Your investigation team has been called by McNorton-Dunham, a defense contractor working on the next generation of predator drones for the U.S. Department of Defense.Elaborate the scenario.

Your investigation team has been called by McNorton-Dunham, a defense contractor working on the next generation of predator drones for the U.S. Department of Defense.  On Friday, March 18, 2016, the whistleblowing website, Wikileaks, published several classified documents detailing communication between McNorton-Dunham and officials at the Pentagon regarding the X11-a5, the newest generation of predator drones that McNorton-Dunham is currently testing.  Following the release of the documents, McNorton-Dunham’s computer network came under a DDOS attack that is still continuing today.  Messages on Twitter and videos on Youtube have been found showing the hacktivist group, Anonymous, taking credit for the continuing attack.  Because of the threat to national security posed by the release of confidential communications, McNorton-Dunham and officials at the Pentagon wants all parties involved prosecuted to the furthest extent possible.

Officials at McNorton-Dunham believe that the leaked documents were the work of an insider.  All of the employees who had legitimate access to the leaked documents have been polygraphed and have been found to have no knowledge of the leak.  General policy for the company is that all employees must swipe a key card to gain entrance to McNorton-Dunham.  All personal items; purses, lunch bags, backpacks and briefcases; are inspected by security personnel upon entrance and exit from the company.  All employees use an RSA token and password to be authenticated on the McNorton-Dunham computer network.  The company maintains a number of closed-circuit surveillance cameras throughout the physical plant including all of the points of entrance/exit as well as at entrances to classified areas.

While McNorton-Dunham has only one physically computer-based network, access to data is strictly controlled using a RBAC system.  All of the computers at McNorton-Dunham contain no drives that would allow an employee to use any type of removable storage device (USB) or optical disc (CD, DVD).  Wi-Fi is not used at McNorton-Dunham.  The network administrators have firewalls at several locations throughout the company’s network and employ the use of an intrusion detection system.  The IDS logs prior to Friday do not indicate any type of intrusion prior to the current DDoS attack.  All incoming traffic passes through an application gateway proxy firewall and outgoing traffic is logged via a circuit-level proxy firewall.

The human resources department at McNorton-Dunham is responsible for all background checks done for all employees at the company.  They have developed a short list of employees who have either filed grievances in the past year, or who have had other events occur that could indicate a possible security problem.  They have identified the following employees as the potential leaker.  None of the employees had direct access to the communications that were leaked.

 

  • Linda Blair – 38-year-old administrative assistant, employed by McNorton-Dunham for the past 15 years. Linda was reprimanded for the use of an intoxicant while on the job.  She attended a 15-day rehab program and has been back at work for the past 5 weeks with no indication of further intoxicant use on the job.

 

  • Marty Feldman – 45-year-old flight specialist, employed by McNorton-Dunham for the past 20 years. Marty has a long record of insubordination to female supervisors.  The most recent incident occurred three months prior to document leak when criticism from a female superior led to Marty using derogatory language toward the woman.  He was suspended without pay for three days and was demoted one pay level.

 

  • Katherine Hutton – 26-year-old accounts payable clerk, employed by McNorton-Dunham for the past year. Katherine has a spotty attendance record and has received several verbal warnings due to her poor attendance.  Human Resources reports that several of Katherine’s co-workers have heard her discussing trips to the local gambling casino prior to many of her absences.  Katherine is also rumored to be involved with her immediate supervisor, James Douglass.

 

  • James Douglass – 32-year-old accountant, employed by McNorton-Dunham for the past eight years. While Douglass’s employment record is spotless, Human Resources has added Mr. Douglass to the list because of his reported involvement with Ms. Hutton.  At this time, Mr. Douglass is married and father to two small children.  Several coworkers reported that Mr. Douglass and Ms. Hutton have been spotted leaving the parking lot together in the same vehicle at lunchtime and the two have been spotted together at a local bar after work.

 

Dr. Jane Newman, the chief engineer for the X11-a5 predator drone project at McNorton-Dunham has reported that her RSA token was missing.  Dr. Newman noticed that the token was missing upon her return to McNorton-Dunham on Tuesday, March 22, 2016.   Dr. Newman was meeting with officials at the Pentagon on Friday, March 18 and Monday, March 21, 2016 and had stayed in Washington, DC over the weekend.  Dr. Newman did not attempt to log in to her McNorton-Dunham account while she was in Washington.

At first, she was not concerned about the missing token because in December of 2015, her new Labrador retriever puppy had eaten her previous token.  In fact, the incident had become a joke in her department.  Dr. Newman originally suspected that the dog was the cause of the missing token, but when evidence of the token failed to turn up, Dr. Newman began to suspect that the dog was not responsible this time. This means that her token was lost or stolen sometime between Thursday afternoon, March 17 and Tuesday morning, March 22, 2016.

Following the release of the 11X-a5 drone documents on Wikileaks web site, Dr. Newman became concerned that the security of her office had been compromised.  When Dr. Newman checked the metadata for the X11-a5 documents she discovered that the documents had been last accessed at 4:25PM on Thursday, March 17, 2016.  Dr. Newman told investigators that it was impossible for her to have accessed the documents at that time since she was traveling to Washington, DC.  She further stated that her trip to DC had been in regards to a project other than the X11-a5 drone and that she had not accessed any of the X11-a5 document since the 14th of March, 2016.

When investigators attempted to retrieve the video surveillance of the entrance to Dr. Newman’s office, they were told by security department at McNorton-Dunham that the equipment at that location was not functioning from March 10h until March 24th, 2016.  Other employees questioned stated that the closed-circuit surveillance system had frequent operation problems and was as likely to be not functioning as it as to be working.

 

Due to the new information, it is believed that the documents were most likely stolen late in the day on Thursday, March 17, 2016.  The log files that will be provided to the investigation team are based on this assumption.  Also, log files have been filtered, where possible, to only include data regarding the four suspects in the case.

 

 

Additional Personal Internet Account Information

 

Using company e-mail, the following information was discovered.  This information has not yet been confirmed!!

 

108.160.160.177 – IP number believed to be Katherine Hutton’s personal computer Internet ISP account

 

64.145.86.64 – IP number believed to be Marty Feldman’s personal computer Internet ISP account

 

65.55.200.138 – IP number believed to be Linda Blair’s personal computer Internet ISP account

 

199.47.216.173– IP number believed to be James Douglass’s personal computer Internet ISP account

 

64:b9:e8:a8:a9:d5 – MAC address of the network card in Dr. Jane Newman’s desktop computer

Your investigation team must try to determine several things for McNorton-Dunham:

 

  • What information do you need to determine which of the insiders should be questioned about the leak? (Log files, surveillance videos, building entrance logs, etc.)  Requested log files will be made .
  • How could the information have been exfiltrated from the company?

 

Are you looking for a similar paper or any other quality academic essay? Then look no further. Our research paper writing service is what you require. Our team of experienced writers is on standby to deliver to you an original paper as per your specified instructions with zero plagiarism guaranteed. This is the perfect way you can prepare your own unique academic paper and score the grades you deserve.

Use the order calculator below and get started! Contact our live support team for any assistance or inquiry.

[order_calculator]