Activity4 - Incidentanalysis - Script L Band 3r
Activity4 - Incidentanalysis - Script L Band 3r
Activity4 - Incidentanalysis - Script L Band 3r
Use the section headings below to structure a response for each evidence item.
Method of acquiring the evidence: Documentation that would have been made
when the network was first set up.
Evidence detail: The diagram shows how the Main Switch is the main component of
the network, this is because each component connects to it. There are no connections
between individual components, on single connections to the Main Switch.
Evidence reliability: Good. There is nothing that suggests that the layout has been
changed.
Conclusions: The diagram shows us all the possibilities that an attacker could use in
order to gain access to the floor. It is apparent that the main switch has the most
important role in the network and it is a possibility that is how the thief's managed to
gain access. There is a possibility that the thief's used a Wi-Fi connection to attack
and gain control to the Electronic door control system. However, this situation is less
likely to happen, as the information that was gathered in tasks 2&3 suggests an
alternative form of access to the floor.
Given the evidence which was presented, I believe the most likely explanation is that
the employee cards were either stolen or manipulated in some way. There is a link
between the phantom card charges and the access to the floor. A likely situation is
that the thieves used the contactless card technology to get the information of
employee cards. Once collecting the cards, they then proceeded to go to the 19th floor
and try different employee cards unit one of them worked, giving them access. Once
inside, the thieves grabbed what they could easily get, the laptop and phone left on
the table and various appliances from systems. The thieves then exited the floor using
the push button that unlocks the doors from the inside. I believe that this is the most
likely explanation as the information given by the employees, whose cards were
involved, all places them at a different location to where the theft went down. As well
as the reports to the phantom card charges and thefts which occurred the day before
the incident.
A less likely explanation is that the electrical appliances were stolen by either the
cleaners or security team. This may have occurred anyone of the times they logged
into the floor, while doing their job. However, in the meeting which Baljinder attended,
it was made clear that the employees are employed directly from EH and they have
better pay and working conditions compared to similar jobs in the area.
The least likely explanation is that attackers were able to manipulate the Main Switch
on the floor to gain access to the doors. The attackers may have been able to hack
the main switch while using a device connected to the Wi-Fi. I feel this is the least
likely explanation, as the software needed to complete this task is very complicated,
and the items that were stolen don’t seem to be worth the time or effort.