Title: Cybercrime
1Cybercrime
- Decision Group / CEO
- Casper Kan Chang
- Chang_kan_at_decision.com.tw
2Two Major categories of Cybercrime
Crimes committed via internet Examples
Spreading Virus, Hacking, Illegal Access, Illegal
interception, Data Interference and communication
Interference.
Network Packet
Crime operation methods
Evidence from
Traditional crimes committed via Internet.
Examples Internet Auction fraud, trafficking in
contraband goods, Internet sexual assault,
internet-advertising bank loans fraud
3Cybercrime Investigation Steps
4Case Study of Cybercrime
- Crime Time
- Crime location
- Corpus delicti
- Crime method
- Perpetrator Analysis
- Criminal damage
- Criminal charges
Evidence Collection
Internet Interception
Complete Forensic analysis and interpret the
evidence found for legal/courtroom setting
5Collection of Cyber Crime Information
- Computer Audit Record Collection To collect the
login audit records of the victim including DNS,
IP, Account details, MAC and local times etc.. - User Login credential authentication To check
users login credentials including user account,
name, address, phone etc.. - To obtain the computer communication record and
contents including E-mail, IM chat, web browsing
and file transfers etc.. - Suspects statements criminal offence etc
- The seizure of the suspects computer audit
records Web, IP, account, MAC and time etc
6Internet advertising bank loan fraud case-1
In May 2009 KCGPB (Kaohsiung City Government
Police Bureau) announced that they had received a
number of bank reports alleging forged documents
fraudulently representing bids for credit. This
resulted in bank loan frauds with huge financial
losses. An in-depth investigation revealed that
the offenders flooded xx shares with others to
form the fraud group. They used a domestic portal
website for free web space to falsely post or
sticker advertising published in the Office of
credit and information. This was done to attract
the much-needed cash flow of the head customer.
The members of the Group forged tax, payroll and
other documents to falsely strengthen the
lender's financial resources and created
documents to mislead the head bank customer whose
credit bid to financial institutions was caught
in an error of the approved loan, the group
charged the customer exorbitant fees to gain
large profits of financial fraud.
7Internet advertising bank loan fraud case
8Internet Sexual Assault cases!
Internet sexual assault cases in 2007 Daily 1.5
case, more than 60 are 12-18 years old. June
10, 2009 Apple Daily Taipei Taiwan
Two suspects
9Is truly pathetic and inferior to animals
July 2008 Taipei two suspects use the Internet
to invite Female net friends to participate in a
party. The Female net friend is used to meet a
woman at a Motel, and in turn require a sexual
relationship. The victim refuses to cooperate and
is physically abused and raped. The police
arrested the two suspects and further
investigations revealed that as many as a dozen
other people had been injured. The victims are
unwilling to report to the police due to
humiliation. The police monitor the network
address of the motel access to number and are
able to obtain enough evidence to arrest tow
suspects. The police linked the two offenders to
other crimes committed in July 2008 .
Questioning of the offenders revealed various
nicknames were used by yahoo messenger and Peas
chat rooms and various other websites. The
suspects revealed that another 5 or 6 offenders
had assisted in the crimes. Police are continuing
their investigations and tracing the other
accomplices.
10Hacker Data Theft 1Hacker Su x-jung work for
the underworld to steal data
2007/09/22 China Times / Taipei / Choi Min-Yue
CIB High-Technology Crime Prevention Center and
Technology have found that the Internet nickname
Odin" a Lin, high-school sophomore, and the
nickname CB Su x-jung, used an academic
department as the backbone network springboard
with a host hidden within a Taiwan Academic
Network. The use of Trojan horse programs,
together with web site vulnerabilities against
well-known Web sites were used to harvest
intrusive information and then, to circumvent
tracing, stored this data on a foreign hosted
website. Xx telecom companies user accounts and
password were compromised with more than 2.4
million pins stolen. Some websites have been
damaged by having their programs removed.
11 Hacker Data Theft 2 Hacker Su x-jung works
for the underworld to steal data
12Forensics tools
To assist in the forensic acquisition of digital
evidence, it is essential that every computer
crime investigator has access to the correct
forensic hardware and software tools. This plays
a critical role in the detection of computer
related crimes as well as the collection and
analysis of evidence.
13Network Packet Forensics Classification
1.
Viruses Worms, Hacking Trojans ... ...
Email , Web Mail ,IM, FTP , P2P, VoIP, Video
Streaming , HTTP, Online Games, Telnet ,
2.
14Cyber-crime Forensics Tools
1
Providing a mobile and 10 G base cyber forensics
in assisting Homeland Security capabilities
15Function of Forensics Tool
16Network Packet Forensics Tool
By Using Off-Line packet reconstruction software
to reconstruct the recorded traffic data
17To produce forensic results
Digital Evidence
Court
Forensic Analysis
18Total Solutions for Cyber Forensics
- Wired packet reconstruction
- Wireless (802.11 a/b/g/n) packet reconstruction
- HTTPS/SSL interceptor
- VOIP packet reconstruction
- Off-line packet reconstruction software
- Network packet forensics analysis training
For more information www.digi-forensics.com
19Network Packet Forensics Analysis Training
The knowledge of network packet analysis is
important for Forensic Investigators and Lawful
Enforcement Agency (LEA) to carry out their daily
duty. Network Packet Forensics Analysis Training
(NPFAT) provides useful and sufficient knowledge
required to analyze network packets. Participants
will be able to identify different packet types
according to various Internet Protocols. These
include Email (POP3, SMTP and IMAP), Web Mail
(Yahoo Mail, Gmail, Hotmail), Instant Messaging
(Windows Live Messenger, Yahoo, ICQ etc.), FTP,
Telnet, HTTP and VOIP. Forensic investigation is
a skillful technique, science and an art.
20Reference site in Taiwan
21Reference site
ST Electronics
Singapore Government Agencies
Malaysia Government Agencies