官术网_书友最值得收藏!

Log-based evidence

In the previous chapter, we looked at various network protocol captures that define evidence in motion or data captured while in action. However, it is crucial for a network forensic investigator to have a brief knowledge of the various types of logs generated at the endpoints while traveling. These logs prove to be extremely handy when the scenario doesn't contain network captures, and it is up to the investigator to deduce and conclude the forensic investigation and reach a definitive result. Consider a situation where a company named Acme Inc. has faced a massive breach of customer data through its website, and the company hasn't kept any packet-capture files for the incoming data. In such cases, the forensic investigation solely relies on the logs generated at various endpoints, such as application servers, databases, and firewalls, as shown in the following diagram:

In the preceding scenario, we can see that the attacker has attacked an externally-hosted application server, which makes a connection to an internal network for database access that has limited connectivity to the external world, except for the application server.

In such scenarios, the following set of questions needs an answer:

  • How was the attacker able to penetrate the application server?
  • Why did the firewall allow access to the external attacker?
  • What set of queries did the attacker execute on the database?
  • Did the attacker alter the database?
  • Can we identify the origin of the attack?

To answer the preceding questions, we will require access to the logs of the external application server, and since the firewall permitted access to the attacker, we will need access to the firewall logs. The attacker executed queries on the database. Therefore, we will expect access to the database logs as well.

主站蜘蛛池模板: 尼木县| 江安县| 额敏县| 蒲江县| 旌德县| 和龙市| 黄山市| 阿合奇县| 黄梅县| 望江县| 天长市| 富锦市| 麻江县| 上高县| 彩票| 慈溪市| 于田县| 宜兰市| 台湾省| 丹江口市| 宜昌市| 正宁县| 遂平县| 句容市| 林西县| 广元市| 吕梁市| 嘉善县| 东兰县| 潞西市| 湾仔区| 武夷山市| 定兴县| 南木林县| 桦南县| 岳阳市| 安平县| 卢龙县| 民权县| 土默特左旗| 枝江市|