On MovieTome: SEX AND THE CITY clips are here!

Search:
Go!




Click Here
advertisement

Security Watch : Don't get burned by viruses and hackers
When digital discovery
meets CSI
By Robert Vamosi 
Senior editor, CNET Reviews
June 17, 2005

Don't get me wrong: CBS's CSI (the original) is one of my favorite TV shows. But whenever Sara Sidle starts moving a mouse on a suspect's computer, or when Nick Stokes starts typing away on a victim's keyboard looking for recent e-mail, or Archie back at the lab miraculously pulls up deleted files, I'm either laughing or throwing something at the TV. I realize that Americans have short attention spans and that these dodges are done to keep the narrative moving--after all, this is a TV show about science, how unusual is that?--but the world of computer forensics is interesting in its own right.

Please, don't touch that mouse!
A few years ago, there was much debate within the computer security community about whether you should power off a computer known to be involved in a computer crime. Windows, for example, keeps a number of tasks and services running in active memory; by pulling the power, those signatures are instantly destroyed (thereby changing the computer's state). The same is true when moving the mouse while the computer is in screensaver mode: it changes the Windows environment slightly.

Actually, the world of computer forensics is interesting in its own right.
If the criminal is really savvy, there might be a logic bomb installed so that if someone tries to reboot the computer without performing a specific sequence, all the data will be erased. In one case, a forensics expert told me about a small explosive device found inside a computer case that would be triggered upon an improper reboot. Listen, if you feel you have to pull anything at a crime scene, pull the Internet or network connection plug. If the computer is broadcasting spam or viruses or is otherwise remotely controlled, there are times when you'll want that to end as soon as possible.

Eighty percent of all cybercrime is caused by corporate insiders, not outside script kiddies.
Fortunately, the debate over keeping a suspect's computer on or off has subsided now that professionals can apply new forensic tools on live machines. Encase, from Guidance Software, allows investigators and system administrators to connect to the suspect's live machine and begin making a byte-by-byte copy of the working hard drive (that is, a copy of the entire drive, used and unused portions alike), including the active portions used by Windows. Previously, forensic software required investigators to reboot into DOS in order to image a drive correctly. Encase is used by the FBI, the U.S. Secret Service, and other government law enforcement agencies worldwide. An enterprise version of Encase is used by some larger corporations, since 80 percent of all cybercrime is caused by corporate insiders, not outside script kiddies.

Total data destruction
Last week, I talked about data destruction, and many readers wanted to know more. First, reformatting your hard drive will not erase the data. Reformatting replaces only the master index used to look up specific files; by reformatting, you are merely removing the current index and starting over. The data files themselves remain exactly where they were on the hard drive and will remain there until new data overwrites them. So reformatting (even if you do it several times) won't erase the data on your hard drive.

As for why you should overwrite the data with ones and zeroes several times, consider this: If I lay down a new file over an old one that puts a number one where a one was before, there's no change. Programs like Encase can sniff down through layers of changes and piece together overwritten files one or two generations before (after that, the signatures gets murky). By overwriting with ones and zeroes at least seven times (the current U.S. government standard), it's virtually impossible for anyone, even Archie back at the lab, to re-create evidence from your hard drive.

Back to CSI
A final myth from CSI is that your average field investigator is skilled in evidence collection, DNA processing, medical examination, and digital forensics. In truth, there's a digital forensics specialist on call who comes out to a crime scene and specifically photographs the computer as is, makes a byte-by-byte image of the drive, powers down the computer, then labels and bags everything so that the unit can be reconstructed later, if need be, back at the crime labs. Often reconstruction is unnecessary. Once a copy of the hard drive has been burned to disc, investigators use that copy (not the original) to complete the investigation. I realize CSI is only a TV show, but with all the forensic consultants on the show, I wish they'd get the computer segments right.

What's the most boneheaded computer security thing you've seen on TV recently? Talk back to me.




Security Center
Top antivirus apps
From CNET Reviews
Top antispyware apps
From CNET Reviews
Virus and security alert forums
From CNET Message Boards


More commentary
Buzz Report
Molly Wood
Taking a bite out of hype.
Security Watch
Robert Vamosi
Don't get burned by viruses and hackers.
Fully Equipped
David Carnoy
The electronics you lust for.
On Call
Kent German
Solutions for your wireless woes.
Driving It
Wayne Cunningham
What's hot and what's not in car tech.

TalkBack
81 messages

Article discussion: When digital discovery meets CSI


Latest post:

"The worst this season had to be SVU...."
by gigglesnortguffaw (See profile) - July 15, 2005 8:29 PM PDT
OH NO!!! A degaussing loop? A standard television degaussing loop nailed to the wall "wipes" the HD....not unless that sucker's a liquid helium cooled superconducting magnet as use... (Read more).
Sort by: Title |
Date
| Most helpful

Just relax when entertainment meets reality.

The mistakes abound in just about every area of expertise you can find. You need... (Read more)
by powerpro (See profile) - July 6, 2005 7:49 PM PDT

Technology & TV

I suspect that if one is expert in any particular domain, the depiction of that ... (Read more)
by northca707 (See profile) - July 4, 2005 9:40 PM PDT

funny

For some reason I find that to be the funniest post I have yet to see on c|net (Read more)
by austin416 (See profile) - July 3, 2005 3:03 AM PDT

High Voltage Control Systems

It seems that on every space ship control panel, they all blow up because they a... (Read more)
by jboisseau (See profile) - June 30, 2005 8:06 AM PDT

Would aliens use ASCII?

Even assuming the aliens had no concept of computer security or viruses, there w... (Read more)
by albizzia (See profile) - June 29, 2005 2:43 PM PDT

not the only tv show...

Law and Order: Criminal Intent used a similar instant locate scam identifying a ... (Read more)
by panacealater (See profile) - June 29, 2005 10:05 AM PDT

efficient service

I wish all TV/Satelite services to prove how good is the digital program... (Read more)
by amitieljusa (See profile) - June 29, 2005 12:39 AM PDT

Really Awsome

I always enjoy the way they go to the computer w\windows and begin typing and it... (Read more)
by glaw11 (See profile) - June 28, 2005 5:50 PM PDT

BBC - right on! MI5, for example

I started watching MI5 from the BBC on A&E this year (the season is over). A... (Read more)
by baldwinl (See profile) - June 27, 2005 3:42 PM PDT


© 2008 CNET Networks, Inc., a CBS Company. All rights reserved. | Privacy Policy | Terms of Use