Bài giảng Management information systems - Module H: Computer Crime and Digital Forensics

Extended Learning Module HComputer Crime and Digital ForensicsINTRODUCTIONComputers are involved in crime in two waysAs the targets of misdeedsAs weapons or tools of misdeedsComputer crimes can be committed Inside the organizationOutside the organizationExamples of Computer Crimes Outside the OrganizationMalware – software designed to harm your computer or computer securityVirus – software that is written with malicious intent to cause annoyance or damageWorm – a computer virus that spreads itself from computer to computer via e-mail and other Internet trafficOther Types of MalwareSpoofingTrojan HorseKeylogger (key trapper) software – a program that, when installed on your computer, records every keystroke and mouse clickMisleading e-mailDenial-of-service attacks RootkitWeb defacingDistributed Denial-of-Service AttackCyber WarCyber war – actions by a nation-state to penetrate another nation’s computers or networks for the purposes of causing damage or disruptionMaybe the next major attack on the U.S.Some intrusions into critical systems have already taken place PlayersHackers – knowledgeable computer users who use their knowledge to invade other people’s computersThrill-seeker hackers – break into computer systems for entertainmentWhite-hat (ethical) hackers – computer security professionals who are hired by a company to uncover vulnerabilities in a networkPlayersBlack hat hackers – cyber vandals. They’re the people who exploit or destroy information Crackers – hackers for hire, the people who engage in electronic corporate espionageSocial engineering – acquiring information that you have no right to by means of deceptionPlayersHacktivists – politically motivated hackers who use the Internet to send a political messageCyberterrorists – those who seek to cause harm to people or destroy critical systems or informationPlayersScript kiddies (or bunnies) – people who would like to be hackers but don’t have much technical expertiseAre often used by experienced hackers as shieldsDIGITAL FORENSICSDigital forensics – the collection, authentication, preservation, and examination of electronic information for presentation in courtTwo phasesCollecting, authenticating, and preserving electronic evidenceAnalyzing the findingsPhase 1: PreservationIf possible, hard disk is removed without turning computer onSpecial forensics computer is used to ensure that nothing is written to drive Forensic image copy – an exact copy or snapshot of all stored informationPhase 2: AnalysisInterpretation of information uncoveredRecovered information must be put into contextDigital forensic software pinpoints the file’s location on the disk, its creator, the date it was created and many other features of the fileModern Digital Forensics Has Many Components
