email and internet evidence

11
1 Email and Internet Evidence Mark Pollitt Associate Professor, Engineering Technology

Upload: sutton

Post on 06-Jan-2016

24 views

Category:

Documents


0 download

DESCRIPTION

Email and Internet Evidence. Mark Pollitt Associate Professor, Engineering Technology. Web 1.0 Technologies. Technologies Email Web Skype IM Web 1.0 because: Static content Application standards Client based. Forensics on Web 1.0 Technologies. Focus on two elements: - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: Email and Internet Evidence

1

Email and Internet Evidence

Mark PollittAssociate Professor,

Engineering Technology

Page 2: Email and Internet Evidence

Web 1.0 Technologies

• Technologies– Email– Web– Skype– IM

• Web 1.0 because:– Static content– Application standards– Client based

Page 3: Email and Internet Evidence

Forensics on Web 1.0 Technologies

• Focus on two elements:– The application– The data

• Looking for:– The content– The connections

Page 4: Email and Internet Evidence

Applications

• Developers need to build three things into communications applications:– User interface– Data processing/storage– Communications protocols

• Multiple Applications can share a common protocol– Outlook, Thunderbird, Zimbra– Hotmail, Yahoo, Gmail

Page 5: Email and Internet Evidence

Web Browsers

• All share HTML• Some support other technologies:– Active X, Flash, XML, etc.

• All store a cache of recent files and a history– Most store those differently– Usually, it takes a specific tool to look at browser

histories• Documenting both Internet history and

reconstructing web pages is important evidence

Page 6: Email and Internet Evidence

Doing Browser Forensics

• Know how the browser stores data• Know the location of the data• Have a tool that can read that data• Great resources:

http://www.symantec.com/connect/articles/web-browser-forensics-part-1http://www.symantec.com/connect/articles/web-browser-forensics-part-2

Page 7: Email and Internet Evidence

Email

• Very simple in concept:– Client/Server– SMTP protocol

• Two basic interfaces:– Web mail (Hotmail, Yahoo, Gmail)– Client based (POP, IMAP, SMTP)– Some support both

• Features vary by client

Page 8: Email and Internet Evidence

Email Clients

• Like Browsers, they share some features:– Communications protocols (POP, IMAP, SMTP, etc.)– User Interface– Storage – usually some form of database

Page 9: Email and Internet Evidence

Internet History Browsers

• Nirsoft – IEHistory View/Mozilla Cache View• Security Exploded – Browser History Spy*• Sqlite Viewer - Firefox

Page 10: Email and Internet Evidence

Email Investigations

• Client Software– Outlook– Thunderbird– Zimbra

• Forensic Suites– EnCase– FTK

• Webmail– Use browser forensics

Page 11: Email and Internet Evidence

Thank You for your Attention!