Anti forensics and data hiding Flashcards

(21 cards)

1
Q

What are the applications of Stenography

A

Military
Diplomatic
Personal Property
Intellectual Property

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is stenography

A

The process of hiding a secret message within an ordinary message and extracting it at its destination
Anyone else viewing it will fail to knows its hidden/encrypted data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Describe the process of modern stenography

A

Data is encrypted then inserted and hidden using a special algorithm which may add/modify the file contents
Process may append data to file or disperse it throughout
Effective programs apply encrypted data in patterns that appear normal

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the aim of modern stenography

A

To only be detectable if a secret key is known

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Describe how stenography remains undetected

A

Unmodified cover medium must be kept secret
If exposed, a comparison between the cover and stego media immediately reveals changes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Define staganalysis

A

Identifying the existence of a message
NOT extracting the message

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are the methods of detecting the use of stenography

A

Visual detection
Audible detection
Statistical detection
Structural detection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the aim of cryptography

A

To provide the means to encrypt the message

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the 5 steps of Cryptanalysis

A

Identify program used to hide the message
Identify the location of the program signature in the file
Identify the location of the password in the file
Identify the location of the hidden message in the file
Identify the algorithm used to encrypt the hidden message

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Describe alternate data streams

A

One file can be linked to multiple alternate data streams of any size
ADS is hidden
Allows for hiding of files and directories
Difficult to detect
Does not show up using dir command

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

How do you hide data from Windows explorer and other Windows file searches

A

Store it in a NTFS stream

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What do you do if you find a potentially steganized file while performing forensics

A

Look for evidence of stenography programs on the computer
Leverage other OS and application passwords found on the machine as they could be the same as the password used to hide the message
Look for other hints such as password written down in notes, letters, diaries, etc.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is the importance of writing reports

A

Communicate results of your investigation
Required by courts for expert witnesses

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is an examination plan

A

What questions to expect when testifying
Used by your attorney to guide you in your testimony
You can propose changes to clarify/define information
Helps your attorney learn the terns and functions used in computer forensics

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is a verbal report

A

Less structured
Attorneys cannot be forced to release verbal reports
Preliminary report
Addresses areas of investigation yet to be completed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is a written report

A

Affidavit or declaration
Limit what you write and pay attention to details

17
Q

What are the 4 criteria to allow an expert witness to testify to an opinion or conclusion

A

Opinion/conclusion depends on special knowledge/skills
Expert is qualified as a true expert
Expert must testify to a certain degree of certainty
Experts must either describe facts that their opinions are based on or testify to a hypothetical question

18
Q

What can be included in a report

A

Anything you wrote down in your examination
High-risk documents
Spoliation
Same information as verbal report

19
Q

What is a technical witness

A

Only testify to facts experienced, not opinions

20
Q

What is an Expert witness

A

A qualified third party whose testimony can be accepted in a criminal or civil case
Permitted to issue opinions/ conclusions on matters that relate to their expertise