IT225 Computer Security and Cyber Law

Computer Security and Cyber LawUnit 913 min read

Digital Forensics & Incident Response: Processes, Tools & Legal Frameworks

Unit 9 of Computer Security and Cyber Law explores digital forensics principles, incident response workflows, forensic investigation procedures, and legal considerations for evidence handling in cybercrime cases—with real-world applications in Nepalese e-governance and financial systems.

TAKEAWAYS:

  • Digital forensics is the scientific acquisition, preservation, and analysis of digital evidence for legal proceedings, following strict chain-of-custody protocols.
  • Incident response follows a 4-phase lifecycle (Preparation → Detection & Analysis → Containment → Eradication & Recovery) to minimize cyberattack damage.
  • Forensic tools like FTK Imager, Autopsy, and Wireshark extract evidence from disks, logs, and network traffic without altering data.
  • Legal admissibility requires evidence to be authentic, complete, reliable, and obtained lawfully under Nepal’s Electronic Transaction Act (2008) and Cyber Security Act (2018).
  • Common attack scenarios (e.g., ransomware, phishing) demand tailored forensic responses, from memory dumps to malware analysis.
  • Human factors (e.g., insider threats, social engineering) often trigger incidents, requiring behavioral forensics alongside technical investigations.

Core Concepts: What Is Digital Forensics?

Digital forensics is the application of scientific methods to identify, collect, examine, and present digital evidence in a legally defensible manner. Unlike general IT troubleshooting, forensic analysis:

  • Preserves evidence integrity (no modification of original data).
  • Follows legal standards (e.g., Nepal’s Electronic Evidence Act, 2075).
  • Covers all digital media: disks, RAM, mobile devices, cloud storage, and even IoT sensors.

The Forensic Process: A Step-by-Step Workflow

1. IdentificationIdentify potentialevidence (e.g., logs, 2. PreservationSecure evidence toprevent tampering (e.g3. CollectionGather evidenceusing forensic tools (4. ExaminationExamine evidencefor artifacts (e.g., m5. AnalysisCorrelate findingsto reconstruct events 6. ReportingDocument findingsin a legally admissibl7. PresentationPresent evidencein court with Chain of
The 7-step forensic process with key actions at each stage (NIST SP 800-86).

Key Terms:

  • Chain of Custody: Unbroken record of evidence handling (who, when, how).
  • Write Blockers: Hardware/software to prevent accidental data modification during acquisition.
  • Hashing: Cryptographic verification (e.g., MD5, SHA-256) to detect tampering.

Real-World Example 1: eSewa’s Fraud Investigation

Scenario: In 2022, eSewa detected unauthorized transactions from a user’s account. The forensic team:

  1. Preserved the user’s transaction logs and server logs using write-blocked drives.
  2. Collected RAM dumps to check for memory-resident malware (e.g., keyloggers).
  3. Analyzed network traffic with Wireshark to trace the attacker’s IP (found to be a sim-swapping attack).
  4. Reported findings to Nepal Police’s Cyber Crime Unit, leading to the arrest of a money mule in Kathmandu.

Forensic Tool Used: wireshark packet capture labelled diagramWireshark filtering for suspicious DNS requests (e.g., `bank.com` → `malicious-ip`). (Image: Oluwatobi TJ, CC0, via Wikimedia Commons)


Incident Response: The 4-Phase Lifecycle

Incident response (IR) is the structured approach to detect, contain, and recover from cyber incidents. Nepal’s Nepal Computer Emergency Response Team (NPCERT) follows this model for national critical infrastructure (e.g., NTC, NEPSE).

Asset inventoryIncident response planForensic toolkitPhase 1: PreparationLog analysisThreat intelligenceForensic imagingPhase 2: Detection & AnalysisIsolate affected systemsBlock malicious IPsPreserve evidencePhase 3: ContainmentPatch vulnerabilitiesRestore from clean backupPost-incident reviewPhase 4: Eradication & RecoveryIncident Response Lifecycle
Hierarchical breakdown of incident response phases with key tasks.

Phase 1: Preparation

  • Assets: Inventory all systems (e.g., Ncell’s SS7 signaling servers).
  • Policies: Define incident response teams (IRT) and escalation paths (e.g., Daraz’s security operations center).
  • Tools: Deploy SIEM systems (e.g., Splunk) for log correlation.

Phase 2: Detection & Analysis

Example: Pathao’s ride-hailing app detected a DDoS attack during Dashain 2023.

  • Indicators:
    • Sudden spike in API calls (10,000+ requests/sec).
    • Unusual geolocation (traffic from Russia → Kathmandu).
  • Tools:
    • Snort (IDS) flagged malicious packets.
    • Autopsy analyzed driver app logs for data exfiltration.

Phase 3: Containment

Strategies:

Containment Type Example (Nepal) Risk
Isolation NEPSE suspended trading during a hack attempt Market volatility
Rate Limiting Khalti blocked suspicious IPs Legitimate users affected
Patch Deployment NTC updated routers after a zero-day exploit Downtime

Phase 4: Eradication & Recovery

  • Root Cause: Pathao’s attack was a misconfigured AWS S3 bucket (exposed driver data).
  • Actions:
    1. Removed backdoor scripts from the app’s backend.
    2. Restored data from immutable backups.
    3. Retrained staff on secure coding (OWASP Top 10).

Forensic Investigation Procedures

023.7547.571.2595Chain of Custody95Evidence Integrity88Legal Admissibility72
Nepal Police Cyber Crime Unit’s forensic case success rates (2022–2023).

Step 1: Evidence Acquisition

Methods:

  1. Bitstream Imaging: Exact copy of a disk (e.g., using FTK Imager).
  2. Log Analysis: Windows Event Logs, Linux /var/log/, or SIEM alerts.
  3. Memory Dump: Capture RAM contents (e.g., Volatility Framework) to find malware.

Worked Example: Bank Loan Fraud in Nepal Scenario: A customer reported unauthorized loan approvals from a bank’s online portal. Forensic Steps:

  1. Acquired the bank’s web server logs (Apache/Nginx).
  2. Compared hashes of the original loan application vs. the submitted file (found a PDF metadata tampering).
  3. Traced the attacker’s VPN exit node to a cybercafé in Lalitpur.

Step 2: Evidence Analysis

Tools & Techniques:

Tool Purpose Example Use Case
Autopsy GUI-based disk analysis Recover deleted chat logs from a WhatsApp Business account
Wireshark Network protocol analysis Capture phishing emails in transit
The Sleuth Kit File system analysis Find hidden partitions on a hard drive
Guymager Mobile forensics (Android/iOS) Extract call logs from a stolen phone

Nepal’s Legal Requirements:

  • Electronic Transaction Act (2008): Evidence must be unaltered and authenticated.
  • Cyber Security Act (2018): Forensic reports must be signed by a certified examiner.
  • Criminal Procedure Code: Digital evidence must be presented in court with a chain of custody.

Example Report Structure:

**Case**: Unauthorized Access to Ncell Customer Database
**Evidence**:
- **Disk Image**: MD5: `a1b2c3...` (original vs. copy match)
- **Logs**: `auth.log` shows brute-force attempts from IP `192.168.1.100`
- **Network Capture**: Wireshark PCAP with **SQL injection payload**
**Conclusion**: Attacker used **credential stuffing** via a **compromised VPN**.
**Recommendations**:
1. Enforce **MFA** for all admin accounts.
2. Deploy **WAF** to block SQLi attempts.

Digital Forensics vs. Incident Response: Key Differences

Aspect Digital Forensics Incident Response
Primary Goal Legal evidence for prosecution Minimize damage during an attack
Timeline Post-incident (after the fact) Real-time (during the incident)
Key Tools FTK, Autopsy, EnCase SIEM, Snort, Firewalls
Legal Focus Admissibility in court Compliance (e.g., GDPR, IT Act)
Example in Nepal Investigating Khalti hack (2021) NTC’s response to a DDoS attack

In the Real World

  1. eSewa’s Anti-Fraud Forensics

    • Idea Used: Transaction log analysis + RAM forensics.
    • How: When a user reported a fake payment, eSewa’s team used Volatility to check for memory-resident keyloggers and Autopsy to recover deleted transaction records from the server’s hard drive.
    • Outcome: Identified a malware-infected POS terminal in a local shop.
  2. Ncell’s SIM Swap Defense

    • Idea Used: Network traffic forensics (SS7 protocol analysis).
    • How: After a surge in SIM swap fraud, Ncell deployed deep packet inspection (DPI) to detect unusual IMSI catcher activity. Forensic analysis of base station logs revealed rogue towers in Thapathali.
    • Tool: Erlang/OTP (for analyzing Ericsson switches).
  3. NEPSE’s Trading System Breach

    • Idea Used: Database forensics (SQL transaction logs).
    • How: During a 2023 hack attempt, NEPSE’s forensic team:
      • Restored the database from WAL (Write-Ahead Log) backups.
      • Analyzed pg_stat_activity to find the malicious SQL query:
        UPDATE users SET balance = balance + 1000000 WHERE user_id = 12345;
        
    • Tool: pgForensics (PostgreSQL forensic toolkit).

Common Attack Scenarios & Forensic Responses

Attack Type Forensic Clues Tools Nepalese Example
Ransomware Encrypted files, ransom note, process logs FTK, Volatility 2022 Kathmandu Hospital attack
Phishing Malicious email headers, logins from new IPs Mimecast, Email Header Analyzer Khalti phishing scam (2021)
Insider Threat Unusual access times, data exfiltration Splunk, User Behavior Analytics Bank employee leaking customer data
DDoS Spiked bandwidth, source IP spoofing Wireshark, Snort Pathao Dashain outage (2023)

Exam Tip

How This Unit Is Tested in TU Exams:

  1. Definition-Based Questions (10 marks)

    • Expected: Define digital forensics, chain of custody, or incident response plan.
    • Tip: Use one-sentence definitions with legal context (e.g., "Digital forensics is the legally sound collection of digital evidence under Nepal’s Electronic Evidence Act, 2075").
  2. Procedure Explanation (15 marks)

    • Expected: Explain steps of a forensic investigation or incident response phases.
    • Tip: Use the mermaid flowchart above and link to real tools (e.g., "In Phase 2, Wireshark is used to analyze network traffic, as seen in Pathao’s DDoS case").
  3. Scenario-Based Questions (20 marks)

    • Expected: Analyze a given scenario (e.g., "A bank’s ATM system was hacked. Describe the forensic steps to recover evidence.").
    • Tip:
      • Start with evidence preservation (write blockers).
      • Mention specific tools (e.g., "Autopsy to recover deleted transaction logs").
      • End with legal compliance (e.g., "Ensure the chain of custody is documented per the Cyber Security Act, 2018").
  4. Tool Comparison (10 marks)

    • Expected: Compare FTK vs. Autopsy or Snort vs. Suricata.
    • Tip: Use a table (like the one above) with Nepal-relevant examples.

Common Pitfalls to Avoid:

  • Ignoring legal frameworks: Always tie answers to Nepal’s IT Act, Cyber Security Act, or Electronic Evidence Act.
  • Overlooking human factors: In insider threat cases, mention behavioral analysis (e.g., "Unusual late-night logins").
  • Assuming all evidence is digital: Include physical forensics (e.g., "Examining a stolen USB drive’s serial number").

Quick Revision Checklist

Before the exam, ensure you can: ✅ Explain the 6 steps of digital forensics with tools for each step. ✅ Draw the incident response lifecycle and label Nepal-specific examples. ✅ Describe how to handle a ransomware attack forensically (from isolation to recovery). ✅ List 3 forensic tools and their use cases in Nepal (e.g., Autopsy for Khalti fraud cases). ✅ Explain why a forensic image must be hashed (using MD5/SHA-256). ✅ Name 2 Nepalese laws governing digital evidence and 1 real case they applied to.


Based on the TU BITM syllabus for Computer Security and Cyber Law (IT225), unit 9.

Discussion

Loading…