Loading presentation...

Present Remotely

Send the link below via email or IM

Copy

Present to your audience

Start remote presentation

  • Invited audience members will follow you as you navigate and present
  • People invited to a presentation do not need a Prezi account
  • This link expires 10 minutes after you close the presentation
  • A maximum of 30 users can follow your presentation
  • Learn more about this feature in our knowledge base article

Do you really want to delete this prezi?

Neither you, nor the coeditors you shared it with will be able to recover it again.

DeleteCancel

Make your likes visible on Facebook?

Connect your Facebook account to Prezi and let your likes appear on your timeline.
You can change this under Settings & Account at any time.

No, thanks

Opensource Writeblocker

No description
by

Lee Tobin

on 6 March 2014

Comments (0)

Please log in to add your comment.

Report abuse

Transcript of Opensource Writeblocker

Features
Imaging
Write-blocking
Image Verification
Image storage
Encryption
EWF support
Diskless
Highly configurable

DCFLDD
http://dcfldd.sourceforge.net/
"dcfldd is an enhanced version of GNU dd with features useful for forensics and security."
LIO SCSI Target
http://linux-iscsi.org/wiki/Main_Page
iBlock Backstore
Linux BLOCK device as a backstore
SCSI access over FireWire
Backstore viewable over FireWire
MD5 Hashing
RAID storage
Initialised via FIREBrick menu
Can be accessed over writeblocked FireWire
RAID0/RAID1 (Mirror/Stripe)
Automatically detected from SATA port configuration
https://code.google.com/p/cryptsetup/
"LUKS is the standard for Linux hard disk encryption"
Could be SHA-1, SHA-2...
LibEWF
https://code.google.com/p/libewf/
Ewfacquire
Ewfacquire
"ewfacquire is a utility to acquire media data from a source and store it in EWF format"
Coreboot
Coreboot.org
"coreboot is a Free Software project aimed at replacing the proprietary BIOS (firmware) found in most computers"
Future development
Keyword searches
"Scoville" indication
Report generation
Form factor development
Drive hot swapping
Networking/remote imaging
Mobile device acquisition
USB/Audio/Packet capture
Web frontend
Writeblocking over ethernet (iSCSI)
...also file searching, hash searching...
...should I image this drive?
...save a report of disk contents
...mini-itx, nano-itx
Diskless
Quick booting
Less chance to change OS
user activity
triage tool
More robust
Cheaper
Storage can be encrypted!
Tried and tested tool
triage
Q & A
dfire.ucd.ie
https://github.com/leetobin/firebrick


lee.tobin@ucdconnect.ie

Imaging
Write-blocking
Image verification
Image storage
Encryption
Expert Witness Format - Encase
Diskless
Caveats
Not a competitor to commercial write-blockers
Not certified
yet
(IEEE, ISO, NIST etc)
Well tested, however test as you develop.

Remote FIREBrick (v2)
Use your phone to control the FIREBrick
Acts as a wireless access point
Smaller, no LCD screen required
Remote access
Lee Tobin
digitalfire.ucd.ie
Shopping list
Motherboard - ASRock E350M1
RAM - 1GB DDR3 (1333 or 1066)
Firewire card - Dynamode PCIX3FW 3-Port
Case + power supply
Quickstart
Download the FIREBrick BIOS file
Boot the system from a USB key
Flash the stock BIOS with the FIREBrick BIOS
Open source write-blocker/imager
FIREBrick
Lee Tobin
Full transcript