Question

In: Statistics and Probability

Now you may understand why you need a statistics course. As a forensics analyst, how would...

Now you may understand why you need a statistics course. As a forensics analyst, how would you use statistical flow analysis to identify a compromised host? How about to confirm or disprove data leakage? How would it be used to create a profile of an individual? Can statistical flow analysis be used to prevent either a host becoming compromised or data being leaked?

Solutions

Expert Solution

Statistical flow analysis can be used to identify a compromised host by analysis and search of a system's native forensic sources of evidence -- i.e., what's preserved by the operating system on its own during normal system operations. This includes the ability to run quick, targeted searches for files, processes, log entries, artifacts in memory and other evidence across systems at scale. It complements the use of a continuous event recorder and can be used to broaden the scope of an investigation and find additional leads that might not otherwise have been preserved.

To confirm or disprove data leakage products can proactively collect and analyze the sources of data cited , and compare it to structured threat intelligence (such as Indicators of Compromise), rules or other heuristics intended to detect malicious activity. The data that's been gathered is used to prove (or disprove!) the case being built by examiners. For each relevant data item, examiners will answer the basic questions about it — who created it? who edited it? how was it created? when did this all happen? — and attempt to determine how it relates to the case.

To create a profile of an individual various methods are used to identify and extract data. This step can be divided into preparation, extraction and identification. Important decisions to make at this stage are whether to deal with a system that's live (for instance, to power up a seized laptop) or dead (for instance, connecting a seized hard drive to a lab computer). Identification means determining whether individual pieces of data are relevant to the case at hand — particularly when warrants are involved, the information examiners are allowed to learn may be limited.

Yes,statistical flow analysis be used to prevent either a host becoming compromised or data being leaked by evidence collection from individual hosts of interest. As investigators identify systems that warrant further inspection, they may conduct "deep-dive" evidence collection and analysis across the entirety of a subject system's historical telemetry (if present and recorded), files on disk and memory. Most organizations prefer to perform remote, triage-level analysis of live systems in lieu of comprehensive forensic imaging wherever possible.


Related Solutions

Why is it important to understand the difference between sample and population in a statistics course?
Why is it important to understand the difference between sample and population in a statistics course?
You need to establish a procedure for your organization on how to validate a new forensics...
You need to establish a procedure for your organization on how to validate a new forensics software package. Write two to three pages outlining the procedure you plan to use in your lab. Be sure to cite references, such as the ISO standard or NIST, to support your procedure.
. Big picture question: Now that you understand statistics. I want you to answer a couple...
. Big picture question: Now that you understand statistics. I want you to answer a couple of questions. Can a skilled statistician “make anything significant”? How would this be/not be accomplished? How could you design a study to guarantee significance? What is statistical power and how is it relevant to this big picture question? [6 Points]
Big picture question: Now that you understand statistics. I want you to answer a couple of...
Big picture question: Now that you understand statistics. I want you to answer a couple of questions. Can a skilled statistician “make anything significant”? How would this be/not be accomplished? How could you design a study to guarantee significance? What is statistical power and how is it relevant to this big picture question? [6 Points]
Big picture question: Now that you understand statistics. I want you to answer a couple of...
Big picture question: Now that you understand statistics. I want you to answer a couple of questions. Can a skilled statistician “make anything significant”? How would this be/not be accomplished? How could you design a study to guarantee significance? What is statistical power and how is it relevant to this big picture question?
Congratulations! After passing your course in Business Statistics, you received a job as a statistical analyst...
Congratulations! After passing your course in Business Statistics, you received a job as a statistical analyst at a major business corporation. Your first task is to decide which statistical test would be the most appropriate to use to analyze the following   problems.    Luckily, you remember learning about the following statistical tests in your favorite (and only) business statistics course. A.   z-test for one sample mean                                           H.    t- test for paired data B. z -test for one sample proportion                                   I.   ...
7. Big picture question: Now that you understand statistics. I want you to answer a couple...
7. Big picture question: Now that you understand statistics. I want you to answer a couple of questions. Can a skilled statistician “make anything significant”? How would this be/not be accomplished? How could you design a study to guarantee significance?
How much would you need to deposit in an account now in order to have $6000...
How much would you need to deposit in an account now in order to have $6000 in the account in 5 years? Assume the account earns 2% interest compounded daily. $ You decide to contribute to a mutual fund that averages 3.6% return per year. If you contribute $225 quarterly. Round all answers to the nearest cent as needed. a) How much will be in the account after 15 years? $ b) How much of this money did you deposit?...
If you are the instructor of a course, how would you structure the course and its...
If you are the instructor of a course, how would you structure the course and its content to incorporate the anagogical approach in a college class. Instead of traditional lectures in class, what would you suggest as learning activities that would be challenging but effective in acquiring knowledge of skills in the course?
Now that you understand what GDP is and how it is calculated do you think it...
Now that you understand what GDP is and how it is calculated do you think it is a good measure of economic activity. Make sure you reference any problems you may have with Real versus Nominal GDP. Just for your information a very big discussion is currently underway concerning Real versus Nominal GDP as a target of economic policy. If any takes intermediate Macroeconomics we will spend time examining that issue.
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT