45
Prospective EESP use scenarios and solutions Florence 25 th September 2019 Mattia Epifani / CNR-IGSG

Prospective EESP use scenarios and solutions · 2019-10-02 · EVIDENCE2e-Codex project Florence, 25th September 2019 manufacturer Samsung Model SM-G900F IMEI 356765064657669 Serial

  • Upload
    others

  • View
    4

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Prospective EESP use scenarios and solutions · 2019-10-02 · EVIDENCE2e-Codex project Florence, 25th September 2019 manufacturer Samsung Model SM-G900F IMEI 356765064657669 Serial

Prospective EESP

use scenarios and solutions

Florence

25th September 2019

Mattia Epifani / CNR-IGSG

Page 2: Prospective EESP use scenarios and solutions · 2019-10-02 · EVIDENCE2e-Codex project Florence, 25th September 2019 manufacturer Samsung Model SM-G900F IMEI 356765064657669 Serial

• Preparing the floor for the electronic exchange of electronic

evidence in all the EU MS in the specific scenario of

the European Investigation Order (EIO) and Mutual Legal

Assistance (MLA) procedures

• Initiating the harmonization of the legal and technological

frameworks and the stakeholder awareness on the treatment

and the exchange of electronic evidence in the EIO and

MLA procedures

• Implementing a ‘true to life’ example of successfully linking

the EVIDENCE Project to e-CODEX Project’s results in support of an EIO case

EVIDENCE2e-CODEX Project

EVIDENCE2e-Codex project Florence, 25th September 2019

Page 3: Prospective EESP use scenarios and solutions · 2019-10-02 · EVIDENCE2e-Codex project Florence, 25th September 2019 manufacturer Samsung Model SM-G900F IMEI 356765064657669 Serial

EVIDENCE2e-Codex project Florence, 25th September 2019

E2E project: how can the goal be accomplished?

Page 4: Prospective EESP use scenarios and solutions · 2019-10-02 · EVIDENCE2e-Codex project Florence, 25th September 2019 manufacturer Samsung Model SM-G900F IMEI 356765064657669 Serial

EVIDENCE2e-Codex project Florence, 25th September 2019

What is missing from this scenario?

Page 5: Prospective EESP use scenarios and solutions · 2019-10-02 · EVIDENCE2e-Codex project Florence, 25th September 2019 manufacturer Samsung Model SM-G900F IMEI 356765064657669 Serial

• Message, with the EP attached, will travel

through the R.I. and over e-Codex

• The EP could be exchanged as a simple

attachment

• It is essential to use a standard to represent

the EP (data and meta data)

• UCO/CASE language

Standard representation for the EP

EVIDENCE2e-Codex project Florence, 25th September 2019

Page 6: Prospective EESP use scenarios and solutions · 2019-10-02 · EVIDENCE2e-Codex project Florence, 25th September 2019 manufacturer Samsung Model SM-G900F IMEI 356765064657669 Serial

CASE is a community-developed standard to

support:

• reporting of digital traces

• exchanging of digital traces

• tool validation

www.caseontology.org

Cyber-investigation

Analysis Standard Expression

EVIDENCE2e-Codex project Florence, 25th September 2019

Page 7: Prospective EESP use scenarios and solutions · 2019-10-02 · EVIDENCE2e-Codex project Florence, 25th September 2019 manufacturer Samsung Model SM-G900F IMEI 356765064657669 Serial

www.caseontology.org

EVIDENCE2e-Codex project Florence, 25th September 2019

Page 8: Prospective EESP use scenarios and solutions · 2019-10-02 · EVIDENCE2e-Codex project Florence, 25th September 2019 manufacturer Samsung Model SM-G900F IMEI 356765064657669 Serial

EVIDENCE2e-Codex project Florence, 25th September 2019

Page 9: Prospective EESP use scenarios and solutions · 2019-10-02 · EVIDENCE2e-Codex project Florence, 25th September 2019 manufacturer Samsung Model SM-G900F IMEI 356765064657669 Serial

What does the Evidence Package

contain?

People

InvestigativeAction

Process /Lifecycle

Trace

Relationship

Instrument

Role

Martin Rohde - Forensic ExpertSaga Norén - Police OfficerMagnus Krepper - SuspectMaria Kulle - Judge

Search and seizureForensic Acquisition, Forensic Extraction– Date/Time- Who, What, When

- Input and OutputLegal authorization –

Search warrant /Forensic Tool - Plaso

Chain of Custody

Chain of Evidence

Mobile Device, Disk

File, Message, PhoneAccount,

EmailAccount

Page 10: Prospective EESP use scenarios and solutions · 2019-10-02 · EVIDENCE2e-Codex project Florence, 25th September 2019 manufacturer Samsung Model SM-G900F IMEI 356765064657669 Serial

Sources of evidence

EVIDENCE2e-Codex project Florence, 25th September 2019

•Computer

•Smartphone

•Media (USB)

•Server

•CCTV

•IoT

•Cloud Infrastructure

Device

•Subscriber Information

•Traffic Data

•Content Data

ISP/CSP

•Voice traffic

•Network traffic

•State Trojan

Interception

Page 11: Prospective EESP use scenarios and solutions · 2019-10-02 · EVIDENCE2e-Codex project Florence, 25th September 2019 manufacturer Samsung Model SM-G900F IMEI 356765064657669 Serial

• Country A requests a search and seizure of digital devices

• Country B performs the search and seizure of a smartphone

SCENARIO ATransfer of source of evidence

SCENARIO BTransfer of acquired data (forensic image/extraction)

SCENARIO CTransfer of processed/extract data

• Ex. Call Logs, SMS, WhatsApp, Images, etc.

Devices

EVIDENCE2e-Codex project Florence, 25th September 2019

Page 12: Prospective EESP use scenarios and solutions · 2019-10-02 · EVIDENCE2e-Codex project Florence, 25th September 2019 manufacturer Samsung Model SM-G900F IMEI 356765064657669 Serial

EVIDENCE2e-Codex project Florence, 25th September 2019

EIO – Timeline in the Evidence Exchange Context

Page 13: Prospective EESP use scenarios and solutions · 2019-10-02 · EVIDENCE2e-Codex project Florence, 25th September 2019 manufacturer Samsung Model SM-G900F IMEI 356765064657669 Serial

• Search and Seizure

• Case preparation (Select methods and

tools)

• Forensic Acquisition (Imaging)

• Forensic Extraction (Data processing)

• Tools comparison

Actions

EVIDENCE2e-Codex project Florence, 25th September 2019

Page 14: Prospective EESP use scenarios and solutions · 2019-10-02 · EVIDENCE2e-Codex project Florence, 25th September 2019 manufacturer Samsung Model SM-G900F IMEI 356765064657669 Serial

• Application useful to generate UCO / CASE

languange object

• It can be used by

• LE / JA to describe non-technical actions

• FL to describe technical actions

• For example a «Search and Seizure» action

• Authorization (JA)

• Performer (LE)

• Location

• Result

Tool: UCO / CASE Generator

EVIDENCE2e-Codex project Florence, 25th September 2019

Page 15: Prospective EESP use scenarios and solutions · 2019-10-02 · EVIDENCE2e-Codex project Florence, 25th September 2019 manufacturer Samsung Model SM-G900F IMEI 356765064657669 Serial

Search and Seizure

EVIDENCE2e-Codex project Florence, 25th September 2019

manufacturer SamsungModel SM-G900FIMEI 356765064657669Serial Number FDG764192Storage capacity 64 GBClock setting 2018-05-31 6:00Mobile account +393319420019Item number ITEM_00001

Carrier Telecom ItaliaSimType SIMSIMForm Micro SIMICCID 89390100001847875453IMSI 222014603559590Phone Number 393319420019PIN 7571PUK 86245177

Page 16: Prospective EESP use scenarios and solutions · 2019-10-02 · EVIDENCE2e-Codex project Florence, 25th September 2019 manufacturer Samsung Model SM-G900F IMEI 356765064657669 Serial

Search and Seizure

EVIDENCE2e-Codex project Florence, 25th September 2019

Page 17: Prospective EESP use scenarios and solutions · 2019-10-02 · EVIDENCE2e-Codex project Florence, 25th September 2019 manufacturer Samsung Model SM-G900F IMEI 356765064657669 Serial

Search and Seizure

EVIDENCE2e-Codex project Florence, 25th September 2019

Page 18: Prospective EESP use scenarios and solutions · 2019-10-02 · EVIDENCE2e-Codex project Florence, 25th September 2019 manufacturer Samsung Model SM-G900F IMEI 356765064657669 Serial

• Digital forensics Tools Catalogue

• About 1500 tools mapped

• Acquisition and Analysis tools

• Tools categorized based on• Features (Computer/Mobile/Network)

• License type (Free/Commercial/Only LE)

• Platform (Windows/Linux/MacOS)

Tool: Digital Forensics Tools Catalogue

EVIDENCE2e-Codex project Florence, 25th September 2019

Page 19: Prospective EESP use scenarios and solutions · 2019-10-02 · EVIDENCE2e-Codex project Florence, 25th September 2019 manufacturer Samsung Model SM-G900F IMEI 356765064657669 Serial

EVIDENCE2e-Codex project Florence, 25th September 2019

Tool: Digital Forensics Tools Catalogue

Page 20: Prospective EESP use scenarios and solutions · 2019-10-02 · EVIDENCE2e-Codex project Florence, 25th September 2019 manufacturer Samsung Model SM-G900F IMEI 356765064657669 Serial

EVIDENCE2e-Codex project Florence, 25th September 2019

Tool: Digital Forensics Tools Catalogue

Page 21: Prospective EESP use scenarios and solutions · 2019-10-02 · EVIDENCE2e-Codex project Florence, 25th September 2019 manufacturer Samsung Model SM-G900F IMEI 356765064657669 Serial

https://www.dftoolscatalogue.eu/

EVIDENCE2e-Codex project Florence, 25th September 2019

Page 22: Prospective EESP use scenarios and solutions · 2019-10-02 · EVIDENCE2e-Codex project Florence, 25th September 2019 manufacturer Samsung Model SM-G900F IMEI 356765064657669 Serial

https://www.dftoolscatalogue.eu/

EVIDENCE2e-Codex project Florence, 25th September 2019

Page 23: Prospective EESP use scenarios and solutions · 2019-10-02 · EVIDENCE2e-Codex project Florence, 25th September 2019 manufacturer Samsung Model SM-G900F IMEI 356765064657669 Serial

https://www.dftoolscatalogue.eu/

EVIDENCE2e-Codex project Florence, 25th September 2019

Page 24: Prospective EESP use scenarios and solutions · 2019-10-02 · EVIDENCE2e-Codex project Florence, 25th September 2019 manufacturer Samsung Model SM-G900F IMEI 356765064657669 Serial

Forensic Acquisition

EVIDENCE2e-Codex project Florence, 25th September 2019

Page 25: Prospective EESP use scenarios and solutions · 2019-10-02 · EVIDENCE2e-Codex project Florence, 25th September 2019 manufacturer Samsung Model SM-G900F IMEI 356765064657669 Serial

Forensic Acquisition

EVIDENCE2e-Codex project Florence, 25th September 2019

Page 26: Prospective EESP use scenarios and solutions · 2019-10-02 · EVIDENCE2e-Codex project Florence, 25th September 2019 manufacturer Samsung Model SM-G900F IMEI 356765064657669 Serial

Forensic Acquisition

Page 27: Prospective EESP use scenarios and solutions · 2019-10-02 · EVIDENCE2e-Codex project Florence, 25th September 2019 manufacturer Samsung Model SM-G900F IMEI 356765064657669 Serial

Forensic Acquisition

Page 28: Prospective EESP use scenarios and solutions · 2019-10-02 · EVIDENCE2e-Codex project Florence, 25th September 2019 manufacturer Samsung Model SM-G900F IMEI 356765064657669 Serial

Data processing and extraction

EVIDENCE2e-Codex project Florence, 25th September 2019

Page 29: Prospective EESP use scenarios and solutions · 2019-10-02 · EVIDENCE2e-Codex project Florence, 25th September 2019 manufacturer Samsung Model SM-G900F IMEI 356765064657669 Serial

SMS Messages

EVIDENCE2e-Codex project Florence, 25th September 2019

Page 30: Prospective EESP use scenarios and solutions · 2019-10-02 · EVIDENCE2e-Codex project Florence, 25th September 2019 manufacturer Samsung Model SM-G900F IMEI 356765064657669 Serial

NOT deleted SMS Messages

CELLEBRITE UFED PA

EVIDENCE2e-Codex project Florence, 25th September 2019

Page 31: Prospective EESP use scenarios and solutions · 2019-10-02 · EVIDENCE2e-Codex project Florence, 25th September 2019 manufacturer Samsung Model SM-G900F IMEI 356765064657669 Serial

NOT deleted SMS Messages

MAGNET AXIOM

EVIDENCE2e-Codex project Florence, 25th September 2019

Page 32: Prospective EESP use scenarios and solutions · 2019-10-02 · EVIDENCE2e-Codex project Florence, 25th September 2019 manufacturer Samsung Model SM-G900F IMEI 356765064657669 Serial

Exporting data from different tools

EVIDENCE2e-Codex project Florence, 25th September 2019

Page 33: Prospective EESP use scenarios and solutions · 2019-10-02 · EVIDENCE2e-Codex project Florence, 25th September 2019 manufacturer Samsung Model SM-G900F IMEI 356765064657669 Serial

Comparing reports

EVIDENCE2e-Codex project Florence, 25th September 2019

Page 34: Prospective EESP use scenarios and solutions · 2019-10-02 · EVIDENCE2e-Codex project Florence, 25th September 2019 manufacturer Samsung Model SM-G900F IMEI 356765064657669 Serial

• Intermediate software layer developed to convert

the output of a forensic tool in UCO/CASE standard

• As a PoC it supports

• XML report generated by Cellebrite UFED

• XML report generated by Magnet Axiom (WIP)

• XML Logicube Falcon hardware duplicator

Tool: UCO / CASE Converter

EVIDENCE2e-Codex project Florence, 25th September 2019

Page 35: Prospective EESP use scenarios and solutions · 2019-10-02 · EVIDENCE2e-Codex project Florence, 25th September 2019 manufacturer Samsung Model SM-G900F IMEI 356765064657669 Serial

EVIDENCE2e-Codex project Florence, 25th September 2019

Page 36: Prospective EESP use scenarios and solutions · 2019-10-02 · EVIDENCE2e-Codex project Florence, 25th September 2019 manufacturer Samsung Model SM-G900F IMEI 356765064657669 Serial

• Support the development of UCO / CASE

language in forensic tools

• Develop tools to map/convert the output

produced by different tools in UCO / CASE

• Work with software developers and cloud

providers to facilitate the native adoption of UCO /

CASE language

The future…

EVIDENCE2e-Codex project Florence, 25th September 2019

Page 37: Prospective EESP use scenarios and solutions · 2019-10-02 · EVIDENCE2e-Codex project Florence, 25th September 2019 manufacturer Samsung Model SM-G900F IMEI 356765064657669 Serial

Conversion and parsing tools

EVIDENCE2e-Codex project Florence, 25th September 2019

Page 38: Prospective EESP use scenarios and solutions · 2019-10-02 · EVIDENCE2e-Codex project Florence, 25th September 2019 manufacturer Samsung Model SM-G900F IMEI 356765064657669 Serial

Obtaining Cloud Provider datahttps://www.facebook.com/records/login/

EVIDENCE2e-Codex project Florence, 25th September 2019

Page 39: Prospective EESP use scenarios and solutions · 2019-10-02 · EVIDENCE2e-Codex project Florence, 25th September 2019 manufacturer Samsung Model SM-G900F IMEI 356765064657669 Serial

Obtaining Cloud Provider data

EVIDENCE2e-Codex project Florence, 25th September 2019

Page 40: Prospective EESP use scenarios and solutions · 2019-10-02 · EVIDENCE2e-Codex project Florence, 25th September 2019 manufacturer Samsung Model SM-G900F IMEI 356765064657669 Serial

Analyzing Cloud Provider data

EVIDENCE2e-Codex project Florence, 25th September 2019

Page 41: Prospective EESP use scenarios and solutions · 2019-10-02 · EVIDENCE2e-Codex project Florence, 25th September 2019 manufacturer Samsung Model SM-G900F IMEI 356765064657669 Serial

Obtaining Cloud Provider datahttps://legalrequests.twitter.com/

EVIDENCE2e-Codex project Florence, 25th September 2019

Page 42: Prospective EESP use scenarios and solutions · 2019-10-02 · EVIDENCE2e-Codex project Florence, 25th September 2019 manufacturer Samsung Model SM-G900F IMEI 356765064657669 Serial

Analyzing Cloud Provider data

EVIDENCE2e-Codex project Florence, 25th September 2019

Page 43: Prospective EESP use scenarios and solutions · 2019-10-02 · EVIDENCE2e-Codex project Florence, 25th September 2019 manufacturer Samsung Model SM-G900F IMEI 356765064657669 Serial

Analyzing Cloud Provider data…

EVIDENCE2e-Codex project Florence, 25th September 2019

Page 44: Prospective EESP use scenarios and solutions · 2019-10-02 · EVIDENCE2e-Codex project Florence, 25th September 2019 manufacturer Samsung Model SM-G900F IMEI 356765064657669 Serial

Conversion and parsing

Cloud Provider data

EVIDENCE2e-Codex project Florence, 25th September 2019

Page 45: Prospective EESP use scenarios and solutions · 2019-10-02 · EVIDENCE2e-Codex project Florence, 25th September 2019 manufacturer Samsung Model SM-G900F IMEI 356765064657669 Serial

EVIDENCE2e-Codex project Florence, 25th September 2019

Thanks for your attention

Questions?

Mattia Epifani / CNR-IGSG

[email protected]