NIST guide to forensics in incident response

Opinion
Oct 3, 20063 mins

* NIST publication gives guidance on integrating forensics into incident response

As I mentioned in previous columns, there’s a new set of draft documents from the Computer Security Resource Center of the National Institute of Standards and Technology (NIST). In addition, SP 800-86, “Guide to Integrating Forensic Techniques into Incident Response” by Karen Kent, Suzanne Chevalier, Tim Grance and Hung Dang has reached final-version stage. The PDF file is available for download.

The document has the following structure:

1. Introduction

2. Establishing and Organizing a Forensics Capability

3. Performing the Forensic Process

4. Using Data from Data Files

5. Using Data from Operating Systems

6. Using Data From Network Traffic

7. Using Data from Applications

8. Using Data from Multiple Sources

Highlights of the recommendations as shown in the Executive Summary include:

* “Organizations should ensure that their policies contain clear statements addressing all major forensic considerations, such as contacting law enforcement, performing monitoring, and conducting regular reviews of forensic policies and procedures.”

* “Organizations should create and maintain procedures and guidelines for performing forensic tasks, based on the organization’s policies and all applicable laws and regulations.”

* “Organizations should ensure that their policies and procedures support the reasonable and appropriate use of forensic tools.”

* “Organizations should ensure that their IT professionals are prepared to participate in forensic activities.”

The 121-page document includes a set of appendices that includes a collection of all the major recommendations (Appendix A, 4 pages).

Appendix B will be useful to everyone but particularly so to educators who use the document in awareness, training and education exercises: it consists of a list of proposed discussion points and a number of interesting scenarios to help workshop participants apply their new knowledge. The questions are as follows (quoting directly):

1. What are the potential sources of data?

2. Of the potential sources of data, which are the most likely to contain helpful information and why?

3. Which data source would be checked first and why?

4. Which forensic tools and techniques would most likely be used? Which other tools and techniques might also be used?

5. Which groups and individuals within the organization would probably be involved in the forensic activities?

6. What communications with external parties might occur, if any?

7. From a forensic standpoint, what would be done differently if the scenario had occurred on a different day or at a different time (regular hours versus off-hours)?

8. From a forensic standpoint, what would be done differently if the scenario had occurred at a different physical location (onsite versus offsite)?

The scenarios are as follows:

1. Possible DDoS Attack

2. Online Payment Problems

3. Unknown Wireless Access Point

4. Reinfected Host

5. Mistaken Identity

6. Unwanted Screen Saver

7. Phishing Attempts

8. Encrypted Files

For example, Scenario 1 begins as follows:

“On a Saturday afternoon, external users start having problems accessing the organization’s public Web sites. Over the next hour, the problem worsens to the point where nearly every attempt to access any of the organization’s public Web sites fails. Meanwhile, a member of the organization’s networking staff responds to automatically generated alerts from an Internet border router and determines that much of the organization’s Internet bandwidth is being consumed by an unusually large volume of User Datagram Protocol (UDP) packets to and from both of the organization’s public Domain Name System (DNS) servers.”

Each scenario has additional specific questions; for example Scenario 1 continues with these questions:

1. How would the forensic activity change if the DDoS attack appeared to be coming from a network in a different state? In a different country?

2. How would the forensic activity change if the DDoS attack appeared to be coming from a business partner’s network?

SP 800-86 will be an excellent resource for all computer-incident response team planners.