270 likes | 284 Views
E-Detective Decoding Centre (EDDC) Offline Decoding & Reconstruction Solution. Decision Group www.edecision4u.com. EDDC Application Diagram (2). EDDC Application Diagram (2). Offline Raw Data Decoding and Reconstruction system. Comes with User and Case Management functions. Collect,
E N D
E-Detective Decoding Centre (EDDC)Offline Decoding & Reconstruction Solution Decision Group www.edecision4u.com
EDDC Application Diagram (2) Offline Raw Data Decoding and Reconstruction system. Comes with User and Case Management functions. Collect, Import Raw Data For Case 1 Case 1 Investigator 1 Case 1 Case 1 Results Collect, Import Raw Data For Case 2 Case 2 Investigator 2 Case 2 Case 2 Results Reconstruct various Internet Protocols
EDDC Home Page Dashboard Reports Top-Down View Report
Email Webmail HTTP (Link, Content, Reconstruct, Upload Download) IM/Chat (Yahoo, MSN, ICQ, QQ, IRC, Google Talk Etc.) File Transfer FTP, P2P Others Online Games Telnet etc. Internet Protocols Supported
Sample Reconstruction: Email (SMTP) Company Logo
Sample Reconstruction: Webmail (Read) Supports various Webmail Type such as Yahoo Mail, Gmail, Hotmail etc.
Sample Reconstruction: IM - QQ QQ messages are encrypted. QQ cracking tool is provided.
Sample : File Transfer (P2P File Sharing Log) Bittorent, eMule/eDonkey, FastTrack, Gnutella
Sample : HTTP Web Link Content Reconstruct Company Logo
Sample: HTTP Video Streaming (FLV) Youtube, Google Video, Metacafe etc.
Sample: VoIP Reconstruction (Playback) Codecs: G.711a-law G.711µ-law G.729 ILBC
Sample: HTTPS/SSL Decryption SSL Private Key must be known
EDDC User Management Admin create multiple users that can have access to authority to use this system.
EDDC Case Management User can create own case based on their authority assigned by Administrator.
Import Analysis (Manual Import Raw Data) User import raw data files to be parsed and analyzed (reconstructed)
Sniffer Mode (Raw Data Retention) System can be connected to the network. Raw data can be captured and reserved through mirror mode. Only when administrator require to see the content of traffic at specific period (date-time), these raw data files can be imported, parsed and analyzed.
References – Implementation Sites and Customers • Criminal Investigation Bureau • The Bureau of Investigation Ministry of Justice • National Security Agency (Bureau) in various countries • Intelligence Agency in various countries • Ministry of Defense in various countries • Counter/Anti Terrorism Department • National Police, Royal Police in various countries • Government Ministries in various countries • Federal Investigation Bureau in various countries • Telco/Internet Service Provider in various countries • Banking and Finance organizations in various countries • Others Notes: Due to confidentiality of this information, the exact name and countries of the various organizations cannot be revealed.
Thank You ! Decision Group www.edecision4u.com