Posted in

Why Should Organizations Investigate Cyber Security Incidents?

Has anyone tried to steal your sensitive data or encrypt your servers? How exactly did the attackers penetrate the network? Investigating cybersecurity incidents helps to determine the vector of malicious actions and find a malicious insider, as well as uncover possible APT (Advanced Persistent Threat) campaigns.

Specialists involved in investigating cybersecurity incidents can be compared to the heroes of detective novels. Let us try to understand whether all companies need to investigate incidents in information security, whether it is possible to properly investigate the incident without involving outside specialists, and whether it is always important to find the organizer of the attack.

What is cybersecurity incident investigation?

For a long time, the information security industry offered customers protection against various threats. Today, it is clear that it is impossible to prevent security incidents completely. The key question in this situation is: What to do if an incident occurs? The answer can include a wide range of actions, from identifying non-compliance with instructions by a specific employee to identifying a large-scale hacking campaign and sharing information with law enforcement agencies.

Investigation of incidents is solving specific problems encountered by the customer. If the customer suspects that some unlawful activity has occurred within his infrastructure, it is necessary to initiate an investigation or incident response (these two concepts are strongly related in practice).

One of the stages of the incident response life cycle is the analysis and reconstruction of the attack. These actions may become the most significant part of the investigation. Often, in our understanding, an investigation is the actions of law enforcement agencies when the collected data about the infrastructure or tools of the attackers is used to search for intruders.

However, the bulk of the investigation routines revolves around reconstructing the attack and finding out how it happened.

An important factor, which is sometimes forgotten, is the valuation of damage caused. It is crucial to understand what data and systems have been compromised, as well as develop responses to the current attack.

It is also important to remember that the primary purpose of the investigation is to help the company fix the vulnerability and build its processes so that such an attack could not happen again.

Vendors started offering security products because incidents happened. This is the basis and meaning of information security tools of any class and type. There is a large class of products that facilitate the investigation of security incidents. At the same time, the skills of specialists in interpreting the data that tools collect are very difficult to automate.

Sometimes an investigation is initiated because the customer has a suspicion that a cybersecurity incident has occurred. In this case, the absence of actual proof, that is, non-confirmation of the fact of the attack is the best result of the work of specialists. Such cases happen from time to time.

How are cybersecurity incidents investigated?

Speaking about the investigation of cybersecurity incidents, two areas of activity should be distinguished:

1. Attribution of the attack, that is, understanding how and by what means it was carried out.

2. Legal support of the incident, which includes finding the attacker and cooperating with law enforcement agencies.

As I noted above, the customer is primarily interested in preventing similar attacks in the future. So, the main value for the business is precisely the commercial investigation of the incident.

At the same time, for example, when it comes to an attack carried out by an insider, it is important to find people involved in the incident and take the necessary measures in relation to them. Not all cybersecurity incident investigation companies provide this service. We know that lawyers can be awfully expensive, and legal support can cost significantly more than a “technical” investigation.

Avoiding malicious insiders is not a trivial task. You have to build strong relationships between HR dept, legal dept, and law enforcement. HR managers should screen all new comers carefully but running background checks and using lie detectors.

Can you investigate incidents without the involvement of third-party specialists?

According to security experts, a company with sufficiently mature security and IT departments is able to do a big part of the investigation of an incident.

The problem is that in the process of analyzing the incident, the customer is likely to face the need to attract a narrow specialist. It is often unprofitable to keep such people on the staff.

Specialized service providers have the ability to build well-trained investigative teams from both internal and external experts.

How to collect the information necessary for the investigation without paralyzing business processes?

When conducting an investigation, it is essential to properly build interaction with the customer’s team. Competent employees of the customer who understand how the infrastructure works can wholly or partially take over the function of collecting the necessary data without disrupting business processes. The service provider must only set the task correctly: what data and from what objects need to be collected.

Responding to an ongoing attack and “expelling” the attacker from the network can significantly impact business processes. However, if the investigation is conducted correctly, the business stop will be short-lived.

Is it possible to automate the investigation by handing it over to specialized tools?

Some experts argue that with the right selection of software solutions, security specialists may be required only as a last resort to analyze the most complex cases.

Another part of the experts does not agree with this approach, claiming that the interpretation of the data collected in an automatic mode can be incorrect and should be done by people.

Who is behind the incident?

The largest number of cybersecurity incidents falls on organized cyber crime, which is primarily interested in commercial companies. If we talk about government agencies, they are most often attacked by APT groups. The qualifications of an attacker can often be judged only by indirect signs – the complexity of the tools used, the methods used, and some other factors.

It is critical for the target organization to know who is behind the incident in order to understand what consequences it can bring. Is the incident the tip of the iceberg that will turn into a massive campaign, or is it an isolated episode resulting from a coincidence? Response methods also depend on the targets of the attackers.

Investigating incidents that happened in the cloud

Obtaining logs from a cloud provider is usually difficult. Some cloud operators provide such information only at the request of law enforcement agencies. Even interaction with the support service of a cloud provider can be complicated since it is necessary to form a request correctly.

On the other hand, getting a disk image from a cloud provider is often even easier than working with your own server. Most major providers offer this functionality.

It is recommended to discuss the audit and logging settings with the provider at the contract signing stage and include these functions in the list of services provided.

Practical issues of the investigation of cybersecurity incidents

During the investigation process, outside experts sometimes encounter opposition from the customer’s IT department. This may be due to an attempt to hide flaws in the security of the infrastructure or the complicity of employees in the attack. There are many examples when, in an attempt to cover their tracks, the customer’s employees tried to delete logs, disable remote access, and even swallow a USB flash drive with data.

Do governments provide support in investigating cybersecurity incidents?

Businesses have a wary attitude towards government authorities, whose actions sometimes complicate the investigation. At the same time, there is a positive trend in the work of law enforcement agencies, especially in the field of interstate cooperation and solving cyber crimes on different continents.

Another function of state bodies is educational. Through regulation, they explain the importance of investigations, making it much easier for information security professionals to work with government enterprises.

What is next for the computer forensic science and industry in the coming years?

I expect the increasing role of automation in the processes of investigating information security incidents. Specialized systems will be able to receive information from more sources.

They will also actively use machine learning. At the same time, the role of people in the investigation will continue to be significant. Defense mechanisms that are not looked after are ineffective against human-controlled attacks.

Conclusion

Understanding the pattern of the attack, the penetration techniques, and the tools used by the attackers can help an organization prevent similar incidents in the future. However, cybersecurity investigations are not limited to the attribution of the attack. Specialized companies are able not only to assist in working with law enforcement agencies and help find cyber criminals but also reveal their motives. The latter is especially important since a seemingly insignificant incident may only be the visible part of a large, targeted attack.

To effectively investigate information security incidents, a dedicated team of specialists is required, and not every company is able to hire and keep such people. At the same time, effective interaction with the customer’s employees can significantly help vendor companies analyze the incident and identify the culprits.

Unfortunately, while investigating cybersecurity incidents, there are some cases of opposition on the part of the IT departments who try to hide their unprofessionalism or blunt sabotage.

 

Alex Vakulov is a cybersecurity researcher with over 20 years of experience in malware analysis. Alex has strong malware removal skills. He is writing for numerous tech-related publications sharing his security experience.

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.