SlideShare uma empresa Scribd logo
1 de 48
Baixar para ler offline
European Antitrust Forensic IT Tools
Nino Vincenzo Verde
verde@di.uniroma1.it
Dipartimento di Informatica
Universita` di Roma "La Sapienza"
113 Via Salaria, 00198 Roma, ITALY
email: verde@di.uniroma1.it
4/17/15verde@di.uniroma1.it
About me
4/17/15verde@di.uniroma1.it
● Primo appuntamento sui temi del Master:
– Come: Tavola rotonda "Cybercrime e Informatica forense: errori,
professionalità e ambiti di applicazione"
– Dove: Aula alfa, via Salaria 113
– Quando: 28/4/2015 ore 16-19
– Discussant: esponenti della Corte di Cassazione, Procura, Polizia Postale,
Albo psicologi, etc.
● Info: mastersicurezza@di.uniroma1.it
Dipartimento di Informatica della Facoltà di Ingegneria
dell'Informazione, Informatica e Statistica
dell’Università degli Studi di Roma “La Sapienza”
4/17/15verde@di.uniroma1.it
Obiettivi del master
● Promuovere una professionalità multidisciplinare che
integri le competenze, attualmente scisse nel mondo
della formazione, del settore informatico, giuridico e
psicologico
● Sviluppare un profilo di esperienza che possa
intervenire, con una competenza analitica, tecnico-
investigativa in ambito giudiziario, aziendale e nella
pubblica amministrazione
4/17/15verde@di.uniroma1.it
Aree tematiche principali
● Computer Security and Computer Forensics
● Malware Analysis and Investigation
● Mobile Device Forensics
● Live Data Forensics
● Money Laundering Investigations
● Criminal profiling and crime investigations
● Risk analysis for reputation preservation
● Big Data e Data Mining
● Enterprise Reputation and Risk Management
4/17/15verde@di.uniroma1.it
Outline of the talk
● Introduction about the antitrust activities
● International context of the project
● The EAFIT_TOOLS project
– Objectives
– Project phases
– Peculiarities of the Antitrust Investigations
● EAFIT_TOOLS indexing software
● Final remarks
4/17/15verde@di.uniroma1.it
Introduction about the Antitrust Activities
● Competition encourages companies to offer consumers
goods and services at the most favourable terms
– Anticompetitive practices cases
– Abuse of dominance cases
● Cartels:
– is a specific type of antitrust enforcement.
– A cartel is a group of similar, independent companies which join together to fix
prices, to limit production or to share markets or customers between them.
4/17/15verde@di.uniroma1.it
Introduction about the Antitrust Activities
● Competition encourages companies to offer consumers
goods and services at the most favourable terms
– Anticompetitive practices cases
– Abuse of dominance cases
● Cartels:
– is a specific type of antitrust enforcement.
– A cartel is a group of similar, independent companies which join together to fix
prices, to limit production or to share markets or customers between them.
● Terminology:
– Competition Authority (CA) = Antitrust
4/17/15verde@di.uniroma1.it
Fighting against cartels: typical workflow
4/17/15verde@di.uniroma1.it
Fighting against cartels: typical workflow
LENIENCY
PROGRAM
4/17/15verde@di.uniroma1.it
Fighting against cartels: typical workflow
LENIENCY
PROGRAM
4/17/15verde@di.uniroma1.it
Fighting against cartels: typical workflow
LENIENCY
PROGRAM TRIAL
4/17/15verde@di.uniroma1.it
Examples of Fines: AGCM – Italy (2014)
4/17/15verde@di.uniroma1.it
Examples of Fines: AGCM – Italy (2014)
4/17/15verde@di.uniroma1.it
Examples of Fines: AGCM – Italy (2014)
I due gruppi si sono accordati illecitamente per ostacolare la diffusione dell’uso di un farmaco molto
economico, Avastin, nella cura della più diffusa patologia della vista tra gli anziani e di altre gravi malattie
oculistiche, a vantaggio di un prodotto molto più costoso, Lucentis, differenziando artificiosamente i due
prodotti.
Per il Sistema Sanitario Nazionale l’intesa ha comportato un esborso aggiuntivo stimato in oltre 45 milioni di
euro nel solo 2012, con possibili maggiori costi futuri fino a oltre 600 milioni di euro l’anno.
4/17/15verde@di.uniroma1.it
Examples of Fines: AGCM – Italy (2014)
I due gruppi si sono accordati illecitamente per ostacolare la diffusione dell’uso di un farmaco molto
economico, Avastin, nella cura della più diffusa patologia della vista tra gli anziani e di altre gravi malattie
oculistiche, a vantaggio di un prodotto molto più costoso, Lucentis, differenziando artificiosamente i due
prodotti.
Per il Sistema Sanitario Nazionale l’intesa ha comportato un esborso aggiuntivo stimato in oltre 45 milioni di
euro nel solo 2012, con possibili maggiori costi futuri fino a oltre 600 milioni di euro l’anno.
4/17/15verde@di.uniroma1.it
Examples of Fines: AGCM – Italy (2014)
Fine of €180 millions
I due gruppi si sono accordati illecitamente per ostacolare la diffusione dell’uso di un farmaco molto
economico, Avastin, nella cura della più diffusa patologia della vista tra gli anziani e di altre gravi malattie
oculistiche, a vantaggio di un prodotto molto più costoso, Lucentis, differenziando artificiosamente i due
prodotti.
Per il Sistema Sanitario Nazionale l’intesa ha comportato un esborso aggiuntivo stimato in oltre 45 milioni di
euro nel solo 2012, con possibili maggiori costi futuri fino a oltre 600 milioni di euro l’anno.
4/17/15verde@di.uniroma1.it
Examples of Fines: DG Comp (2014)
4/17/15verde@di.uniroma1.it
Examples of Fines: DG Comp (2014)
4/17/15verde@di.uniroma1.it
Examples of Fines: DG Comp (2014)
Dominant position in the x86 CPU market
(1) granting rebates to 4 PC and server manufacturers (Dell, HP, NEC, Lenovo) conditional on
them obtaining all or almost all of their supplies from Intel, and payments to one downstream
computer retailer (Media Markt) conditional on it only selling PCs with Intel CPUs ("conditional
rebates"); and
(2) granting direct payments to 3 computer manufacturers (HP, Acer and Lenovo) to halt, delay or
limit the launch of specific products incorporating chips from Intel’s only rival, AMD (so-called
“naked restrictions”).
4/17/15verde@di.uniroma1.it
Examples of Fines: DG Comp (2014)
Fine of €1.06 billion
Dominant position in the x86 CPU market
(1) granting rebates to 4 PC and server manufacturers (Dell, HP, NEC, Lenovo) conditional on
them obtaining all or almost all of their supplies from Intel, and payments to one downstream
computer retailer (Media Markt) conditional on it only selling PCs with Intel CPUs ("conditional
rebates"); and
(2) granting direct payments to 3 computer manufacturers (HP, Acer and Lenovo) to halt, delay or
limit the launch of specific products incorporating chips from Intel’s only rival, AMD (so-called
“naked restrictions”).
4/17/15verde@di.uniroma1.it
International Context of the Project
● European Competition Network (ECN)
● In 2010 the ECN Forensic IT (FIT) WG was formally established
(informal meetings held since 2003)
– A forum for the European competition authorities helping them to solve technical, procedural
and legal issues
● A number of important initiatives have been undertaken:
– First training programme (March 2009 – March 2010)
● Forty-four (44) officials belonging to 25 European competition authorities representing 23 different
countries
– EATEP_FIT (Sep 2011 – Aug 2014)
● Training and exchange programme (September 2011 – August 2014)
● 125 officers (56 FIT experts and 69 case-handlers) have attended the courses.
● 52 exchanges have taken place, some of them providing cross-border FIT assistance in dawn raids
– EAFIT_TOOLS
4/17/15verde@di.uniroma1.it
The EAFIT_TOOLS Project
● European project with financial support from the
Prevention of and Fight against Crime Programme
of the European Union - European Commission -
Directorate - General Home Affairs
● Funding Programme: Prevention of and Fight
against Crime
● Coordinator: Italian Competition Authority – AGCM
– Dott. Mauro La Noce
● Scientific Coordination: Roberto Di Pietro
● Total Funding: €710.080,39
● Period: November 2013 – October 2015
4/17/15verde@di.uniroma1.it
Partners
4/17/15verde@di.uniroma1.it
Partners
Partners
4/17/15verde@di.uniroma1.it
Partners
Partners Stakeholders
4/17/15verde@di.uniroma1.it
EAFIT_TOOLS Project Objectives
● To boost the technical convergence of tools, protocols
and procedures for forensic analysis in the ECN.
– Collect a set of widely shared requirements about the forensics activities and
procedures on cartels investigation and antitrust enforcement of the European
Competition Authorities (CAs).
– To recognize and classify already exiting tools in order to create a map between
the CAs requirements and the existing open-source libraries and tools.
– To integrate the selected open-source tools and develop a prototype of an
European Antitrust Forensic IT software.
● Focus on Open source software
4/17/15verde@di.uniroma1.it
Project Phases
● Phase 1: Requirements analysis
● Phase 2: Open Source tools recognition and
classification
● Phase 3: Implementation, Testing and User Training
4/17/15verde@di.uniroma1.it
Requirement Analysis
● Elicitation
– On site interviews
● 7 Competition Authorities have been visited
– Requirements workshop
● 42 attendees from 27 national and transnational Competition Autorities - 2 days
● Result: 155 raw requirements
● Specification
● Validation
4/17/15verde@di.uniroma1.it
Peculiarities of Antitrust investigations
4/17/15verde@di.uniroma1.it
Peculiarities of Antitrust investigations
1. PRE DAWN RAID
- Raid preparation (intelligence phase, keywords elicitation, team
compositions, etc.)
- OSInt
4/17/15verde@di.uniroma1.it
Peculiarities of Antitrust investigations
1. PRE DAWN RAID
- Raid preparation (intelligence phase, keywords elicitation, team
compositions, etc.)
- OSInt
2. DAWN RAID
- 1 or 2 days on-site for most of the Antitrusts
- On average 5 to 10 sites investigated at the same time
- They try to bring home only relevant evidence (no disk
images when possible)
- Interesting artifacts:
Office documents, pdf, etc... (content and metadata)
Deleted files
Emails (also from mail servers)
Backups, Instant Messaging, Mobile phones
- FIT activities most of time end with the dawn raid
- Wiping
4/17/15verde@di.uniroma1.it
Peculiarities of Antitrust investigations
1. PRE DAWN RAID
- Raid preparation (intelligence phase, keywords elicitation, team
compositions, etc.)
- OSInt
2. DAWN RAID
- 1 or 2 days on-site for most of the Antitrusts
- On average 5 to 10 sites investigated at the same time
- They try to bring home only relevant evidence (no disk
images when possible)
- Interesting artifacts:
Office documents, pdf, etc... (content and metadata)
Deleted files
Emails (also from mail servers)
Backups, Instant Messaging, Mobile phones
- FIT activities most of time end with the dawn raid
- Wiping
4/17/15verde@di.uniroma1.it
Peculiarities of Antitrust investigations
1. PRE DAWN RAID
- Raid preparation (intelligence phase, keywords elicitation, team
compositions, etc.)
- OSInt
2. DAWN RAID
- 1 or 2 days on-site for most of the Antitrusts
- On average 5 to 10 sites investigated at the same time
- They try to bring home only relevant evidence (no disk
images when possible)
- Interesting artifacts:
Office documents, pdf, etc... (content and metadata)
Deleted files
Emails (also from mail servers)
Backups, Instant Messaging, Mobile phones
- FIT activities most of time end with the dawn raid
- Wiping
3. POST DAWN RAID
- Most of the Antitrusts cannot review the collected evidence without
the part
- Only a few have a large infrastructure lab (DK, DE)
4/17/15verde@di.uniroma1.it
Sets of requirements: relevance
4/17/15verde@di.uniroma1.it
The EAFIT_TOOLS Indexing software
● It will be delivered at the end of the project (Oct 2015):
– Distributed system easy to set-up
– Indexing of massive amount of documents (parallelizing computation On Site)
– Team file reviewing
– Multi user and multi case management
– Collaborative tagging and labelling
– Flexible:
● On site
● In Lab
– It will be probably released under GPLv3 licence
The dawn raid use-case scenario
Triage Phase Analysis Phase (On Site)
The dawn raid use-case scenario
Case Handler
Fit Expert 2
Triage Phase Analysis Phase (On Site)
Administrator
Fit Expert 1
The dawn raid use-case scenario
Case Handler
Fit Expert 2
Triage Phase Analysis Phase (On Site)
Administrator
Fit Expert 1
Live Distribution EAFIT_TOOLS Software
The dawn raid use-case scenario
Case Handler
Fit Expert 2
Triage Phase Analysis Phase (On Site)
Administrator
Fit Expert 1
Live Distribution EAFIT_TOOLS Software
The dawn raid use-case scenario
Case Handler
Fit Expert 2
Triage Phase Analysis Phase (On Site)
Administrator
Fit Expert 1
Live Distribution EAFIT_TOOLS Software
The dawn raid use-case scenario
Case
Handler
Case
Handler
Case
Handler
Case Handler
Fit Expert 2
Triage Phase Analysis Phase (On Site)
Administrator
Fit Expert 1
Live Distribution EAFIT_TOOLS Software
The dawn raid use-case scenario
Case
Handler
Case
Handler
Case
Handler
Case Handler
Fit Expert 2
Triage Phase Analysis Phase (On Site)
Administrator
Fit Expert 1
Live Distribution EAFIT_TOOLS Software
The dawn raid use-case scenario
Case
Handler
Case
Handler
Case
Handler
Administrator
Fit Expert 1
Case Handler
Fit Expert 2
Triage Phase Analysis Phase (On Site)
Administrator
Fit Expert 1 Case Handler
Fit Expert 2
Live Distribution EAFIT_TOOLS Software
The dawn raid use-case scenario
Case
Handler
Case
Handler
Case
Handler
Administrator
Fit Expert 1
Case Handler
Fit Expert 2
Triage Phase Analysis Phase (On Site)
Administrator
Fit Expert 1 Case Handler
Fit Expert 2
Live Distribution EAFIT_TOOLS Software
4/17/15verde@di.uniroma1.it
The EAFIT_TOOLS Indexing software: the architecture
4/17/15verde@di.uniroma1.it
Final remarks
● Forensic IT areas are rapidly expanding and Antitrust
investigations are a clear example
● Forensic collection of artifacts + On Site Indexing of a
large amount of data + collaborative reviewing is a
MUST for them
● OSInt is another point of attention
– i.e.: Recover info about outsourced services before dawnraid
● The european antitrust strategy: Open Source!
* Responsibility for the information and views expressed in this presentation lies
entirely with the author.
4/17/15verde@di.uniroma1.it
Presentazione del master in “Cybercrime e Informatica forense”
– Quando: 28/4/2015 ore 16-19
– Dove: Aula alfa, via Salaria 113

Mais conteúdo relacionado

Mais procurados

Requirements Engineering Methods for Documenting Requirements (lecture slides)
Requirements Engineering Methods for Documenting Requirements (lecture slides)Requirements Engineering Methods for Documenting Requirements (lecture slides)
Requirements Engineering Methods for Documenting Requirements (lecture slides)Dagmar Monett
 
Experiences in Software Testing (lecture slides)
Experiences in Software Testing (lecture slides)Experiences in Software Testing (lecture slides)
Experiences in Software Testing (lecture slides)Dagmar Monett
 
Eckhard Behrendt - id2market consulting
Eckhard Behrendt - id2market consultingEckhard Behrendt - id2market consulting
Eckhard Behrendt - id2market consultingVitor Pereira
 
FP7 Legal Aspects (March 2007)
FP7 Legal Aspects (March 2007)FP7 Legal Aspects (March 2007)
FP7 Legal Aspects (March 2007)CPN_Africa
 
FP7 Information (March 2007)
FP7 Information (March 2007)FP7 Information (March 2007)
FP7 Information (March 2007)CPN_Africa
 
FP7 Specific Programme Capacities (March 2007)
FP7 Specific  Programme  Capacities (March 2007)FP7 Specific  Programme  Capacities (March 2007)
FP7 Specific Programme Capacities (March 2007)CPN_Africa
 
590X15 European Export Controls S
590X15 European Export Controls S590X15 European Export Controls S
590X15 European Export Controls SSTEPHANIE C HART
 
FP7 Financial Issues (March 2007)
FP7 Financial   Issues (March 2007)FP7 Financial   Issues (March 2007)
FP7 Financial Issues (March 2007)CPN_Africa
 
Estándares en Unión Europea: Marco, Desafíos y Oportunidades - Francisco Garc...
Estándares en Unión Europea: Marco, Desafíos y Oportunidades - Francisco Garc...Estándares en Unión Europea: Marco, Desafíos y Oportunidades - Francisco Garc...
Estándares en Unión Europea: Marco, Desafíos y Oportunidades - Francisco Garc...Asociación XBRL España
 
Pcp final-ramboll-report-js2 en
Pcp final-ramboll-report-js2 enPcp final-ramboll-report-js2 en
Pcp final-ramboll-report-js2 enDr Lendy Spires
 
FP7 Specific Programme Cooperation (March 2007)
FP7 Specific Programme Cooperation (March 2007)FP7 Specific Programme Cooperation (March 2007)
FP7 Specific Programme Cooperation (March 2007)CPN_Africa
 
Horizon 2020: Eurostars SME funding programme
Horizon 2020: Eurostars SME funding programme Horizon 2020: Eurostars SME funding programme
Horizon 2020: Eurostars SME funding programme EUREKA Secretariat
 
UK FP7 National Contact Point ICT, Peter Walters, FP7UK National Contact Poin...
UK FP7 National Contact Point ICT, Peter Walters, FP7UK National Contact Poin...UK FP7 National Contact Point ICT, Peter Walters, FP7UK National Contact Poin...
UK FP7 National Contact Point ICT, Peter Walters, FP7UK National Contact Poin...Invest Northern Ireland
 
Methods for Validating and Testing Software Requirements (lecture slides)
Methods for Validating and Testing Software Requirements (lecture slides)Methods for Validating and Testing Software Requirements (lecture slides)
Methods for Validating and Testing Software Requirements (lecture slides)Dagmar Monett
 
Opportunities for external funding in Flanders and The Netherlands
Opportunities for external funding in Flanders and The NetherlandsOpportunities for external funding in Flanders and The Netherlands
Opportunities for external funding in Flanders and The NetherlandsIS-X
 
OECD workshop on measuring the link between public procurement, R&D and innov...
OECD workshop on measuring the link between public procurement, R&D and innov...OECD workshop on measuring the link between public procurement, R&D and innov...
OECD workshop on measuring the link between public procurement, R&D and innov...STIEAS
 
Horizon2020 - SMEs in Horizon 2020, Catriona Ward, Enterprise Ireland - 27 Ma...
Horizon2020 - SMEs in Horizon 2020, Catriona Ward, Enterprise Ireland - 27 Ma...Horizon2020 - SMEs in Horizon 2020, Catriona Ward, Enterprise Ireland - 27 Ma...
Horizon2020 - SMEs in Horizon 2020, Catriona Ward, Enterprise Ireland - 27 Ma...Invest Northern Ireland
 
Fit for health 2.0, introduction to H2020
Fit for health 2.0, introduction to H2020Fit for health 2.0, introduction to H2020
Fit for health 2.0, introduction to H2020Pasteur_Tunis
 

Mais procurados (20)

Requirements Engineering Methods for Documenting Requirements (lecture slides)
Requirements Engineering Methods for Documenting Requirements (lecture slides)Requirements Engineering Methods for Documenting Requirements (lecture slides)
Requirements Engineering Methods for Documenting Requirements (lecture slides)
 
Experiences in Software Testing (lecture slides)
Experiences in Software Testing (lecture slides)Experiences in Software Testing (lecture slides)
Experiences in Software Testing (lecture slides)
 
Innovation Procurement in the General / e-Government sector – PCP case exampl...
Innovation Procurement in the General / e-Government sector – PCP case exampl...Innovation Procurement in the General / e-Government sector – PCP case exampl...
Innovation Procurement in the General / e-Government sector – PCP case exampl...
 
Eckhard Behrendt - id2market consulting
Eckhard Behrendt - id2market consultingEckhard Behrendt - id2market consulting
Eckhard Behrendt - id2market consulting
 
FP7 Legal Aspects (March 2007)
FP7 Legal Aspects (March 2007)FP7 Legal Aspects (March 2007)
FP7 Legal Aspects (March 2007)
 
FP7 Information (March 2007)
FP7 Information (March 2007)FP7 Information (March 2007)
FP7 Information (March 2007)
 
FP7 Specific Programme Capacities (March 2007)
FP7 Specific  Programme  Capacities (March 2007)FP7 Specific  Programme  Capacities (March 2007)
FP7 Specific Programme Capacities (March 2007)
 
590X15 European Export Controls S
590X15 European Export Controls S590X15 European Export Controls S
590X15 European Export Controls S
 
FP7 Financial Issues (March 2007)
FP7 Financial   Issues (March 2007)FP7 Financial   Issues (March 2007)
FP7 Financial Issues (March 2007)
 
Estándares en Unión Europea: Marco, Desafíos y Oportunidades - Francisco Garc...
Estándares en Unión Europea: Marco, Desafíos y Oportunidades - Francisco Garc...Estándares en Unión Europea: Marco, Desafíos y Oportunidades - Francisco Garc...
Estándares en Unión Europea: Marco, Desafíos y Oportunidades - Francisco Garc...
 
Pcp final-ramboll-report-js2 en
Pcp final-ramboll-report-js2 enPcp final-ramboll-report-js2 en
Pcp final-ramboll-report-js2 en
 
FP7 Specific Programme Cooperation (March 2007)
FP7 Specific Programme Cooperation (March 2007)FP7 Specific Programme Cooperation (March 2007)
FP7 Specific Programme Cooperation (March 2007)
 
Horizon 2020: Eurostars SME funding programme
Horizon 2020: Eurostars SME funding programme Horizon 2020: Eurostars SME funding programme
Horizon 2020: Eurostars SME funding programme
 
UK FP7 National Contact Point ICT, Peter Walters, FP7UK National Contact Poin...
UK FP7 National Contact Point ICT, Peter Walters, FP7UK National Contact Poin...UK FP7 National Contact Point ICT, Peter Walters, FP7UK National Contact Poin...
UK FP7 National Contact Point ICT, Peter Walters, FP7UK National Contact Poin...
 
ACT4-B6
ACT4-B6ACT4-B6
ACT4-B6
 
Methods for Validating and Testing Software Requirements (lecture slides)
Methods for Validating and Testing Software Requirements (lecture slides)Methods for Validating and Testing Software Requirements (lecture slides)
Methods for Validating and Testing Software Requirements (lecture slides)
 
Opportunities for external funding in Flanders and The Netherlands
Opportunities for external funding in Flanders and The NetherlandsOpportunities for external funding in Flanders and The Netherlands
Opportunities for external funding in Flanders and The Netherlands
 
OECD workshop on measuring the link between public procurement, R&D and innov...
OECD workshop on measuring the link between public procurement, R&D and innov...OECD workshop on measuring the link between public procurement, R&D and innov...
OECD workshop on measuring the link between public procurement, R&D and innov...
 
Horizon2020 - SMEs in Horizon 2020, Catriona Ward, Enterprise Ireland - 27 Ma...
Horizon2020 - SMEs in Horizon 2020, Catriona Ward, Enterprise Ireland - 27 Ma...Horizon2020 - SMEs in Horizon 2020, Catriona Ward, Enterprise Ireland - 27 Ma...
Horizon2020 - SMEs in Horizon 2020, Catriona Ward, Enterprise Ireland - 27 Ma...
 
Fit for health 2.0, introduction to H2020
Fit for health 2.0, introduction to H2020Fit for health 2.0, introduction to H2020
Fit for health 2.0, introduction to H2020
 

Destaque

Forensic Profiling with Digital Data
Forensic Profiling with Digital DataForensic Profiling with Digital Data
Forensic Profiling with Digital Datapiccimario
 
15 07-01 session 16.1 c connell
15 07-01 session 16.1 c connell15 07-01 session 16.1 c connell
15 07-01 session 16.1 c connellCatyC
 
2009 04-08 uni-mi_jpeg forensics
2009 04-08 uni-mi_jpeg forensics2009 04-08 uni-mi_jpeg forensics
2009 04-08 uni-mi_jpeg forensicsDavide Gabrini
 
2009 10-24 foss-e-computer-forensics
2009 10-24 foss-e-computer-forensics2009 10-24 foss-e-computer-forensics
2009 10-24 foss-e-computer-forensicsDavide Gabrini
 
Smau Milano 2011 Gentili-Fratepietro backtrack
Smau Milano 2011 Gentili-Fratepietro backtrackSmau Milano 2011 Gentili-Fratepietro backtrack
Smau Milano 2011 Gentili-Fratepietro backtrackSMAU
 
Deftcon 2013 - Giuseppe Vaciago - Osint e prevenzione dei Crimini
Deftcon 2013 - Giuseppe Vaciago - Osint e prevenzione dei CriminiDeftcon 2013 - Giuseppe Vaciago - Osint e prevenzione dei Crimini
Deftcon 2013 - Giuseppe Vaciago - Osint e prevenzione dei CriminiDeft Association
 
Vm sistemi suite data discovery
Vm sistemi suite data discoveryVm sistemi suite data discovery
Vm sistemi suite data discoverySilvia Montanari
 
Giuseppe Vaciago - Introduzione alla Computer Forensic e garanzie dell'indaga...
Giuseppe Vaciago - Introduzione alla Computer Forensic e garanzie dell'indaga...Giuseppe Vaciago - Introduzione alla Computer Forensic e garanzie dell'indaga...
Giuseppe Vaciago - Introduzione alla Computer Forensic e garanzie dell'indaga...HTLaw
 
Il ruolo dei dispositivi informatici
Il ruolo dei dispositivi informaticiIl ruolo dei dispositivi informatici
Il ruolo dei dispositivi informaticiMassimo Farina
 
CAUSAL MODEL FOR THE FORENSIC INVESTIGATION OF STRUCTURAL FAILURES_SEMC2013
CAUSAL MODEL FOR THE FORENSIC INVESTIGATION OF STRUCTURAL FAILURES_SEMC2013CAUSAL MODEL FOR THE FORENSIC INVESTIGATION OF STRUCTURAL FAILURES_SEMC2013
CAUSAL MODEL FOR THE FORENSIC INVESTIGATION OF STRUCTURAL FAILURES_SEMC2013StroNGER2012
 
OWASP Day 3 - Analisi forense dei sistemi compromessi
OWASP Day 3 - Analisi forense dei sistemi compromessiOWASP Day 3 - Analisi forense dei sistemi compromessi
OWASP Day 3 - Analisi forense dei sistemi compromessiDavide Gabrini
 
Deftcon 2013 - Alessandro Rossetti & Massimiliano Dal Cero - OSint a supporto...
Deftcon 2013 - Alessandro Rossetti & Massimiliano Dal Cero - OSint a supporto...Deftcon 2013 - Alessandro Rossetti & Massimiliano Dal Cero - OSint a supporto...
Deftcon 2013 - Alessandro Rossetti & Massimiliano Dal Cero - OSint a supporto...Sandro Rossetti
 
Deftcon 2012 - Gianluca Costa - Xplico, un Network Forensic Analysis Tool sca...
Deftcon 2012 - Gianluca Costa - Xplico, un Network Forensic Analysis Tool sca...Deftcon 2012 - Gianluca Costa - Xplico, un Network Forensic Analysis Tool sca...
Deftcon 2012 - Gianluca Costa - Xplico, un Network Forensic Analysis Tool sca...Sandro Rossetti
 
OSINT: analisi dei metadati ed acquisizione da fonti aperte con FOCA e Shodan
OSINT: analisi dei metadati ed acquisizione da fonti aperte con FOCA e ShodanOSINT: analisi dei metadati ed acquisizione da fonti aperte con FOCA e Shodan
OSINT: analisi dei metadati ed acquisizione da fonti aperte con FOCA e ShodanDanilo De Rogatis
 
Medical careers powepoint (forensic anthropology)
Medical careers powepoint (forensic anthropology)Medical careers powepoint (forensic anthropology)
Medical careers powepoint (forensic anthropology)Anastasia K
 
Methodologies and techniques for forensic analysis of mobile phone devices
Methodologies and techniques for forensic analysis of mobile phone devicesMethodologies and techniques for forensic analysis of mobile phone devices
Methodologies and techniques for forensic analysis of mobile phone devicesMariagrazia Cinti
 
OSINT su siti web
OSINT su siti webOSINT su siti web
OSINT su siti webdalchecco
 
Marco Signorelli 19 09 2008 Ordine Degli Avvocati Di Bergamo
Marco Signorelli   19 09 2008 Ordine Degli Avvocati Di BergamoMarco Signorelli   19 09 2008 Ordine Degli Avvocati Di Bergamo
Marco Signorelli 19 09 2008 Ordine Degli Avvocati Di BergamoAndrea Rossetti
 
Windows 10 Forensics: OS Evidentiary Artefacts
Windows 10 Forensics: OS Evidentiary ArtefactsWindows 10 Forensics: OS Evidentiary Artefacts
Windows 10 Forensics: OS Evidentiary ArtefactsBrent Muir
 

Destaque (19)

Forensic Profiling with Digital Data
Forensic Profiling with Digital DataForensic Profiling with Digital Data
Forensic Profiling with Digital Data
 
15 07-01 session 16.1 c connell
15 07-01 session 16.1 c connell15 07-01 session 16.1 c connell
15 07-01 session 16.1 c connell
 
2009 04-08 uni-mi_jpeg forensics
2009 04-08 uni-mi_jpeg forensics2009 04-08 uni-mi_jpeg forensics
2009 04-08 uni-mi_jpeg forensics
 
2009 10-24 foss-e-computer-forensics
2009 10-24 foss-e-computer-forensics2009 10-24 foss-e-computer-forensics
2009 10-24 foss-e-computer-forensics
 
Smau Milano 2011 Gentili-Fratepietro backtrack
Smau Milano 2011 Gentili-Fratepietro backtrackSmau Milano 2011 Gentili-Fratepietro backtrack
Smau Milano 2011 Gentili-Fratepietro backtrack
 
Deftcon 2013 - Giuseppe Vaciago - Osint e prevenzione dei Crimini
Deftcon 2013 - Giuseppe Vaciago - Osint e prevenzione dei CriminiDeftcon 2013 - Giuseppe Vaciago - Osint e prevenzione dei Crimini
Deftcon 2013 - Giuseppe Vaciago - Osint e prevenzione dei Crimini
 
Vm sistemi suite data discovery
Vm sistemi suite data discoveryVm sistemi suite data discovery
Vm sistemi suite data discovery
 
Giuseppe Vaciago - Introduzione alla Computer Forensic e garanzie dell'indaga...
Giuseppe Vaciago - Introduzione alla Computer Forensic e garanzie dell'indaga...Giuseppe Vaciago - Introduzione alla Computer Forensic e garanzie dell'indaga...
Giuseppe Vaciago - Introduzione alla Computer Forensic e garanzie dell'indaga...
 
Il ruolo dei dispositivi informatici
Il ruolo dei dispositivi informaticiIl ruolo dei dispositivi informatici
Il ruolo dei dispositivi informatici
 
CAUSAL MODEL FOR THE FORENSIC INVESTIGATION OF STRUCTURAL FAILURES_SEMC2013
CAUSAL MODEL FOR THE FORENSIC INVESTIGATION OF STRUCTURAL FAILURES_SEMC2013CAUSAL MODEL FOR THE FORENSIC INVESTIGATION OF STRUCTURAL FAILURES_SEMC2013
CAUSAL MODEL FOR THE FORENSIC INVESTIGATION OF STRUCTURAL FAILURES_SEMC2013
 
OWASP Day 3 - Analisi forense dei sistemi compromessi
OWASP Day 3 - Analisi forense dei sistemi compromessiOWASP Day 3 - Analisi forense dei sistemi compromessi
OWASP Day 3 - Analisi forense dei sistemi compromessi
 
Deftcon 2013 - Alessandro Rossetti & Massimiliano Dal Cero - OSint a supporto...
Deftcon 2013 - Alessandro Rossetti & Massimiliano Dal Cero - OSint a supporto...Deftcon 2013 - Alessandro Rossetti & Massimiliano Dal Cero - OSint a supporto...
Deftcon 2013 - Alessandro Rossetti & Massimiliano Dal Cero - OSint a supporto...
 
Deftcon 2012 - Gianluca Costa - Xplico, un Network Forensic Analysis Tool sca...
Deftcon 2012 - Gianluca Costa - Xplico, un Network Forensic Analysis Tool sca...Deftcon 2012 - Gianluca Costa - Xplico, un Network Forensic Analysis Tool sca...
Deftcon 2012 - Gianluca Costa - Xplico, un Network Forensic Analysis Tool sca...
 
OSINT: analisi dei metadati ed acquisizione da fonti aperte con FOCA e Shodan
OSINT: analisi dei metadati ed acquisizione da fonti aperte con FOCA e ShodanOSINT: analisi dei metadati ed acquisizione da fonti aperte con FOCA e Shodan
OSINT: analisi dei metadati ed acquisizione da fonti aperte con FOCA e Shodan
 
Medical careers powepoint (forensic anthropology)
Medical careers powepoint (forensic anthropology)Medical careers powepoint (forensic anthropology)
Medical careers powepoint (forensic anthropology)
 
Methodologies and techniques for forensic analysis of mobile phone devices
Methodologies and techniques for forensic analysis of mobile phone devicesMethodologies and techniques for forensic analysis of mobile phone devices
Methodologies and techniques for forensic analysis of mobile phone devices
 
OSINT su siti web
OSINT su siti webOSINT su siti web
OSINT su siti web
 
Marco Signorelli 19 09 2008 Ordine Degli Avvocati Di Bergamo
Marco Signorelli   19 09 2008 Ordine Degli Avvocati Di BergamoMarco Signorelli   19 09 2008 Ordine Degli Avvocati Di Bergamo
Marco Signorelli 19 09 2008 Ordine Degli Avvocati Di Bergamo
 
Windows 10 Forensics: OS Evidentiary Artefacts
Windows 10 Forensics: OS Evidentiary ArtefactsWindows 10 Forensics: OS Evidentiary Artefacts
Windows 10 Forensics: OS Evidentiary Artefacts
 

Semelhante a deftcon 2015 - Nino Vincenzo Verde - European Antitrust Forensic IT Tools

Startup Europe: EU funding for start-ups
Startup Europe: EU funding for start-upsStartup Europe: EU funding for start-ups
Startup Europe: EU funding for start-upsIraklis Agiovlasitis
 
MARIE - lieve bos_eos_udine_17.05.2013
MARIE - lieve bos_eos_udine_17.05.2013MARIE - lieve bos_eos_udine_17.05.2013
MARIE - lieve bos_eos_udine_17.05.2013AREA Science Park
 
4_12_November_-_2.10pm_-_LIVIA_KECEROVA.pptx
4_12_November_-_2.10pm_-_LIVIA_KECEROVA.pptx4_12_November_-_2.10pm_-_LIVIA_KECEROVA.pptx
4_12_November_-_2.10pm_-_LIVIA_KECEROVA.pptxBotaQ2
 
French innovation - opportunities for Singaporean companies
French innovation - opportunities for Singaporean companiesFrench innovation - opportunities for Singaporean companies
French innovation - opportunities for Singaporean companiesMartine Lesponne
 
BDVe Webinar Series - TransformingTransport – Big Data in the Transport Doma...
 BDVe Webinar Series - TransformingTransport – Big Data in the Transport Doma... BDVe Webinar Series - TransformingTransport – Big Data in the Transport Doma...
BDVe Webinar Series - TransformingTransport – Big Data in the Transport Doma...Big Data Value Association
 
Insurtech - Connected Insurance Observatory
Insurtech - Connected Insurance ObservatoryInsurtech - Connected Insurance Observatory
Insurtech - Connected Insurance ObservatoryMatteo Carbone
 
2015.04.09 f inish intro workshop v1
2015.04.09 f inish intro workshop v12015.04.09 f inish intro workshop v1
2015.04.09 f inish intro workshop v1Cor Verdouw
 

Semelhante a deftcon 2015 - Nino Vincenzo Verde - European Antitrust Forensic IT Tools (20)

Startup Europe: EU funding for start-ups
Startup Europe: EU funding for start-upsStartup Europe: EU funding for start-ups
Startup Europe: EU funding for start-ups
 
OiRA - Online interactive Risk Assessment - an overview of the project
OiRA - Online interactive Risk Assessment - an overview of the projectOiRA - Online interactive Risk Assessment - an overview of the project
OiRA - Online interactive Risk Assessment - an overview of the project
 
Summary of the Workshop: e-tools and their implementation in the field of Occ...
Summary of the Workshop: e-tools and their implementation in the field of Occ...Summary of the Workshop: e-tools and their implementation in the field of Occ...
Summary of the Workshop: e-tools and their implementation in the field of Occ...
 
Jornada convocatoria experimentos H2020 FORTISSIMO2
Jornada convocatoria experimentos H2020 FORTISSIMO2Jornada convocatoria experimentos H2020 FORTISSIMO2
Jornada convocatoria experimentos H2020 FORTISSIMO2
 
1 ecso general_ext_sept2017_bari
1 ecso general_ext_sept2017_bari1 ecso general_ext_sept2017_bari
1 ecso general_ext_sept2017_bari
 
SIEC presentation
SIEC presentationSIEC presentation
SIEC presentation
 
SIEC: a safe reference for the AV Pro Systems Integration industry
SIEC: a safe reference for the AV Pro Systems Integration industrySIEC: a safe reference for the AV Pro Systems Integration industry
SIEC: a safe reference for the AV Pro Systems Integration industry
 
Ipctoolkit shared by absoluteproducers
Ipctoolkit shared by absoluteproducersIpctoolkit shared by absoluteproducers
Ipctoolkit shared by absoluteproducers
 
SIEC: a safe reference for the AV Pro Systems Integration industry
SIEC: a safe reference for the AV Pro Systems Integration industrySIEC: a safe reference for the AV Pro Systems Integration industry
SIEC: a safe reference for the AV Pro Systems Integration industry
 
Presentation siec 19.03.2014 en
Presentation siec 19.03.2014 enPresentation siec 19.03.2014 en
Presentation siec 19.03.2014 en
 
MARIE - lieve bos_eos_udine_17.05.2013
MARIE - lieve bos_eos_udine_17.05.2013MARIE - lieve bos_eos_udine_17.05.2013
MARIE - lieve bos_eos_udine_17.05.2013
 
4_12_November_-_2.10pm_-_LIVIA_KECEROVA.pptx
4_12_November_-_2.10pm_-_LIVIA_KECEROVA.pptx4_12_November_-_2.10pm_-_LIVIA_KECEROVA.pptx
4_12_November_-_2.10pm_-_LIVIA_KECEROVA.pptx
 
French innovation - opportunities for Singaporean companies
French innovation - opportunities for Singaporean companiesFrench innovation - opportunities for Singaporean companies
French innovation - opportunities for Singaporean companies
 
RETHINKbig
RETHINKbigRETHINKbig
RETHINKbig
 
2.1.2 2nd WS. Market Place: AT Market Fragmentation C. Pastor
2.1.2 2nd WS. Market Place: AT Market Fragmentation C. Pastor2.1.2 2nd WS. Market Place: AT Market Fragmentation C. Pastor
2.1.2 2nd WS. Market Place: AT Market Fragmentation C. Pastor
 
BDVe Webinar Series - TransformingTransport – Big Data in the Transport Doma...
 BDVe Webinar Series - TransformingTransport – Big Data in the Transport Doma... BDVe Webinar Series - TransformingTransport – Big Data in the Transport Doma...
BDVe Webinar Series - TransformingTransport – Big Data in the Transport Doma...
 
Oportunitats a Europa
Oportunitats a EuropaOportunitats a Europa
Oportunitats a Europa
 
Insurtech - Connected Insurance Observatory
Insurtech - Connected Insurance ObservatoryInsurtech - Connected Insurance Observatory
Insurtech - Connected Insurance Observatory
 
2015.04.09 f inish intro workshop v1
2015.04.09 f inish intro workshop v12015.04.09 f inish intro workshop v1
2015.04.09 f inish intro workshop v1
 
Focus on R&D Community_Votis Konstantinos_CERTH/ITI
Focus on R&D Community_Votis Konstantinos_CERTH/ITIFocus on R&D Community_Votis Konstantinos_CERTH/ITI
Focus on R&D Community_Votis Konstantinos_CERTH/ITI
 

Mais de Deft Association

deftcon 2015 - Giuseppe Serafini - PCI - DSS Forensics - Soggetti, strumenti ...
deftcon 2015 - Giuseppe Serafini - PCI - DSS Forensics - Soggetti, strumenti ...deftcon 2015 - Giuseppe Serafini - PCI - DSS Forensics - Soggetti, strumenti ...
deftcon 2015 - Giuseppe Serafini - PCI - DSS Forensics - Soggetti, strumenti ...Deft Association
 
deftcon 2015 - Stefano Mele - La cyber-security nel 2020
deftcon 2015 - Stefano Mele - La cyber-security nel 2020deftcon 2015 - Stefano Mele - La cyber-security nel 2020
deftcon 2015 - Stefano Mele - La cyber-security nel 2020Deft Association
 
deftcon 2015 - Paolo Dal Checco - Riciclaggio e Anti riciclaggio nell’era del...
deftcon 2015 - Paolo Dal Checco - Riciclaggio e Anti riciclaggio nell’era del...deftcon 2015 - Paolo Dal Checco - Riciclaggio e Anti riciclaggio nell’era del...
deftcon 2015 - Paolo Dal Checco - Riciclaggio e Anti riciclaggio nell’era del...Deft Association
 
deftcon 2015 - Epifani, Picasso, Scarito, Meda - Tor Browser forensics on Win...
deftcon 2015 - Epifani, Picasso, Scarito, Meda - Tor Browser forensics on Win...deftcon 2015 - Epifani, Picasso, Scarito, Meda - Tor Browser forensics on Win...
deftcon 2015 - Epifani, Picasso, Scarito, Meda - Tor Browser forensics on Win...Deft Association
 
deftcon 2015 - Dave Piscitello - DNS Traffic Monitoring
deftcon 2015 - Dave Piscitello - DNS Traffic Monitoringdeftcon 2015 - Dave Piscitello - DNS Traffic Monitoring
deftcon 2015 - Dave Piscitello - DNS Traffic MonitoringDeft Association
 
deftcon 2015 - Stefano Capaccioli - Riciclaggio e Antiriciclaggio nell’era de...
deftcon 2015 - Stefano Capaccioli - Riciclaggio e Antiriciclaggio nell’era de...deftcon 2015 - Stefano Capaccioli - Riciclaggio e Antiriciclaggio nell’era de...
deftcon 2015 - Stefano Capaccioli - Riciclaggio e Antiriciclaggio nell’era de...Deft Association
 
deftcon 2014 - Pasquale Stirparo e Marco Carlo Spada - Electronic Evidence Gu...
deftcon 2014 - Pasquale Stirparo e Marco Carlo Spada - Electronic Evidence Gu...deftcon 2014 - Pasquale Stirparo e Marco Carlo Spada - Electronic Evidence Gu...
deftcon 2014 - Pasquale Stirparo e Marco Carlo Spada - Electronic Evidence Gu...Deft Association
 
Deftcon 2014 - Stefano Fratepietro - Stato del Progetto Deft
Deftcon 2014 - Stefano Fratepietro - Stato del Progetto DeftDeftcon 2014 - Stefano Fratepietro - Stato del Progetto Deft
Deftcon 2014 - Stefano Fratepietro - Stato del Progetto DeftDeft Association
 
Deftcon 2013 - Nicodemo Gawronski - iPBA 2.0 - Plugin Skype
Deftcon 2013 - Nicodemo Gawronski - iPBA 2.0 - Plugin SkypeDeftcon 2013 - Nicodemo Gawronski - iPBA 2.0 - Plugin Skype
Deftcon 2013 - Nicodemo Gawronski - iPBA 2.0 - Plugin SkypeDeft Association
 
Deftcon 2013 - Mario Piccinelli - iPBA 2 - iPhone Backup Analyzer 2
Deftcon 2013 - Mario Piccinelli - iPBA 2 - iPhone Backup Analyzer 2Deftcon 2013 - Mario Piccinelli - iPBA 2 - iPhone Backup Analyzer 2
Deftcon 2013 - Mario Piccinelli - iPBA 2 - iPhone Backup Analyzer 2Deft Association
 
Deftcon 2012 - Meo Bogliolo - SQLite Forensics
Deftcon 2012 - Meo Bogliolo - SQLite ForensicsDeftcon 2012 - Meo Bogliolo - SQLite Forensics
Deftcon 2012 - Meo Bogliolo - SQLite ForensicsDeft Association
 
Deftcon 2012 - Marco Giorgi - Acquisizione di memorie di massa con DEFT Linux
Deftcon 2012 - Marco Giorgi - Acquisizione di memorie di massa con DEFT LinuxDeftcon 2012 - Marco Giorgi - Acquisizione di memorie di massa con DEFT Linux
Deftcon 2012 - Marco Giorgi - Acquisizione di memorie di massa con DEFT LinuxDeft Association
 
Deftcon 2014 - Marco Giorgi - Metodologie di Acquisizione di Dispositivi Android
Deftcon 2014 - Marco Giorgi - Metodologie di Acquisizione di Dispositivi AndroidDeftcon 2014 - Marco Giorgi - Metodologie di Acquisizione di Dispositivi Android
Deftcon 2014 - Marco Giorgi - Metodologie di Acquisizione di Dispositivi AndroidDeft Association
 
Paolo Dal Checco, Alessandro Rossetti, Stefano Fratepietro - DEFT 7 Manual
Paolo Dal Checco, Alessandro Rossetti, Stefano Fratepietro - DEFT 7 ManualPaolo Dal Checco, Alessandro Rossetti, Stefano Fratepietro - DEFT 7 Manual
Paolo Dal Checco, Alessandro Rossetti, Stefano Fratepietro - DEFT 7 ManualDeft Association
 
Paolo Dal Checco, Alessandro Rossetti, Stefano Fratepietro - Manuale DEFT 7
Paolo Dal Checco, Alessandro Rossetti, Stefano Fratepietro - Manuale DEFT 7Paolo Dal Checco, Alessandro Rossetti, Stefano Fratepietro - Manuale DEFT 7
Paolo Dal Checco, Alessandro Rossetti, Stefano Fratepietro - Manuale DEFT 7Deft Association
 
Deftcon 2014 - Marco Albanese - Andlink: Un’applicazione a supporto per le at...
Deftcon 2014 - Marco Albanese - Andlink: Un’applicazione a supporto per le at...Deftcon 2014 - Marco Albanese - Andlink: Un’applicazione a supporto per le at...
Deftcon 2014 - Marco Albanese - Andlink: Un’applicazione a supporto per le at...Deft Association
 
deftcon 2014 - Federico Grattirio - TIMESHARK: Uno strumento per la visualizz...
deftcon 2014 - Federico Grattirio - TIMESHARK: Uno strumento per la visualizz...deftcon 2014 - Federico Grattirio - TIMESHARK: Uno strumento per la visualizz...
deftcon 2014 - Federico Grattirio - TIMESHARK: Uno strumento per la visualizz...Deft Association
 
Deftcon 2014 - Stefano Zanero - Comprehensive Black-box Methodology for Testi...
Deftcon 2014 - Stefano Zanero - Comprehensive Black-box Methodology for Testi...Deftcon 2014 - Stefano Zanero - Comprehensive Black-box Methodology for Testi...
Deftcon 2014 - Stefano Zanero - Comprehensive Black-box Methodology for Testi...Deft Association
 
DEFTCON 2014 – Luigi Ranzato - Windows Registry Artifacts: "Most Recently Use...
DEFTCON 2014 – Luigi Ranzato - Windows Registry Artifacts: "Most Recently Use...DEFTCON 2014 – Luigi Ranzato - Windows Registry Artifacts: "Most Recently Use...
DEFTCON 2014 – Luigi Ranzato - Windows Registry Artifacts: "Most Recently Use...Deft Association
 

Mais de Deft Association (20)

Deft - Botconf 2017
Deft - Botconf 2017Deft - Botconf 2017
Deft - Botconf 2017
 
deftcon 2015 - Giuseppe Serafini - PCI - DSS Forensics - Soggetti, strumenti ...
deftcon 2015 - Giuseppe Serafini - PCI - DSS Forensics - Soggetti, strumenti ...deftcon 2015 - Giuseppe Serafini - PCI - DSS Forensics - Soggetti, strumenti ...
deftcon 2015 - Giuseppe Serafini - PCI - DSS Forensics - Soggetti, strumenti ...
 
deftcon 2015 - Stefano Mele - La cyber-security nel 2020
deftcon 2015 - Stefano Mele - La cyber-security nel 2020deftcon 2015 - Stefano Mele - La cyber-security nel 2020
deftcon 2015 - Stefano Mele - La cyber-security nel 2020
 
deftcon 2015 - Paolo Dal Checco - Riciclaggio e Anti riciclaggio nell’era del...
deftcon 2015 - Paolo Dal Checco - Riciclaggio e Anti riciclaggio nell’era del...deftcon 2015 - Paolo Dal Checco - Riciclaggio e Anti riciclaggio nell’era del...
deftcon 2015 - Paolo Dal Checco - Riciclaggio e Anti riciclaggio nell’era del...
 
deftcon 2015 - Epifani, Picasso, Scarito, Meda - Tor Browser forensics on Win...
deftcon 2015 - Epifani, Picasso, Scarito, Meda - Tor Browser forensics on Win...deftcon 2015 - Epifani, Picasso, Scarito, Meda - Tor Browser forensics on Win...
deftcon 2015 - Epifani, Picasso, Scarito, Meda - Tor Browser forensics on Win...
 
deftcon 2015 - Dave Piscitello - DNS Traffic Monitoring
deftcon 2015 - Dave Piscitello - DNS Traffic Monitoringdeftcon 2015 - Dave Piscitello - DNS Traffic Monitoring
deftcon 2015 - Dave Piscitello - DNS Traffic Monitoring
 
deftcon 2015 - Stefano Capaccioli - Riciclaggio e Antiriciclaggio nell’era de...
deftcon 2015 - Stefano Capaccioli - Riciclaggio e Antiriciclaggio nell’era de...deftcon 2015 - Stefano Capaccioli - Riciclaggio e Antiriciclaggio nell’era de...
deftcon 2015 - Stefano Capaccioli - Riciclaggio e Antiriciclaggio nell’era de...
 
deftcon 2014 - Pasquale Stirparo e Marco Carlo Spada - Electronic Evidence Gu...
deftcon 2014 - Pasquale Stirparo e Marco Carlo Spada - Electronic Evidence Gu...deftcon 2014 - Pasquale Stirparo e Marco Carlo Spada - Electronic Evidence Gu...
deftcon 2014 - Pasquale Stirparo e Marco Carlo Spada - Electronic Evidence Gu...
 
Deftcon 2014 - Stefano Fratepietro - Stato del Progetto Deft
Deftcon 2014 - Stefano Fratepietro - Stato del Progetto DeftDeftcon 2014 - Stefano Fratepietro - Stato del Progetto Deft
Deftcon 2014 - Stefano Fratepietro - Stato del Progetto Deft
 
Deftcon 2013 - Nicodemo Gawronski - iPBA 2.0 - Plugin Skype
Deftcon 2013 - Nicodemo Gawronski - iPBA 2.0 - Plugin SkypeDeftcon 2013 - Nicodemo Gawronski - iPBA 2.0 - Plugin Skype
Deftcon 2013 - Nicodemo Gawronski - iPBA 2.0 - Plugin Skype
 
Deftcon 2013 - Mario Piccinelli - iPBA 2 - iPhone Backup Analyzer 2
Deftcon 2013 - Mario Piccinelli - iPBA 2 - iPhone Backup Analyzer 2Deftcon 2013 - Mario Piccinelli - iPBA 2 - iPhone Backup Analyzer 2
Deftcon 2013 - Mario Piccinelli - iPBA 2 - iPhone Backup Analyzer 2
 
Deftcon 2012 - Meo Bogliolo - SQLite Forensics
Deftcon 2012 - Meo Bogliolo - SQLite ForensicsDeftcon 2012 - Meo Bogliolo - SQLite Forensics
Deftcon 2012 - Meo Bogliolo - SQLite Forensics
 
Deftcon 2012 - Marco Giorgi - Acquisizione di memorie di massa con DEFT Linux
Deftcon 2012 - Marco Giorgi - Acquisizione di memorie di massa con DEFT LinuxDeftcon 2012 - Marco Giorgi - Acquisizione di memorie di massa con DEFT Linux
Deftcon 2012 - Marco Giorgi - Acquisizione di memorie di massa con DEFT Linux
 
Deftcon 2014 - Marco Giorgi - Metodologie di Acquisizione di Dispositivi Android
Deftcon 2014 - Marco Giorgi - Metodologie di Acquisizione di Dispositivi AndroidDeftcon 2014 - Marco Giorgi - Metodologie di Acquisizione di Dispositivi Android
Deftcon 2014 - Marco Giorgi - Metodologie di Acquisizione di Dispositivi Android
 
Paolo Dal Checco, Alessandro Rossetti, Stefano Fratepietro - DEFT 7 Manual
Paolo Dal Checco, Alessandro Rossetti, Stefano Fratepietro - DEFT 7 ManualPaolo Dal Checco, Alessandro Rossetti, Stefano Fratepietro - DEFT 7 Manual
Paolo Dal Checco, Alessandro Rossetti, Stefano Fratepietro - DEFT 7 Manual
 
Paolo Dal Checco, Alessandro Rossetti, Stefano Fratepietro - Manuale DEFT 7
Paolo Dal Checco, Alessandro Rossetti, Stefano Fratepietro - Manuale DEFT 7Paolo Dal Checco, Alessandro Rossetti, Stefano Fratepietro - Manuale DEFT 7
Paolo Dal Checco, Alessandro Rossetti, Stefano Fratepietro - Manuale DEFT 7
 
Deftcon 2014 - Marco Albanese - Andlink: Un’applicazione a supporto per le at...
Deftcon 2014 - Marco Albanese - Andlink: Un’applicazione a supporto per le at...Deftcon 2014 - Marco Albanese - Andlink: Un’applicazione a supporto per le at...
Deftcon 2014 - Marco Albanese - Andlink: Un’applicazione a supporto per le at...
 
deftcon 2014 - Federico Grattirio - TIMESHARK: Uno strumento per la visualizz...
deftcon 2014 - Federico Grattirio - TIMESHARK: Uno strumento per la visualizz...deftcon 2014 - Federico Grattirio - TIMESHARK: Uno strumento per la visualizz...
deftcon 2014 - Federico Grattirio - TIMESHARK: Uno strumento per la visualizz...
 
Deftcon 2014 - Stefano Zanero - Comprehensive Black-box Methodology for Testi...
Deftcon 2014 - Stefano Zanero - Comprehensive Black-box Methodology for Testi...Deftcon 2014 - Stefano Zanero - Comprehensive Black-box Methodology for Testi...
Deftcon 2014 - Stefano Zanero - Comprehensive Black-box Methodology for Testi...
 
DEFTCON 2014 – Luigi Ranzato - Windows Registry Artifacts: "Most Recently Use...
DEFTCON 2014 – Luigi Ranzato - Windows Registry Artifacts: "Most Recently Use...DEFTCON 2014 – Luigi Ranzato - Windows Registry Artifacts: "Most Recently Use...
DEFTCON 2014 – Luigi Ranzato - Windows Registry Artifacts: "Most Recently Use...
 

Último

Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingEdi Saputra
 
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Jeffrey Haguewood
 
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...Zilliz
 
Ransomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdfRansomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdfOverkill Security
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdflior mazor
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesrafiqahmad00786416
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoffsammart93
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAndrey Devyatkin
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?Igalia
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfsudhanshuwaghmare1
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProduct Anonymous
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...Zilliz
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDropbox
 
MS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsMS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsNanddeep Nachan
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)wesley chun
 
AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024The Digital Insurer
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Scriptwesley chun
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...DianaGray10
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...apidays
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FMESafe Software
 

Último (20)

Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
 
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
 
Ransomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdfRansomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdf
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challenges
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor Presentation
 
MS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsMS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectors
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 

deftcon 2015 - Nino Vincenzo Verde - European Antitrust Forensic IT Tools

  • 1. European Antitrust Forensic IT Tools Nino Vincenzo Verde verde@di.uniroma1.it Dipartimento di Informatica Universita` di Roma "La Sapienza" 113 Via Salaria, 00198 Roma, ITALY email: verde@di.uniroma1.it
  • 3. 4/17/15verde@di.uniroma1.it ● Primo appuntamento sui temi del Master: – Come: Tavola rotonda "Cybercrime e Informatica forense: errori, professionalità e ambiti di applicazione" – Dove: Aula alfa, via Salaria 113 – Quando: 28/4/2015 ore 16-19 – Discussant: esponenti della Corte di Cassazione, Procura, Polizia Postale, Albo psicologi, etc. ● Info: mastersicurezza@di.uniroma1.it Dipartimento di Informatica della Facoltà di Ingegneria dell'Informazione, Informatica e Statistica dell’Università degli Studi di Roma “La Sapienza”
  • 4. 4/17/15verde@di.uniroma1.it Obiettivi del master ● Promuovere una professionalità multidisciplinare che integri le competenze, attualmente scisse nel mondo della formazione, del settore informatico, giuridico e psicologico ● Sviluppare un profilo di esperienza che possa intervenire, con una competenza analitica, tecnico- investigativa in ambito giudiziario, aziendale e nella pubblica amministrazione
  • 5. 4/17/15verde@di.uniroma1.it Aree tematiche principali ● Computer Security and Computer Forensics ● Malware Analysis and Investigation ● Mobile Device Forensics ● Live Data Forensics ● Money Laundering Investigations ● Criminal profiling and crime investigations ● Risk analysis for reputation preservation ● Big Data e Data Mining ● Enterprise Reputation and Risk Management
  • 6. 4/17/15verde@di.uniroma1.it Outline of the talk ● Introduction about the antitrust activities ● International context of the project ● The EAFIT_TOOLS project – Objectives – Project phases – Peculiarities of the Antitrust Investigations ● EAFIT_TOOLS indexing software ● Final remarks
  • 7. 4/17/15verde@di.uniroma1.it Introduction about the Antitrust Activities ● Competition encourages companies to offer consumers goods and services at the most favourable terms – Anticompetitive practices cases – Abuse of dominance cases ● Cartels: – is a specific type of antitrust enforcement. – A cartel is a group of similar, independent companies which join together to fix prices, to limit production or to share markets or customers between them.
  • 8. 4/17/15verde@di.uniroma1.it Introduction about the Antitrust Activities ● Competition encourages companies to offer consumers goods and services at the most favourable terms – Anticompetitive practices cases – Abuse of dominance cases ● Cartels: – is a specific type of antitrust enforcement. – A cartel is a group of similar, independent companies which join together to fix prices, to limit production or to share markets or customers between them. ● Terminology: – Competition Authority (CA) = Antitrust
  • 10. 4/17/15verde@di.uniroma1.it Fighting against cartels: typical workflow LENIENCY PROGRAM
  • 11. 4/17/15verde@di.uniroma1.it Fighting against cartels: typical workflow LENIENCY PROGRAM
  • 12. 4/17/15verde@di.uniroma1.it Fighting against cartels: typical workflow LENIENCY PROGRAM TRIAL
  • 15. 4/17/15verde@di.uniroma1.it Examples of Fines: AGCM – Italy (2014) I due gruppi si sono accordati illecitamente per ostacolare la diffusione dell’uso di un farmaco molto economico, Avastin, nella cura della più diffusa patologia della vista tra gli anziani e di altre gravi malattie oculistiche, a vantaggio di un prodotto molto più costoso, Lucentis, differenziando artificiosamente i due prodotti. Per il Sistema Sanitario Nazionale l’intesa ha comportato un esborso aggiuntivo stimato in oltre 45 milioni di euro nel solo 2012, con possibili maggiori costi futuri fino a oltre 600 milioni di euro l’anno.
  • 16. 4/17/15verde@di.uniroma1.it Examples of Fines: AGCM – Italy (2014) I due gruppi si sono accordati illecitamente per ostacolare la diffusione dell’uso di un farmaco molto economico, Avastin, nella cura della più diffusa patologia della vista tra gli anziani e di altre gravi malattie oculistiche, a vantaggio di un prodotto molto più costoso, Lucentis, differenziando artificiosamente i due prodotti. Per il Sistema Sanitario Nazionale l’intesa ha comportato un esborso aggiuntivo stimato in oltre 45 milioni di euro nel solo 2012, con possibili maggiori costi futuri fino a oltre 600 milioni di euro l’anno.
  • 17. 4/17/15verde@di.uniroma1.it Examples of Fines: AGCM – Italy (2014) Fine of €180 millions I due gruppi si sono accordati illecitamente per ostacolare la diffusione dell’uso di un farmaco molto economico, Avastin, nella cura della più diffusa patologia della vista tra gli anziani e di altre gravi malattie oculistiche, a vantaggio di un prodotto molto più costoso, Lucentis, differenziando artificiosamente i due prodotti. Per il Sistema Sanitario Nazionale l’intesa ha comportato un esborso aggiuntivo stimato in oltre 45 milioni di euro nel solo 2012, con possibili maggiori costi futuri fino a oltre 600 milioni di euro l’anno.
  • 20. 4/17/15verde@di.uniroma1.it Examples of Fines: DG Comp (2014) Dominant position in the x86 CPU market (1) granting rebates to 4 PC and server manufacturers (Dell, HP, NEC, Lenovo) conditional on them obtaining all or almost all of their supplies from Intel, and payments to one downstream computer retailer (Media Markt) conditional on it only selling PCs with Intel CPUs ("conditional rebates"); and (2) granting direct payments to 3 computer manufacturers (HP, Acer and Lenovo) to halt, delay or limit the launch of specific products incorporating chips from Intel’s only rival, AMD (so-called “naked restrictions”).
  • 21. 4/17/15verde@di.uniroma1.it Examples of Fines: DG Comp (2014) Fine of €1.06 billion Dominant position in the x86 CPU market (1) granting rebates to 4 PC and server manufacturers (Dell, HP, NEC, Lenovo) conditional on them obtaining all or almost all of their supplies from Intel, and payments to one downstream computer retailer (Media Markt) conditional on it only selling PCs with Intel CPUs ("conditional rebates"); and (2) granting direct payments to 3 computer manufacturers (HP, Acer and Lenovo) to halt, delay or limit the launch of specific products incorporating chips from Intel’s only rival, AMD (so-called “naked restrictions”).
  • 22. 4/17/15verde@di.uniroma1.it International Context of the Project ● European Competition Network (ECN) ● In 2010 the ECN Forensic IT (FIT) WG was formally established (informal meetings held since 2003) – A forum for the European competition authorities helping them to solve technical, procedural and legal issues ● A number of important initiatives have been undertaken: – First training programme (March 2009 – March 2010) ● Forty-four (44) officials belonging to 25 European competition authorities representing 23 different countries – EATEP_FIT (Sep 2011 – Aug 2014) ● Training and exchange programme (September 2011 – August 2014) ● 125 officers (56 FIT experts and 69 case-handlers) have attended the courses. ● 52 exchanges have taken place, some of them providing cross-border FIT assistance in dawn raids – EAFIT_TOOLS
  • 23. 4/17/15verde@di.uniroma1.it The EAFIT_TOOLS Project ● European project with financial support from the Prevention of and Fight against Crime Programme of the European Union - European Commission - Directorate - General Home Affairs ● Funding Programme: Prevention of and Fight against Crime ● Coordinator: Italian Competition Authority – AGCM – Dott. Mauro La Noce ● Scientific Coordination: Roberto Di Pietro ● Total Funding: €710.080,39 ● Period: November 2013 – October 2015
  • 27. 4/17/15verde@di.uniroma1.it EAFIT_TOOLS Project Objectives ● To boost the technical convergence of tools, protocols and procedures for forensic analysis in the ECN. – Collect a set of widely shared requirements about the forensics activities and procedures on cartels investigation and antitrust enforcement of the European Competition Authorities (CAs). – To recognize and classify already exiting tools in order to create a map between the CAs requirements and the existing open-source libraries and tools. – To integrate the selected open-source tools and develop a prototype of an European Antitrust Forensic IT software. ● Focus on Open source software
  • 28. 4/17/15verde@di.uniroma1.it Project Phases ● Phase 1: Requirements analysis ● Phase 2: Open Source tools recognition and classification ● Phase 3: Implementation, Testing and User Training
  • 29. 4/17/15verde@di.uniroma1.it Requirement Analysis ● Elicitation – On site interviews ● 7 Competition Authorities have been visited – Requirements workshop ● 42 attendees from 27 national and transnational Competition Autorities - 2 days ● Result: 155 raw requirements ● Specification ● Validation
  • 31. 4/17/15verde@di.uniroma1.it Peculiarities of Antitrust investigations 1. PRE DAWN RAID - Raid preparation (intelligence phase, keywords elicitation, team compositions, etc.) - OSInt
  • 32. 4/17/15verde@di.uniroma1.it Peculiarities of Antitrust investigations 1. PRE DAWN RAID - Raid preparation (intelligence phase, keywords elicitation, team compositions, etc.) - OSInt 2. DAWN RAID - 1 or 2 days on-site for most of the Antitrusts - On average 5 to 10 sites investigated at the same time - They try to bring home only relevant evidence (no disk images when possible) - Interesting artifacts: Office documents, pdf, etc... (content and metadata) Deleted files Emails (also from mail servers) Backups, Instant Messaging, Mobile phones - FIT activities most of time end with the dawn raid - Wiping
  • 33. 4/17/15verde@di.uniroma1.it Peculiarities of Antitrust investigations 1. PRE DAWN RAID - Raid preparation (intelligence phase, keywords elicitation, team compositions, etc.) - OSInt 2. DAWN RAID - 1 or 2 days on-site for most of the Antitrusts - On average 5 to 10 sites investigated at the same time - They try to bring home only relevant evidence (no disk images when possible) - Interesting artifacts: Office documents, pdf, etc... (content and metadata) Deleted files Emails (also from mail servers) Backups, Instant Messaging, Mobile phones - FIT activities most of time end with the dawn raid - Wiping
  • 34. 4/17/15verde@di.uniroma1.it Peculiarities of Antitrust investigations 1. PRE DAWN RAID - Raid preparation (intelligence phase, keywords elicitation, team compositions, etc.) - OSInt 2. DAWN RAID - 1 or 2 days on-site for most of the Antitrusts - On average 5 to 10 sites investigated at the same time - They try to bring home only relevant evidence (no disk images when possible) - Interesting artifacts: Office documents, pdf, etc... (content and metadata) Deleted files Emails (also from mail servers) Backups, Instant Messaging, Mobile phones - FIT activities most of time end with the dawn raid - Wiping 3. POST DAWN RAID - Most of the Antitrusts cannot review the collected evidence without the part - Only a few have a large infrastructure lab (DK, DE)
  • 36. 4/17/15verde@di.uniroma1.it The EAFIT_TOOLS Indexing software ● It will be delivered at the end of the project (Oct 2015): – Distributed system easy to set-up – Indexing of massive amount of documents (parallelizing computation On Site) – Team file reviewing – Multi user and multi case management – Collaborative tagging and labelling – Flexible: ● On site ● In Lab – It will be probably released under GPLv3 licence
  • 37. The dawn raid use-case scenario Triage Phase Analysis Phase (On Site)
  • 38. The dawn raid use-case scenario Case Handler Fit Expert 2 Triage Phase Analysis Phase (On Site) Administrator Fit Expert 1
  • 39. The dawn raid use-case scenario Case Handler Fit Expert 2 Triage Phase Analysis Phase (On Site) Administrator Fit Expert 1 Live Distribution EAFIT_TOOLS Software
  • 40. The dawn raid use-case scenario Case Handler Fit Expert 2 Triage Phase Analysis Phase (On Site) Administrator Fit Expert 1 Live Distribution EAFIT_TOOLS Software
  • 41. The dawn raid use-case scenario Case Handler Fit Expert 2 Triage Phase Analysis Phase (On Site) Administrator Fit Expert 1 Live Distribution EAFIT_TOOLS Software
  • 42. The dawn raid use-case scenario Case Handler Case Handler Case Handler Case Handler Fit Expert 2 Triage Phase Analysis Phase (On Site) Administrator Fit Expert 1 Live Distribution EAFIT_TOOLS Software
  • 43. The dawn raid use-case scenario Case Handler Case Handler Case Handler Case Handler Fit Expert 2 Triage Phase Analysis Phase (On Site) Administrator Fit Expert 1 Live Distribution EAFIT_TOOLS Software
  • 44. The dawn raid use-case scenario Case Handler Case Handler Case Handler Administrator Fit Expert 1 Case Handler Fit Expert 2 Triage Phase Analysis Phase (On Site) Administrator Fit Expert 1 Case Handler Fit Expert 2 Live Distribution EAFIT_TOOLS Software
  • 45. The dawn raid use-case scenario Case Handler Case Handler Case Handler Administrator Fit Expert 1 Case Handler Fit Expert 2 Triage Phase Analysis Phase (On Site) Administrator Fit Expert 1 Case Handler Fit Expert 2 Live Distribution EAFIT_TOOLS Software
  • 47. 4/17/15verde@di.uniroma1.it Final remarks ● Forensic IT areas are rapidly expanding and Antitrust investigations are a clear example ● Forensic collection of artifacts + On Site Indexing of a large amount of data + collaborative reviewing is a MUST for them ● OSInt is another point of attention – i.e.: Recover info about outsourced services before dawnraid ● The european antitrust strategy: Open Source! * Responsibility for the information and views expressed in this presentation lies entirely with the author.
  • 48. 4/17/15verde@di.uniroma1.it Presentazione del master in “Cybercrime e Informatica forense” – Quando: 28/4/2015 ore 16-19 – Dove: Aula alfa, via Salaria 113