by Sam Stover

Guidance merges incident response with forensics

Reviews
Oct 17, 20058 mins

EnCase Enterprise 5 from Guidance expands into incident response realm.

Guidance Software’s most recent release of EnCase Enterprise puts incident-response capabilities into the IT security manager’s toolbox. In our Clear Choice Test, we found that with this aggregation of incident-response and forensic capabilities not yet seen in competing products, EnCase Enterprise can (for a pretty big price tag) help a network investigator establish relationships between open ports, open files, network connections, hidden files or processes and malicious network activity.


Tapping IDS for automated incient response

Archive of Network World tests

Subscribe to the Network Product Test Results newsletter


Unix and Linux administrators are always going to have tools/utilities such as lsof (list open files), netstat (list open ports and more), bvi (binary file editing) and a bevy of other (even more capable) incident-response tools. However, that approach is limited in a corporate environment by the effort required to coordinate these disparate tools.

Imagine that your network intrusion-detection system (IDS) generates an alert that shows traffic to Port 2222 on your Web server. Then, seconds later, your host-based IDS for that same machine generates an alert showing that the kernel has been modified. Then you have to access the box via a Secure Shell (SSH) connection (or traipse to the building where the box physically sits to use the console) and start nosing around to see what is going on.

With EnCase Enterprise, you receive the IDS alerts, swivel your chair to a different console and pull that same information – all transparent to the potential attacker who could be watching for a root logon via local or SSH connection. While there is a bit of a learning curve to complete some complex forensic investigation, getting started with basic functions such as checking for open ports, running processes and suspicious files (plus any relationship between them) is rather easy.

There are three parts to the EnCase Enterprise system: the Secure Authentication for EnCase (SAFE), the Enterprise Examiner GUI front end and the Servlet agent software.

SAFE takes care of all authentication processes. Each user is assigned a profile in the SAFE that defines what resources he can access.

The Examiner GUI – EnCase Enterprise’s bread and butter from a security analysis point of view – bears a striking resemblance to the interface of the more law enforcement- focused EnCase Forensic edition. Overall, the GUI lets you navigate easily between the parameters you’ve established and the detailed file or port and process information you’ll need to investigate.

Lastly, Servlet agents run on monitored boxes and communicate with the Examiner. This agent works at a basic level in the operating system and allows the analyst access to detailed information about the host. The Servlet is completely reactive; ir presents information to the Examiner only when queried. It has almost no effect on the host’s performance, unless an investigator is taking action.

A primary tenet of incident response built into EnCase Enterprise is the ability to remove from consideration, as fast as possible, the “known good,” be it ports, files, processes, log entries or even registry entries. The faster an analyst can filter through what is known and focus on what is unknown, the shorter the investigation time. In some enterprise environments, IDS alerts can easily number in the tens of thousands each day. In most cases, at least a token investigation beyond the information provided by the IDS is required to determine whether the event is a false positive or warrants further attention. The easier it is for an analyst to make this decision, the more efficient the entire system becomes. EnCase Enterprise is capable of providing the information an analyst needs to make such a decision.

The three main mechanisms for sorting out the unknown information are Filters, EnScripts and Conditions. Guidance provides defaults for each of these, but the user can add more.

We found EnCase Enterprise filters to be very basic, handling file permissions, deleted files and specific types of Web pages.

How we did it
The SAFE was installed on a dual-Xeon Dell Precision with 1G byte RAM running Windows 2003 Server Enterprise. The Examiner was installed on a Pentium IV Dell Dimension with 1G byte RAM running Windows XP Professional. The target machines examined were a mix of Windows 2000 Server, Windows XP Professional, RedHat 9.0 and RedHat Fedora Core 3. All systems were connected via Linksys 10/100M bit/sec hub. Different aspects of the incident response functionality of EnCase Enterprise were exercised after installing both rootkits (Hacker Defender and FU) and command and control (Optix) programs. As the greater functionality of EnCase Enterprise focuses on Windows for detecting these types of tools, the majority of testing was done with Windows targets.

EnScript is a proprietary language that lets you build code for complex activities, such as collecting data from the Servlet, initializing databases and setting up filter combinations. The name of the EnScript that polls data from the Servlet is Enterprise Sweep. By default, it captures only port, file, process and physical system information. However, the user is presented with approximately 25 optional modules for data collection that can be selected. For example, in our tests we retrieved log files for Windows and Linux via the Windows Event Log Parser and Linux SysLog Parser, respectively.

Conditions is unique to EnCase Enterprise and provides a way to combine multiple filters to define a single criterion. This mechanism lets users to create EnScript capabilities without having to learn the language. For example, the “hidden process” condition is not provided by default, but you can create one without knowing EnScript. While we did not find this process to be very intuitive at first, it will prove easier to learn than the EnScript language, especially for non-programmers.

Another way to filter out known good files is the Application Descriptor listing. This lets users build a list of all known good files and their attributes – namely, file names and hash values. This capability could be useful in an environment with a standard configuration. All known good files could be profiled, and a quick look at the Application Descriptors search results would show only unknown files, making it easier for an investigator to see whether new files had been installed.

Another feature we found interesting is the ability to search for common files and process-hiding techniques available with most rootkits. Hidden ports cannot be found in the current release, but this is slated for the next release set for mid-2006.

An aggressive feature is the ability to remediate a specific problem. EnScripts can be built to kill processes and delete files. In our test labs, we loaded up the FU rootkit, then killed the process and verified that the rootkit was no longer functioning. This activity is not suitable for every occasion, but the capability exists.

Guidance Software is expected to release an add-on tool to EnCase Enterprise that will integrate with IDSs and help automate certain initial investigative steps.

NETWORK FORENSIC TOOLS
ENCASE ENTERPRISE 5 OVERALL RATING
4.25
Company: Guidance Software Cost: $85,000 (as tested) for 1 SAFE, 1 Examiner, 1 user and 3 concurrent connections. Pros: Good aggregation of Incidence Response tools; Servlet agent has minimal impact on host; EnScript language is very capable, provides good cross-OS platform for IR. Application Descriptor capability is very powerful once populated. Cons: Building Conditions is not very intuitive; steep learning curve for EnScript; hard to integrate home-grown scripts.
The breakdown   

Features 40%

4
Performance 25% 5
Administration/ease of use 25% 4
Installation/documentation 10% 5
TOTAL SCORE  4.25
Scoring Key: 5: Exceptional; 4: Very good; 3: Average; 2: Below average; 1: Consistently subpar

Remote-media acquisition, such as a hard drive from a system in a different building, is possible, but probably not practical, considering hard drive sizes today. Consider trying to get an image of a 120G-byte hard drive at a remote site connected via T1.

Overall, EnCase Enterprise provides an easy way to mount incident-response investigations from a centralized console. The default resources should provide basic investigative information out of the box, but adding custom Conditions is not very intuitive. Seasoned incident response personnel could become frustrated when trying to port homegrown, data-gathering shell/python/perl scripts into Conditions or EnScripts.

Is EnCase Enterprise a silver bullet for all incident-response issues? Certainly not, but it is a tool that could make it easier to do a quick litmus test of whether an incident requires further attention. Eventually, IDS integration should make this even more efficient.

Stover is the director of testing and evaluation at the Advanced Technology Research Center at Lockheed Martin IT. He can be reached at sam.stover@gmail.com.