SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Information Architecture >> Identity Management

Forensics education pays off, says examiner

Forensics education pays off, says examiner

By:  Jeff Jedras  On: 29 Sep 2005 For: ComputerWorld Canada Creator

As a senior security specialist and forensic examiner with Vancouver’s Totally Connected Security, Ryan Purtia has worked closely for a number of years with corporate and law enforcement clients in the field of computer forensics. He talked with ComputerWorld Canada Senior Writer Jeff Jedras about the field of computer forensics and how it can help the enterprise.

As a senior security specialist and forensic examiner with Vancouver’s Totally Connected Security, Ryan Purtia has worked closely for a number of years with corporate and law enforcement clients in the field of computer forensics. He talked with ComputerWorld Canada Senior Writer Jeff Jedras about the field of computer forensics and how it can help the enterprise.

How did you get into the field of computer forensics?

I did a lot of computer security work in the past and a lot of my work involved breaking into computer systems, telling companies how I did it and how to fix it. One of the biggest things I had to do was hide things so the administrators wouldn’t know the particular piece of software allowing me access was still there until I was able to compile my report and show it all to them. It was a natural progression to go from hiding stuff and doing ethical hacking to finding it.

How would you define the concept of computer forensics, and how does it differ from other fields of computer security?

Computer forensics is very different from IT security in the sense that computer forensics is usually a reactive step. Either someone has broken into [a firm’s] systems or it could be the receptionist accessing files they shouldn’t. Computer forensics plays its role when they think something has occurred, whether it is insider theft or a hacker. It’s brought in to determine how the event happened, how far they got, and what they had access to.

Is this a responsibility that you could assign to your Information Techno-logy manager?

If you were a CIO, you would never want your internal staff have a go at the computer. Usually, if an employee leaves and they suspect he’s taken something, they go to their IT administrator and say, ‘Pull up all his e-mails, look for these files on his computer, check to see if he accessed this.’ But unless they’re trained as a forensic investigator, they’re actually destroying evidence as they go along. When you click on a file in Windows, for example, it will change the date and time stamp of that file, which may be crucial to a forensic investigator when they’re trying to construct a timeline. If you have an incident, don’t do anything until you mirror the hard drive. Once you’ve done that you can go at that original machine all you want, it doesn’t matter.

Is there awareness among companies that these options and skills are out there and available to them?

No, not a lot. When we go out and explain to people we can pull up deleted e-mails and files that have been deleted, or that most of the time when a hard drive has been reformatted, we can usually get 100 per cent of the data back, all we get is dropped jaws. People still don’t know these things are possible. It’s surprising that after forensics has been around now for 10 years at least, there’s still that lack of knowledge, whereas everyone knows what a firewall is.


Sign up for our Newsletters
Tags:












Print |  Views: 578   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Jeff Jedras Jeff Jedras joined CDN as a senior writer in 2007. While he was new to the channel he was no stranger to technology journalism, beginning his career in Ottawa with Silicon Valley NORTH in 1998, where he... more

Related Content

RIM details features in BlackBerry Enterprise Server 5.0
RIM details features in BlackBerry Enterprise Server 5.0Updates give administrators more visibility, simplified deployment and better management and reporting, the company says. Users call it a major step forward
Usability critical for good mobile security
Usability critical for good mobile securityThe consequences of a data breach can be far-reaching and complex, but in almost every case the cause is simple. An employee, the 'average user', has either taken a shortcut around the security procedures or lost a device with critical data in a public place, or both.
White House insider urges cyber-security rethink
White House insider urges cyber-security rethinkTechnology exists to build protection systems into IT’s infrastructure, but the biggest challenge remains the human element.
Passport Canada lets all kind of personal data through
i guess i’ll be standing in line to apply for my passport after all.given the long lineups and crazy backlog that has placed the passport cana

Comments (0)

No Comments!
Name: (required) eMail: (optional)

Your email address will not appear online and will be used only if the editor wishes to contact you personally for additional comments.