Showing posts with label hardware. Show all posts
Showing posts with label hardware. Show all posts

Tuesday, May 1, 2007

Forensic Lab Update

We received the computers for the lab and I already set them up. Now, we need to add a network switch in the room so that each computer can communicate with each other. Once the switch is in place, we can share the hard drives from each computer to allow easy file transfers among the machines.

Although there are three computers, we are only using two monitors. We have the two LCD monitors that came with the new PCs and two huge CRT monitors. However, due to limited space, we removed the CRT monitors from the room. Instead, we are using a KVM switch for two of the computers. We also need to get the forensic server up. I am trying to get all of this set up as soon as possible because it will be put to the test soon!

Some companies in the private sector do some things to impress a client such as running simulated processes on multiple screens. It's all for show. However, the public sector is different. There are no clients to impress. Sometimes, we need to work with what we have and aim for functionality. That's not to say that labs in the public sector are not impressive. I have seen some very nice labs from the state and federal government.

Saturday, April 28, 2007

Forensic Network

Our plan is to have a forensic network separate from the agency's network. The forensic network should not have any connection to the Internet. This is to prevent any chance of outside access to the evidence. We have three forensic machines and one forensic server. The forensic server will be used to store the case files and images we acquire. It is still best to work on the images locally. Therefore, we would copy the images to our local machines, examine the data, and then upload the case files and report to the server. This has many advantages. First, instead of storing different cases on each forensic machine, we have one centralized location. This allows each machine to have access to all cases from the server. Second, we can archive each case more easily. The standard cables we use are cat5e. For faster access, we may switch to fiber optic, but this is more expensive.

We want to make the lab more efficient for investigators and let them focus only on examinations. They do not need to worry about running out of space or backing up the evidence. The agency's IT staff or forensic technicians can take care of this. If the forensic server is located in the data center, it can be maintained accordingly.

For convenience, it would be nice to have a machine with internet connection next to the forensic machines so that the investigator can use the Internet for reference, get software updates (and transfer it to a forensic machine to install), look for assistance on forums, and check emails.

One more thing I like to do is to remote into the other forensic machines from my forensic machine, and do work on each one from one location. Then I can easily check up on each, without having to get up and look at each screen.

Thursday, April 19, 2007

Computer Forensics Hardware

Although our forensic machines are capable of performing multiple tasks such as wiping, duplicating, and archiving data, dedicated hardware can make our lab more efficient. While we cannot currently afford any of these equipment, we are trying to get the money to do so. These are some of the equipment that I have experience using and will recommend to my supervisor.


Wiping:
Wiping a drive can take several minutes or hours to wipe each, depending on size and method used. If we were wiping one drive at a time, we can spend a whole day wiping drives on a machine that could have otherwise been use for investigations. For wiping multiple drives, I would use Logicube's Omniclone 5Xi.

This model has six bays, one for the master drive, and five for the drives to be wiped. It also has other capabilities, such as copying, although I am not certain that it does forensic copies. The light bar, which resembles a stop light, notifies the technicians when it is functioning properly (green), waiting for a response (yellow), or an error occurred (red). The good thing about this is that we can wipe multiple drives, walk away, come back, and check up on it. It also does not tie down our forensic machines. We usually wipe drives of the same size so that they all finish at the same time. For much larger drives, we wipe them overnight (to not tie down the Omniclone itself) and come back the next day.


Duplicating:
We always create forensic duplicates of the original evidence, and usually do so in EnCase or FTK Imager. However, there are times when we have to go outside the lab to perform an acquisition. It would be impractical to take our lab machines with us to the scene. Therefore, we usually rely on a mobile solution. This can include a laptop in a briefcase, with the forensic software installed. However, I prefer to use Logicube's Forensic Talon.

The source (evidence drive) goes outside, destination (forensic copy) inside. Within a few minutes, we can have it set up and creating dd images. We bring the copies back to our lab, and can either convert them to EnCase images, which are compressed to save space, or just add the images directly into the case. Because dd images are not compressed, and we don't know the size of the evidence drive to begin with, we usually carry high capacity hard drives. Also, the destination drive inside the case can get really hot, so we keep the Talon open when acquiring.


Archiving:
Image files are usually placed on our forensic servers and take up space when they are no longer needed. Once a case becomes inactive, we need to archive it. If it is a large case, we usually archive to tape. However, many cases are small enough to fit on DVDs. Currently, we are using one of our forensic machine to burn these files to DVD. However, this manual task can get tedious. First, we have to make sure the files all fit in one DVD. If not, we must manually split them. Then, once each DVD is done, we must manually remove one DVD and put the next one in and repeat the process. This wastes the investigator's time and the machine used to burn the DVDs. A better method is to use an automated machine. I have had good experience with Primera's Optivault Archival Appliance.

This robot uses the Retrospect backup software that lets you archive, backup, and restore files to DVDs and other media. The best part of this machine is that it is pretty much a start and forget system. Once we archive a case, the machine will take care of burning the files, switching DVDs, printing labels, and verifying that files were copied correctly. This minimizes both human and CPU time.

We usually create two sets per case. One is sent to a remote location and one stays in-house. This is so that we can restore the case if necessary and can get the second backup if something is wrong with the first.