Computer Security and Cyber LawUnit 913 min read
Digital Forensics & Incident Response: Processes, Tools & Legal Frameworks
Unit 9 of Computer Security and Cyber Law explores digital forensics principles, incident response workflows, forensic investigation procedures, and legal considerations for evidence handling in cybercrime cases—with real-world applications in Nepalese e-governance and financial systems.
TAKEAWAYS:
- Digital forensics is the scientific acquisition, preservation, and analysis of digital evidence for legal proceedings, following strict chain-of-custody protocols.
- Incident response follows a 4-phase lifecycle (Preparation → Detection & Analysis → Containment → Eradication & Recovery) to minimize cyberattack damage.
- Forensic tools like FTK Imager, Autopsy, and Wireshark extract evidence from disks, logs, and network traffic without altering data.
- Legal admissibility requires evidence to be authentic, complete, reliable, and obtained lawfully under Nepal’s Electronic Transaction Act (2008) and Cyber Security Act (2018).
- Common attack scenarios (e.g., ransomware, phishing) demand tailored forensic responses, from memory dumps to malware analysis.
- Human factors (e.g., insider threats, social engineering) often trigger incidents, requiring behavioral forensics alongside technical investigations.
Core Concepts: What Is Digital Forensics?
Digital forensics is the application of scientific methods to identify, collect, examine, and present digital evidence in a legally defensible manner. Unlike general IT troubleshooting, forensic analysis:
- Preserves evidence integrity (no modification of original data).
- Follows legal standards (e.g., Nepal’s Electronic Evidence Act, 2075).
- Covers all digital media: disks, RAM, mobile devices, cloud storage, and even IoT sensors.
The Forensic Process: A Step-by-Step Workflow
Key Terms:
- Chain of Custody: Unbroken record of evidence handling (who, when, how).
- Write Blockers: Hardware/software to prevent accidental data modification during acquisition.
- Hashing: Cryptographic verification (e.g., MD5, SHA-256) to detect tampering.
Real-World Example 1: eSewa’s Fraud Investigation
Scenario: In 2022, eSewa detected unauthorized transactions from a user’s account. The forensic team:
- Preserved the user’s transaction logs and server logs using write-blocked drives.
- Collected RAM dumps to check for memory-resident malware (e.g., keyloggers).
- Analyzed network traffic with Wireshark to trace the attacker’s IP (found to be a sim-swapping attack).
- Reported findings to Nepal Police’s Cyber Crime Unit, leading to the arrest of a money mule in Kathmandu.
Forensic Tool Used:
Wireshark filtering for suspicious DNS requests (e.g., `bank.com` → `malicious-ip`). (Image: Oluwatobi TJ, CC0, via Wikimedia Commons)
Incident Response: The 4-Phase Lifecycle
Incident response (IR) is the structured approach to detect, contain, and recover from cyber incidents. Nepal’s Nepal Computer Emergency Response Team (NPCERT) follows this model for national critical infrastructure (e.g., NTC, NEPSE).
Phase 1: Preparation
- Assets: Inventory all systems (e.g., Ncell’s SS7 signaling servers).
- Policies: Define incident response teams (IRT) and escalation paths (e.g., Daraz’s security operations center).
- Tools: Deploy SIEM systems (e.g., Splunk) for log correlation.
Phase 2: Detection & Analysis
Example: Pathao’s ride-hailing app detected a DDoS attack during Dashain 2023.
- Indicators:
- Sudden spike in API calls (10,000+ requests/sec).
- Unusual geolocation (traffic from Russia → Kathmandu).
- Tools:
- Snort (IDS) flagged malicious packets.
- Autopsy analyzed driver app logs for data exfiltration.
Phase 3: Containment
Strategies:
| Containment Type | Example (Nepal) | Risk |
|---|---|---|
| Isolation | NEPSE suspended trading during a hack attempt | Market volatility |
| Rate Limiting | Khalti blocked suspicious IPs | Legitimate users affected |
| Patch Deployment | NTC updated routers after a zero-day exploit | Downtime |
Phase 4: Eradication & Recovery
- Root Cause: Pathao’s attack was a misconfigured AWS S3 bucket (exposed driver data).
- Actions:
- Removed backdoor scripts from the app’s backend.
- Restored data from immutable backups.
- Retrained staff on secure coding (OWASP Top 10).
Forensic Investigation Procedures
Step 1: Evidence Acquisition
Methods:
- Bitstream Imaging: Exact copy of a disk (e.g., using FTK Imager).
- Log Analysis: Windows Event Logs, Linux
/var/log/, or SIEM alerts. - Memory Dump: Capture RAM contents (e.g., Volatility Framework) to find malware.
Worked Example: Bank Loan Fraud in Nepal Scenario: A customer reported unauthorized loan approvals from a bank’s online portal. Forensic Steps:
- Acquired the bank’s web server logs (Apache/Nginx).
- Compared hashes of the original loan application vs. the submitted file (found a PDF metadata tampering).
- Traced the attacker’s VPN exit node to a cybercafé in Lalitpur.
Step 2: Evidence Analysis
Tools & Techniques:
| Tool | Purpose | Example Use Case |
|---|---|---|
| Autopsy | GUI-based disk analysis | Recover deleted chat logs from a WhatsApp Business account |
| Wireshark | Network protocol analysis | Capture phishing emails in transit |
| The Sleuth Kit | File system analysis | Find hidden partitions on a hard drive |
| Guymager | Mobile forensics (Android/iOS) | Extract call logs from a stolen phone |
Step 3: Reporting & Legal Admissibility
Nepal’s Legal Requirements:
- Electronic Transaction Act (2008): Evidence must be unaltered and authenticated.
- Cyber Security Act (2018): Forensic reports must be signed by a certified examiner.
- Criminal Procedure Code: Digital evidence must be presented in court with a chain of custody.
Example Report Structure:
**Case**: Unauthorized Access to Ncell Customer Database
**Evidence**:
- **Disk Image**: MD5: `a1b2c3...` (original vs. copy match)
- **Logs**: `auth.log` shows brute-force attempts from IP `192.168.1.100`
- **Network Capture**: Wireshark PCAP with **SQL injection payload**
**Conclusion**: Attacker used **credential stuffing** via a **compromised VPN**.
**Recommendations**:
1. Enforce **MFA** for all admin accounts.
2. Deploy **WAF** to block SQLi attempts.
Digital Forensics vs. Incident Response: Key Differences
| Aspect | Digital Forensics | Incident Response |
|---|---|---|
| Primary Goal | Legal evidence for prosecution | Minimize damage during an attack |
| Timeline | Post-incident (after the fact) | Real-time (during the incident) |
| Key Tools | FTK, Autopsy, EnCase | SIEM, Snort, Firewalls |
| Legal Focus | Admissibility in court | Compliance (e.g., GDPR, IT Act) |
| Example in Nepal | Investigating Khalti hack (2021) | NTC’s response to a DDoS attack |
In the Real World
eSewa’s Anti-Fraud Forensics
- Idea Used: Transaction log analysis + RAM forensics.
- How: When a user reported a fake payment, eSewa’s team used Volatility to check for memory-resident keyloggers and Autopsy to recover deleted transaction records from the server’s hard drive.
- Outcome: Identified a malware-infected POS terminal in a local shop.
Ncell’s SIM Swap Defense
- Idea Used: Network traffic forensics (SS7 protocol analysis).
- How: After a surge in SIM swap fraud, Ncell deployed deep packet inspection (DPI) to detect unusual IMSI catcher activity. Forensic analysis of base station logs revealed rogue towers in Thapathali.
- Tool: Erlang/OTP (for analyzing Ericsson switches).
NEPSE’s Trading System Breach
- Idea Used: Database forensics (SQL transaction logs).
- How: During a 2023 hack attempt, NEPSE’s forensic team:
- Restored the database from WAL (Write-Ahead Log) backups.
- Analyzed
pg_stat_activityto find the malicious SQL query:UPDATE users SET balance = balance + 1000000 WHERE user_id = 12345;
- Tool: pgForensics (PostgreSQL forensic toolkit).
Common Attack Scenarios & Forensic Responses
| Attack Type | Forensic Clues | Tools | Nepalese Example |
|---|---|---|---|
| Ransomware | Encrypted files, ransom note, process logs | FTK, Volatility | 2022 Kathmandu Hospital attack |
| Phishing | Malicious email headers, logins from new IPs | Mimecast, Email Header Analyzer | Khalti phishing scam (2021) |
| Insider Threat | Unusual access times, data exfiltration | Splunk, User Behavior Analytics | Bank employee leaking customer data |
| DDoS | Spiked bandwidth, source IP spoofing | Wireshark, Snort | Pathao Dashain outage (2023) |
Exam Tip
How This Unit Is Tested in TU Exams:
Definition-Based Questions (10 marks)
- Expected: Define digital forensics, chain of custody, or incident response plan.
- Tip: Use one-sentence definitions with legal context (e.g., "Digital forensics is the legally sound collection of digital evidence under Nepal’s Electronic Evidence Act, 2075").
Procedure Explanation (15 marks)
- Expected: Explain steps of a forensic investigation or incident response phases.
- Tip: Use the mermaid flowchart above and link to real tools (e.g., "In Phase 2, Wireshark is used to analyze network traffic, as seen in Pathao’s DDoS case").
Scenario-Based Questions (20 marks)
- Expected: Analyze a given scenario (e.g., "A bank’s ATM system was hacked. Describe the forensic steps to recover evidence.").
- Tip:
- Start with evidence preservation (write blockers).
- Mention specific tools (e.g., "Autopsy to recover deleted transaction logs").
- End with legal compliance (e.g., "Ensure the chain of custody is documented per the Cyber Security Act, 2018").
Tool Comparison (10 marks)
- Expected: Compare FTK vs. Autopsy or Snort vs. Suricata.
- Tip: Use a table (like the one above) with Nepal-relevant examples.
Common Pitfalls to Avoid:
- Ignoring legal frameworks: Always tie answers to Nepal’s IT Act, Cyber Security Act, or Electronic Evidence Act.
- Overlooking human factors: In insider threat cases, mention behavioral analysis (e.g., "Unusual late-night logins").
- Assuming all evidence is digital: Include physical forensics (e.g., "Examining a stolen USB drive’s serial number").
Quick Revision Checklist
Before the exam, ensure you can: ✅ Explain the 6 steps of digital forensics with tools for each step. ✅ Draw the incident response lifecycle and label Nepal-specific examples. ✅ Describe how to handle a ransomware attack forensically (from isolation to recovery). ✅ List 3 forensic tools and their use cases in Nepal (e.g., Autopsy for Khalti fraud cases). ✅ Explain why a forensic image must be hashed (using MD5/SHA-256). ✅ Name 2 Nepalese laws governing digital evidence and 1 real case they applied to.
Based on the TU BITM syllabus for Computer Security and Cyber Law (IT225), unit 9.
Discussion
Loading…