DFIR Briefly Expained – Part 1

DFIR Briefly Expained – Part 1

Since we are going to be learning in future blog posts the specifics of Digital Forensics & Incident Response (DFIR), we first need to establish a foundation of basic knowledge from which we will build upon. The easiest way I know how to do that (without writing an entire book) is to define the common terminologies in use and provide additional context as necessary. (If you are looking for a good book on DFIR I would highly recommend this one: [I have no affiliation with the owner/author/seller] Incident Response & Computer Foresnics.)

  • What is DFIR?
  • DFIR (pronounced: “dē-’fər”) stands for Digital Forensics & Incident Response.
  • Digital Forensics & Incident Response is a sub-specialty of Cyber-security that deals with identifying, investigating, and restoring from a security related incident or compromise on a computer network.
  • In my experience, typical DFIR teams are usually composed of various key members of the larger business model (IT department, Security Operations Center, Forensic Examiners/Analysts, Legal Department, C-Suite representatives, Human Resources, etc.) The DFIR team can be either full-time or part-time depending on the size and needs of the business.
  • What is digital forensics?
  • According to NIST, digital forensics is defined as, “In its strictest connotation, the application of computer science and investigative procedures involving the examination of digital evidence – following proper search authority, chain of custody, validation with mathematics, use of validated tools, repeatability, reporting, and possibly expert testimony.”
  • What is “Incident Response”?
  • According to the Incident Response & Computer Forensics Third Edition, “Incident Response is a coordinated and structured approach to go from incident detection to resolution.”
  • Incident Response is a set of processes and procedures used to detect, identify, analyze, and remediate security incidents.

The next few definitions come from “RFC’s.” RFC’s are documents that have been reviewed, approved, and published by the Internet Engineering Task Force (IETF) and are the de facto manual for regards to policy, protocol, and technical documentation.

  • What is a “Security Incident”?
  • Defined in RFC 4949 as, “A security event that involves a security violation.”
  • What is a “Security Intrusion”?
  • Also defined in RFC 4949 as, “A security event, or a combination of multiple security events, that constitutes a security incident in which an intruder gains, or attempts to gain, access to a system or system resource without having authorization to do so.”

For the sake of simplicity, we will consider a security incident and a security intrusion as one and the same. That is, bad or potentially bad activity that was detected in the environment and warrants further investigation by properly trained individuals in accordance with the current best practices and procedures.

  • What is digital evidence?
  • Digital evidence is data that is stored or transmitted digitally and may be relied upon in a court of law or other legal proceeding.
  • What standards govern the collection of digital evidence?
  • Specifically, RFC 3227, is the document that deals with the collection of digital evidence and the order of volatility. See RFC 3227 – Guidelines for Evidence Collection and Archiving”.

Please take the time to read RFC 3227 as this will be a foundational reference for all of our future work.

Share this post

Leave a Reply

Your email address will not be published. Required fields are marked *