The Newberry Group Blog RSS Feed
http://www.newberrygroup.com/feedGen.aspxThe latest Blog Entries from The Newberry Group.(c) 2017The Newberry Group.5Technical Considerations for IP Theft - Part 6 in a 6 Part Series<p style="margin: 0in 0in 10pt;"><em>(scroll down for parts 1-5)</em><br />
<br />
Technical Considerations for IP Theft</p>
<p style="margin: 0in 0in 10pt;">Over the past 5 blogs, I have talked about IP theft and focused on two cases; one case that was done correctly and one case, which in my opinion could have been done better. Now I get to the question that organizations always ask after they have been through an IP case… Can IP theft be stopped or at least reduced?</p>
<p style="margin: 0in 0in 10pt;">Short answer is, no, theft of IP (intellectual property) can’t be completely stopped, but you can greatly reduce the ways that data is taken and the amount of data that is taken. On top of that, you can get alerted earlier that IP is being taken. There is no technology that is going to provide a silver bullet to solve all of your problems. To be honest, solving the problem does not even start with having the appropriate technology in place. It starts with those words that most people in IT hate; Policies and Procedures. Without strong, consistently enforced policies and procedures, putting in expensive monitoring technology could be a waste of time and money.</p>
<p style="margin: 0in 0in 10pt;">Review Your Policies</p>
<p style="margin: 0in 0in 10pt;">Most companies have at least some policies in place, but let’s be honest, how often do they get updated? How often is the employee handbook reviewed with employees? Do they just have to hand you a piece of paper saying they read it? How well versed is IT in the polices that are out there? Has IT seen these policies and agreed they are enforceable with the current technology that is in place? Is an after action review held after every incident of IP theft so policies and procedures can be reviewed and updated? Do you have policies in place that address BYOD (Bring Your Own Device), Cloud or Social Media? Or is it still not mentioned? If the answer is no, to any one of those questions – you may already have unwittingly made it easier for people to get away with stealing IP.</p>
<p style="margin: 0in 0in 10pt;">Policies are pretty easy. They are NOT paragraph after paragraph of bloated legal language. Policies need to be short and to the point. It is my opinion that a policy should be no longer than 3 sentences. With that being said, most policies can be written with one sentence. Think of this as a policy “Any device that connects to the corporate network will be monitored” or “ABC Company allows employees to use their own phone for work as long as they sign the BYOD agreement”. These are both short and to the point. There is no question what they mean, however the meat of a policy is in the procedure that is attached to that policy. A policy may stay the same for years, but the procedures for that policy may change often. These procedures can be very detailed and in a lot of instances, are written based on the type of technology that the organization has in place to enforce the policy.</p>
<p style="margin: 0in 0in 10pt;">Now let’s jump to that new hire. Did they get a handbook or at least some corporate documentation when they started? While I am not an HR specialist, I have learned over the years that certain paperwork needs to be given to an employee or your IP theft case could potentially get thrown out. Some of the key documents that every employee needs to be given on the first day of their employment are:</p>
<ul>
<li>Acceptable Use Policy </li>
</ul>
<ul>
<li>Email and Internet Usage Agreement </li>
</ul>
<ul>
<li>Confidentiality Agreement </li>
</ul>
<ul>
<li>Proprietary Information Agreement </li>
</ul>
<p style="margin: 0in 0in 10pt;">And when an employee leaves:</p>
<ul>
<li>Return of Company Property Document (Employee signs at departure) </li>
</ul>
<p style="margin: 0in 0in 10pt;">Most of these documents are self-explanatory, but there are a few things that I want to highlight. Work with your legal counsel so the documents confer the message that the employee has “no right to privacy” and that the company has the “right to monitor”. Without these two statements, many types of technology that you could use to detect theft of IP would be an invasion of privacy in the workplace, and your case could potentially get thrown out. We also recommend that companies go one step further and create a logon banner for the computer or when a device first attaches to their network that states there is no right to privacy and they will be monitored. In addition, it is important that the policies also state that data is company property not just devices like so many people initially think.</p>
<p style="margin: 0in 0in 10pt;">Another important step is to make sure that you have a termination plan which ensures that everyone who leaves the organization, either voluntary or involuntary is handled the same way: access to all their accounts are shut off, devices that are the property of the organization are returned, and the return of company data and documents is verified. Suggestions for inclusion into the termination plan:</p>
<ul>
<li>Creation of a “Return of Company Property Document” which would be signed by employee upon termination or resignation and verified by IT, </li>
</ul>
<ul>
<li>Outline when IT is notified of an employee’s departure, </li>
</ul>
<ul>
<li>Outline when IT shuts off all access to all accounts the employee has access to. </li>
</ul>
<p style="margin: 0in 0in 10pt;">You would be surprised how often this step is skipped because HR doesn’t tell IT right away when someone leaves.</p>
<ul>
<li>Outline the creation of forensic images of all the electronic devices and network shares, including hard drives, corporate email, USB devices, home and public network shares, </li>
</ul>
<ul>
<li>Determine when you will ask for and create forensic images of any BYOD item that the employee was allowed to use while employed, this would be outlined in the BYOD agreement, </li>
</ul>
<ul>
<li>Determine a place to store all images which is a secure and fault tolerant location, </li>
</ul>
<ul>
<li>Outline who will wipe their work hard drive, </li>
</ul>
<ul>
<li>And after the drive has been wiped, when to re-install the corporate standard “gold” image. If you don’t have a “gold” image, we suggest one be created and be used moving forward. </li>
</ul>
<p style="margin: 0in 0in 10pt;">After you are done with the creation of a termination plan, it is time to create a forensic readiness plan. This plan is designed to outline, depending on the employee that leaves, what if any forensics investigation will be done on the employee’s devices that they returned, which were imaged during the termination process.</p>
<p style="margin: 0in 0in 10pt;">The last thing that needs to be in place is a corrective action and reporting plan. This plan is created with help from your human resources (HR) folks. Once you put technology in place to detect the theft of IP, it will also pick up “other issues” inside the organization that will need to be handled. IT and HR need to make sure that everyone is treated the same, no matter who they are. If you are not consistent in the ways you treat employees, you could face a wrongful termination claim in the future. Consistent enforcement of this plan will hopefully prevent that from happening. </p>
<p style="margin: 0in 0in 10pt;"><b>Corporate security as a Tootsie-Pop<a href="#_edn1" name="_ednref1"><b><span style="line-height: 115%; color: #0000ff; font-size: 11pt;">[i]</span></b></a>: IP Theft Detection Technology</b></p>
<p style="margin: 0in 0in 10pt;">Now that you have gotten your policies and procedures in order, it is time to think about what technology you might want to have in place to help with the detection of data leaving. I refer to corporations and their security as a Tootsie-Pop, you know with the hard crunchy shell and a soft gooey center.</p>
<p style="margin: 0in 0in 10pt;">Corporations spend millions to keep people out that don’t belong, with firewall and IDS/IPS devices. While these types of devices are very important for all organizations to have in place, they forget that sometimes, the largest danger is from within the organization, the trusted employees. I call this Internal Threat Management. </p>
<p style="margin: 0in 0in 10pt;">For years, Internal Threat Management has been a manual process. Just as I outlined in my previous blogs, a corporation thought that they might have a problem for various reasons and they sent the devices for us to look through for signs of IP Theft. This manual detection process is a good start, but with anything that is manual there is a chance that something can get missed or the employee is technically savvy and was able to cover their tracks.</p>
<p style="margin: 0in 0in 10pt;">As technology has gotten more advanced, we are moving Internal Threat Management into a world where corporations are starting to be able to automatically prevent data from leaving. This advanced technology makes things easier to demonstrate corporate compliance, instills confidence in the organization, and most importantly, saves time and money. A lot of people for simplistic reasons, call this data loss prevention.</p>
<p style="margin: 0in 0in 10pt;">When you dig into data loss prevention, there are actually two main areas, Device Control and Network Content Monitoring.</p>
<p style="margin: 0in 0in 10pt;">Our first recommendation of technology to put in place is Device Control. Most employees that take IP with them on departure do so by using USB drives. Device control allows you to know what external devices have been hooked up to the system. Depending on the technology chosen, you will be able to:</p>
<ul>
<li>See what files/folders have been copied on/off the device, </li>
</ul>
<ul>
<li>Allow or deny specific devices depending on a list of variables, </li>
</ul>
<ul>
<li>Make copies of all files that have been copied into a “safe area” so that they can be later viewed for investigation reasons (note: don’t make this the “C Drive” as it is easy to wipe), </li>
</ul>
<ul>
<li>Make devices read only, </li>
</ul>
<ul>
<li>Allow coping/moving of files based on a list of variables (i.e. block MS Word files, but allow photos), </li>
</ul>
<ul>
<li>Block coping of files based on keywords. </li>
</ul>
<p style="margin: 0in 0in 10pt;">For example, a client of ours which has device control in place, upon the departure of an employee will pull up the device control logs for that employee to see what actually happened prior to the employee leaving. Those logs are then compared to the Return of Company Property Document to help with validation that all devices and IP has actually been returned.</p>
<p style="margin: 0in 0in 10pt;">Previously, I mentioned reverse IP theft, which is when a new employee brings that stolen IP from a previous employer in to use at your company. Another advantage of Device Control is that it can be setup so that it detects data coming onto your network, giving you a warning that reverse IP theft may be happening.</p>
<p style="margin: 0in 0in 10pt;">Network Content Monitoring is another type of technology we highly recommend to put in place to detect IP theft. This technology is a lot like an IDS/IPS device in that it watches network traffic. However, this technology watches traffic going in both directions for actual content. Meaning it is looking for readable text and looking for key words or concepts. Depending on the technology, it can also be setup to block content. We do not recommend that companies block. Blocking is very dangerous, as critical time sensitive documents may inadvertently get blocked due to content, so be very careful if you turn on blocking and be ready to respond to angry employees 24/7 when there are emails that don’t get sent.</p>
<p style="margin: 0in 0in 10pt;">For content monitoring, we highly recommend that you work with a 3<sup>rd</sup> party to monitor these logs so that no one with a potential conflict of interest is monitoring the logs. In addition, depending on the technology you choose, you might also identify HR related issues that need to be addressed which will call for utilizing your corrective action plan. Note: It is very important to have your updated policies and procedures in place before you turn on network monitoring. It will save time and headache in the long run.</p>
<p style="margin: 0in 0in 10pt;">Lastly – remember to do an after action report on every investigation of theft of intellectual property, no matter the result After action reports (AAR’s) are formal documents that are essential in evaluating performance, identifying areas of improvement within your policies and procedures, and proposing adjustments and recommendations for your policies, procedures, and implemented technology.</p>
<p style="margin: 0in 0in 10pt;">As you can see, stopping IP from leaving your company is not as easy as flipping a switch. It takes many moving parts to make the system work properly. Having HR, IT, and Legal all involved is necessary for it to be successful along with the proper technology and forensic services.</p>
<p style="margin: 0in 0in 10pt;">Newberry Group provides an array of solutions that can assist an organization in minimizing the loss of IP. Some of these include:</p>
<ul>
<li><a href="http://www.newberrygroup.com/Solutions/Cyber-Security-Services.aspx#securityprogram" target="_blank">Security Program and Policy Development</a>. Newberry aligns your business practices with contemporary risk models and effective governance to protect and support sustained growth. We provide recommendations for your team to implement, or we can manage and guide the process of establishing best practices in your organization. </li>
</ul>
<ul>
<li>Forensic Analysis of new and departing employee activity. Through our <a href="http://www.newberrygroup.com/Digital-Forensics/New-Hire-Program.aspx" target="_blank">New Hire Program </a>and <a href="http://www.newberrygroup.com/Digital-Forensics/Departing-Employee-Program.aspx" target="_blank">Departing Employee Program </a>we analyze digital evidence to determine what data is coming in to and out of your organization. Just as you are concerned with theft of your IP, you should also be concerned with IP that has been stolen from a competitor that is brought in. </li>
</ul>
<ul>
<li><a href="http://www.newberrygroup.com/Technologies/Forcepoint.aspx" target="_blank">Forcepoint’s SureView Insider Threat </a>detects suspicious activity, whether it is a hijacked system, rogue insider, or simply a user making a mistake. It ensures that your intellectual property or regulatory compliant data is not compromised. </li>
</ul>
<ul>
<li><a href="http://www.newberrygroup.com/Technologies/ForeScout.aspx" target="_blank">ForeScout CounterACT </a>for Network Access Control (NAC) is an automated security control platform that lets you see, monitor, and control everything on your network—all devices, all operating systems, all applications, all users. ForeScout CounterACT lets employees, contractors, and guests remain productive on your network while you protect critical network resources and sensitive data. </li>
</ul>
<ul>
<li><a href="http://www.newberrygroup.com/Technologies/Forcepoint.aspx" target="_blank">Forcepoint’s TRITON AP-DATA and AP-ENDPOINT </a>extends data security controls to enterprise cloud applications and to your endpoints. Safely leverage powerful cloud services like Microsoft Office 365, Google for Work and SalesForce.com, as well as protecting your sensitive data and intellectual property on Windows and Mac laptops, both on and off-network. </li>
</ul>
<p style="margin: 0in 0in 10pt;">For more information about these products or any others that we offer, contact us at <a href="mailto:[email protected]"><span style="color: #0000ff;">[email protected]</span></a> and we will be glad to have a discussion about what is best for you.</p>
<div><br clear="all" />
<hr align="left" size="1" width="33%" />
<div id="edn1">
<p style="margin: 0in 0in 0pt;"><a href="#_ednref1" name="_edn1"><span style="line-height: 115%; color: #0000ff; font-size: 10pt;">[i]</span></a><span style="font-size: 13px;"> Tootsie-Pop is a registered <span style="color: #000000;">trademark of Tootsie Roll Industries and WorldPantry.com</span></span></p>
</div>
</div> <br /><i><a href='/Blog/?id=62'>Click here</a> for more information.</i><br/>Forensic Analysishttp://www.newberrygroup.com/Blog/?id=62Jeremy WunschMon, 24 Oct 2016 09:35:00 GMTTechnical Considerations When Working With Lawyers - Part 5 in a 6 Part Blog Series<p style="margin: 0in 0in 10pt;" class="MsoNormal"><span style="font-size: 13px;">As a forensic consultant, the phone is constantly ringing. Calls come from law firms and from corporations; you never know who you will be talking to when you pick up the phone. <span style="mso-spacerun: yes;"> </span>More importantly, the other unknown when you pick up the phone is the level of technical knowledge the person you are talking with has. <span style="mso-spacerun: yes;"> </span>Over the years, we have worked with people that we have had to educate on technology and in other instances we have dealt with technologically savvy individuals. I am not saying that your legal team needs to understand technology at the same level as your forensic consultant, but it is critically important to your case that whoever is involved, knows how to properly work a theft of IP case.<o:p></o:p></span></p>
<p style="margin: 0in 0in 10pt;" class="MsoNormal"><span style="font-size: 13px;">One of the first cases that I ever worked on for a theft of IP was with a senior partner of a mid-sized law firm.<span style="mso-spacerun: yes;"> </span>While talking with him, it was readily apparent that his understanding of technology was fairly low. He would never ask questions and wanted me to believe that he completely understood technology he was dealing with.<span style="mso-spacerun: yes;"> </span>As we worked together, I realized that I would have to mix case details with technology education, without making him realize I was teaching him.<span style="mso-spacerun: yes;"> </span>Lucky for us, the lawyer on the other side knew even less about technology than the lawyer I was working with. My client won their case and everyone was happy, but I have to share one last question that I was asked by the lawyer I had been working with after the case was completed.<span style="mso-spacerun: yes;"> </span>He asked - “What is a hard drive?”<span style="mso-spacerun: yes;"> </span>I was shocked.<span style="mso-spacerun: yes;"> </span>I didn’t know if I should laugh or cry, as we had been talking about data being stolen from hard drives throughout the entire case.<span style="mso-spacerun: yes;"> </span>From that moment on, I paid very close attention to the technical knowledge level of everyone that I worked with.<o:p></o:p></span></p>
<p style="margin: 0in 0in 10pt;" class="MsoNormal"><span style="font-size: 13px;">Before I continue, a disclaimer. I’m not here to tell you which law firm or specific lawyer you should work with.<span style="mso-spacerun: yes;"> </span>I’m not talking negatively about any specific firm or specific lawyer. <span style="mso-spacerun: yes;"> </span>But as my years of experience have shown me, I have found it very important that when you are selecting counsel for a case; make sure to retain lawyers that truly understand technology and that your case is not the first time that they have been involved with theft of IP.<span style="mso-spacerun: yes;"> </span>I would encourage asking for a list of theft of IP cases that they have taken to trial and ask for references.<o:p></o:p></span></p>
<p style="margin: 0in 0in 10pt;" class="MsoNormal"><span style="font-size: 13px;">And here is why.<o:p></o:p></span></p>
<p style="margin: 0in 0in 10pt;" class="MsoNormal"><b style="mso-bidi-font-weight: normal;"><span style="font-size: 13px;">Home Based Employee Case Study Continued:<o:p></o:p></span></b></p>
<p style="margin: 0in 0in 10pt;" class="MsoNormal"><span style="font-size: 13px;">I’m going to jump back in to our home based employee case study that we have been discussing in previous blog posts.<span style="mso-spacerun: yes;"> </span>Again, I am not here to say this is a bad firm, nor am I hear to say that the lawyers at the firm that I worked with should not be used again for cases like this.<span style="mso-spacerun: yes;"> </span>I want to point out opportunities to work the case differently, allowing the case to move along faster.<span style="mso-spacerun: yes;"> </span>Perhaps more importantly, potentially reduce and maybe even eliminate legal fees for our client.<o:p></o:p></span></p>
<p style="margin: 0in 0in 10pt;" class="MsoNormal"><span style="font-size: 13px;">Let’s recap a few of the key things that happened after we gave our initial findings report to the original law firm:<o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l2 level1 lfo1;" class="MsoListParagraphCxSpFirst"><span style="font-size: 13px;"><span style="mso-fareast-font-family: symbol; mso-bidi-font-family: symbol; mso-list: ignore;">·<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>Our client thought they would be better represented by having a law firm that was based in the location of the two employees that left.<o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l2 level1 lfo1;" class="MsoListParagraphCxSpMiddle"><span style="font-size: 13px;"><span style="mso-fareast-font-family: symbol; mso-bidi-font-family: symbol; mso-list: ignore;">·<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>The firm that they chose was a very large international firm.<o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l2 level1 lfo1;" class="MsoListParagraphCxSpMiddle"><span style="font-size: 13px;"><span style="mso-fareast-font-family: symbol; mso-bidi-font-family: symbol; mso-list: ignore;">·<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>The transition to the new law firm for our part of the case was not smooth. Weeks passed and no contact was made even though we were the only ones with “smoking gun” evidence in this case.<span style="mso-spacerun: yes;"> </span><o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l2 level1 lfo1;" class="MsoListParagraphCxSpMiddle"><span style="font-size: 13px;"><span style="mso-fareast-font-family: symbol; mso-bidi-font-family: symbol; mso-list: ignore;">·<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>Knowing that time was of the essence in order to get a TRO; concern was growing that I had not heard from the new law firm for weeks after I was told about the change.<o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l2 level1 lfo1;" class="MsoListParagraphCxSpMiddle"><span style="font-size: 13px;"><span style="mso-fareast-font-family: symbol; mso-bidi-font-family: symbol; mso-list: ignore;">·<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>When the new law firm called us, it as an associate of the senior partner that the corporation had hired, and we were told that they had received the report and that someone would get back to me.<o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l2 level1 lfo1;" class="MsoListParagraphCxSpMiddle"><span style="font-size: 13px;"><span style="mso-fareast-font-family: symbol; mso-bidi-font-family: symbol; mso-list: ignore;">·<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>Weeks went by and I received another call to “understand” the findings of the report.<span style="mso-spacerun: yes;"> </span>To the law firm’s defense, because of the home based network that one of the employees had, it was not your typical report and the complexity of the report would have been difficult for all but the most technical lawyers to understand.<o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l2 level1 lfo1;" class="MsoListParagraphCxSpMiddle"><span style="font-size: 13px;"><span style="mso-fareast-font-family: symbol; mso-bidi-font-family: symbol; mso-list: ignore;">·<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>In the end, the new law firm opted not to pursue a TRO against the two departed employees.<span style="mso-spacerun: yes;"> </span>They wanted to “play nice” assuming that the employees would just turn over their personal devices when requested to do so.<o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l2 level1 lfo1;" class="MsoListParagraphCxSpMiddle"><span style="font-size: 13px;"><span style="mso-fareast-font-family: symbol; mso-bidi-font-family: symbol; mso-list: ignore;">·<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>The employees each retained their own lawyers to fight turning over their personal devices and instead of heading to court to fight this battle of stolen IP, it was decided to opt for arbitration instead.<span style="mso-spacerun: yes;"> </span><o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 10pt 0.5in; mso-list: l2 level1 lfo1;" class="MsoListParagraphCxSpLast"><span style="font-size: 13px;"><span style="mso-fareast-font-family: symbol; mso-bidi-font-family: symbol; mso-list: ignore;">·<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>Upon the decision to go through arbitration, we did not hear from the new law firm for the next 8 months.<o:p></o:p></span></p>
<p style="margin: 0in 0in 10pt;" class="MsoNormal"><span style="font-size: 13px;">So we pick up the story 8 months later. To be honest, we thought the case had settled and we were not notified, as our emails and phone calls were going unanswered.<span style="mso-spacerun: yes;"> </span>Then out of the blue, I got a phone call from the associate at the firm.<span style="mso-spacerun: yes;"> </span>We were told that they were in settlement discussions with both of the former employees and they needed our help finishing up writing a settlement agreement. I asked them to send what they had up to this point and I would make changes and recommendations to it. <span style="mso-spacerun: yes;"> </span>What she told us next was very alarming.<span style="mso-spacerun: yes;"> </span>We were told that the agreement was actually in final stages of development and both the arbitrator and the lawyers for the other sides had already seen it.<span style="mso-spacerun: yes;"> </span>At this point, we knew we had a potential problem.<o:p></o:p></span></p>
<p style="margin: 0in 0in 10pt;" class="MsoNormal"><span style="font-size: 13px;">From the discussions 8 months prior, I had already figured out that both the associate and the senior partner at this firm had limited knowledge about technology.<span style="mso-spacerun: yes;"> </span>Because of the very technical details of this case with this large home network, concern was growing over what we might see in a settlement agreement that had been drafted without our help.<span style="mso-spacerun: yes;"> </span>When the document arrived, my suspicions were correct.<span style="mso-spacerun: yes;"> </span>It was one of, if not the worst settlement agreement that I had seen in 20 years being a forensics examiner.<span style="mso-spacerun: yes;"> </span>Here are some of the highlights:<o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo3;" class="MsoListParagraphCxSpFirst"><span style="font-size: 13px;"><span style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-list: ignore;">1.<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>One employee admitted that he still had the virtual machine (VM) that contained corporate email but yet the settlement agreement stated that they agreed to take at face value the word of the former employees that they had no data in their possession. <o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo3;" class="MsoListParagraphCxSpMiddle"><span style="font-size: 13px;"><span style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-list: ignore;">2.<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>The employees agreed to send the computers to check for IP, but there was no timeline for when the machines needed to arrive at our facility for forensics investigation.<o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo3;" class="MsoListParagraphCxSpMiddle"><span style="font-size: 13px;"><span style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-list: ignore;">3.<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>In the initial reports, we listed countless devices that were used and might contain stolen IP, and they didn’t ask for most of those devices to be sent to be investigated.<o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo3;" class="MsoListParagraphCxSpMiddle"><span style="font-size: 13px;"><span style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-list: ignore;">4.<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>We were prohibited from telling our lawyers and our corporate client what devices were actually coming in.<o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo3;" class="MsoListParagraphCxSpMiddle"><span style="font-size: 13px;"><span style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-list: ignore;">5.<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>We were prohibited from telling our lawyers and our corporate client how much data we were searching on the devices that came in.<o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo3;" class="MsoListParagraphCxSpMiddle"><span style="font-size: 13px;"><span style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-list: ignore;">6.<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>We were prohibited from telling our lawyers and our corporate client if we were finding any stolen IP.<o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo3;" class="MsoListParagraphCxSpMiddle"><span style="font-size: 13px;"><span style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-list: ignore;">7.<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>We were prohibited from telling our lawyers and our corporate client how much stolen IP we had found.<o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo3;" class="MsoListParagraphCxSpMiddle"><span style="font-size: 13px;"><span style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-list: ignore;">8.<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>We had to redact our invoice to remove any identifiable information that would inform the lawyers or our corporate client anything relating to points 4-7.<span style="mso-spacerun: yes;"> </span>Basically we were only able to hand them an invoice with a dollar amount and no supporting documentation.<span style="mso-spacerun: yes;"> </span>Not the way we usually do business.<o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 10pt 0.5in; mso-list: l1 level1 lfo3;" class="MsoListParagraphCxSpLast"><span style="font-size: 13px;"><span style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-list: ignore;">9.<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>Most importantly, the company that had their IP stolen had to pay.<o:p></o:p></span></p>
<p style="margin: 0in 0in 10pt;" class="MsoNormal"><span style="font-size: 13px;">Horrified does not even begin to describe how we felt about this agreement. <span style="mso-spacerun: yes;"> </span>This agreement failed to take in to consideration the type of technology in question and how that technology can not only be used to store IP but how we as a digital forensics company can identify our corporate client’s data contained on the machines and drives.<span style="mso-spacerun: yes;"> </span>We feared this agreement would end up being a very large and costly mistake. We raised our concerns with our client but they said they trusted the new law firm. <o:p></o:p></span></p>
<p style="margin: 0in 0in 10pt;" class="MsoNormal"><span style="font-size: 13px;">We suggested corrections/changes to technical aspects of the settlement agreement and at the same time, we created an internal protocol for how we were going to be handling the data that arrived from these two former employees.<span style="mso-spacerun: yes;"> </span>We were able to change the settlement so that the individuals would have to turn over anything that they had in their possession or household that could store electronic information.<span style="mso-spacerun: yes;"> </span>Items that this included were:<o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2;" class="MsoListParagraphCxSpFirst"><span style="font-size: 13px;"><span style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-list: ignore;">1.<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>All laptops/desktop computer (including ones belonging to kids/spouse)<o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2;" class="MsoListParagraphCxSpMiddle"><span style="font-size: 13px;"><span style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-list: ignore;">2.<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>All USB devices that were used at the former employer, their new employer and at home (including kids/spouse).<o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2;" class="MsoListParagraphCxSpMiddle"><span style="font-size: 13px;"><span style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-list: ignore;">3.<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>Cell/Smart phones that could store email or documents (including kids/spouse)<o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2;" class="MsoListParagraphCxSpMiddle"><span style="font-size: 13px;"><span style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-list: ignore;">4.<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>Cloud based storage accounts<o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2;" class="MsoListParagraphCxSpMiddle"><span style="font-size: 13px;"><span style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-list: ignore;">5.<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>Online email (ie, gmail, yahoo, etc)<o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2;" class="MsoListParagraphCxSpMiddle"><span style="font-size: 13px;"><span style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-list: ignore;">6.<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>All NAS and DAS devices<o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2;" class="MsoListParagraphCxSpMiddle"><span style="font-size: 13px;"><span style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-list: ignore;">7.<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>Their new work computer<o:p></o:p></span></p>
<p style="text-indent: -0.25in; margin: 0in 0in 10pt 0.5in; mso-list: l0 level1 lfo2;" class="MsoListParagraphCxSpLast"><span style="font-size: 13px;"><span style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-list: ignore;">8.<span style="line-height: normal; font-variant: normal; font-style: normal; font-size: 7pt; font-weight: normal;"> </span></span>Their new work email and network shares<o:p></o:p></span></p>
<p style="margin: 0in 0in 10pt;" class="MsoNormal"><span style="font-size: 13px;">The reason we created that list is that we had evidence that the stolen IP had been moved and stored on some of the first 6 types of devices listed.<span style="mso-spacerun: yes;"> </span>Based on our experience, we assumed that the data also made its way to the new work computer and network. It took a few more months, but the technical changes we suggested finally made their way into the settlement agreement.<span style="mso-spacerun: yes;"> </span><span style="mso-spacerun: yes;"> </span>Our requests to remove the language which did not allow us to effectively communicate was not granted so points 4-7 remained in the settlement agreement. I knew this was a disaster waiting to happen as we had never not been allowed to talk to our client about what was happening – especially when they were paying for the work.<o:p></o:p></span></p>
<p style="margin: 0in 0in 10pt;" class="MsoNormal"><span style="font-size: 13px;">Jumping ahead, some of the devices from the large home network started to show up.<span style="mso-spacerun: yes;"> </span>Surprise! The devices we received had large amounts of storage space and they were all pretty full. We quickly realized that we would not be searching a few GB’s of data; we were going to be searching terabytes and terabytes of data (one device alone had 8 terabytes on it) blowing our price estimates out of the water.<span style="mso-spacerun: yes;"> </span>But now we have a problem – we can’t tell our client any of this, but they are asking for an estimate of what the cost would be.<span style="mso-spacerun: yes;"> </span>When we told them a dollar number, there was dead silence on the phone. Then there was anger.<span style="mso-spacerun: yes;"> </span>Then there was a demand to tell us how we got that number and all we could say was there is a lot of data but I can’t tell you anything else because of the settlement agreement. <span style="mso-spacerun: yes;"> </span>They had no idea the amount of data that we were being sent, and we had not even received 50% of the data yet.<span style="mso-spacerun: yes;"> </span>It was finally beginning to sink in to them that this might not have been a very good settlement agreement. The project was immediately put on hold due to cost considerations.<o:p></o:p></span></p>
<p style="margin: 0in 0in 10pt;" class="MsoNormal"><span style="font-size: 13px;">We told them that there was not much we could do unless some part of our hands were untied.<span style="mso-spacerun: yes;"> </span>The attorneys went back and got part of the settlement agreement removed so I could now tell them how many devices had come in and how much data was on each device. When we told them – their jaws dropped. But yet, I still could not tell them how much IP I was finding.<o:p></o:p></span></p>
<p style="margin: 0in 0in 10pt;" class="MsoNormal"><span style="font-size: 13px;">The law firm decided to have us search for very specific extensions to reduce costs.<span style="mso-spacerun: yes;"> </span>While this might sound like a reasonable idea to reduce cost, we had already found IP in file formats that were images, audio and video.<span style="mso-spacerun: yes;"> </span>The only way to search these types of documents is to actually put “eyes on the file”, meaning someone would have to take the time to review each one.<span style="mso-spacerun: yes;"> </span><span style="mso-spacerun: yes;"> </span>The law firm and the client decided in a cost benefit analysis it was not worth having someone review those non searchable files. <o:p></o:p></span></p>
<p style="margin: 0in 0in 10pt;" class="MsoNormal"><span style="font-size: 13px;">The law firm also decided to reduce the number of devices that were going to be delivered to us.<span style="mso-spacerun: yes;"> </span>They had already agreed on doing the search and delete on a rolling production, meaning we would get a few machines to run the protocol on them and then send them back. Here is the problem with this scenario. If there were other machines still at their homes that were not sent to us, yet contained IP, they could very easily go ahead and move the files between machines.<span style="mso-spacerun: yes;"> </span>In our initial protocol, we would have looked for this type of file movement, but our original protocol was scrapped. The law firm had limited understanding of what technology could do and at what cost.<span style="mso-spacerun: yes;"> </span>They also decided not to take a look at all machines and devices in their household.<span style="mso-spacerun: yes;"> </span>This meant all the former employees had to do was say a computer belonged to their spouse, and they wouldn’t have to send it in for inspection, even if it contained IP.<o:p></o:p></span></p>
<p style="margin: 0in 0in 10pt;" class="MsoNormal"><span style="font-size: 13px;">All along we were ringing alarms bells to our client as much as possible.<span style="mso-spacerun: yes;"> </span>I even asked our corporate client, if you are not going to do it right, why even do it at all.<span style="mso-spacerun: yes;"> </span>They went silent and couldn’t answer the question.<span style="mso-spacerun: yes;"> </span>They finally came back to us confirming their trust in their law firm. Here is the sad reality.<span style="mso-spacerun: yes;"> </span>We finished the project with the new protocol developed by the law firm, objected to by us. The law firm wasted their clients’ money and after all was said and done; we know that the two employees still have copies of IP that they took. <o:p></o:p></span></p>
<p style="margin: 0in 0in 10pt;" class="MsoNormal"><span style="font-size: 13px;">The mistakes that were made by the new law firm because of their lack of understanding in both technology and IP theft cases were some of the worst we have ever seen. <span style="mso-spacerun: yes;"> </span>If you remember in my last blog post, the other case that I outlined had roughly 2000 documents stolen and they were awarded $14 million in damaged.<span style="mso-spacerun: yes;"> </span>In this particular case, there were millions of documents stolen (we assume well over 8 million files were stolen) and we believe that some of them are probably still in the employee’s possession. In the end, our client was awarded nothing due to the settlement agreement, yet they had more than $1 million in legal and third party fees that they had to pay for out of pocket.<o:p></o:p></span></p>
<p style="margin: 0in 0in 10pt;" class="MsoNormal"><span style="font-size: 13px;">The choice not to listen to our expert advice and the decision to “play nice” backfired costing the corporation millions in legal and other associated fees and their competition is probably using their IP as we speak.<span style="mso-spacerun: yes;"> </span>Had the law firm worked the case differently, understood the forensics process, and understood the capabilities of the technology, the company would have been able to have all the IP identified and removed and have the other side pay for it.<o:p></o:p></span></p>
<p style="margin: 0in 0in 10pt;" class="MsoNormal"><span style="font-size: 13px;">Moral of these stories - when you have a theft of IP case, do your due diligence. Do not assume that the law firm you currently utilize can handle a theft of IP case. Theft of IP is very serious and very costly. Make sure law firm treats it that way also.<o:p></o:p></span></p>
<p style="margin: 0in 0in 10pt;" class="MsoNormal"><o:p><span style="font-size: 13px;"> </span></o:p></p>
<p style="margin: 0in 0in 10pt;" class="MsoNormal"><o:p><span style="font-size: 13px;"> </span></o:p></p> <br /><i><a href='/Blog/?id=61'>Click here</a> for more information.</i><br/>Forensic Analysishttp://www.newberrygroup.com/Blog/?id=61Jeremy WunschThu, 28 Jul 2016 16:32:00 GMTReverse IP Theft - Know What's Coming In To Your Organization. Part 4 in a 6 Part Blog Series<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">As you have been reading my blog series about theft of IP when an employee departs, I have mentioned that reports have said that about 50% of all departing employees take intellectual property with them to their new employer. After all, chances are great that they got their new job because of the work that they did at their previous employer. </span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">We have been talking a lot about that departed employee and how to detect if and what data they may have taken. But now let’s turn things around. Your company is the one that has hired an employee that stole Intellectual Property (IP) and they bring it inside your company. How do you know they brought stolen IP in? Do you have some type of legal exposure? When they end up leaving your company, will they also steal IP from you? The list of concerns with employees bringing stolen IP inside can go on and on.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">Reverse Intellectual Property Theft is when a new hire brings stolen IP into your company. Chances are that in your hiring process, asking questions about stolen IP is not something that people think to ask about. Most companies that I have worked with rarely do much to discourage or stop IP from coming in until it is too late and they get caught. One simple measure to help discourage new employees bringing in stolen IP is to incorporate some documentation regarding n<span style="line-height: 115%;">o disclosure or use of Confidential Information of Others. The intent of this language is to make sure that the new employee is aware they are not to bring into your organization IP from another company. It should also address that they not use in the performance of their responsibilities at the Company any confidential or proprietary information, materials, trade secrets, intellectual property, or documents of a former employer or other third party that are not generally available to the public, unless the employee or the company has obtained written authorization from the former employer or third party for their possession and use</span><span style="line-height: 115%;">. </span> In addition, you might consider making random checks of new hires machines to make sure that other companies IP has not been brought in and outlining consequences if they do bring it in. </span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">While this won’t stop you from getting sued if data makes its way onto your network, it should make an employee think twice before doing it.</span></p>
<p style="margin: 0in 0in 10pt;"><b><span style="font-size: 13px;">Internal Employee Case Study Continued:</span></b></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">Now, let’s get back to our case studies. We are going to go back to the case study of that internal employee that left and went to work for the competition. As you may remember we were able to prove multiple things up to this point. The departed employee:</span></p>
<ul>
<li><span style="font-size: 13px;">Used a sync function on some of the last days of employment. </span></li>
</ul>
<ul>
<li><span style="font-size: 13px;">The sync function appeared to sync IP to one or two USB devices. </span></li>
</ul>
<ul>
<li><span style="font-size: 13px;">Multiple USB devices (over 20) were used on the computer, and some were only used during his final days of employment. </span></li>
</ul>
<ul>
<li><span style="font-size: 13px;">We put in a request through the lawyers to get our hands on the 20+ USB devices, but only 4 arrived. </span></li>
</ul>
<ul>
<li><span style="font-size: 13px;">One of the USB devices that arrived was never used at his old work. </span></li>
</ul>
<ul>
<li><span style="font-size: 13px;">We asked for and received access to his home computer. </span></li>
</ul>
<ul>
<li><span style="font-size: 13px;">We identified that most of the USB devices had been used on both his home and old work computer. </span></li>
</ul>
<ul>
<li><span style="font-size: 13px;">The home computer showed us that the two USB devices that we were looking for where both used on the home computer after his last day of employment. </span></li>
</ul>
<ul>
<li><span style="font-size: 13px;">Data from his former company had been opened on his home computer after he started his new job. </span></li>
</ul>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">It was at this point that the judge gave us access to his new work computer. As I mentioned in the previous post, we performed the “New Hire Program” package on his new work computer. This type of analysis is virtually the same as we perform when an employee departs but there is a key difference. We are now looking for data artifacts that show that data is moving onto, and not off of, the device that we are investigating. We also continue to look for USB devices; we are still searching for IP. However this time we are trying to match things up between the old employer’s computer, his home computer and his new employer’s computer. </span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">To correctly match everything up, we created a timeline for the three machines. It is important to note that to do this correctly, you need to make sure that you take into account the time zone of the computer you are analyzing, as some data movement is not far apart.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">When we started to look at his new work computer, we quickly identified that the key USB device had been used on the new work computer. Knowing the date and the time that the key USB device was plugged in, we started searching the work computer for data that was created after that date. Looking for files created within an hour of the time the device was plugged in; we found copies of files that appeared to be the stolen IP had been copied down to his new work computer. While this was a nice nail in the coffin, we finish our investigation process and what we found shocked even the new company.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">In-between his start date at the new company and the date we received his new work computer, he had already changed the IP taken from our client, his former employer, and updated it with his new employers company information and logos. For example: he took his former employers’ divisions business plan and executed a “find and replace” of the old company name to the new company name. He opened presentations and changed all the footers and logos to the new company. It was determined that he had repurposed roughly 100 of the 2000 files that he had taken by just removing the old companies name and logo.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">We reported our finding to our client’s legal team and they reported what we had found to the new company. In turn the new company immediately fired the employee. You might think the story ends there, but it does not. We continued our investigation, as we needed to be able to confirm that the repurposed IP had not made its way to the corporate network or to anyone else inside this company. </span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">Unfortunately, we were able to confirm that data that he had brought with him had already been copied up to the corporate servers and more importantly we found that the data had been emailed out to the team he worked with, his boss and to his peers. It was beginning to look like this data was spreading within the new company.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">All of this information was provided to the court. The judge in the case ruled that we needed to go into the new company and search their network shares, the computers of his boss, and all his peers to track down and delete all the IP that was stolen. Due to the volume and the extent of what was found, this deletion of IP took much longer than expected as we found that the people he had sent the data to had forward the data to others in addition to saving it to their network shares. Over time, the trail just kept growing and we kept on following it and deleting the data wherever it was found.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">As the search for stolen IP continues, we start the analysis on his boss’s computer and boy, were we surprised at what we found. An examination of the boss’s computer found that he had stolen IP from our client years prior to him starting at the company. We began to wonder if there was an insider that was sending the boss this information. Through deeper analysis of this newly found “old” IP, and from conversations with our client, we discovered that the boss had been an employee of our client. When he left, he also stole IP, brought it into and disseminated throughout the new company. Once this information was given to the new company, he too was fired.</span></p>
<p style="margin: 0in 0in 10pt;"><b><span style="font-size: 13px;">The Final Word of the Court:</span></b></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">Let’s jump forward in time. This case was not just about making sure that the data was removed from the new company servers and laptops and those two employees getting fired. Our client wanted the other company to reimburse them for all that they had spent on legal fees and all third party fees, including for the forensic work that had been done over the entire time period of this case. They were also asking for damages in addition to expenses. After a long trial, the judge ruled in favor of our client and awarded them over $14 million in damages and fees. As you can imagine, our client was very happy with the outcome.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">The company that hired these two employees on the other hand was not happy at all. At no time did anyone in the organization think that hiring one individual would cost them over $14 million. So to answer one of my original questions, yes, you do have legal exposure if you hire someone that brings in stolen IP to your company.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">Both companies involved in this matter have now taken additional steps during the hiring process to let all new hires know that bringing in outside data from previous employers is not allowed and it is cause for immediate termination. They have instituted simple forensic checks that give visibility to newly used USB devices and data that gets copied off of them. This data is randomly checked to make sure it is not from any of their previous employers. Utilizing the </span><a href="http://www.newberrygroup.com/Digital-Forensics/New-Hire-Program.aspx"><span style="color: #0000ff; font-size: 13px;">New Hire Program</span></a><span style="font-size: 13px;"> is how they are hoping to never have to experience a situation like this again.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">While you might think that awards like the court handed down are rare, they are not. In most cases that I have been a part of, if we prove that data was stolen, it is very common for legal fees and other third party expenses to be awarded back to the company that had their data stolen. We all know that legal fees are going up and cases like the ones I am presenting here are no longer considered anomalies. As I mentioned, employees will continue to take IP out of and bring it into organizations. And, with the increased legal action that is occurring as a result of the ease of identifying those malicious actions through expert forensic analysis, organizations are paying closer attention to the data flowing in and out of employees hands.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">The moral of this cautionary tale: Take precautions and make sure stolen IP isn’t being brought into your company. </span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">Coming up – I will finish the story of the second case study. Stay tuned!<br />
<br />
<span style="widows: 1; text-transform: none; text-indent: 0px; letter-spacing: normal; font: 13px/21px arial, helvetica, sans-serif; white-space: normal; color: rgb(0,0,0); word-spacing: 0px; -webkit-text-stroke-width: 0px;">For more information on these services as well as other Forensic-related services we offer, please visit our website at</span><a href="http://www.newberrygroup.com/" style="widows: 1; text-transform: none; text-indent: 0px; letter-spacing: normal; font: bold 14px/21px arial, helvetica, sans-serif; white-space: normal; color: rgb(153,0,0); word-spacing: 0px; text-decoration: none; -webkit-text-stroke-width: 0px;border: medium none;"><b><span style="padding-bottom: 0in; padding-left: 0in; padding-right: 0in; color: rgb(5,99,193); font-size: 13px; padding-top: 0in;border-width: 1pt;border-color: windowtext;">www.newberrygroup.com</span></b></a><span style="widows: 1; text-transform: none; text-indent: 0px; letter-spacing: normal; font: 13px/21px arial, helvetica, sans-serif; white-space: normal; color: rgb(0,0,0); word-spacing: 0px; -webkit-text-stroke-width: 0px;"><span class="apple-converted-space"> </span>or email us at<span class="apple-converted-space"> </span></span><a href="mailto:[email protected]" style="widows: 1; text-transform: none; text-indent: 0px; letter-spacing: normal; font: bold 14px/21px arial, helvetica, sans-serif; white-space: normal; color: rgb(153,0,0); word-spacing: 0px; text-decoration: none; -webkit-text-stroke-width: 0px;border: medium none;"><b><span style="padding-bottom: 0in; padding-left: 0in; padding-right: 0in; color: rgb(5,99,193); font-size: 13px; padding-top: 0in;border-width: 1pt;border-color: windowtext;">[email protected]</span></b></a></span></p> <br /><i><a href='/Blog/?id=60'>Click here</a> for more information.</i><br/>Forensic Analysishttp://www.newberrygroup.com/Blog/?id=60Jeremy WunschMon, 27 Jun 2016 13:00:00 GMTTemporary Restraining Orders. Part 3 in a 6 Part Blog Series<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">In my last blog post, I began two case studies. In both instances, we found that intellectual property had been taken when the employees left the company. Following our process, we created the Departing Employee Report that outlined all of our findings. We gave the report(s) to our clients and their external counsel. It is at this point in the story that these two very similar cases went in completely different directions.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">In most cases, after our client and their law firm have a chance to review our findings and determine a course of action we are typically asked to write either an affidavit or a declaration. We take the information in our report(s) and put it into an accepted legal format (the affidavit or declaration) that can be presented in court. Which document we create depends on the law firm we are working with. Typically one of these documents is presented with a TRO (temporary restraining order). </span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">When you hear TRO, many of you might immediate think of some type of harassment or abuse case. However a TRO has other purposes as well. One such instance that I have seen used over and over again in theft of Intellectual Property (IP) cases is requesting a TRO where the employee that left and took IP with them, not be allowed to go to work for the new company until the theft of IP case has been resolved in some manner. Typically in these cases where this type of TRO is requested, the law firm and the forensic company must move quickly so that the legal team has the information that they need to file for a TRO. </span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">I cannot stress enough how important speed is when working a case like this. Because if the new employee has already been working at the new company for a few months, there is a high likelihood that the information that was taken has already been disseminated around the new company and a TRO is less likely to be effective. While I am not saying that you can’t get a TRO after a few months, you can, but you will just have more hoops to jump through. This scenario alone is a great reason to have a relationship established with a forensic company that excels at investigating IP theft cases.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">Let’s get back to those two case studies. While these two case studies are of two companies in completely different industries, they are very much alike from a forensic standpoint. Data was taken upon employee departure, the departing employees went to work for the competitor and the companies hired external law firm to help. In both of these cases we were initially hired by the same law firm, a law firm that we had worked with for years and had a well-established process with. </span></p>
<p style="margin: 0in 0in 10pt;"><b><span style="font-size: 13px;">Internal Employee Case Study Continued:</span></b></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">For this case, we wrote an affidavit to go with the TRO and the documentation went to both the departed employee and the departed employees “new” company. The “new” company was a Fortune 100 company, they were large enough that their first response back to the TRO was “if we wanted that companies IP, we would have just bought them”. At this point, the fun really started.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">Along with the TRO, it was requested that the employee send all USB drives that they had used at our client’s company so that we could forensically examine them to find and remove our client’s IP. If our client’s IP was found on any of the devices, the court would uphold the TRO and the employee would not be able to work until the case was resolved.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">Based on the request, the former employee sent four USB drives. As you may remember from the previous blog post, we were expecting over 20 to show up. So the fact that we only got four devices surprised us and angered the legal team. However, we still analyzed the 4 drives that we were given. Once the serial numbers were identified, we realized that only 3 of the devices that were sent to us had been used at the former company. The one extra USB drive was completely new to us. In addition, the key USB device that we were looking for was not one of the four that was sent to us.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">All of this information was sent to the court, along with a request to get access to the former employee’s home computer. When the court learned that only 4 USB devices had been turned over, the court ordered that the home computer had to be sent to us for analysis.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">A few days later, the home computer arrived and performed the full departing employee analysis on the home computer. Undertaking a USB analysis on the computer, we were able to identify that most of the 20+ USB devices that we were looking for were also used on his home computer, along with several other USB devices that were used at home but not on his old work computer. During this investigation, it was discovered that the one USB device that we didn’t have information on, showed up as being used on his home computer. What was the most shocking/concerning to our client, was that the key USB device had been used on his home computer just after he had resigned.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">Since we had a lot of information about this key USB device, we performed some special searches for files that we knew had, at one time, resided on that device which belonged to his former employer, our client. We were able to determine that these files had been accessed and opened on his home computer, from that USB device after he had already started at the new company. These facts were presented to the court. The court did two things, first they granted the TRO and the employee couldn’t work anymore until the case was settled and secondly, the court gave us access to his work laptop. This upset his new company as they didn’t want to give up his work laptop. </span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">A few days after the court order, his new work laptop arrived in our forensic lab. Once the device was in our lab, we performed the New Hire Program package on his machine. Stay tuned to future blog posts to see what this uncovered and how both companies responded.</span></p>
<p style="margin: 0in 0in 10pt;"><b><span style="font-size: 13px;">Home Based Employee Case Study Continued:</span></b></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">In the case of the home based employee for this case study, things took a completely different spin once we delivered to outside counsel the report and they showed our client that had the employees leave. This company decided it would be in their best interest to change law firms and retain a firm in the state which the two former employees resided. I have worked many cases where our clients have changed law firms mid investigation, but this change did surprise me because the original law firm had a well know reputation for successfully litigating IP theft matters and I knew nothing about the new firm besides the fact that they were a very large international firm.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">Our client and the now former law firm had told me that our report had been sent to the new firm and that I would be hearing from them shortly. Weeks passed and I had heard nothing. Knowing that we were initially going down the path of a TRO for both these employees I was getting concerned that I had not heard from the new law firm. </span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">I contacted our client and let them know that I had not been contacted by the new law firm. They were surprised and said someone would reach out to me within 24 hours. Not one hour later, my phone rang. It was an associate at the new law firm. She said the partner asked her to touch base with me just to let me know that they got the initial report and they were working their way through it.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">The clock was ticking for a TRO and it still took them two more weeks before they called again. This time they actually asked me to step them through the report so that they could better understand what IP had been stolen. This call ended up being the first of many phone calls to discuss the report and help better understand it.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">In the end, the new law firm opted not to pursue a TRO against the two departed employees. They decided to “play nice”, reasoning that the employees would willing turn over their personal devices for us to search and remove all IP associated with their former employer. As you can imagine, that was not what happened. The employees each retained their own counsel, which vigorously fought any request to turn over their personal devices. In the end, instead of utilizing the courts to litigate the stolen IP, the decision was made to continue the “play nice”. It was decided they would pursue arbitration instead. It would be 8 months before I would hear from the new law firm again.</span></p>
<p style="margin: 0in 0in 10pt;"><b><span style="font-size: 13px;">Where to Go From Here:</span></b></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">As you can see, two cases that were nearly identical at the start, have taken off in different directions. Is there are right or wrong way to take these cases? I would say yes… Over the next few blog posts, I will explain why as we continue with these two case studies. In addition, I will take a look at some things you can do to both prevent IP from being taken from your company and from new hires bringing stolen IP into your company.</span></p>
<p style="line-height: 15.75pt; margin-bottom: 10pt;"><span style="font-size: 13px;"><span style="color: #231f20; font-size: 11pt;">Newberry Group has services that can support all of your needs in these areas. Our experienced team can conduct investigations that cover both the departing employee as well as the new hire for a fraction of the cost that you could incur should the examples above play out. Our <a href="http://www.newberrygroup.com/Digital-Forensics/Departing-Employee-Program.aspx" target="_blank"><span style="text-decoration: underline;">Departing Employee Program </span></a>and <a href="http://www.newberrygroup.com/Digital-Forensics/New-Hire-Program.aspx" target="_blank"><span style="text-decoration: underline;">New Hire Program</span></a> are</span> <span style="color: #231f20; font-size: 11pt;">fixed fee programs that consists of defined computer investigation service packages that identify and report on employee data activity. The packages vary as to scope and cost in order to provide you with a level of assurance proportionate to the value of the employee and the access that the employee had to your IP.</span> </span></p>
<p style="line-height: 15.75pt; margin-bottom: 10pt;"><span style="color: #000000; font-size: 11pt;"><span style="font-size: 13px;">For more information on these services as well as other Forensic-related services we offer, please visit our website at </span><a href="http://www.newberrygroup.com/"><b><span style="padding-bottom: 0in; padding-left: 0in; padding-right: 0in; color: #0563c1; font-size: 13px; padding-top: 0in;border-width: 1pt;border-color: windowtext;">www.newberrygroup.com</span></b></a><span style="font-size: 13px;"><span class="apple-converted-space"> </span>or email us at<span class="apple-converted-space"> </span></span><a href="mailto:[email protected]"><b><span style="padding-bottom: 0in; padding-left: 0in; padding-right: 0in; color: #0563c1; font-size: 13px; padding-top: 0in;border-width: 1pt;border-color: windowtext;">[email protected]</span></b></a></span></p>
<p style="line-height: 15.75pt; margin: 0in 0in 10pt;"><span style="color: #000000; font-size: 11pt;"> Next Blog: Reverse IP Theft</span></p> <br /><i><a href='/Blog/?id=59'>Click here</a> for more information.</i><br/>Forensic Analysishttp://www.newberrygroup.com/Blog/?id=59Jerermy WunschWed, 08 Jun 2016 12:06:00 GMTWhen The Threat Strikes. Part 2 of a 6 Part Blog Series<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">As I mentioned in my first blog post, the internal threat is very real and it strikes ALL companies. (Yes, even forensic companies that investigate internal threats.) The smallest company that I have identified theft of IP during employee departure had 5 employees. The largest client was a Fortune 100 company whose name all you would instantly recognize. Even forensics companies are not immune. When I was the CEO at LuciData, I had a former forensic investigator leave and “take” IP with him to start a competing company. It happens all the time. Numerous articles quote statistics that over 50% of departing employees take IP when they leave.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">50% is a pretty large percentage of people. Think of how many employees have left your company. Think about what information they had access to. Now assume that 50% did actually take information and brought it to a competitor. What would a competitor be able to do once they got their hands on that data? What would the impact be to your company should that happen? Loss of revenue, loss of competitive advantage?</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">Theft of your IP has happened to you with or without your knowledge. It might be happening right now and you don’t know it. In this blog and other blogs to follow; I am going to step through two examples of internal theft: an internal employee working at the office and a home based employee that was granted remote access to the network. The blogs will address what was done right and what could have been done better. </span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">There are always lessons to learn with departing employees, and most of those lessons deal with controlling your data better.</span></p>
<p style="margin: 0in 0in 10pt;"><b><span style="font-size: 13px;">Internal Employee Case Study:</span></b></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">This was not the first time that our client had called us to investigate a potential theft of IP from a departing employee. We had put in place a protocol to cover the first initial steps to investigate any departing employee that they suspected of taking IP.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">As with all the other cases with this company, a “key employee” had departed, moved across the country to work for a competitor. What caused our clients suspicion was that the competitor did not have a marketable “product” like the employee had been working on for our client, but the competitor was trying to get a foothold into that space. The data that this employee had access to was incredibly valuable to the competitor.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">As we were completing the initial first steps of the protocol and started digging into the data, there were red flags that we discovered that started to raise questions for us. The first red flag we found was the sheer number of USB devices that had been used on the computer; including a few devices that were used during the last few days of his employment with our client. While devices used on the last few days of employment don’t always point to a problem, for some of these devices, it was determined that it was the first time that they had ever been used. </span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">The next red flag we saw was that a special folder sync function had been run. This function was setup to sync multiple folders from the employee’s computer to what was labeled as “other device”. This meant that it could sync to something like a network share or to a USB device, basically anything that wasn’t internal to the computer.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">What was helpful to us was that this sync function left a log of the folders that it was syncing with, along with the last time that the sync took place. Unfortunately, the folders that were synced were deleted by the former employee. Not to be deterred, using our forensics capabilities, we were able to recover the deleted folders and found just over 2,500 files in those folders that had been synced to other devices. A copy of the recovered files list was given to the client to review and determine the “value” of the data. We determined that most of the files contained documents that had “confidential” or “internal use only” written on the documents, leading us to believe these indeed would be very valuable documents to a competitor – a fact that was quickly confirmed by the client.. Our client asked us to immediately start working on determining if we could tell them where these documents went to (other devices, network share etc.)</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">Using time information from both the USB and the sync function logs we were able to determine that the data went to one or two USB devices on the same day the employee turned in his resignation notice. We were able to determine the common name of the USB devices (like one gigabyte SanDisk) and we also had the serial number of the devices we could now start searching for. This information was given to our client so their Information Technology department could determine if the devices still resided in the former employee’s office or some other place within the company. When it was determined that the company did not have possession or access to these two USB devices and that the former employee most likely took them when he left, we helped our client’s counsel write the request for the former employee to turn over all USB devices that he used while employed at the company on that computer. Based on our initial USB analysis, we were expecting 24 USB devices to be turned over. With that request, the hunt for stolen IP began in earnest.</span></p>
<p style="margin: 0in 0in 10pt;"><b><span style="font-size: 13px;">Home Based Employee Case Study:</span></b></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">In this case, we have a home based sales employee that was allowed to use his own personal computer for work purposes. His request to use his home based computer was granted by management even though it was in violation of company policy. Because his personal laptop was a Mac, a request was made by the employee for a virtual machine partition to be placed on the machine so that he could use “normal” Microsoft Outlook for work related email. Again, a request granted by management and a violation of company policy.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">When the employee left our client’s employment to go to work for a competitor, the company wisely asked for his computer to “image” it to make sure they had access to his email that was in the virtual partition. However, this image was not a traditional forensic image. Luckily the image did capture all the data on the disk; which included all the Mac data and all the data in the Windows virtual machine. Confident that they now had a copy of his email allowing them to answer any customer questions that might arise, they returned his personal computer back to him without deleting the virtual machine that contained years of corporate email. They put the image on the shelf and did nothing with it.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">Shortly after this first resignation, a 2<sup>nd</sup> sales employee resigned. This employee was going to the same competitor as the first employee that left and this employee would reportto the first employee. Concern was rising that something nefarious might be going on as the competitor they went to work for was the number one competitor of our client. Losing both of these top sales people, was a grave concern in the very tight market that both these companies were in. For the purpose of this blog post and so we can keep them straight, we will name the home based employee with the Mac, Bob and the employee that left second, Steve.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">We were sent the work computer (which was a Windows computer) from Steve and we were sent the image of the home Mac computer that Bob used for work. We initiated our departing employee protocol to determine if there might have been any visible signs of solicitation and to determine if any confidential data may have been taken by either of them.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">While we did find signs that they were both communicating with each other, we didn’t find any signs that Bob asked Steve to leave and bring data with him. At that point, our investigation turned strictly into theft of IP and we began to look at each of them individually.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">Investigating both former employees’ computers, we determined that they both had USB drives hooked up to their computers. Both of them used those USB drives on their final days of employment. There were also signs that data may have been transferred over to those devices. We worked with our client and their legal team to request that Steve hand over all the USB drives that he had used during his employment. This process was pretty straight forward with Steve’s computer, Bob and his computer was another story.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">As we mentioned, Bob used his personal laptop for work. This a machine was also used by family members. Because of this, we were not completely sure the best way to ask for access to the devices, given the high likelihood that we would not be granted access to family member’s devices unless we could clearly prove that data had been transferred to that specific device. This computer had been used for years and not only were there traditional USB storage devices that had been hooked up to it, but there were also iPhones, iPads and iPods that had been attached to this machine. These devices, while traditionally used for other reasons, also have the ability to store data. </span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">Which devices were his, which belonged to his wife’s and his kids? As the investigation continued into Bob’s computer, we started to notice references to network storage devices, like network attached storage (NAS) and references to Apple’s Time Machine backup, which appeared to backup his entire laptop. Remember, Bob had the virtual machine that contained all his work email containing confidential information on this machine. We realized that the work email was in the Time Machine backup, so we had to make sure to request access to that backup as well. As it was becoming clear the type of home network that Bob had established, we realized that one of his NAS devices was syncing on a regular basis with his Mac. If you are able to follow the trail - we now know that work email is stored in at least three locations – on his personal Mac in the company provided VM, the Time Machine Backup and on the NAS. </span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">We gave our client a file list of some of the files on the Mac image that contained the word “confidential”. We handed over copies of documents, spreadsheets, PowerPoints and PDFs for them to look through. It was quickly determined by our client those files were very key to the company, and Bob should never have been allowed to leave with that data still on his personal Mac that he used for work. Like with Bob’s email, we were assuming that these files containing the documents, spreadsheets, PowerPoints and PDFs etc. were also on the Time Machine Backup and the NAS and potentially other USB devices.</span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">At that point, the lawyers knew what we needed access to, but with Bob’s non-traditional home network this wasn’t going to be your normal legal request. This was going to be a case with many unexpected twists and turns.</span></p>
<p style="margin: 0in 0in 10pt;"><b><span style="font-size: 13px;">Hurry up and wait.</span></b></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;">As with all cases, once we find that IP may have been taken during employee departure we provide our reports, declarations and/or affidavits. The lawyers then take over and it is hurry up and wait while the legal process runs its course. Stay tuned to the next blog post to see what happened with these legal requests and the corresponding TROs (Temporary Restraining Order).</span></p>
<p style="line-height: 15.75pt; margin-bottom: 10pt;"><span style="color: #000000; font-size: 9pt;"><span style="font-size: 13px;">Newberry Group has services that can support all of your needs in these areas. Our experienced team can conduct investigations that cover both the departing employee as well as the new hire for a fraction of the cost that you could incur should the examples above play out. Our<span class="apple-converted-space"> </span></span><a href="http://www.newberrygroup.com/Digital-Forensics/Departing-Employee-Program.aspx"><b><span style="padding-bottom: 0in; padding-left: 0in; padding-right: 0in; color: #0563c1; font-size: 13px; padding-top: 0in;border-width: 1pt;border-color: windowtext;">Departing Employee Program</span></b></a><span style="font-size: 13px;"><span class="apple-converted-space"> </span>is a</span></span><span style="font-size: 13px;"><span style="color: #231f20; font-size: 9pt;" class="apple-converted-space"> </span><span style="color: #231f20; font-size: 9pt;">fixed fee program that consists of defined computer investigation service packages that identify and report on employee data activity. The packages vary as to scope and cost in order to provide you with a level of assurance proportionate to the value of the employee and the access that the employee had to your IP.</span> </span></p>
<p style="line-height: 15.75pt; margin-bottom: 10pt;"><span style="color: #000000; font-size: 9pt;">Our Incoming Employee Package consists of 2 services. 1<sup>st</sup>, it verifies that policies and procedures are appropriate so new employees understand that under no circumstances should any IP from previous employers be brought with them. 2<sup>nd</sup>, at a predetermined time (usually 30-60 days after the employees start date), we will check the new hire’s drive for signs of external IP. If data is found, you can take immediate steps to remediate the data before any litigation commences. </span></p>
<p style="line-height: 15.75pt; margin-bottom: 10pt;"><span style="color: #000000; font-size: 9pt;"><span style="font-size: 13px;">For more information on these services as well as other Forensic-related services we offer, please visit our website at </span><a href="http://www.newberrygroup.com/"><b><span style="padding-bottom: 0in; padding-left: 0in; padding-right: 0in; color: #0563c1; font-size: 13px; padding-top: 0in;border-width: 1pt;border-color: windowtext;">www.newberrygroup.com</span></b></a><span style="font-size: 13px;"><span class="apple-converted-space"> </span>or email us at<span class="apple-converted-space"> </span></span><a href="mailto:[email protected]"><b><span style="padding-bottom: 0in; padding-left: 0in; padding-right: 0in; color: #0563c1; font-size: 13px; padding-top: 0in;border-width: 1pt;border-color: windowtext;">[email protected]</span></b></a></span></p>
<p style="margin: 0in 0in 10pt;"><span style="font-size: 13px;"> Next Blog: Temporary Restraining Orders (TRO)</span></p> <br /><i><a href='/Blog/?id=58'>Click here</a> for more information.</i><br/>Forensic Analysishttp://www.newberrygroup.com/Blog/?id=58Jerermy WunschWed, 08 Jun 2016 11:41:00 GMTThe hacker, the departing employee, the new hire. Which one can cost you more?
Part 1 of a 6 Part Blog Series<p style="margin: 0in 0in 10pt;">After almost 20 years of doing computer forensic investigations, and specializing in investigating data breaches and IP theft, I have realized a few things. Hackers are here to stay and those employees you trust the most can hurt you the most.<b></b></p>
<p style="margin: 0in 0in 10pt;"><b>The Hacker</b></p>
<p style="margin: 0in 0in 10pt;">Let’s start where most organizations are mistakenly focused, hackers. </p>
<p style="margin: 0in 0in 10pt;">Hackers are malicious but most are only looking to steal usernames and passwords but some do try to steal personally identifiable information (PII) to sell or they are looking to run some other type of scam with the stolen information. Rarely, do hackers steal data to create a competing product or service.</p>
<p style="margin: 0in 0in 10pt;">Yes, hackers cause harm. They steal identities; people fall for their scams. Hacks have been a daily occurrence for some time now. Most firms spend a lot of time and money trying to prevent them and have a budget set aside for investigating them. </p>
<p style="margin: 0in 0in 10pt;">But when we look back, what is the real cost to the organization of a hack? Google “cost of a hack” and you will find countless examples of what it costs organizations. But the numbers are all different. The real answer is that nobody knows. Realistically, unless you are part of some of the largest breaches in the world, the cost of a hack does not create a very large dent on the organizations profit and loss statement. The “official statement” says, sorry we were hacked, change your passwords and move on.</p>
<p style="margin: 0in 0in 10pt;"><b>The Departing Employee</b></p>
<p style="margin: 0in 0in 10pt;">This is my favorite person in the company. They are leaving for that new job. Why did they get that job? You guessed it, because of what they did at your company. </p>
<p style="margin: 0in 0in 10pt;">Organizations as a whole are still a trusting bunch. “Oh, my employees would not maliciously take information with them.” We hate to be the bearer of bad news – they will and it is probably happening a lot more than you realize. In the thousands of cases we have done over the years, I can count on one hand the number of times during an investigation where we didn’t find the employee stealing intellectual property (IP) and taking it with them.</p>
<p style="margin: 0in 0in 10pt;">If the departing employee left to start their own competing business or worse yet – went to your #1 competitor – more than likely they have taken some of your IP (think customer lists, pricing data, product development details, business planning details to name a few) with them to help them hit the ground running. It is time to start an investigation to see what they took.</p>
<p style="margin: 0in 0in 10pt;">When do you pull in legal? It all depends on the organization and if legal is in-house or not. But most pull in the legal team after it has been identified that IP may have been taken. Another key question when pulling in the legal team is to ask “do you have an experienced legal team to help you during the investigation?”</p>
<p style="margin: 0in 0in 10pt;">The “experienced legal team” is a delicate subject, but it must be brought up. While the organization is going through the investigation, it cannot be stressed enough: make sure your legal counsel – both inside and outside counsel understand the technology, the terminology and the forensics process.</p>
<p style="margin: 0in 0in 10pt;">Beware of what I refer to as the “Legal Tech Lawyer”. These are attorneys from firms that got their experience from going to a few conferences and listened to a few webinars yet consider themselves experts in technology cases. In addition, beware of outside counsel that does not have any actual experience in conducting cases that had computer forensics examinations in the area of IP theft. </p>
<p style="margin: 0in 0in 10pt;">Having an experienced legal team; especially experienced outside counsel that understand the process and what forensics technology can and cannot do will cost more per hour than an attorney that doesn’t, but in the end, it will be worth it. Not understanding the life cycle of an investigation; the differences in terminology, understanding the limitations of technology and what to ask for during the investigation will most likely cause the organization to incur additional downstream investigation fees because the investigation is not streamlined. Uneducated attorneys are less likely to ask pertinent questions, will have to do additional research to understand what they need to have done, may ask for things to be done that are not necessary, or miss finding critical evidence that is germane to your case. All of this will likely result in increased legal fees.</p>
<p style="margin: 0in 0in 10pt;">Legal expenses tend to be a very large chunk of the total cost of an IP theft investigation. Choosing the right attorney (s) is critical not only to the success of your investigation; but also to keeping your costs from spiraling out of control, especially when you are going after a temporary restraining order (TRO), and requesting access to both their home and “new work” computers. </p>
<p style="margin: 0in 0in 10pt;"><b>Your New Hire</b></p>
<p style="margin: 0in 0in 10pt;">Let us introduce you to your most expensive hire; the new employee that you just hired away from your #1 competitor. The employee that took IP from their previous employer, who brought IP with them and is currently using that IP in their new job with you.</p>
<p style="margin: 0in 0in 10pt;">You didn’t ask them to steal IP from their previous employer, but they did. You hired them because of their experience and their past contacts and connections. They told you they can help you beat their former employer; what they didn’t inform you about is they are bringing data with them that will be housed inside your walls. </p>
<p style="margin: 0in 0in 10pt;">This data now resides someplace on your network. It could be a little, it could be a lot. For example, maybe they took a PowerPoint presentation. They changed a few words and logos and now your next project is the exact same project they were working on at their previous company. They shared a copy with their boss. Their boss shared it with their boss who presented it at the national sales conference. You get the picture.</p>
<p style="margin: 0in 0in 10pt;">Now imagine this scenario. Their previous employer knows you have hired their employee and suspects that they have taken IP – lots of it. They hire a forensic company to look at the former employee’s work machine and they find IP was taken. They suspect you now have it. They want it back or eradicated and they want monetary damages. </p>
<p style="margin: 0in 0in 10pt;">The next thing you know, you are served with a TRO and litigation hold. You are getting sued by your new hires former employer for theft of IP. You know nothing about this, you didn’t ask them to take it, but they did. Courts are starting to open up the doors to allow forensic companies to investigate inside the “new company” to verify that the previous company’s data is or is not inside the new company. The Forensics Investigation Team has been allowed full access to email servers, network servers and storage, laptops and desktop, cell phones, tablets and cloud accounts that may have the stolen IP on them. </p>
<p style="margin: 0in 0in 10pt;">If that happens to you; more than likely your organization will be responsible for the cost of that investigation. If IP is found, the costs ramp up even further. The IP will have to be remediated and most likely the courts could issue some pretty large judgment against you. We have had cases where the judgment in 1 IP theft alone was upwards of twenty ($20) million dollars that the “new company” had to pay the “former company” because the departed employee took IP with them and used it at the new company. While judgements of this amount are not common, they do happen. It is becoming more common to get judgements against the new company of a few million plus all third party fees (legal, computer forensics, court costs, etc).</p>
<p style="margin: 0in 0in 10pt;"><b>What Can You Do To Be Proactive?</b></p>
<ol>
<li>Have an appropriate IT budget to spend on and implement monitoring solutions that watch internal employees in how they use the organizations data. Whether it is device control, DLP solutions or BYOD technology – having monitoring technology is a must these days. </li>
</ol>
<ol>
<li>Have current AUP (acceptable use policy) and any other corporate policies governing the use of corporate data. Nothing is more painful than learning that you allow employees to take whatever they want. </li>
</ol>
<ol>
<li>Be consistent in enforcing those policies. Precedent is a big word in the legal community and I have seen many cases lost on precedent. </li>
</ol>
<ol>
<li>Ask the right questions of legal team on their experience level in conducting forensics investigations. </li>
</ol>
<ol>
<li>Get an experienced Digital Forensics team that understands IP theft considerations for departing and incoming employees. </li>
</ol>
<p style="margin: 0in 0in 10pt;"><b>How can you protect yourself?</b></p>
<p style="margin: 0in 0in 10pt;">There are economical ways to forensically determine what data and or IP was taken from an organization or brought into an organization. An excellent program will:</p>
<ul>
<li>Have a well-defined AUP covering both incoming and outgoing IP. </li>
</ul>
<ul>
<li>Consist of defined computer investigation service packages that identify and report on employee data activity </li>
</ul>
<ul>
<li>Be able to identify data that was taken from your network as well as brought in to your network. </li>
</ul>
<p style="margin: 0in 0in 10pt;"><b>Conclusion</b></p>
<p style="margin: 0in 0in 10pt;">Hackers are here to stay. Most companies are well prepared to defend against hacks and have budgeted for such an event.</p>
<p style="margin: 0in 0in 10pt;">Employees will also continue to take IP. It is not a question of if IP theft will happen, it is a matter of when and at what cost to the organization. Most companies are not as well prepared to investigate theft of IP. Nor have they budgeted for what the potential investigation might cost them or what the effects of a theft might be – loss of revenue, loss of clients, loss of productivity, business interruption – the list goes on and on.</p>
<p style="margin: 0in 0in 10pt;">Does an investigation have to break the bank to learn what IP might be taken? No, it does not. Investigations can be streamlined, simplified and be cost effective if an organization has the proper team and services in place prior to kick off of an event.</p>
<p style="margin: 0in 0in 10pt;">As to the initial question that we started with, “The hacker, the departing employee, the new hire. Which one can cost you more?” Stay tuned to future posts to learn, but I can tell you, it isn’t the hacker.</p>
<p style="margin: 0in 0in 10pt;">Newberry Group has services that can support all of your needs in these areas. Our experienced team can conduct investigations that cover both the departing employee as well as the new hire for a fraction of the cost that you could incur should the examples above play out. Our <a href="http://www.newberrygroup.com/Digital-Forensics/Departing-Employee-Program.aspx"><span style="color: #0000ff;">Departing Employee Program</span></a> is a<span style="color: #231f20;"> fixed fee program that consists of defined computer investigation service packages that identify and report on employee data activity. The packages vary as to scope and cost in order to provide you with a level of assurance proportionate to the value of the employee and the access that the employee had to your IP.</span></p>
<p style="margin: 0in 0in 10pt;">Our Incoming Employee Package consists of 2 services. 1<sup>st</sup>, it verifies that policies and procedures are appropriate so new employees understand that under no circumstances should any IP from previous employers be brought with them. 2<sup>nd</sup>, at a predetermined time (usually 30-60 days after the employees start date), we will check the new hire’s drive for signs of external IP. If data is found, you can take immediate steps to remediate the data before any litigation commences. </p>
<p style="margin: 0in 0in 10pt;">For more information on these services as well as other Forensic-related services we offer, please visit our website at <a href="http://www.newberrygroup.com/"><span style="color: #0000ff;">www.newberrygroup.com</span></a> or email us at <a href="mailto:[email protected]"><span style="color: #0000ff;">[email protected]</span></a></p>
<p style="margin: 0in 0in 10pt;">Next Blog: Newberry Group’s Departing Employee Program.</p> <br /><i><a href='/Blog/?id=57'>Click here</a> for more information.</i><br/>Forensic Analysishttp://www.newberrygroup.com/Blog/?id=57Jeremy WunschFri, 26 Feb 2016 11:06:00 GMTSalvaging Digital Video Fragments<p>Digital video is becoming a more common form of digital evidence with the increasing prevalence of video in computers, mobile devices and cameras. Digital cameras can create high quality videos, most smart phones can create videos, and the iPad2 has two cameras that can create videos. The videos created by such digital devices can be stored on removable storage media and on the devices themselves. Frequent creation and deletion of videos on these kinds of devices can result in fragments of deleted video clips that most file carving tools cannot salvage. In addition, when dealing with Flash memory dumps acquired from mobile devices, data at the physical level is often fragmented. Specialized methods and tools are needed to salvage deleted video fragments as demonstrated in this article using the contents of Flash memory acquired from a Motorola V3 (RAZR) mobile device.</p>
<h3>File Carving Limitations</h3>
<p>Most file carving tools require a known file header in order to salvage deleted data. For instance, to recover a deleted 3gp file, most carving tools look for the file headers such as the following.</p>
<p><img alt="" src="/data/images/cmdLabsImages/image001.png" /><br />
<em>Hex view of 3gp header in the Motorola V3 Flash memory dump</em></p>
<p>If the file is fragmented or the header is missing, the file carving approach will not salvage the deleted video successfully. In this example, a file carving tool that searched the Motorola V3 memory dump for several 3gp header signatures found two files in as shown in the audit log: </p>
<ul>
<pre>05/24/2011, 11:26:35
QuickTime 3GP (3gp), header: ftypisom
QuickTime 3GP (3gp), header: ftyp3gp
QuickTime 3GP (3gp), header: ftypmmp4
Default file size: 1024 KB
Maximum file size: 100 times (individual file type definition defaults sizes respected)
E:\Physical GSM Motorola V3 RAZR\Flex Partition 1140000-1fe0000.bin
Scope: 000000 - E9FFFF
Extensive byte-level search
9D0E80 - AD0E7F: 00001.3gp
B888F0 - C888EF: 00002.3gp
05/24/2011, 11:26:35
2 file headers were found. 2 files were retrieved.
</pre>
</ul>
<p>However, the salvaged files were invalid because the original files were fragmented. Furthermore, the names and directory paths of these files were not obtained using this method, demonstrating a further limitation of file carving. <br />
<br />
</p>
<h3>Salvaging Video Fragments</h3>
<p>When video files are fragmented, it is necessary to consider the video file format in more detail. Fortunately, many digital video formats have a structure that can be used to find and salvage individual frames. A frame is a discrete section of the video that can have a timecode or sequence number and other characteristics that can be useful for salvaging digital video clips.</p>
<p>The <a target="_blank" href="http://defraser.sourceforge.net/">defraser tool</a> can be used to identify frames for several video formats in a forensic duplicate of any piece of storage media, including a removable storage card, computer hard drive and Flash dump from a mobile device. The following screenshot shows defraser used to detect video related data in the Motorola V3 memory dump.</p>
<p><img alt="" src="/data/images/cmdLabsImages/img_3.png" /><br />
<em>Defraser showing video related data in the Motorola V3 memory dump</em></p>
<p>Although the defraser tool does not automatically piece together the frames into a video that can be played, it does make the frames available for manual reconstruction. With some effort, defraser may be used to combine fragmented frames into a valid video file that can be played.</p>
<p>As with file carving methods that rely on header signatures, the carving methods employed by defraser do not provide the filenames and directory path of salvaged video data in the context of the original file system. </p>
<h3>File System Reconstruction</h3>
<p>Ultimately, the most effective approach to extracting digital video files from acquired digital evidence such as a Flash memory dump from mobile device is to reconstruct the logical arrangement of data. On mobile devices, this logical structure involves the flash abstraction layer and file system. Using mobile device forensic tools such as <a href="http://www.cellebrite.com" target="_blank">Cellebrite Physical</a> and <a href="http://www.msab.com" target="_blank">XRY</a>, it is possible to reconstruct and review logical file structure of a Flash memory dump as shown below with a 3gp video stored in an MMS related file in the Motorola V3 memory dump. Note that different tools may interpret the logical structure differently and show more files and folders, clearly demonstrating the importance of validating the results of forensic examination tools.</p>
<p><img alt="" src="/data/images/cmdLabsImages/img_5.png" /><br />
<em>XRY/XACT showing the logical file system in the Motorola V3 memory dump</em></p>
<p><img alt="" src="/data/images/cmdLabsImages/img_7.png" /><br />
<em>Cellebrite Physical showing the logical file system in the Motorola V3 memory dump</em></p>
<p>Extracting the MMS file using such a mobile device forensic tool and extracting the video content as discussed in the “<a href="http://www.cmdlabs.com/Blog/Default.aspx?id=24" target="_self">Delving into Mobile Device File Systems</a>” blog post results in a 3gp file that can be played using VLC media player.</p>
<p><img alt="" src="/data/images/cmdLabsImages/image009.png" /><br />
<em>Playing salvaged digital video using VLC Player</em></p>
<h3>Examination of Salvaged Video</h3>
<p>After salvaging digital video files it is important to review the resulting data closely for potential anomalies. For instance, using MediaInfo [http://mediainfo.sourceforge.net/en] to extract metadata from video files shows details related to its creation and format. The following screenshot shows metadata from a 3gp video extracted from the Motorola V3 memory dump, revealing that the embedded date-time stamp was set to an incorrect date. </p>
<p><img alt="" src="/data/images/cmdLabsImages/image011.png" /><br />
<em>Metadata within a 3gp video displayed using MediaInfo</em></p>
<p>In addition, reviewing individual frames within a salvaged video file can reveal anomalies such as portions of two unrelated videos being combined into one salvage file. The following screenshot shows frames extracted from a 3gp file using DCCI Video Validator [http://video-validator.sourceforge.net/] revealing footage from two unrelated video files.</p>
<p><img alt="" src="/data/images/cmdLabsImages/videovalidator3.png" /><br />
<em>Frames extracted from digital video using DCCI Video Validator</em></p>
<h3>Conclusions</h3>
<p>When a video file is fragmented or the header of a video file is overwritten, carving methods that rely on header signatures and contiguous files will not salvage video files successfully and may even incorrectly combine unrelated video fragments into a single file or fail to detect the presence of video content altogether. However, using specialized tools such as defraser, a digital investigator may be able to salvage fragments of video files and piece them together into a valid video file. This process of reconstructing video fragments is time consuming and error prone, particularly when dealing with numerous video files on a single piece of storage media or mobile device. Therefore, whenever feasible, it is preferable to reconstruct the logical arrangement of data to extract the complete content of video files. Whichever method is most effective for salvaging digital video, it is important to examine the results closely to ensure the accuracy and completeness of the resulting videos. Such a review includes inspecting embedded metadata for anomalies and reviewing keyframes for possible fragments of unrelated video footage.</p> <br /><i><a href='/Blog/?id=18'>Click here</a> for more information.</i><br/>Forensic Analysishttp://www.newberrygroup.com/Blog/?id=18Eoghan CaseySat, 17 Dec 2011 15:11:00 GMTWinner of DFRWS2011 Forensics Challenge Announced<p>This year Eoghan Casey worked with Tim Vidas at Carnegie Mellon University and Matthew Geiger at CERT to create the DFRWS Forensics Challenge in an effort to advance forensic analysis of Android mobile devices. The winners of the challenge were Ivo Pooters, Steffen Moorrees and Pascal Arends from Fox-IT. Their submission provides a suite of utilities written in Python for extracting information from data acquired from Flash memory on Android devices. Complete results are posted on the DFRWS Web site.</p>
<p>The scenarios for the DFRWS 2011 Forensics Challenge were two seemingly unrelated crimes that turned out to be tightly linked with each other. The first scenario was a suspicious death and the goal of the investigation was to determine whether the victim killed himself or was murdered. The second scenario was an intellectual property theft case and the goal of the investigation was to document any evidence that intellectual property was stolen and to support termination of the suspected insider.</p>
<p>An interesting outcome of the challenge was that using dd to acquire data from the Android device in Scenario 1 did not copy the important information in out-of-band (OOB) areas of the YAFFS2 file system. As a result, it was not possible to reconstruct the file system. However, contestants were still able to carve out usable content from this data.</p>
<p>The winning submission provides a technical analysis of data structures found in memory dump from Android mobile devices and provides an Android analysis toolkit that extracts specific items and formats them in a report. Using this toolkit to perform a forensic examination of a full NAND dump of a YAFFS2 file system (such as in Scenario 2 of the DFRWS 2011 Forensics Challenge) first requires the file system to be mounted under Linux as an emulated Flash device (using nandsim).</p>
<p>A sample of the information extracted by the winners from the SQLite database located on the Android device in Scenario 2 (mtd8\data\com.android.providers.telephony\databases\mmssms.db) is provided here:</p>
<table border="1" cellspacing="3" cellpadding="3">
<tbody>
<tr>
<th>Address</th>
<th>date/time (UTC)</th>
<th>read</th>
<th>type</th>
<th>body</th>
</tr>
<tr>
<td>[email protected]</td>
<td>05/06/2011 01:34:55 AM</td>
<td>True</td>
<td>in</td>
<td>(Nearby! Coming for my beer) Hey Yob, I am closing in on Fat Heads. See ya soon.</td>
</tr>
<tr>
<td>[email protected]</td>
<td>05/06/2011 05:53:30 PM</td>
<td>True</td>
<td>in</td>
<td>Reminder, planned IT outage this weekend. This maintenance window will start at 3 PM today and continue for approx 48 hours.</td>
</tr>
<tr>
<td>[email protected]</td>
<td>05/06/2011 05:55:16 PM</td>
<td>True</td>
<td>in</td>
<td>This effects external services such as website, email, webmail, and the ftp server. Use the secondary email access and helpdesk # for emergencies</td>
</tr>
<tr>
<td>[email protected]</td>
<td>05/07/2011 11:39:16 PM</td>
<td>True</td>
<td>in</td>
<td>(Save me!) If Luke asks, I’m going out with you to dinner, OK?<br />
I just can’t face Mr. Smooth tonight.<br />
Shandra</td>
</tr>
<tr>
<td>6245</td>
<td>05/07/2011 11:44:27 PM</td>
<td>True</td>
<td>out</td>
<td>Sure thing. Do you know where the wine loft is?</td>
</tr>
<tr>
<td>6245</td>
<td>05/07/2011 11:54:37 PM</td>
<td>True</td>
<td>out</td>
<td>I ran into some friends at the double wide, meetup at 8:30 or so?</td>
</tr>
<tr>
<td>6245</td>
<td>05/07/2011 11:56:53 PM</td>
<td>True</td>
<td>out</td>
<td>Or you can walk down Carson and join us</td>
</tr>
</tbody>
</table>
<p>Much more information was extracted from both Android devices as detailed in the reports, which include an <a href="http://sandbox.dfrws.org/2011/fox-it/DFRWS2011_results/Report/DFRWS%202011%20-%20timeline.png" target="_blank">impressive graphical reconstruction of events</a>. </p> <br /><i><a href='/Blog/?id=15'>Click here</a> for more information.</i><br/>Forensic Analysishttp://www.newberrygroup.com/Blog/?id=15Eoghan CaseyWed, 09 Nov 2011 13:13:00 GMTSQLite for Digital Forensic Practitioners<p>An increasing number of programs are employing SQLite to store data that can be of relevance in an investigation. Forensic practitioners who become familiar with SQLite and learn how to interpret these files will be in a better position to obtain the most usable information from available digital evidence. We cover this and other useful forensic techniques in our Mobile Device Forensics course (<a href="http://www.sans.org/security-training/mobile-device-forensics-1297-mid" target="_blank">SANS SEC563</a>).</p>
<p>Backup files from an iPhone or iPod Touch provide an excellent example of SQLite databases that digital forensic examiners can exploit with relative ease, provided they are not encrypted. Data backed up from an iPhone using iTunes such as call logs, contacts, multimedia, and other files are, by default, stored in SQLite database files under “~/Library/Application/Support/MobileSync/Backup” Mac. On Windows XP these backup files are stored in the user’s profile under “C:\Documents and Settings\[userprofile]\Application Data\Apple Computer\MobileSync\Backup” and Windows Vista has a “Roaming” subfolder in this path.</p>
<p>SQLite databases can be examined using a command line tool like <a href="http://www.sqlite.org/" target="_blank">sqlite3.exe</a> or with a GUI tool like <a href="http://sqlitebrowser.sourceforge.net/" target="_blank">SQLite Database Browser</a> shown here with the call log backed up from an iPhone.</p>
<p><img alt="" src="/data/images/cmdLabsImages/sql-1.png" /></p>
<p>The dates are in Unix string format and can be converted using Perl as shown here:</p>
<ul>
<pre>$ perl -e "print scalar(gmtime(1247848584))"
Fri Jul 17 16:36:24 2009</pre>
</ul>
<p>The use of SQLite databases gives forensic practitioners the ability to query the available data directly using the SQL database language. Although a full treatment of SQL is beyond the scope of this discussion, simple examples are provided here to get you started.</p>
<ul>
<pre>C:\>sqlite3.exe E:\iPhoneBackup\call_history.db
SQLite version 3.6.16
Enter ".help" for instructions
Enter SQL statements terminated with a ";"
sqlite> .tables
_SqliteDatabaseProperties call
sqlite> select * from call WHERE address like '%868%';
2|+186835xxxxx|1247848584|60|4|-1
3|+186835xxxxx|1247853361|0|5|-1
4|+186835xxxxx|1247854453|0|5|-1
9|+186831xxxxx|1247895923|60|4|-1
10|+186835xxxxx|1247936960|60|5|-1
11|+186835xxxxx|1247941792|0|4|-1
12|+186835xxxxx|1247941827|0|4|-1
13|+186835xxxxx|1247941920|0|4|-1
14|+186835xxxxx|1247942844|0|4|-1
16|+186835xxxxx|1248015352|60|4|-1
17|+186835xxxxx|1248015674|0|4|-1
18|+186835xxxxx|1248016092|0|5|-1
26|+186835xxxxx|1248177103|0|5|3</pre>
</ul>
<p>The Symbian operating system for mobile devices also makes use of SQLite databases, and other computer applications store investigatively useful information in SQLite databases, including Firefox 3 and Skype. For instance, the moz_places table in the places.sqlite file from Firefox 3 is shown below.</p>
<p><img alt="" src="/data/images/cmdLabsImages/sql-2.png" /></p>
<p>This file can also be queried using SQL, as shown here being queried for all URLs containing the cmdLabs web site.</p>
<ul>
<pre>C:\tools>sqlite3 E:\firefox\places.sqlite
SQLite version 3.6.16
Enter ".help" for instructions
Enter SQL statements terminated with a ";"
sqlite> .tables
moz_anno_attributes moz_favicons moz_keywords
moz_annos moz_historyvisits moz_places
moz_bookmarks moz_inputhistory
moz_bookmarks_roots moz_items_annos
sqlite> select * from moz_places WHERE url like '%cmdlabs%';
621|<a href="http://www.cmdlabs.com/">http://www.cmdlabs.com/</a>|Home|moc.sbaldmc.www.|1|0|1||2000
622|<a href="http://www.cmdlabs.com/page11/page11.html">http://www.cmdlabs.com/page11/page11.html</a>|Blog|moc.sbaldmc.www.|1|0|0||100
623|<a href="http://www.cmdlabs.com/services/services.html">http://www.cmdlabs.com/services/services.html</a>|Services|moc.sbaldmc.www.|1|0|0||100
624|<a href="http://www.cmdlabs.com/services/services/services-4.html">http://www.cmdlabs.com/services/services/services-4.html</a>|Training and Education|moc.sbaldmc.www.|1|0|0||100</pre>
</ul>
<p>Programs like Firefox that maintain usage records in these databases may leave remnants of deleted items that may be recoverable from unallocated disk space as detailed in Murilo Tito Pereira’s article “Forensic analysis of the Firefox 3 internet history and recovery of deleted SQLite records” (<a href="http://www.digitalinvestigation.net">www.digitalinvestigation.net</a>).</p> <br /><i><a href='/Blog/?id=25'>Click here</a> for more information.</i><br/>Forensic Analysishttp://www.newberrygroup.com/Blog/?id=25cmdLabs StaffTue, 08 Nov 2011 16:37:00 GMTHandbook of Digital Forensics and Investigation Released<p>At long last and with the help of many talented experts, I have put together a new Handbook. This book provides an advanced reference for conducting digital investigations and performing forensic examinations. The first part of the book provides comprehensive methodologies and practical tips from experienced practitioners in the areas of forensic analysis, electronic discovery and intrusion investigation. The second part of the book delves into technical aspects of digital evidence on computers, networks, and embedded systems. The technologies covered include Windows, UNIX, and Macintosh computers, cellular telephones and other mobile devices, networks and mobile telecommunications technology.</p>
<p>The Network Investigations chapter written by cmdLabs personnel is <a href="/contact.aspx">available in PDF form upon request.</a><br />
<br />
<img alt="" style="float: left; margin-right: 10px;" src="/data/images/cmdLabsImages/handbook2.png" /><br />
F-Response is giving a copy of the Handbook with purchase of their tool:<br />
<br />
Buy F-Response, Get a copy of <a href="http://www.f-response.com/index.php?option=com_content&view=article&id=216%3%20Abuy-f-response-get-a-copy-of-the-handbook-of-digital-forensics-and-investig%20ation&catid=34%3Ablog-posts&Itemid=58" target="_blank">The Handbook of Digital Forensics and Investigation</a></p>
<p> </p>
<p><em><br />
<br />
<br />
My deepest thanks to the contributors: Cory Altheide (Mandiant) – Christopher Daywalt (cmdLabs) – Andrea de Donno (Lepta) – Dario Forte (DFLabs) – James Holley (Ernst & Young) – Andy Johnson (University of Maryland, Baltimore County) – Ronald van der Knijff (Netherlands Forensic Institute) – Anthony Kokocinski (CSC) – Paul Luehr (Stroz Friedberg) – Terrance Maguire (cmdLabs) – Ryan Pittman (US Army) – Curtis Rose (Curtis W. Rose & Associates) – Joseph Schwerha (TraceEvidence) – Dave Shaver (US Army) – Jessica Reust Smith (Stroz Friedberg).<br />
</em></p> <br /><i><a href='/Blog/?id=23'>Click here</a> for more information.</i><br/>Forensic Analysishttp://www.newberrygroup.com/Blog/?id=23Eoghan CaseyTue, 08 Nov 2011 15:56:00 GMTThe Pitfalls of File Initialization for Forensic Analysts<p>File initialization is a normal Windows file system behavior that can create problems for forensic analysts. We have encountered file initialization behaviors in a number of cases and find that it creates significant confusion if the underlying cause is not understood. In several cases, incomplete file initialization was misinterpret as backdating, and in another matter it hampered data salvaging efforts.</p>
<h3>File Initialization</h3>
<p>File initialization is a process that Microsoft Windows uses when creating a new file system entry. Basically, when a new file is being created, an appropriate amount of unallocated space is reserved for the data that will be stored in the new file. Under certain circumstances, the storage space reserved for the new file may not be used in its entirety, or at all.</p>
<p>When only a portion of the disk space that was reserved for a new file is used to store data associated with that file, this leaves a discrepancy between the logical file size and the actual amount of data stored in the file. As a result, you can have a file that appears to have a logical size larger than the actual amount of data stored for that file. The space between the end of valid data and the end of file is called uninitialized space.</p>
<p>“In NTFS, there are two important concepts of file length: the End of File (EOF) marker and the Valid Data Length (VDL). The EOF indicates the actual length of the file. The VDL identifies the length of valid data on disk. Any reads between VDL and EOF automatically return 0 in order to preserve the C2 object reuse requirement.” (<a href="http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/fsutil_file.mspx?mfr=true" target="_blank">Microsoft fsutil documentation</a>)<br />
<br />
Uninitialized space is similar in concept to file slack except that it is contained within the logical file size. Unlike file slack which is no longer associated with a file, data in uninitialized space is in a kind of limbo, trapped at the end of an allocated file but not actually part of that file. </p>
<p><img alt="" src="/data/images/cmdLabsImages/uninitializedDiagram.png" /><br />
<em>Figure: Diagram of file with a logical size that is larger than its valid data length, leaving uninitialized space</em></p>
<p>The effect of file initialization behaviors are most easily demonstrated on Windows XP with fsutil as shown here. First, we create a new file that can contain 1024 bytes:?</p>
<ul><code>C:\Test>fsutil file createnew cmdLabs-setvaliddata 1024<br />
File C:\Test\cmdLabs-setvaliddata is created</code></ul>
<p>Then we set the valid data length of the new file to 1000 bytes, which leaves 24 bytes unused at the end of the file.</p>
<code>C:\Test>fsutil file setvaliddata cmdLabs-setvaliddata 1000?<br />
Valid data length is changed</code>
<ul></ul>
<p>NTFS captures the difference between logical file size and valid data length in two MFT fields as shown here:</p>
<p><img alt="" src="/data/images/cmdLabsImages/uninitializedMFT.png" /><br />
<em>Figure:MFT entry with logical size and valid data length viewed using X-Ways Forensics</em></p>
<h3>Salvaging Data from File System Limbo</h3>
<p>The significance of this from a forensic analysis standpoint is that a file with a valid data length smaller than the logical file size can contain data associated with two files: data associated with the new file (VDL bytes), and data from the old file in uninitialized space (logical file size – VDL bytes).</p>
<p>From a forensic analysis perspective, this uninitialized space can be beneficial. While various disk cleaning utilities can be configured to wipe file slack, they generally do not touch data in uninitialized space. As a result, deleted data can remain in uninitialized space indefinitely, even despite data destruction efforts, and can be salvaged by forensic analysts.</p>
<p>However, this arrangement of data can create complications for forensic analysts, particularly when dealing with larger files that have substantial amounts of uninitialized space. For instance, when carving for certain file types, it is common to export unallocated space. However, any data in uninitialized space will not be included in unallocated space. Similarly, when performing keyword searches, a forensic analyst could incorrectly attribute a hit in the uninitialized space with the new file.</p>
<p>In one case, several approaches were employed in an effort to salvage video fragments:</p>
<ul>
<li>examined deleted video files still referenced by file system </li>
<li>performed file carving on unallocated space only </li>
<li>processed file slack only for fragments of video files </li>
</ul>
<p>None of these approaches recovered videos from a time period of interest. It was not until we conducted a forensic analysis of uninitialized space that additional video fragment were found.</p>
<h3>Misinterpreting Normal File System Behavior as Backdating?</h3>
<p>Another complication from a forensic analysis standpoint arises when the file creation process is interrupted before the contents of the file is written to disk, because the new file system entry will point to a cluster that still contains data associated with an older file. When this occurs and a date can be associated with the older file, forensic analysts might think that a newer file was overwritten by an older one. This phenomenon can be misinterpreted as evidence of backdating.</p>
<p>As an example, consider a newly created file that has not been initialized and has not had any associated data saved to disk as shown here using fsutil:</p>
<ul><code>C:\Test>fsutil file createnew cmdLabs-creatnew 1024<br />
File C:\Test\cmdLabs-creatnew is created<br />
</code></ul>
<p>When a file is initialized but the associated contents was not written to disk, the initialized file system entry may point to a cluster that contains old data as shown below using EnCase. By default, EnCase shows uninitialized space in blue text. The cluster that was allocated to the new file “cmdLabs-createnew” contains older data (folder entries of files from earlier in January).</p>
<p><img alt="" src="/data/images/cmdLabsImages/fsutlis.png" /><br />
<em>Figure: EnCase showing folder entries from early January in the cluster allocated to the new initialized file system entry</em></p>
<p>This situation can be misinterpreted as backdating if the forensic analyst assumes that the clock had to be set back to the old date when the file contents was saved to disk.</p> <br /><i><a href='/Blog/?id=21'>Click here</a> for more information.</i><br/>Forensic Analysishttp://www.newberrygroup.com/Blog/?id=21Eoghan CaseyTue, 08 Nov 2011 15:48:00 GMTDigital Evidence & Computer Crime, 3rd Edition Released<p>After six years of work, the expanded and updated third edition of <a href="http://www.amazon.com/gp/product/0123742684?ie=UTF8&tag=wwwcmdlabscom-20&linkCode=as2&camp=1789&creative=9325&creativeASIN=0121631044" target="_blank">Digital Evidence and Computer Crime: Forensic Science, Computers and the Internet</a> is now complete. The 800 printed pages and one online chapter cover the methods and tools relevant to incident responders, forensic analysts, police and lawyers.</p>
<p><img alt="" style="float: left; margin-right: 10px;" src="/data/images/cmdLabsImages/casey_1.png" />This book is divided into five parts, beginning with the fundamental concepts and legal issues relating to digital evidence and computer crime in Part 1 (Digital Forensics: Chapters 1 – 5). Part 2 of this text (Digital Investigations: Chapters 6 – 9) covers investigative aspects of digital evidence and computer crime. Part 3 of this text (Apprehending Offenders: Chapters 10 – 14) deals with specific types of investigations with a focus on apprehending offenders, including Violent Crime in Chapter 10, Sex Offenders on the Internet in Chapter 12 and Investigating Computer Intrusions in Chapter 13. Part 4 of this book (Computer Forensics: Chapters 15 – 20) begins by introducing basic Forensic Science concepts in the context of a single computer, and goes on to apply these concepts in updated chapters dedicated to networked Windows, Unix, and Macintosh computers and mobile devices. Part 5 (Network Forensics: Chapters 21 – 25) covers computer networks from an investigative perspective, focusing specifically on the Internet and performing forensic analysis on network logs and traffic.</p>
<p>This material provides the foundation for the more advanced companion text, the <a href="http://www.amazon.com/Handbook-Digital-Forensics-Investigation-Eoghan/dp/0123742676/ref=sr_1_1?ie=UTF8&qid=1320729067&sr=8-1" target="_blank">Handbook of Digital Forensics and Investigation</a>.</p>
Many thanks to <a href="http://www.udayton.edu/law/faculty_and_staff/brenner_susan.php" target="_blank">Susan Brenner</a>, <a href="http://www.cmdlabs.com/Christopher_Daywalt.aspx" target="_blank">Christopher Daywalt</a>, <a href="http://www.techforensicexperts.com/53/index.html" target="_blank">Monique Mattei Ferraro</a>, <a href="http://www.tilburguniversity.edu/webwijs/show/?uid=e.j.koops" target="_blank">Bert-Jaap Koops</a>, <a href="http://www.cmdlabs.com/Terrance_Maguire.aspx" target="_blank">Terrance Maguire</a>, Mike McGrath, Tessa Robinson, <a href="http://www.schatzforensic.com.au/" target="_blank">Bradley Schatz</a>, Ben Turnbull and <a href="http://www.corpus-delicti.com/brent/brent_cv.html" target="_blank">Brent Turvey</a> for their excellent contributions to this textbook. <br /><i><a href='/Blog/?id=17'>Click here</a> for more information.</i><br/>Forensic Analysishttp://www.newberrygroup.com/Blog/?id=17Eoghan CaseyTue, 08 Nov 2011 14:47:00 GMTGeolocational Log Analysis: Think Globally, Act Locally (with code)<p>In many network environments the administrators and security engineers have an understanding of the full geographical scope and reach of their network. While some corporations have a global audience and expect traffic from the far reaches of the world, others are more localized and target a specific small region.</p>
<p>A health care provider for Alaska would monitor its network connections to ensure that network connections are limited to its main source of users, i.e. those in Alaska. An insurance company in St. Louis will see mostly traffic from IP addresses in Missouri, but Illinois as well, due to the city being on the state line. Occasionally, administrators may notice connections being made from Hawaii, Bermuda, or Italy, signifying users who are on vacation but are still wired in to their work. However, a long-term series of connections from a Eircom subscriber, Ireland’s largest ISP, should spark interest to the network administrator of a Seattle tax firm.</p>
<p>While anonymous web connections from global addresses are common, specific attention should be paid to such addresses being used to access password-protected areas of a corporation. This could include remote file access, VPN and web-based corporate email.</p>
<p>In such cases the logs from these applications, usually supplied in plain text or W3C format, contain details about transactions to include the remote IP address and the account name being authorized. In reviewing logs from various incident responses cmdLabs has found details to show that a short log review made on a daily basis could help smaller corporations determine quickly if a user account was compromised and accessed from a remote location.</p>
<p>For example, the log sample below from a Cisco ASA tracks VPN connections. The user “cmdLabs\bbaskin” was accessed via the IP address of 159.134.100.100 on 2 April, 2011, an IP that was traced back to Ireland. A few hours later the same account was accessed from an IP address in Austria.</p>
<ul><code>Apr 2 21:53:37 192.168.1.1 Apr 02 2011 21: 53:08: %ASA-6-302013: Built outbound TCP connection 7823 for inside:10.10.10.50/389 (10.10.10.50/389) to NP Identity Ifc:192.168.1.1/1047 (192.168.1.1/1047)<br />
Apr 2 21:53:37 192.168.1.1 Apr 02 2011 21: 53:08: %ASA-6-1<br />
04: AAA user authentication Successful : server = 10.10.10.50 : user = cmdLabs\bbaskin<br />
Apr 2 21:53:37 192.168.1.1 Apr 02 2011 21: 53:08: %ASA-6-113009: AAA retrieved default group policy (DfltGrpPolicy) for user = cmdLabs\bbaskin<br />
Apr 2 21:53:37 192.168.1.1 Apr 02 2011 21: 53:08: %ASA-6-113008: AAA transaction status ACCEPT : user = cmdLabs\bbaskin<br />
Apr 2 21:53:37 192.168.1.1 Apr 02 2011 21: 53:08: %ASA-6-734001: DAP: User cmdLabs\bbaskin, Addr 159.134.100.100, Connection Clientless: The following DAP records were selected for this connection: DfltAccessPolicy</code></ul>
<p>For this small set of data it is trivial to query each IP address to determine its country of origin, netblock owner, and other details that would highlight unauthorized access. The problem arises when you have hundreds of thousands of such transactions in your daily log files. One service that cmdLabs uses regularly is the IP to <a href="http://www.team-cymru.org/Services/ip-to-asn.html" target="_blank">ASN WHOIS server</a> run by Team Cymru. This server provides quick and easy access to country codes for a given IP address. However, it has two limitations: it requires Internet-access which is not readily available from a forensic workstation and to process a large bulk of IPs you have to use their Netcat process which only returns ASNs and not country codes. To overcome these limitations I’ve developed a simple solution that could process hundreds of thousands of IP addresses to determine country codes. This solution is a small Python script called IP2CC that takes an IP address as input and outputs the originating country code for that IP. This solution requires three components:</p>
<ol>
<li>The free country code database located at <a href="http://www.maxmind.com/app/geolitecountry" target="_blank">http://www.maxmind.com/app/geolitecountry</a> (updated monthly) </li>
<li>Python API module to access this database located at <a href="http://code.google.com/p/pygeoip/" target="_blank">http://code.google.com/p/pygeoip/</a> </li>
<li>The IP2CC.py script. Downloadable at the end of this blog post. </li>
</ol>
The script allows for input to be given via the command line, stdin, or an input file. In normal use it will simply output the country code. With the –c or -t option the output will contain both the IP and country code in either a comma-separated version (CSV) or tab-separated (TSV) output, respectively.<br />
<br />
<ul><code>Python ip2cc.py –i <ip> -f <input file> [-c] [-t]
<p>> python ip2cc.py -i 11.11.11.11<br />
US</p>
<p>> python ip2cc.py -i 22.22.22.22 -c<br />
22.22.22.22,US</p>
<p>> echo 33.33.33.33 | python ip2cc.py<br />
US</p>
</code>
<p><code>> python ip2cc.py -f IP.txt -c<br />
14.48.7.101,AU<br />
12.51.21.19,US<br />
10.61.14.9,Internal<br />
</code></p>
</ul>
<br />
In one use, we’ll eliminate known intranet/extranet IP addresses and run the resulting list through IP2CC to produce a master list of foreign accesses. This script will run in Linux and OSX in conjunction with the native OS command line tools. For a Windows environment you will find additional capabilities by installing the necessary <a href="http://gnuwin32.sourceforge.net/" target="_blank">GnuWin32</a> components. For example, when reviewing a <a href="http://technet.microsoft.com/en-us/library/cc737651(WS.10).aspx" target="_blank">NCSA-formatted log </a>with the IP address in the first field:
<ul><code>D:\> type in051611.log | egrep –v “^192” | gawk “{print $1}” | python ip2cc.py -t | egrep –v “US|Internal” | gawk -F\t "{print $1}" | sort | uniq > DailyForeignIPs.txt<br />
D:\> for /F %i in (DailyForeignIPs.txt) do grep “%i” in051611.log >> DailyForeignConnections.txt</code></ul>
<p>The first command above will save a simple text listing of all unique foreign IP addresses into a file for processing. The second line takes each IP address from that resulting file and compares it back against the logs to extract all lines that include its presence. The resulting DailyForeignConnections.txt can then be quickly reviewed to determine if any accounts were accessed from a foreign IP address.<br />
<br />
Dealing with the VPN logs shown earlier, we’ll change our command line a bit. Using the standard <a href="http://www.cisco.com/en/US/docs/security/asa/asa72/system/message/logmsgs.html" target="_blank">Cisco log file index</a> as a source we can see that the <a href="http://www.cisco.com/en/US/docs/security/asa/asa72/system/message/logmsgs.html#wp4887754" target="_blank">log id of 734001</a> will show us the remote IP address of a user login. We’ll search the log for that id and then parse out the IP address in the 15th field. An additional hindrance is that the IP address is appended with a comma, which we’ll remove with the ‘tr’ command.</p>
<ul><code>D:\> type asavpn-051611.log | findstr "734001" | gawk “$15 !~ /^192/ {print $15}” | tr -d "," | python ip2cc.py –t | egrep –v “US|Internal” | sort | uniq > DailyVPNForeignIPs.txt</code></ul>
<p>This is ultimately just a very simple Python script. In-house, we use it as a mere function within larger processes, but its simplicity allows for it to be used in a variety of result-tuning processes. Customization is easy. At times I’ll make an offshoot of the script to process input from `uniq` command with the `-c` count option occasionally. The `uniq –c` adds a new column that specifies the total number of instances of that IP address which is useful when evaluating the persistence of a single IP amongst thousands. A few small changes to the Python will allow you to read this count and add it to the CSV output for easy integration into a spreadsheet.</p>
<p>Usage of a tool like IP2CC is a first step to opening an administrators eyes to traffic beyond their network. A good administrator or security engineer should monitor not only the traffic that flows across their network but also the perceived traffic that flows from a network’s outer nodes to the Internet. Monitoring for your company’s existence in spam black-lists, a malware rating on services like <a href="http://MyWOT.com" target="_blank">Web of Trust</a>, and other indicators can give clues that an infection or intrusion may be underway within your network. We’ll discuss these points, and others, in a future blog post.</p>
<p><strong>Downloads:</strong></p>
<p>IP2CC Python Source Code v1.0 [ip2cc.zip] </p> <br /><i><a href='/Blog/?id=16'>Click here</a> for more information.</i><br/>Forensic Analysishttp://www.newberrygroup.com/Blog/?id=16Brian BaskinTue, 08 Nov 2011 14:45:00 GMTDeeply Embedded Metadata <br/><i><a href='/Blog/?id=27'>Click here</a> for more information.</i><br/><hr />Archivedhttp://www.newberrygroup.com/Blog/?id=27Mon, 01 Jan 0001 00:00:00 GMT