blog post I am pleased to announce the publication of a new ERNW White
Paper about our incident analysis and digital forensics framework. It is
available on our website.
Due to the increasing number and impact of computer security incidents, it has
become essential to develop and implement efficient measures for their
investigation. However, comprehensive forensic analyses are time-consuming, and
this time is often not available to security analysts during computer security
incidents. As a result, automated tools are increasingly being used. These
tools, however, often cover only a limited scope of the necessary analyses and
typically require deep technical expertise to be used effectively.
Last week I gave a talk at #TROOPERS26:
Integrating Incident Analysis and Digital Forensics Tooling for Automated Compromise Detection.
I discussed the challenges of incident analysis, such as increasing storage
capacities and the lack of integration between tools. I presented a modular
framework that integrates established forensic and analysis tools using a
decision-tree-based control mechanism. A workflow was designed to control the
execution of 14 integrated analysis tools in order to reproduce the manual
analysis process usually performed by analysts. Moreover, the framework is
capable of identifying whether a system has been compromised and compiles a
analyst-oriented report. Together with the audience we took a look at the report
in a live demonstration. The evaluation results of the framework were promising
as it was able to identify all compromised systems. However, a significant
number of false positive classifications were also observed. To improve the
framework possible future extensions include functionality such as recovering
already deleted files to detect missed Indicators of Compromise. Additionally,
our team want to integrate artificial intelligence in the workflow to help in
data processing and make more decisions automatically. The slides will be
published next week on the conference website. I will add the link in this blog
post when they become available. A more detailed description of the content of
the talk can be found in the following sections. Looking forward to
#TROOPERS27!