{"id":1409,"date":"2016-02-12T17:47:17","date_gmt":"2016-02-12T17:47:17","guid":{"rendered":"http:\/\/digitalfire.ucd.ie\/?p=1409"},"modified":"2018-07-18T01:30:33","modified_gmt":"2018-07-18T01:30:33","slug":"open-forensic-devices","status":"publish","type":"post","link":"https:\/\/dfire.ucd.ie\/?p=1409","title":{"rendered":"Open Forensic Devices"},"content":{"rendered":"<p>Cybercrime has been a growing concern for the past two decades. What used to be the responsibility of specialist national police has become routine work for regional and district police. Unfortunately, funding for law enforcement agencies is not growing as fast as the amount of digital evidence.<\/p>\n<p>In this paper, we present a forensic platform that is tailored for cost effectiveness, extensibility, and ease of use. The software for this platform is open source and can be deployed on practically all commercially available hardware devices such as standard desktop motherboards or embedded systems such as <em>Raspberry Pi<\/em> and Gizmosphere&#8217;s <em>Gizmo board<\/em>. A novel user interface was designed and implemented, based on <em>Morphological Analysis<\/em>.<\/p>\n<p>The full paper was published\u00a0in <a href=\"http:\/\/ojs.jdfsl.org\/index.php\/jdfsl\/issue\/view\/44\" target=\"_blank\" rel=\"noopener\">Vol 10, No 4<\/a> of the <a href=\"http:\/\/jdfsl.org\/\" target=\"_blank\" rel=\"noopener\">Journal\u00a0of Digital Forensics, Security and Law<\/a>.<\/p>\n<p><a href=\"http:\/\/bit.ly\/mamaui\" target=\"_blank\" rel=\"noopener\">A demo of the user interface that was developed for this project<\/a>.<\/p>\n<p>The <a href=\"https:\/\/dfire.ucd.ie\/wp-content\/uploads\/2016\/02\/Open_Forensic_Devices__SADFE_2015_.pdf\">PDF of this journal publication<\/a> is available to download.<\/p>\n<h1>Introduction<\/h1>\n<p>The process of acquiring images of hard disks is a well documented and usually straight forward task for a forensic investigator. Still, taking forensically sound images of hard disks is an essential step during investigations involving computer systems.<\/p>\n<p>This paper details a system that provides the same functionality as current forensic hardware at a fraction of the cost. While this platform is presented as a write blocker and imaging device, it is designed to be extended and enhanced. Several example developments are detailed in this paper. This project is an attempt to facilitate the building of forensic devices and to enable forensic investigators to add their own functionality and personalisations.<\/p>\n<p>The novel user interface for this platform is based on ideas from <em>Morphological Analysis<\/em>. This responsive web user interface provides a clean and informed way of presenting forensic tasks to a user.<\/p>\n<h2>Commercial Forensic Devices<\/h2>\n<p>Based on our research, current forensic platforms are expensive, some costing thousands of Euro. While this cost is perfectly reasonable for some organisations and departments, it can be an issue for others.<\/p>\n<h3><em>FIREBrick\u00a0<\/em>System<\/h3>\n<p>The <a href=\"http:\/\/digitalfire.ucd.ie\/?page_id=1011\"><em>FIREBrick\u00a0<\/em>Project<\/a> is an open embedded system based on <em>Linux<\/em> that, in its most basic form, provides write-blocking functionality and provides forensically sound copies of hard disks. The system can be built using almost any motherboard.<\/p>\n<p>The <em>FIREBrick\u00a0<\/em> operating system is a minimal customised <em>Linux<\/em> distribution. As this device is <em>Linux<\/em> based, developers can easily develop and enhance the platform using the wide array of available <em>Linux<\/em> software.<\/p>\n<p>To date, the <em>FIREBrick<\/em> Project has received interest from the computer forensic community. Several investigators and many students from around the world have developed new functionality for the platform. In particular, a number of new features were developed by M.Sc. students from the <em>Digital Investigation and Forensic Computing<\/em> programme in University College Dublin.<\/p>\n<h1>Hardware<\/h1>\n<p>The FIREBrick is constructed using common, cost-effective, commercially available hardware. Configurations of <em>Raspberry Pi<\/em>, <em>Gizmosphere&#8217;s Gizmo<\/em> have been built. The desktop computer based device requires the following hardware:<\/p>\n<ul>\n<li>Motherboard (any form factor)<\/li>\n<li>RAM<\/li>\n<li>Case and power supply<\/li>\n<\/ul>\n<h2>Customised Forensic Device<\/h2>\n<p>As the system is open source, it can be tailored for a specific requirement or specific law enforcement agency. Smaller, less powerful hardware could be used and powered by a battery, or a more computationally powerful system could be built that would be larger and less portable.<\/p>\n<h2>Stand Alone Device<\/h2>\n<p>To demonstrate the configurable nature of the platform, the <em>FIREBrick<\/em> can be configured as a stand alone device, not requiring a host system to operate. This configuration might be suitable for investigators that do not wish to carry around a lot of equipment. An LCD screen can be connected to the <em>FIREBrick<\/em> and a simple menu presented to the user.<\/p>\n<figure id=\"attachment_1411\" aria-describedby=\"caption-attachment-1411\" style=\"width: 328px\" class=\"wp-caption alignleft\"><a href=\"http:\/\/digitalfire.ucd.ie\/wp-content\/uploads\/2016\/02\/1.png\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1411 size-full\" src=\"http:\/\/digitalfire.ucd.ie\/wp-content\/uploads\/2016\/02\/1.png\" alt=\"1\" width=\"328\" height=\"205\" \/><\/a><figcaption id=\"caption-attachment-1411\" class=\"wp-caption-text\">Figure 1. LCD screen FIREBrick device<\/figcaption><\/figure>\n<p>This <em>mini-ITX<\/em> device is shown in Figure 1.<\/p>\n<p>Going further with this minimalist concept, a <em>FIREBrick<\/em> can be configured to automatically begin imaging a disk as soon as the disk is connected to the system, providing an audio alert from the speaker on the motherboard when imaging is complete. An example of this configuration is shown in Figure 2.<\/p>\n<p>These examples have been constructed and are currently being used by forensic investigators. The approximate cost of building a minimalist <em>FIREBrick<\/em> device is shown below:<\/p>\n<ul>\n<li>Mini-ITX Motherboard \u20ac70<\/li>\n<li>2Gb RAM \u20ac10<\/li>\n<li>Case &amp; power supply \u20ac20<br \/>\n<strong>Total\u00a0\u20ac100<\/strong><\/li>\n<\/ul>\n<figure id=\"attachment_1412\" aria-describedby=\"caption-attachment-1412\" style=\"width: 328px\" class=\"wp-caption alignright\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1412 size-full\" src=\"http:\/\/digitalfire.ucd.ie\/wp-content\/uploads\/2016\/02\/2.png\" alt=\"2\" width=\"328\" height=\"229\" \/><figcaption id=\"caption-attachment-1412\" class=\"wp-caption-text\">Figure 2. Minimalistic FIREBrick device.<\/figcaption><\/figure>\n<p>&nbsp;<\/p>\n<h2>Extensible Platform<\/h2>\n<p>The <em>FIREBrick\u00a0<\/em>is based on Linux, thus any <em>Linux<\/em> compatible software is available to <em>FIREBrick<\/em>. Tools such as <em>The Sleuth Kit<\/em>, <em>Android Debug Bridge<\/em> and <em>Photorec<\/em> have been used with the <em>FIREBrick<\/em>. One such configuration of the <em>FIREBrick<\/em> platform added a WiFi device allowing a user to connect via any WiFi compatible device. Another configuration performed write-blocking over <em>iSCSI<\/em>, where the user connected to the <em>FIREBrick<\/em> via an Ethernet cable.<\/p>\n<h3>Mobile Device Acquisition<\/h3>\n<p>As the<em> Android Debug Bridge<\/em> software is available to the <em>FIREBrick<\/em>, it can be configured to acquire information from mobile devices such as phones and tablets. While mobile data acquisition is feasible and has been built, it requires further development to support a wider range of makes and models of mobile devices.<\/p>\n<h3>Purpose Built Devices<\/h3>\n<p>Another configuration of the <em>FIREBrick<\/em> is a network packet capture and analysis device. The <em>FIREBrick<\/em> uses <em>TCPDUMP<\/em> and can be connected to a target network to capture network packets. These packets could be analysed for information gathering, threat detection purposes et cetera.<\/p>\n<h3>Scripting<\/h3>\n<p>Scripting is a powerful way of querying and analysing large data sets. In terms of scripting functionality, <em>FIREBrick<\/em> has been build and tested with <em>Node.js<\/em> and with <em>Python<\/em>. Again, the concept with this platform is to allow developers to add their preferred scripting languages to the platform.<\/p>\n<h1>Software<\/h1>\n<h2>Operating System<\/h2>\n<p>The <em>FIREBrick<\/em> operating system (<em>FIREBrick<\/em> OS) is a custom <em>Linux<\/em> distribution built from the ground up using <em>Buildroot<\/em>. The <em>FIREBrick<\/em> OS may be written to the motherboard BIOS, configured as a boot disk, configured as a boot <em>USB<\/em> key, or via <em>PXE<\/em> booting. It is a lightweight OS, unlike other <em>Linux<\/em> based forensic distributions, it comes with a very minimal set of software packages and comes without superfluous libraries. This has benefits in terms of speed, maintainability and security.<\/p>\n<p>The <em>FIREBrick<\/em> OS may be deployed on many hardware platforms. One example is deploying the OS on a desktop motherboard, where the OS is flashed onto the BIOS. This requires no boot device and the system will never boot from evidential drives. Also, this allows the system to run very quickly and boot almost instantly. There are downsides of this approach, such as, the OS size is limited to the size of the BIOS which is usually relatively small (typically 32Mb). However, a minimal system with write-blocking and imaging capability can easily fit into the BIOS of a desktop motherboard.<\/p>\n<h3>Write Blocking Functionality<\/h3>\n<figure id=\"attachment_1426\" aria-describedby=\"caption-attachment-1426\" style=\"width: 298px\" class=\"wp-caption alignleft\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1426 size-full\" src=\"http:\/\/digitalfire.ucd.ie\/wp-content\/uploads\/2016\/02\/Capture.jpg\" alt=\"Capture\" width=\"298\" height=\"72\" \/><figcaption id=\"caption-attachment-1426\" class=\"wp-caption-text\">Figure 3. Typical FIREBrick deployment.<\/figcaption><\/figure>\n<p>Figure 3 shows a typical configuration of a <em>FIREBrick<\/em> system. The user views and interacts with the target device via an iSCSI initiator, this iSCSI target is read-only and hence the evidential drive cannot be altered in any way. Utilising <em>iSCSI<\/em> provides remote access to the <em>FIREBrick<\/em> device. From the prospective of the <em>FIREBrick<\/em> OS, the target drive is never mounted and data is never written to the drive. The user can also control the <em>FIREBrick<\/em> using the web user interface (WUI). The write-blocking functionality is <em>iSCSI<\/em> in this case, however the system can be configured to write-block via a <em>Firewire<\/em> or via <em>USB<\/em> with supplemental hardware.<br \/>\nImaging utilises the <em>DCFLDD<\/em> dcfldd package, a modified version of <em>GNU<\/em> dd, used frequently by forensic investigators.<\/p>\n<h3>Morphological Analysis<\/h3>\n<p><em>Morphological Analysis<\/em> (MA) is a powerful problem-structuring and problem-solving technique created by Fritz Zwicky. MA works by analysing a problem space, arranging it into tabular form and identifying inconsistencies. Ritchey extended MA using software to aid in the process.<\/p>\n<h3>Morphological Analysis User Interface (<a href=\"http:\/\/bit.ly\/mamaui\" target=\"_blank\" rel=\"noopener\">MAUI<\/a>)<\/h3>\n<figure id=\"attachment_1423\" aria-describedby=\"caption-attachment-1423\" style=\"width: 783px\" class=\"wp-caption alignleft\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1423 size-full\" src=\"http:\/\/digitalfire.ucd.ie\/wp-content\/uploads\/2016\/02\/UIModel.png\" alt=\"UIModel\" width=\"783\" height=\"174\" \/><figcaption id=\"caption-attachment-1423\" class=\"wp-caption-text\">Figure 4. The MAUI interface.<\/figcaption><\/figure>\n<figure id=\"attachment_1420\" aria-describedby=\"caption-attachment-1420\" style=\"width: 772px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1420 size-full\" src=\"http:\/\/digitalfire.ucd.ie\/wp-content\/uploads\/2016\/02\/selectedCapture.jpg\" alt=\"selectedCapture\" width=\"772\" height=\"166\" \/><figcaption id=\"caption-attachment-1420\" class=\"wp-caption-text\">Figure 5. <a href=\"https:\/\/dfire.ucd.ie\/maui\/\" target=\"_blank\" rel=\"noopener\">MAUI<\/a> after selecting &#8220;Capture&#8221; from &#8220;Task&#8221;.<\/figcaption><\/figure>\n<p>This novel user interface, based on MA, was designed to facilitate ease of use and provide a way of guiding the user through tasks. The user interface for one configuration of a <em>FIREBrick<\/em> can be seen to provide an intuitive and helpful way of performing forensic tasks that is quite different to regular menu-driven user interfaces. The web user interface is shown in Figure\u00a04.<\/p>\n<p>This interface provides a way of presenting forensics tasks, of grading them, and of accessing each task in an uncluttered fashion. To explain how MA is used as a user interface, we shall consider a simple example. A <em>SATA<\/em> disk taken from\u00a0a computer is to be imaged. Figure 5\u00a0shows the interface after a user selected Capture from Task.<\/p>\n<figure id=\"attachment_1422\" aria-describedby=\"caption-attachment-1422\" style=\"width: 788px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1422 size-full\" src=\"http:\/\/digitalfire.ucd.ie\/wp-content\/uploads\/2016\/02\/UIDisk.png\" alt=\"UIDisk\" width=\"788\" height=\"175\" \/><figcaption id=\"caption-attachment-1422\" class=\"wp-caption-text\">Figure 7. SATA disk imaging task.<\/figcaption><\/figure>\n<p>We can see here that the value of Saved Image from Data Source is unavailable. This is the case because the two values are inconsistent.<\/p>\n<p>Figure 6\u00a0shows each parameter compared with every other parameter. This facilitates the identification of inconsistent pairs of values.<br \/>\nThis information would not be available to the user as it is hard-coded into the interface and represents the logic driving the interface. We can see that <em>Capture<\/em> and <em>Saved Image<\/em> are identified as inconsistent (highlighted in Figure 6). This is so because a saved image cannot be captured, a saved image is already captured. Similarly, <em>View<\/em> and <em>Off<\/em> are inconsistent. A system cannot be viewed that has been turned off for a reasonable amount of time.<\/p>\n<p>At this point, <em>Computer<\/em> from <em>Data Source<\/em>, <em>Disk<\/em> from<em> Data Location<\/em> and <em>Off<\/em> from <em>System State<\/em> are selected. Now the impact on the system would be shown. Once <em>None<\/em> in <em>System<\/em> <em>Impact<\/em> is selected, the task is initiated. The penultimate step can be seen in Figure 7. Parameter values can be chosen in any order. However, all parameters must have a value chosen in order to initiate a task. Once all values are selected, a confirmation dialog box will be displayed.<\/p>\n<p>Using MA as an interface presents forensic tasks to the user, but also provides more information about the tasks to the user. In our example, it allows the user to see the level of system impact the selected task has on the target system. In this example we saw that there was an impact of None, as the disk was taken from the computer and nothing will be written to the disk.<\/p>\n<figure id=\"attachment_1421\" aria-describedby=\"caption-attachment-1421\" style=\"width: 601px\" class=\"wp-caption alignnone\"><a href=\"http:\/\/digitalfire.ucd.ie\/wp-content\/uploads\/2016\/02\/UICCA.png\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1421 size-full\" src=\"http:\/\/digitalfire.ucd.ie\/wp-content\/uploads\/2016\/02\/UICCA.png\" alt=\"UICCA\" width=\"601\" height=\"402\" \/><\/a><figcaption id=\"caption-attachment-1421\" class=\"wp-caption-text\">Figure 6. Identified inconsistent forensic tasks.<\/figcaption><\/figure>\n<p><em>MAUI<\/em> is arranged in a way to show the full spectrum of tasks available to the user in an uncluttered\u00a0and transparent way. There are no nested menus and no extra options as all available tasks are presented to the user. This compact interface is also suitable for mobile devices that have limited screen sizes.<\/p>\n<h1>Results<\/h1>\n<p>In this paper we have detailed a forensic platform that provides the same functionality as commercial forensic devices, at a fraction of the cost. This platform is presented as both a hardware and software platform, the software is similar in some ways to forensic <em>Linux<\/em> distributions such as SANS Investigative Forensic Toolkit or <em>CAINE<\/em>, however the <em>FIREBrick<\/em> OS is built from the ground up. The software only contains what is absolutely necessary to provide forensic functionality. As such, the <em>FIREBrick<\/em> software is well suited for use with embedded hardware.<\/p>\n<h2>Performance<\/h2>\n<p>As the choice of hardware for the <em>FIREBrick<\/em> device is open-ended, performance can vary quite substantially. For the <em>FIREBrick<\/em> device in Figure 1, speeds of 5GB\/min were obtained while imaging a <em>Kingston SSDNOW SERIES V100<\/em>\u00a0SSD drive. Throughput would increase for faster SSD drives and would decrease for slower platter-based drives. The specifications for commercial forensic imaging devices detail speeds ranging from 4GB up to 15GB. These figures have not been verified by the authors of this paper.<\/p>\n<h2>User Interface<\/h2>\n<p>The <a href=\"https:\/\/dfire.ucd.ie\/maui\/\" target=\"_blank\" rel=\"noopener\"><em>MAUI<\/em> user interface<\/a> designed for this project is based on principles from <em>Morphological Analysis<\/em>. This novel user interface provides a clean and informed way of presenting forensic tasks to a user.<\/p>\n<h2>Extensibility<\/h2>\n<p>One of the overall goals of the <em>FIREBrick<\/em> project is to encourage developers to extend the functionality of the platform. Areas of computer forensics such as mobile device acquisition, computer network analysis and file carving could benefit from having an open, stable, extensible device.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cybercrime has been a growing concern for the past two decades. What used to be the responsibility of specialist national police has become routine work for regional and district police. Unfortunately, funding for law enforcement agencies is not growing as fast as the amount of digital evidence. In this paper, we present a forensic platform [&hellip;]<\/p>\n","protected":false},"author":10,"featured_media":1417,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[30,60,63],"tags":[],"class_list":["post-1409","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-windows-forensics","category-hardware","category-morphological-analysis"],"_links":{"self":[{"href":"https:\/\/dfire.ucd.ie\/index.php?rest_route=\/wp\/v2\/posts\/1409"}],"collection":[{"href":"https:\/\/dfire.ucd.ie\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dfire.ucd.ie\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dfire.ucd.ie\/index.php?rest_route=\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/dfire.ucd.ie\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1409"}],"version-history":[{"count":8,"href":"https:\/\/dfire.ucd.ie\/index.php?rest_route=\/wp\/v2\/posts\/1409\/revisions"}],"predecessor-version":[{"id":1510,"href":"https:\/\/dfire.ucd.ie\/index.php?rest_route=\/wp\/v2\/posts\/1409\/revisions\/1510"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dfire.ucd.ie\/index.php?rest_route=\/wp\/v2\/media\/1417"}],"wp:attachment":[{"href":"https:\/\/dfire.ucd.ie\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1409"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dfire.ucd.ie\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1409"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dfire.ucd.ie\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1409"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}