34
Effective Victim Interview Techniques for Incident Responders Alison Naylor Principal Information Security Analyst Red Hat, Inc.

Effective Victim Interview Techniques for Incident Responders · 2019-06-19 · Interviewing Tips Establish rapport ... psychological effects: • Self-blame, guilt, anger • Feeling

  • Upload
    others

  • View
    6

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Effective Victim Interview Techniques for Incident Responders · 2019-06-19 · Interviewing Tips Establish rapport ... psychological effects: • Self-blame, guilt, anger • Feeling

EffectiveVictimInterviewTechniquesforIncidentRespondersAlisonNaylorPrincipalInformationSecurityAnalystRedHat,Inc.

Page 2: Effective Victim Interview Techniques for Incident Responders · 2019-06-19 · Interviewing Tips Establish rapport ... psychological effects: • Self-blame, guilt, anger • Feeling

Overview

•  InterviewBasics• WhyinterviewaspartofIncidentResponse?•  Subject(victimorpersonofinterest)interviewingtechniques•  QualityQuestions•  ActiveListeningandEmotionalIntelligence

•  StructureofanIncidentResponseInterview• CaseStudies

Page 3: Effective Victim Interview Techniques for Incident Responders · 2019-06-19 · Interviewing Tips Establish rapport ... psychological effects: • Self-blame, guilt, anger • Feeling

WhyInterviewforIncidentResponse?

• Gathermoreinformation(obviously)•  Youmayalreadyknowwhathappened,nowfindoutthehowandwhy

• Opportunityforusereducation•  Incidentsareamemorableexperience!

• PositivePRforsecurityteam•  Showyourusershowyoukeeptheirdatasafe•  Securityfolksarepeopletoo!

Page 4: Effective Victim Interview Techniques for Incident Responders · 2019-06-19 · Interviewing Tips Establish rapport ... psychological effects: • Self-blame, guilt, anger • Feeling

Whythistalk?

• Manyofusareintroverts•  Lessthancomfortabletalkingtostrangers

• Ourquestionsaren’tthatgood• Wetendtofocusonthetech,nottheperson•  Oftenmisstheinformationgaps

•  Interviewingisaskillwecandevelop•  Guidelinestobuildconfidence•  Plan,practice,andputintouse!

Page 5: Effective Victim Interview Techniques for Incident Responders · 2019-06-19 · Interviewing Tips Establish rapport ... psychological effects: • Self-blame, guilt, anger • Feeling

TypesofSubjects• Victim

•  Theincidenthappened“to”them• Wasscammed,orperhapsjustmadeamistake•  Usuallycooperative

• Adversarialsubject•  Personofinterest•  May(ormaynot)betheactorbehindtheincident•  Lessthancooperative

“Subject”referstoeithercase–thepersonweareinterviewing

Page 6: Effective Victim Interview Techniques for Incident Responders · 2019-06-19 · Interviewing Tips Establish rapport ... psychological effects: • Self-blame, guilt, anger • Feeling

TypesofQuestions

Closed-endedQuestions• Usuallyelicitashort,one-wordanswer(usuallyyesorno)• Usefultoconfirmfacts• Oftenbeginwith“Doyou..”“Canyou..”“Who”“When”“Where”• Mightmakevictimsanxious• Couldmakeadversarialsubjectshostileorclamup• Canimplyjudgment,oranexpectedanswer

Page 7: Effective Victim Interview Techniques for Incident Responders · 2019-06-19 · Interviewing Tips Establish rapport ... psychological effects: • Self-blame, guilt, anger • Feeling

TypesofQuestions

Open-endedQuestions•  Encourageafull,meaningfulanswerusingboththesubject’sexperiencesandfeelings• Usuallybeginwith“Tellme..”“Whatdoyouthink..”“How”or“Why”• Arereassuringtovictims• Canmakeadversarialsubjectsnervousandchatty• Moreobjective,lessleading

Page 8: Effective Victim Interview Techniques for Incident Responders · 2019-06-19 · Interviewing Tips Establish rapport ... psychological effects: • Self-blame, guilt, anger • Feeling

Closed-Endedvs.Open-Ended

“Canyoutellmewhathappened?”“Doyouknowthesenderofthisemail?”“Doyouhaveanyproblemswithyourboss?”

“Okay,tellmewhathappened.”“Howdoyouknowthisperson?”“Tellmeaboutyourrelationshipwithyourboss.”

Page 9: Effective Victim Interview Techniques for Incident Responders · 2019-06-19 · Interviewing Tips Establish rapport ... psychological effects: • Self-blame, guilt, anger • Feeling

Whentousethem?

Asageneralrule:• Open-endedquestionstostartaconversation• Closed-endedquestionstoclarify,confirmdetails• Backtoopen-endedtocontinueanarrative

Page 10: Effective Victim Interview Techniques for Incident Responders · 2019-06-19 · Interviewing Tips Establish rapport ... psychological effects: • Self-blame, guilt, anger • Feeling

Forparticularlyinvolvedincidents,atraditionalfour-stageinterrogationcanhelp.Weaskthesubjecttodescribe:•  Theentireincident,astheyrememberit(mostlyopen-endedquestions)•  Theperiodbeforetheincidenttookplace(someopen,someclosed)• Detailsabouttheincident(mostlyclosed)•  Theperiodfollowingtheincident(someopen,someclosed)

OrganizingaNarrativeFlow

Page 11: Effective Victim Interview Techniques for Incident Responders · 2019-06-19 · Interviewing Tips Establish rapport ... psychological effects: • Self-blame, guilt, anger • Feeling

QualityQuestions

• Objective•  SpecificandDirect

• Non-Judgmental•  Don’tplayStupidvs.Evil

• Adapttothesubject•  Showthatyou’relistening

•  Toneofvoice•  Matter-of-fact•  Supportive

Itlookslikeyouvisitedalinkatsketchy[.]site.Howdidyoucometoreachthatsite?Idon’tseetheURLinyourbrowserhistory,butIhavenetworklogsindicatingthesitewasvisitedatthistimefromyourIPaddress.Whymightthatmightbe?Iheardyousaythatoncetheyhadremotecontrolofyourdesktop,theyransomecommands.Whatcanyourememberaboutthis?

Page 12: Effective Victim Interview Techniques for Incident Responders · 2019-06-19 · Interviewing Tips Establish rapport ... psychological effects: • Self-blame, guilt, anger • Feeling

InterviewingTips

Establishrapport•  Taketimeforintroductions•  Setexpectationsfortheinterview•  Offerreassurances•  Themagicwords:“You’renotintrouble.”

Bepatient!Don’trush•  Repeatandrephraseasneeded•  Bookmoretimethanyouthinkyouneed

Page 13: Effective Victim Interview Techniques for Incident Responders · 2019-06-19 · Interviewing Tips Establish rapport ... psychological effects: • Self-blame, guilt, anger • Feeling

InterviewingTips

UseActiveListening•  Paraphrase–restatethesubject’sinformationwithdifferentwords•  Summarize–conciselyreiteratemainpointstoidentifyoverallprogress•  Clarify–allowforunclearportionstoberestateduntilintendedmeaningisclear•  Reflect–beattunedtoandreflectfeelings

BeMindfulofBodyLanguage•  Makeeyecontact•  Relaxed,open•  Neutralexpression

Page 14: Effective Victim Interview Techniques for Incident Responders · 2019-06-19 · Interviewing Tips Establish rapport ... psychological effects: • Self-blame, guilt, anger • Feeling

InterviewingTips

ConsidertheInterviewEnvironment•  Howwillthesettingaffectthesubject?•  Boardroomvs.ComfyChairsvs.CubicleAmbush

BringaPartner

•  Oneofyoucanfocusonthesubject•  Theothercanfocusoncapturingdata,fact-checking•  Goodtohaveawitness(especiallyifadversarial)

Page 15: Effective Victim Interview Techniques for Incident Responders · 2019-06-19 · Interviewing Tips Establish rapport ... psychological effects: • Self-blame, guilt, anger • Feeling

SpecialConsiderationsforVictims

• Victimsmayfeeltraumatized—lookforsignsofdistress• Recognizethevictim’sfears,embarrassment,guilt,orconfusion•  Establishasafespace—physicalandotherwise• Offerreassurancespriortoaskinguncomfortablequestions

•  Particularlyaroundbrowserhistory,emails,photos,chatlogs,etc.

• Avoidgettingboggeddownspeculatingabouttheadversary•  Shareapersonalstoryifyou’veexperiencedsomethingsimilar

Page 16: Effective Victim Interview Techniques for Incident Responders · 2019-06-19 · Interviewing Tips Establish rapport ... psychological effects: • Self-blame, guilt, anger • Feeling

It’snotourroletocounselvictimsofcybercrime,butwecanlistenwithempathy,anddirectvictimstoadditional

resourcesthatcanhelp.

EffectsofCybercrime

•  Traumacanleadtolong-lastingpsychologicaleffects:•  Self-blame,guilt,anger•  Feelingvulnerable,powerless•  Isolation,inabilitytotrust

• Physicaleffectscaninclude:•  Difficultyconcentrating•  Appetitechanges•  Insomnia•  Absenteeism

Source:https://www.infosecurity-magazine.com/news/isc2congress-cybercrime-victims/

Page 17: Effective Victim Interview Techniques for Incident Responders · 2019-06-19 · Interviewing Tips Establish rapport ... psychological effects: • Self-blame, guilt, anger • Feeling

BeforeYourInterview

• Planoutyourquestions•  Determinewhatbackgrounddatayoumustrecordforeveryincident.Askyoursubjectonlyforthefactsyoucan’tdiscoverthroughothermeans.

•  Developquestionstailoredtotheparticularincident•  Youmayalreadyhavetheanswers(thatcanbeagoodthing)

•  Tryoutquestionsonateammate—rewriteclosedquestionsasopen!

• Chooseatimeandplace•  Selectalocationappropriateforyoursubject•  Bookmoretimethanyouthinkyou’llneed

Page 18: Effective Victim Interview Techniques for Incident Responders · 2019-06-19 · Interviewing Tips Establish rapport ... psychological effects: • Self-blame, guilt, anger • Feeling

BackgroundData

•  Subjectprofile:name,userid,emailaddress,phonenumber,jobtitle,hiredate,department,location• Deviceprofile:type,manufacturer,revision,operatingsystem,patchlevel,statusofbackups,statusofdiskencryption•  Softwareprofile:packagesinstalled,versions,whatAVorendpointprotectionsoftwareispresent,whatMDMprofileispresent,whatclassificationofdatamaybestoredonthesystemorpassthroughthesystem,etc.

Page 19: Effective Victim Interview Techniques for Incident Responders · 2019-06-19 · Interviewing Tips Establish rapport ... psychological effects: • Self-blame, guilt, anger • Feeling

IOC/ArtifactCollectionChecklist

Collectthefollowingtocorrelatewithsystemlogs,networktrafficrecords,packetcaptures,IDSlogs,AVreports,forensictools,andthird-partyanalysissites:•  Devicevitals:IPaddress,MACaddress,FQDN,localcomputername•  Emailmetadata:To,From,Date,Subject,Attachmentname

•  Copyoftheemailwithfullheadersandattachmentpayloadpreferred!•  Phonecallmetadata:Phonenumbers,CallerID,timestamps,anddurations•  Externalentities:IPAddresses,ports,domainnames,URLs,ASNs•  Forensicartifacts:Files,hashes,payloads,memorydumps,diskimages,backups

Page 20: Effective Victim Interview Techniques for Incident Responders · 2019-06-19 · Interviewing Tips Establish rapport ... psychological effects: • Self-blame, guilt, anger • Feeling

BeginningYourInterview

•  Introduceyourself,givethemachancetodothesame•  Explainthepurposeoftheinterview•  Offerreassurances—thisisaboutinformation,notblame

•  “Weneedyourhelptounderstandwhathappened.”

•  Ifappropriate,usethemagicwords:•  “You’renotintrouble!”

•  Setexpectations—whatyou’llbeasking,whetheryouaretakingnotesorrecording,ifyou’llbeexamininganyartifactsintheirpresence•  Smile,useeyecontact,andspeakcalmly!

Page 21: Effective Victim Interview Techniques for Incident Responders · 2019-06-19 · Interviewing Tips Establish rapport ... psychological effects: • Self-blame, guilt, anger • Feeling

SubjectHistory

• Askyoursubjecttorecountwhathappened.Encouragethemtotaketheirtime,startatthebeginning,includeasmuchdetailastheycan.• Recorddetailednotesonallstatementsprovidedbythevictim.• Correlatewithyourincidenttimelineasmuchaspossible.Includetimestampsfromeventlogs,emails,chatlogs,etc.whenavailable.• Gentlyaskforadditionalinformationandclarificationasneeded.

Page 22: Effective Victim Interview Techniques for Incident Responders · 2019-06-19 · Interviewing Tips Establish rapport ... psychological effects: • Self-blame, guilt, anger • Feeling

PanicMode?

• Askthesubjectwhatstepstheytookoncetheysuspectedaproblem.•  Didtheytrytodoanycleanupontheirownbeforeengagingthesecurityteam?• Whatspecificactionsweretaken?

•  Passwordschanged?Historycleared?Systemunplugged?Softwareuninstalled?• Whoelsemighthavetheyspokentoabouttheincident?• Whatprotectivemeasuresdidtheyalreadyhaveinplace,andwhatwastheireffectiveness?

•  Havetheyexperiencedasimilarincidentbefore?

Page 23: Effective Victim Interview Techniques for Incident Responders · 2019-06-19 · Interviewing Tips Establish rapport ... psychological effects: • Self-blame, guilt, anger • Feeling

AdditionalData

• Usualphysicallocation(s)ofdevice• Whoownsthedevice?Isitcompany-provided,orpersonal?• Whoelsehasaccesstothedevice/account?

•  You’veneverletyourassistant/teammate/partner/child/parentuseit?

•  Isanysuspiciousactivityongoing?•  Isthedevicecurrentlyconnectedtoanynetwork?• Hasthedevicebeenpoweredofforrebooted?• Haveanychangesbeenmadetothedevice?

Page 24: Effective Victim Interview Techniques for Incident Responders · 2019-06-19 · Interviewing Tips Establish rapport ... psychological effects: • Self-blame, guilt, anger • Feeling

InterviewWrap-Up

Attheconclusionoftheinterview,it’simportantto:•  Thankthesubjectfortheirtimeandcooperation• Offeranopportunityforthemtoaskanyquestions

•  e.g.nextsteps,whatwillhappenwiththeircase•  Askiftheyhaveanyconcernsarisingfromtheincident• Provideyourcontactinformation,incasetheyremembersomethingelse

Page 25: Effective Victim Interview Techniques for Incident Responders · 2019-06-19 · Interviewing Tips Establish rapport ... psychological effects: • Self-blame, guilt, anger • Feeling

UserEducation

• Helptheuserunderstandwaystopreventfutureincidents:• Whenindoubt,confirmidentitiesviaanothermethod

• Passwords•  Changeanysuspectpasswords•  Usegoodpassphrases,2FAwhereverpossible•  Don’tre-usepasswords•  Useapasswordmanager

• Prepareforpossibilityofre-victimization•  Compromiseddatacanbere-sold,usedagain

Page 26: Effective Victim Interview Techniques for Incident Responders · 2019-06-19 · Interviewing Tips Establish rapport ... psychological effects: • Self-blame, guilt, anger • Feeling

AdditionalSupport

• Offersuggestionsforadditionalsupport:•  EmployeeAssistancePrograms•  Creditmonitoringservices•  NationalIdentityTheftVictimsAssistanceNetwork•  CybercrimeSupportNetwork

•  Encouragethesubjecttoreachoutiftheyrecallanyfurtherdetails•  Anoverallpositiveinteractionwillincreaselikelihoodofre-contact

Page 27: Effective Victim Interview Techniques for Incident Responders · 2019-06-19 · Interviewing Tips Establish rapport ... psychological effects: • Self-blame, guilt, anger • Feeling

CaseStudy:CryptominerChris

•  Trackingdownacryptominerinanofficebuilding• Unknownsystem,hadn’tauthenticatedtoanythingofficial•  FoundtheMACaddressonaswitch,tracedoutthecable• Approachedtheassociateattheirdesk•  “WHAT’SYOURMACADDRESS?!”•  Theassociatepromptlyclamsupandbecomesuncooperative•  “Let’sstartover”J

Page 28: Effective Victim Interview Techniques for Incident Responders · 2019-06-19 · Interviewing Tips Establish rapport ... psychological effects: • Self-blame, guilt, anger • Feeling

CaseStudy:CryptominerChris

Thisinterviewstartedoutreallypoorly,butwewereabletoturnitaround•  Reallyhadtocalmdowntheassociate—sittingateyelevel,soothingvoice,etc.•  Explainedwhoweare,thatwe’retryingtounderstanddata,andneededhishelp•  Askedabouthiscompany-issuedlaptopfirst,butitdidn’tmatchwhatwe’dseen•  ThenInoticedanotherPConthedesk—hesaiditwasn’this•  Lotsofopen-endedquestionslater,admittedhe’dlifteditfromane-wastebin•  Hehadbroughtittohisdesk,pluggeditin,turnediton,andwalkedaway•  Hewasusedtore-usingeveryscrapofhardware,thoughtthatwasstandard•  Excellentopportunityforusereducationaboutplugginginunknowndevices!

Page 29: Effective Victim Interview Techniques for Incident Responders · 2019-06-19 · Interviewing Tips Establish rapport ... psychological effects: • Self-blame, guilt, anger • Feeling

CaseStudy:PhotoPhil

•  Threateningtweetswithphotosfrominsideacompanyevent•  Triangulatingwhotookthephotofromshotsofthecrowd• Wefoundalow-resolutioncrowdshotpostedonaninternalblogthatcouldpotentiallysolvethemystery• Approachedthephotographer:“Didyoutakethisphoto?We’regoingtoneedyoutohandovertheoriginal!”• Photographerfreakedout!•  “Ohmygod,whoevenareyouguys?Idon’thavetogiveyouanything!Nobodygetsmyphotos,they’remine!”

Page 30: Effective Victim Interview Techniques for Incident Responders · 2019-06-19 · Interviewing Tips Establish rapport ... psychological effects: • Self-blame, guilt, anger • Feeling

CaseStudy:PhotoPhil

Themagicwords:“You’renotintrouble.Wereallyneedyourhelptofigureoutwhat’sgoingon.Canyouhelpussolvethismystery?”•  Timewasoftheessence,unfortunatelyplanningwasnon-existent• Anothercaseofanoverly-intimidatingstarttotheconversation• Alwaysleadwithwhoyouare,whyyou’retalkingtothem,andthatthey’renotintrouble.•  Thisassociatewassuperhappytohelponceherealizeditwasn’tabouthim,veryexcitedandproudthathecouldhelpuscrackthecase!

Page 31: Effective Victim Interview Techniques for Incident Responders · 2019-06-19 · Interviewing Tips Establish rapport ... psychological effects: • Self-blame, guilt, anger • Feeling

CaseStudy:ScammerFiction,DoubleFeature

1.  Associate’sAmazonaccountwascredential-stuffedandcompromised2.  Shewantedtotalktotechsupport,soGoogleditandcalledthefirstnumber3.  Ofcourseitwasascammer—askedhertojoinaWebExsessionforhelp4.  Hetookcontroland“showed”that87evilIPaddresseswereconnected5.  SaidshecouldtakethePCtoa“CiscoStore”orpay$350foronlinehelp6.  Askedhertocheckherbankdetailswhileconnectedandsherefused7.  Thescammergotbelligerentandthreatening,andsheeventuallyhungup8.  Theassociatewassounsettled,sheworriedshewasbeingwatched

Page 32: Effective Victim Interview Techniques for Incident Responders · 2019-06-19 · Interviewing Tips Establish rapport ... psychological effects: • Self-blame, guilt, anger • Feeling

CaseStudy:ScammerFiction,DoubleFeature

Thisinterviewwentreallywell!Wewereabletodosomethingsright:•  Small,comfortableinterviewspace•  Oneinterviewer,onescribe• Weabsolutelyneededdoublethetimewe’dbookedwithher•  Lettingherspeakaboutherfeelings—she’dbeenterrifiedfordays,wasn’tsleeping• Wewereabletoexplainshe’dbeenscammedtwice,byunrelatedactors•  Usereducationhelpedherunderstandwhatactuallyhappened,vs.thefrighteningliesthescammerhadtoldher

•  Sheleftfeelingrelievedandempoweredtoresistfuturescams!

Page 33: Effective Victim Interview Techniques for Incident Responders · 2019-06-19 · Interviewing Tips Establish rapport ... psychological effects: • Self-blame, guilt, anger • Feeling

Questions?Thanksforattending!

Page 34: Effective Victim Interview Techniques for Incident Responders · 2019-06-19 · Interviewing Tips Establish rapport ... psychological effects: • Self-blame, guilt, anger • Feeling

Acknowledgements

•  TheQuestionofQuestionTypesinPoliceInterviews:Areviewoftheliteraturefromapsychologicalandlinguisticperspective(2010:TheInternationalJournalofSpeech,Language,andtheLaw:Oxburg,Myklebust,andGrant)•  InterviewingTechniquesinDomesticViolenceCases(NewJerseyDivisionofCriminalJustice)•  #ISC2Congress:CybercrimeVictimsLeftDepressedandTraumatized

•  https://www.infosecurity-magazine.com/news/isc2congress-cybercrime-victims/

• ALastingImpact:TheEmotionalTollofIdentityTheft•  https://www.equifax.com/assets/PSOL/15-9814_psol_emotionalToll_wp.pdf