A Dive in Incident Handling and Digital Forensics: Using Automation to improve Response to APT Incidents

dc.contributor.authorLucian, Cristiano
dc.contributor.departmentfi=Tietotekniikan laitos|en=Department of Computing|
dc.contributor.facultyfi=Teknillinen tiedekunta|en=Faculty of Technology|
dc.contributor.studysubjectfi=Tietotekniikka|en=Information and Communication Technology|
dc.date.accessioned2023-09-26T21:07:51Z
dc.date.available2023-09-26T21:07:51Z
dc.date.issued2023-09-25
dc.description.abstractOver the last few years, companies have grown enormously in terms of IT; their structure has expanded, and consequently, they have been facing cybersecurity incidents more frequently. The entry of governments into so-called cyberwarfare has allowed threat actors to gain tremendous resources, developing tactics and malicious software that are increasingly complex to detect. The evolution of the attacker has therefore culminated in the Advanced Persistent Threat (APT), which aims to establish itself in stealth mode in a company's IT infrastructure, exfiltrating data and enrooting itself deeper into the system. Experts in the field thus often find themselves unprepared, with tools that are not state-of-the-art, or overloaded with work given the high number of operations to be performed and the pressing time requirements during the incident response phases. These issues lead to more time-consuming investigations or an opposite reduction in the quality of forensic analyses, with possible loss of evidence and unsatisfactory results. This Thesis aims to propose an open-source automation that removes side operations, such as data manipulation, from the professional's workload, while providing support through automated analysis that can result in a more advanced starting point in digital forensics investigations. The proposed toolchain consists of an automated pipeline, built around the necessities of a specific SOC team, that collects data directly from infected machines and remotely sends it to a forensic analysis platform. This information goes through a reorganisation process to obtain a timeline of events critical to understanding the life of the machine under investigation; it is also complete with OSINT knowledge to support the analyst through a meticulous data enrichment procedure. Automation also allows the processing of large amounts of data and the correlation of timelines of different devices in order to have a more general view of the ongoing incident. To evaluate the effectiveness in a potential scenario, an experiment was carried out after deployment by collecting and analysing the artefacts of an APT with two equally experienced analysts, who, one using the proposed solution and the other using spreadsheets, reported their findings while providing personal feedback. This test showed how automation can provide crucial assistance during forensic operations, enhancing the arsenal of blue teams and improving analyst satisfaction.
dc.format.extent96
dc.identifier.olddbid192780
dc.identifier.oldhandle10024/175847
dc.identifier.urihttps://www.utupub.fi/handle/11111/24453
dc.identifier.urnURN:NBN:fi-fe20230926137400
dc.language.isoeng
dc.rightsfi=Julkaisu on tekijänoikeussäännösten alainen. Teosta voi lukea ja tulostaa henkilökohtaista käyttöä varten. Käyttö kaupallisiin tarkoituksiin on kielletty.|en=This publication is copyrighted. You may download, display and print it for Your own personal use. Commercial use is prohibited.|
dc.rights.accessrightssuljettu
dc.source.identifierhttps://www.utupub.fi/handle/10024/175847
dc.subjectIncident Response, Digital Forensics, Automation, Elastisearch, APT, Windows, SOC
dc.titleA Dive in Incident Handling and Digital Forensics: Using Automation to improve Response to APT Incidents
dc.type.ontasotfi=Diplomityö|en=Master's thesis|

Tiedostot

Näytetään 1 - 1 / 1
Ladataan...
Name:
MSc_Thesis___A_Dive_in_Incident_Handling_and_Digital_Forensics.pdf
Size:
4.86 MB
Format:
Adobe Portable Document Format