S3: Insider Threats & Data Exfiltration | Forensics Techniques to Detect & Mitigate | Exterro INFORM
About this lesson
Watch S3: Insider Threats & Data Exfiltration | Forensics Techniques to Detect & Mitigate | Exterro INFORM by ExterroMedia. This content is being analysed by DeepCamp AI to generate a detailed summary.
Full Transcript
Thank you everybody. Let's give a quick one minute. We're right on time. We are live on time. So we just give quick one minute for people to transition from the previous session to this session. We can also see new attendees joining the session. The most important topic for the corporate industry on digital forensics and cyber security. Thank you. Is thank you Dia for joining the call today on time. Excited to >> Thank you so much. >> Yeah. >> Thank you. Raj, >> let's give a quick one minute uh for our people to transition from the previous session to this and then maybe we can get started. All right, I can see people joining in. All right, 60 attendees. We started with 20 25 and then within a minute we have 60 attendees joined from different parts of the world including many from India, South Africa, Sweden, Japan, Romania. Oh wow. Interesting. And we have speakers one from India, another one from Zimbabwe. All right. I think let's get started with no further delays. Let's get started. I would want to give a quick introduction about the session. First of all, welcome everybody including the speakers for today. Welcome everybody to Extter Inform. We are very glad that you joined. So just to give a short introduction about this uh program or this virtual conference. This extrainform virtual conference is a full-day event and it features 15 different regional specific webinars led by industry experts. Uh and this session is timed for approximately 55 minutes to one hour and in this 55 minute to one hour we would be diving into various key challenges like collaborative forensics, cloud forensics, incident response on the cloud, insider threats and everything. Just a few housekeeping rules for the webinar before we get into the topic. Audience join from different parts of the world. Please feel free to submit your questions anytime in the question window that you see on your right side. And if you would like to join the next webinar, as I said, we have 15 different webinars and there's a third one for the day. If you want to join the next webinar after this one, just simply stay online. You don't want to, you know, look for different links. You would be automatically directed to the next session. And it is the same common joining link for all webinars. So we are making your jobs easy. And this webinar will be recorded and we will share our marketing exposed marketing team. We'll be sharing the recording with you in the next few days. And yes, thanks once again everybody for joining from parts of the world. Good morning, good afternoon and good evening. And um thank you Dya and Isa for joining the call today. And one of the most important topic especially targeting the corporate industry insider threats and data exploitation digital forensics techniques to detect and mitigate. So I've already given a brief about this along with me I have few you know industry experts just to give a quick introduction about me. My name is Raj Kumar Manikum and I work for XRO as a regional director of sales and consulting for South Asia, Middle East and Africa. I've been with this organization for the last six year helping six years helping organizations in solving digital forensics and inculc response cases both law enforcement and uh private sector corporate. Along with me I have Mr. Isak Fury who has joined us from Zimbabwe and he works for Sus Technologies and he's an expert in cyber security incident response and digital forensics. Glad to have you here along with us is thanks for joining the call today. Thanks for joining this session and um thank you Diva. Uh Diva works for uh Diva works for AEL and she has great expertise in the V side and she also has a great knowledge and experience forensics and instance response side. So both Isak and Diva will be sharing their insights and their ideas and and their experiences you know that they have been carrying out in their day-to-day jobs. All right, let's get into the topic. So in this session uh we would like to cover more about insider threats. So what constitutes the insider threats uh you know if anyone with an authorized access who misuses or exploits the access for malicious purposes and about data exfiltration and why digital forensics is very important in today's world especially for corporate organizations and we would also want our audience to understand more about data exfiltration. So starting on with Isaac, can you start sharing your idea and insights on these areas please? I would go on mute and you can just start speaking. >> Uh thank you very much man. Um insider threats and data expiltration uh inside the threats is is um in today's landscape in digital landscape is very very uh significant risk in in uh for different organization which often leads to data exfiltration which is uh unauthorized transfer of uh sensitive data. So digital forensics then plays a crucial role in detecting and analyzing, mitigating uh before threats become uh irreparable uh damage. So what is um insider threats and who is an insider threat? So inside the thread um these are risk that originate from employees uh contractors, business partners or anyone with legitimate uh access who may misuse their privilege intentionally or unintentionally. So there are different types of um types of of threats. These are malicious. They are malicious uh insiders who are intentionally uh steal or leak or sabotage uh uh organizational organizational data. The we also have negligent uh employees or insiders who unintentionally unknowingly expose sensitive data uh or information to uh threat actors. Then we have um compromised in insiders. For example, uh in in nowadays people are working from from home, they are carrying their uh devices home and all that. hackers, employees whose accounts or devices are hacked. You know, those are some of um threats that we find in organizations and these are more difficult to detect because they are unknown, you know. So, yeah, basically that's what insider threat is. >> Thank you. Thank you for adding your thoughts uh about it, Isaac. I know you might have seen multiple cases like this in your uh you know in your whole experience with your organization. What what do you see as the impact you know few impact that we have listed or like you know consequences of data excfiltration like financial loss, IP theft you have already touched about it. Do you want to give more I mean some more insights about the impact that you have seen in you know in any of your clients organization or in any of your you know in any of your circle. Yeah, basically the impact of um insider threat is very uh detrimental or very uh big uh in in in organizations for example uh organizations they they lose their their reputation you know they lose business uh some of what I've experienced particularly this uh part of uh the world southern Africa what happens is that most of uh our organizations they do not have all the layers security layers you find that maybe they only have network layer you know uh firewalls and all that they do not have DLPs mobile device management systems and all that so they can't really track so when it happens they they can't do anything, they can't litigate and they are so afraid to to then uh share their story so that maybe others can learn from it. So yeah, it's quite a a it has a huge impact in terms of uh reputational uh damage uh to to different organizations there. >> That's yeah that's more important. Reputational damage is something know that every organization needs to be worried about. But it's not a question of will I be the it should be the question like when my organization would be facing such issues. Thanks for adding your thoughts Diva we would like to hear from you about you know your your thoughts on these areas. So uh basically uh Raj uh like Isaac said there's the huge u reputational damage plus compliance risk plus uh legal legally uh sort of things will running up and you know there will be a a huge damage to an organization if insider threats and if their data is uh you know leaked. So it's a huge huge impact in today's world because uh as in today's world if we see that data is very uh you know very easy to leak right so in today's world uh privacy is a myth but uh to but still we need to you know but still we need to um uh secure our data as if we work in an organization or we work as or we run a business so we should definitely secure our data And these are I guess in in my opinion these are some uh uh major and uh you know very um uh heinous I would say uh if we lose our data so these things uh matter so if we talk about data excfiltration so maybe data excfiltration basically those who don't know what exactly it is so I would say data exfiltration uh basically refers to the unauthorized transfer or extraction of data from a system or network often within the intent to steal or leak or misuse the data basically. So we need to protect our data from insider threats. >> Exactly. Exactly. Thanks for adding about this privacy as well. Yes, I understand that people don't understand the importance of data privacy uh nowadays and you know which data privacy is a part of data uh risks as well. They don't just see privacy as a a small piece. That is a part of the bigger you know uh problem which is data risk as a whole and that is what XRO is trying to address and solve for multiple organizations through our data risk management platform. And again just to give a quick uh you know I would want to highlight very quickly about the important of digital forensics and how it helps in identifying preventing uh various insider threats. So most of us would have I mean people who I mean I talked to multiple organizations uh you know who work for corporate and they talk about the um uh you know the mitigation of malicious or negligent actions you know taken uh performed by individuals within their organization who are considered to be the insider threats. So basically these digital forensics best practice basically the the hygiene in terms of managing the data and maintaining the data helps organizations in terms of identifying the wrongdoing create evidences and prevent from any future wrongdoings or future incidents and basically this also helps them in helps them in terms of strengthening their um security measures and all those things. So digital forensics if organizations are not considering very seriously this is high time for bigger organizations to take it very seriously because most of the organizations when an incident happens then they go and start working with um consulting companies or service providers but this is something that they need to you have some thoughts to it u u Isaac sorry go ahead. Oh yeah, digital forensics is very um critical in this digital uh landscape that we're in. You know, why do we need uh digital forensics? Um you know, we need to be able to to investigate ensure that maybe the threats are discovered before uh the damages escalate, you know. So digital forensic basically it's a science of investigating cyber incidents ensuring that uh insider threats and data exploit protection attempts are not uh they don't escalate you know before damages financial damages litigation uh financial I mean um reputational damage happens to to any organization. So it is uh important for for you for for an organization to to take proactive uh steps uh in investigating and providing and and collecting uh proper evidence to support uh um legal action when whenever it's needed. You know whenever an incident happen you don't want to start from scratch because it can be tedious to discover how these uh uh this uh data was exfiltrated you know. So if we then employ digital forensics uh and com in combating uh in trying to to minimize the risk then uh it's a proactive uh approach of doing so. It also you need to take a proactive uh security measures to prevent uh I mean maybe for example you've already been uh compromised to to prevent or get uh recurrences of of such uh incidences. So there are different uh forensic techniques used uh in inside a threat uh investigation. You know there's uh log analysis where you analyze system logs for unusual um access to to access patterns. You know you can also analyze your timeline uh timeline reconstruction uh rebuilding a sequence of events to track unauthorized uh file access and all that. So digital forensic forensics is is key to to combating um uh inside the threats. >> Yes, very nicely, you know, articulated. Um Isaac, thank you very much for that and I love that the proactive approach. It's all about being proactive rather than being reactive. Again, I would want to, you know, uh reiterate that it's not like when will I it's all about like I mean it's not like I would just look into it when my organization get into that organization. they need to be very clear about anytime we can be under a cyber attack and they should be prepared for that. Thanks for adding your thoughts Isaak and Diva on these areas. Uh I would also want to hear from you about the types of insider threats. So we heard about malicious insider threats, accidental insider threats and compromised insider threats. So could you please elaborate more on this? I said I would want to you know hear from you and then maybe I can go to Divia. Would you like to share your thoughts on this please? >> So malicious insiders these are employees or contractors uh or business partners whom intentionally steal or leak uh your leak damage company data for personal gain. Sometimes they they are revenging. Someone has been laid off. They just want to you know sometimes your marketing team they can be your greatest competitor uh within your organization. They want to start their own organization and all that. So they are collecting all sorts of data so that they can go and compete with you out out there you know uh spying uh government agencies spying on on on on different corporates to try and find out you know so there there are so many different types of uh malicious and the motivations are they vary uh from financial gain uh corporate expunge um stealing uh trade secrets for rival uh companies. There's a perfect example that once happened between Coca-Cola and and Pepsi. Uh uh uh the good thing is that Pepsi they decided to to do the honorable thing and share the information with Coca-Cola and the employee was um was actually fired for for doing that you know. So revenge as well you know you know we we are human beings we catch feelings sometimes. So, so yeah, a disgruntled employee supporting systems before leaving, you know, and this usually happens, I mean, a long time because you never know uh what a human being is thinking. They'll be coming to work, you be thinking you're still together, they've given their notice, but it usually starts way before I mean 60 days or maybe 90 days before they leave. They start collecting the data. by the time they put their notice uh the damage is done. So it is critical to to to employ forensic uh uh forensic uh tools to to to be able to see what's happening within your organization. It could be politically motivated again uh leaking data for ideological uh reasons and all that you see. So yeah there there are many examples that we we can give you know an IT administrator uh downloads confidential source codes to a USB uh before resigning to so that they can give to to their competitor or other reasons or maybe start their own business. We've seen I've seen that quite a lot uh here uh this part of the world. So yeah, I think over to you. >> Thank you very much for nicely covering that. Just wanted to make a comment on uh people who think to revenge about their I mean against their employer or something. Guys, FTK is there. FTK central is there. Don't try that. You could do something on on the cloud or on the network. FTK could do anything. So don't we have deployed it for various organizations and they have just FTK central and FTK connect helped them to come out of those and create evidences and guys are put behind difficult situations. I would want to iterate that. So uh Dia could you share your thoughts about this? >> Yeah. Yeah, definitely Raj I'm totally agree with you that Africa can do anything and uh the so uh as uh Isaac um has mentioned uh people has grudges and they their theft data and sabotaging and fraud sometimes uh we have uh people who don't uh know like they are not aware of that like they are leaking some datas or they're you misusing uh some sort of datas to an organization. So that comes under negligent uh negligent insider threats. So uh how we can uh say that that uh how people comes falls into this category. Sometimes organizations have poor security practices like they do uh they use uh weak uh weak passwords rather than strong passwords and they sometimes they don't even use passwords. They don't have credentials. they just uh turn on their laptops and they wow logged in into the system and sometimes uh some people uh cannot differentiate between uh fishing links right so from from that we can have the credentials of anyone right uh through fishing if uh one cannot uh differentiate between fishing scams and all after that uh we have accidental data loss uh let's say an employee might unintentionally send sensitive information to the wrong person or misplace the data or um uh let's say uh if the data has uh something important and it has in a USB and that person or uh or uh lost that uh you know that hard drive or that USB then that's comes under um accidental loss then um so overall uh negligent uh threats falls under inadequate uh security uh you know awareness. So yeah, so that that's also a major concern because we need to you know uh we need to teach people how to differenti differentiate between you know uh fishing uh links, how to um how to be very uh how to secure uh you know how to safe and secure uh set passwords into our systems or some sort of our cloud storage because uh these are very um very easy to leak. >> Exactly. Now we understand. >> Just to add on that um you know these are these are accidental these are good human beings within the organizations you know sometimes lack of awareness or poor security practices. You know uh employees who do not intend to cause harm they can uh create security risk. So it is important also for organization to begin to uh invest um more on uh human error training their employees on how to identify threats and all that. So sometimes good people also can uh cause uh damages to the organization. >> That's a different perspective. Interesting. Thank you. Thank you both for sharing your thoughts about it. I understand like what you guys uh do on a daily basis how it's hard for you to go and teach them the basics of maintaining hygiene and clicking a link or on the cloud downloading something from different websites and everything. Thanks for that and interestingly we I could see people joining in from different parts of India and again from Zimbabwe, Germany, England, Norway and again Gujarat. Thanks everybody for joining. We are discussing one of the most important topic for the corporate industry insider threats and data exfiltration. Jumping on to the next slide. I mean I asked one more question or I've asked very high I mean highlighted more about the role of digital forensics in the first slide. The reason behind that was we would want to more about the role of digital forensics in detecting insider threats. So I would want to spend some extra time on this because I feel this is more important slide. So um Dya could you talk about the process right from data collection and preservation in in in your world how it starts with collection and how do you preserve and you know followed by other forensics processes. >> Okay. So um as you as you said Raj uh that digital forensics plays a very critical role in identifying investigating and mitigating insider threats right. So here in India we have uh steps while we uh went to uh let's say a crime scene or uh let's say if if an organization has uh some sort of ransomware attack. So when forensic team uh went to uh that uh scene so first we uh you know first we disconnect every um system uh from the network because if uh the system is has been connected to network then it can uh anything uh can happen in the background. So we uh so forensic team basically uh disconnect every systems from their network and then we collect the hard drives and USB and the systems and everything from the scene of crime to and uh by uh by doing this we simultaneously maintain the chain of custody. So what chain of custody is forensic ensures that uh that uh any evidence is gathered at the scene of uh crime is handled properly following legal standards for maintaining the integrity and chain of custody. So um for that uh if after that we gather that uh you know the systems and the evidences whatever we have um collected from the scene of crime or any scene where the attack or ransomware attack happened. So if once we have collected that evidences we um we connected it through the right blocker forensic tool to maintain its integrity and we generate the hash value for that of uh evidences. After that we yes after that we you know analyze the data and if data has been deleted so we do logical and physical imaging through FTK in case whatever the tool is uh using by foreign sec uh experts. After that uh of course after that after um gathering some sort of data or imaging or recover some deleted data then we identifying that uh identifying exactly data expiltration that where the data has been leaked when the data has been leaked or if we talked about network forensics we talk about um when uh the logs has been created we'll uh we get into the windows registry for logs analyst and everything we do and uh then finally comes up with the result that yes uh this attacker this IP address or uh this person this um from this organization has uh you know uh misused the data of the organization. >> Sure. Sure. Thanks for that. U um Isaac could you talk more about the behavioral analysis? How would you do that? how you detect um you know suspicious behavioral pattern uh when you're working on an abnormal um cases. Could you I would like to share from you more about it. >> Yeah. So uh insider threat is is a is I mean you don't know what is happening behind the scenes. So you only know when it has already happened. So basically it is important to to maintain uh critical records you know I mean collecting your your data pre data preservation or digital evidence you know to ensure I mean the integrity um and authenticity when it comes to uh litigation issues or anything that that has happened. So there are key uh things that need to happen. Um make sure that you log uh system logs, authenticating um authentication logs, uh collecting authenticating logs, uh event logs and application logs. uh also file uh and system uh artifacts you know collecting uh delete deleted data uh timestamps unauthorized file uh modification having tools or systems that can actually uh monitor all these things. You also have to have a network uh traffic layer where you look at suspicious outbound and in inbounds of of data transfers and all that endpoint activities what is happening or on the endpoint USB insertion cloud uploads remote uh access loads and all that email or chat logs uh internal leaks via unauthorized email forwarding messages we need to monitor all that. So there are best practices that uh organization can employ uh to for for data collection you know uh using uh forensic uh imaging I'm sure FTK has got a FTK imaging you know uh exter I mean uh then creating a bitby-bit copy of of compromise uh device using tools like uh the imager or autopsy you uh hashing and uh chain custody maintain integrity by maintaining integrity of all hashes and all that. So log aggregation again and and storage using your uh security information uh your SIM uh to to to gather the the whatever digital I mean evidence >> evidences. Yeah. >> Yeah. Got you. Got you. So, um I would want to keep this question open to both of you and would would want to share from you about it. So, how how would you uh I mean how what what are your thoughts or information to people in this webinar in terms of identifying exfiltration attempts in terms of analyzing the network or identifying unusual data transfers? Have you guys done that? Could you share some insights or thoughts about it so people join from different parts of the world can benefit from your thoughts and insights? Diva do you want to go first? Uh so Raj basically uh data exfiltration is as I said that that is very you know very drastic impact to an organization like financial losses uh reputational losses um integrity loss of that uh organization right and and some and for some time their operational disruption is also occurs right if a company has been occur from data expiltration then uh they they have mild chances that their operations are disrupt and they have loss of productivity. Right? After that they may face legal and compliance risk as well. They face non-compliance litigation part after some sort of things. So until they recover from uh this uh data exfiltration part >> uh I'm not sure if I got you right. You are you looking at the how do we >> the network um network forensics how would you identify the xfiltration attempts uh by analyzing a network by analyzing network logs identifying >> all right basically they they are common uh I mean inside the threats behaviors that you then begin to see you know uh an employee can begin to access uh corporate data or company organizational data at odd hours. You know, downloading a large amount of data, you know, which are not necessary, you know, unusual login from different uh locations and user you know from different countries from different locations and all that. This is where uh organization need to then employ uh tools such as an MDM, a mobile device management uh system and your geo fencing uh to say your your data can only be uh accessed in at a certain location at certain certain times and all that. So there's al also excessive uh failed attempts of login you know and also data uh wording those are most common be behavioral I mean that you you need to look out as an organization uh yeah there are also behav I mean uh analystic tools that uh could be used uh by organizations such as uh the this blank. This uses uh machine learning to detect uh user uh anormalities. Uh we have Microsoft uh defender uh uh uh defender for identity. It identifies compromised uh accounts and all that. Exam yeah uh it tracks insider risk scores based on uh the user activities. So there's quite a lot of uh uh activities that begin to to happen you know in an employer uh they may start I mean working odd hours you know so yeah those are some of the things that uh we need to be on the lookout on the lookout for. >> Definitely definitely thanks for that and we also have few uh forensics techniques especially for the insider threat. So before we get into that Isak and Diva maybe Isak I would want to hear from you more about the importance of using forensics analysis tools. So because most of the organization they think that they could solve any forensics problem using open source available on the internet or freeware available on the internet. So what are your thoughts about using forensics analysis tool? Could you talk about um some of the key aspects of going for a forensics analysis tool? And maybe uh the next question I would want to know about is the forensics techniques. But before that let's talk in in you know in short about the forensics tools and its importance. >> Okay. Uh the forensic tools they help you analyze artifacts and logs basically for for your users uh and their activities what's happening within your environment. these tools that can actually help you to to analyze to see for example if you employ a DLP you can actually see who's handling the data when at what time what sort of data are they handling and uh are they authorized to to to to use such uh such data you know so it is it is critical to to use this uh we can actually identify also uh anomaly anomalies uh uh on your on your network you know for example systems like uh wireshark uh it captures and inspect network packets of data and expiltration. So there are different layers uh in which uh you can actually uh employ for you to to be able to um analyze uh these tools. They are very very very important. Uh without which um data is is given for free. >> Got it. Got it. So thanks for that. So uh Da would you like to add anything extra to I said whatever he shared about the importance of having >> Yeah. >> Yes Raj. Um so as uh Isaac said that forensic plays a very important role and forensic tools plays very important role. If we compare to Osen tools because um OSEN tool gives us a very uh limited source of knowledge or limited source of uh you know um analysis but if we use uh forensic tools we have real time monitoring and alerts like so OSEN can do that basically and also we have DP data loss prevention team implementing DLP um solution helps prevent the unauthorized transfer of sensitive data right So the system monitors data as it moves across the network and blocks suspicious transfers whether to external devices or the cloud right we um other than that we have access auditing and forensic logs if we use forensic tools so we have endpoint forensics as well uh which in my knowledge that uh no OSN can perform it um right so if we have endpoint forensics then forensic team should regularly you perform forensic analysis on endpoints to recover data and deleted files. Examine uh users activity. If a large file unauthorized or large file is transferring through the network then DP will you know catch it immediately. So these tools help very uh very very massively if we compare. >> Exactly. Thank you. Thank you for that. And just a quick thought on uh because when we talk to uh I mean me and my colleagues different uh you know from different teams within extra we talk to different people different corporate organizations and most of the people think that DLP can solve problem that arises of uh forensics tool I'm not against DP but more of DLP is all you know it talks only about preventing data breaches in in real time by monitoring various endpoints and all those things and blocking potential leaks. But it completely lacks the forensics depth and the post incident capabilities. What a forensics tool can do is it can >> Yeah. No, I'm I'm adding you know thoughts to to yours. Exactly. I second your your thoughts and I'm adding to it. >> Yeah. >> Yeah. >> There are different uh forensic tools that can be can be used. Uh I think Ive I've I've mentioned the the exter uh uh FTK toolkit. It's it's a it's a it's a very very robust I mean tool for analyzing the the logs the everything that actually you may need to to to to to analyze. We have uh the splank. It also can analyze uh your logs. Uh those are sim tools you know. So yeah there there are different types. So it's important to to employ all levels of of security. I mean when it comes to to this combining I mean uh tools that are available you know. Yeah. >> Yeah. Thank you. you a sec. And you were about to say something. I'm sorry. Uh about the DLP and DF. >> Uh no uh Raj actually I was no actually I was uh saying this thing uh whatever you are saying. >> Okay. Okay. Great. And yeah thanks for >> DLP and affair. Yeah thank you for acknowledging that. And Isaac thanks to you for talking about the SIM and SAR tools because when we talk about forensics uh most of the organizations use cyber security tools various SIM and various tools including Splunk and various other uh thing uh so it it it can do the cyber security part but on from external side we also have a tool for audienc's benefit we also have a tool called FTK connect which works very well with any SIM and sour tools that sits on your infra infrastructure and when this API toolkit could What it does is it it basically automates the collection uh and it creates the job for you and automates the collection. It it automatically does the job for you. Uh it you know uh you don't want to wait and go ahead and start the collection if your Splunk or any of your cyber security tools detect any threat or something coming into your network. It alerts the API alerts and it starts the collection and you know uh well in advance it starts the collection and terms of protecting the evidences and all those things that is something extra offers and any of any of the audiences would like to know more about it please feel free to reach out to me or any of my colleagues or simply email uh us at marketing at the rate.com and we would be able to help you in detail. So we have talked enough about uh you know uh the uh role of digital forensics in uh detecting insider threats. Very quickly on the forensics techniques uh we have various techniques like reconstructing the um timeline analysis of of the logs where we have talked in detail about both Isak and Diva has talked about it. Can we get uh Isaak can we get your insights on the re reconstruction of the timeline social engineering methodologies and uh file integrity monitoring? I would keep it very open so both of you can add your thoughts very quickly. Um in the interest of time we have just 17 more minutes. >> All right. Uh thank you very much. >> You can go ahead. >> Uh uh okay. Thank you so much. Okay. So Raj if we talk about timeline reconstruction then if uh assume let's if a case happened 3 days ago 4 days ago so uh we uh collecting logs uh not from uh the past one year or two year we collect logs maybe maximum maybe from last six months right like how and the activity of the organization the how the data is transferring through the network and how uh what type of data is transferring and uh what uh who is transferring basically so we analysis that logs if we talk about timeline reconstruction um and Isaac over to you now you may add you have >> all right uh thank you very much uh so timeline reconstruction basically maps out uh user activities to detect anomal anomalies such as an authorized entry access or file deletion so insiders often cover their tracks. They really do cover their tracks. You'll never know what they are doing. So, it is uh important for organizations uh to to to uh to practice uh sequence uh to to rebuild uh or practice sequence of events which helps them spot uh what uh suspicious behaviors. And there are different uh techniques that can be uh employed in terms of uh reconstruction of um of timelines you know you know timestamp uh analysis you know extracting uh uh file creation modification and uh access times you know that you can use uh I mean different uh tools from uh FTK exter uh windows logs tracking user login history, their registry uh changes and uh the process of of of execution or you know so network uh connection logs when identify where when and how data was accessed or transferred. You know this is um can use your mobile device management uh systems and all that. So basically uh I think um it's it's critical to to to map a user activities and detect anomalies uh by building a a >> yeah user uh activity history. >> Yeah. Yeah. Thank you for that to uh share your thoughts. Thanks Dia and Isak for adding your thoughts about the different techniques. So we have talked about the challenges, we have talked about the techniques. Now it's time to engage our audience. So you know you you could see a poll or a Q&A on your screen. According to you, what do you consider the biggest challenge when dealing with insider threats and data expiltration in your organization? Is it detecting suspicious behavior in real time? Or is it identifying unauuthorized access to sensitive data? Or is it implementing effective monitoring systems? Or is it educating your employees? Do you think educating your employees is the biggest challenge about your security best practices? Because I keep hearing this when I go on calls with my prospects and customers or the biggest challenge is it managing legal and compliance requirements during investigation. So please share your thoughts about it and we would be able to see u uh your answers and the score that that we get. I I'll be sharing about it. So we could see more responses for detecting suspicious behavior in real time. That is the biggest challenge. Yes, almost 55% of the people has answered the detecting suspicious behavior is the uh in real time is the most challenging part. >> Guys, FTK is there to help you in terms of identifying, detecting suspicious behavior in real time. Please talk to us. Whoever has answered that, talk to us. Hear more about FTK Central and we would be able to help you. Uh, email us marketing the raidextter.com and we are there to support you. You're just one email away. Data exfiltration detection techniques. Um, we talked about DLP systems and we talked about the endpoint monitoring, but I would want to keep it very specific about anomaly detection and traffic analysis. So uh I said could you talk more about anomaly detection and traffic analysis? We just have like three more slides that I would want to cover in the next 12 minutes. So uh could you share your insights uh very quickly for anomaly detection and traffic analysis? >> Okay. uh data exfiltration um uh unauthorized users transfer sensitive data uh or is one of the biggest cyber security threats organization face. So there's need to to to to employ techniques to help detect and prevent data leaks before they they happen. So anomoral detection is one of uh the techniques that could be employed. So basically in inside often bypass traditional security controls uh making it crucially uh crucial to detect anomalies in uh in user behavior, data transfers and network activities. So we could employ uh AIdriven anomaly detection uh tools uh that can identify suspicious activities before the breach occurs. you know anomaly detecting uh strategies. Um we can use u UEA behavior analytics. You detect uh deviations from uh normal uh user activities such as uh maybe a finance employee suddenly accesses engineering documents. You know that's that's very strange you know. So you can actually detect behavior analysis of uh you know to say is it consistent with their what they're supposed to do. You can't have an HR I mean accessing I mean uh trademarks or whatever that's that's an anomaly you know time based monitoring these are just strategies that I'm giving you behavioral analytics time based monitoring you know you you flag large data uh transfer outside business hours you know this helps in a to say okay you see your your employees are now uh leaving work uh 12 uh midnight you know when whereas they're supposed to I mean have ended their shift at 5:00 p.m. That's a that's a red flag. Again, geoloccation. Uh make sure that the devices are geoloed to say they can only be used uh at a specific uh location. You know, this detects login or file access from unusual locations or unknown devices. You know, uh volume data and frequency tracking. You identify employee surgently transferring. I mean gigabytes of data uh at once. So there are also tools that we can use for for anomaly detection. Uh I mentioned earlier on Splunk, Exab, Dark Trace uses machine learning to to detect inside the threats. Varonis, you know, analyzes file access patterns uh or unusual behaviors. Thank you for that. So, Diva, would you like to quickly add your thoughts about uh anomaly detection and traffic analysis please? >> Uh yeah, sure. Raj, basically in my perspective, anomalous behavior is any deviation from normal behavior is considered anomalous. we can um you know judge uh somebody in an organization who is uh you know uh not behaving normally or sometimes this could include a user um accessing accessing sensitive data that they typically don't access right or uh they you uh they are logging into the systems at unusual times and or they're transferring u large amounts of data at odd hours. So this is sort of anomalous behavior. So we can um you know easily um look into in uh if somebody is doing so we can easily point it out that uh yeah some something is wrong with that person if we look closely. So this is uh anomaly yeah detection in my point of view. >> All right thank you. So I've been asking questions or we have been sharing uh information insights more on the generic terms and the techniques and all those things. Now we would like to hear from both of you. Maybe each of you can take one minute to 90 seconds to talk about maybe one of the challenging case study or a real world example that you have you guys have come across your day-to-day life. Uh one each very quickly please if I may ask that. >> Sure Raj I will be uh sharing. >> Okay. Thank you so much uh Raj. Uh so I'll be sharing a case study uh which is a uh institutional financial institution basically who uh was targeted uh by an insider threat. So this institution was sensitive uh uh with having sensitive uh financial data including customer information, transaction records and investment portfolios. So and also this institution has protected by various uh measures such as firewall, IDS and IPS etc and other access controls. So however uh the somebody from their uh organization insider we call X or anything to him let's say we call him insider from their organization. So they were uh who was uh stealing a large amount of data from uh their um from the institution to gain some sort of financial stability in their life. And for that he was uh stealing data and misusing the data and and he was uh you know he was uh toggling with the data basically and then um forensic plays after uh after and he was doing uh for uh grudges uh for that with that uh financial institution and after that uh after he left the organization uh this case remain unspotted. Um I would say around uh 60 or 90 days I guess and after that uh after that uh uh an alert was raised basically uh for an automated audit. The audit was conducted about 90 days and and with that uh this case has been you know uh come uh comes into the point uh that uh their access uh their logs uh you know he has shared very large files into uh from their system. So uh this alerts uh came into their into in front of the organization and then a forensic uh part comes and they analyze the logs and network forensics they do endpoint forensics like how he has transferred the data whether the USB whether he was using USB or system imaging or whatever he was doing. So this uh this is how a forensic plays and this is how a forensic uh experts uh solve this case and we finally get that person into the custody. >> Oh interesting. Uh I don't know I I cannot imagine the reputational damage and the financial loss they might have undergone. It's more of like unusual data transfers on the network on the cloud that we have already addressed. Thanks for sharing this. Uh so Isaac, do you have anything interesting like this that you would want to address to our audience today? >> There's quite a lot of uh interesting ones particularly in in Africa. There's a lot of things happening. Uh Africa has witnessed several insider threats in acrossing banking, government, telecoms and corporate sectors. Many of these cases or involve data leaks and financial frauds and expunge. uh there's a very uh I'll just give you three or maybe examples that we we faced here in in our country uh in 2022 uh insider aids uh corruption I mean so what they did this a this is a government institute tax authority then a malicious insider uh use system tempering to to aid corruption. So what the employer did is that uh they connived with uh uh outsiders so that they could um alter or temper uh tax records illegally to help business evade taxes. So the insider accessed and changed tax assessment records uh reducing tax liabilities for companies in exchange of a of of a bribe uh you know so the the lessons that were learned there uh they implemented uh audit trails to track system changes and to prevent unauthorized uh modification of data uh you know so there's also So a a banking uh one of uh the biggest banks uh in Zimbabwe that was uh 2021 Manchester Insider unauthorized access uh to the system. Uh the employee man manipulated a banking system to approve a fraudulent transaction worth millions of uh uh Zimbabwean dollars. The insider works with uh internal fraud network uh altering account balances and uh approving unauthorized uh withdrawals you know. So the lessons that we learned the implementing access control preventing unauthorized financial uh system uh manipulation uh real-time fraud detection uh you know then one of the biggest uh telecoms uh in the country that is 2023 uh this is a mobile device they have a mobile um banking um that is 2023 unauthorized uh account creation, you know. >> Okay. >> You know, from inside employees helps criminals create uh I mean accounts using stolen identification uh deframes are used uh for money laundering and financial uh fraud and scams and all that. So there's quite a lot of uh >> there are a lot of interesting things happening. Yeah, I could I could understand the reputational damages, financial losses. You talked about the millions of you know uh dollars in your currency going ahead. Yeah, thank you for that and you rightly addressed about how these insider threats can be mitigated. You talked about the access controls. So we recommend that enforcing least privilege access and monitoring and you know uh generating alerts for suspicious behavior and more important is training and raising awareness amongst the employees to identify potential risks and adapting to a zero trust approach is something that helps organizations to stay ahead of uh you know uh incident response and insider threats. So as a closing thought I would like to take this opportunity in terms of uh incident response and remediation, containment and eradication of the threats and recovery and restoration of systems to normal and monitor of any further um signs of data exfiltration and considering the legal implications in terms of conducting a forensics investigation and potential regulatory compliance requirements would always be helpful. Uh we are right on time. Diva and Isaac, thank you very very much for uh spending one hour um with us and our audiences and sharing your insightful experience. The next session is all about uh digital forensics. Uh I'm not I'm sorry I don't know German. So one of our langu one of our colleague will be joining in. Uh the expert joining us today would be Florian. But thank you everybody for joining from different parts of the world and listening to us and reaches at marketing and >> thank you so much Raj. >> Thank you for today's time. >> Thank you so much. Thank you everyone. Bye bye. Bye bye. Thank you. Bye-bye.
Watch on YouTube ↗
(saves to browser)
Sign in to unlock AI tutor explanation · ⚡30
Related Reads
📰
📰
📰
📰
Your HIPAA Posture, in Version Control
Medium · DevOps
hermes-memory-installer: Avoiding Stale Commit Hashes in Consistency Notes
Dev.to AI
Every AWS project starts with copy-pasting last repo's Terraform. I built a generator instead.
Dev.to · Framz
Kubernetes Health Probes: Liveness, Readiness, and Startup Explained
Dev.to · toothbrush
🎓
Tutor Explanation
DeepCamp AI