Kyle Posted January 24, 2006 Posted January 24, 2006 I have been told we are having this Forensic Software on our network. The guy from the company os coming in next week to install it on one of our servers. I have had a quick look at teh installl guide etc and it all seems to be straight forward install of IIS. SQL and the software. The only worrying thing is the client software. It does look like it has to be installed on each PC individually( i will look later to see if i can do a MSI package) IS any one else running this or trialing this and if so what feedback haveyou got? Forensic Software to raise the profile of a new powerful behaviour monitoring software which benefits any agency dealing with the welfare of children, for instance Schools, Police, Health and Social Services. It monitors all user activity on the network.....not just internet use but also emails, chat rooms, and any desktop activity. It captures unsuitable behaviour while it's happening, and reports it in a jpeg format meaning the information can be looked at and used to address behaviour with the relevant children involved. The product is a response to the Every Child Matters initiative to prevent things like: * Bullying * Racism * Missuse of chat rooms * Potential child suicide & self harm * Pornographic material from sex and violent sites If you would like to discuss how to make your network a safer place please email [email protected] or call 01256 827555 and ask for a member of the education team.
Ric_ Posted January 24, 2006 Posted January 24, 2006 Somebody tried to sell this to me once. All the buzz words are in there and it makes SLT listen but it's quite easy to prevent much of the misuse using content filters and denying access to services such as 3rd party email (e.g. hotmail). With most of these, I just tell them straight away that I run Citrix and they soon disappear when they realise they can't run it on our network. Securus rang me last week quoting me rough prices. I asked the marketing guy what the support costs would be in subsequent years - he didn't know and quoted estimates that didn't add up to the final figure he stated! (Securus does work on Citrix though apparantly).
Joedetic Posted January 24, 2006 Posted January 24, 2006 I've heard bad things about Teksys from other techies. The long and short of what I was being told was that they were a bit of a shoddy outfit and to avoid them at all costs.
free4440273 Posted January 24, 2006 Posted January 24, 2006 A colleague of mine used teksys about two yrs ago - and lived to regret it...
Ric_ Posted January 24, 2006 Posted January 24, 2006 @Kyle: Is it just a demo of the Teksys software? Maybe you could review it for the site since some people have heard bad things about it? If you mention to their rep that you intend to send a review to us, they might be more helpful and offer you better pricing.
Joedetic Posted January 24, 2006 Posted January 24, 2006 I looked at the home access solution (24 Hour School) that they are offering and realised that it's just webDAV with a "fancy" front end. It got replicated within a rather short amount of time. I think it's a shame that schools that have had a network capable of webdav and dont think about setting it up and instead outsource to companies like teksys willing to charge extorsionate (however that is spelt) amounts of cash for a solution so simple.
Kyle Posted January 24, 2006 Author Posted January 24, 2006 Problem is......we have already had the demo fo rover a month back in October. We installed it on 25 machines in on IT room. My own personal opinion was that its cr*p. We put a few buzz word sinto a already default library and left it for a month checlikng occasionaly. It found all sorts of screenshots but most were stupid. A sample word was 'sh*t' but it did a screen shot of every word containing thse letters ir Mashita. Also for bullying a racist reason we put 'P*ki' in as a word and it picked up screen shots of pakistan etc. We told the Head of ICT it was a waste of money ( a large amount at that as well as a annual fee) but he took no notice of us ( or should i say the Sys Manager)
m25man Posted January 25, 2006 Posted January 25, 2006 IMOHO, I thought the concept of Forensic softwares product was quite good. However it gets detected by most good AV and spyware as a commercial keylogger and thats really what it is! You must look at this product in an unbiased manner, it has great potential in certain problem areas however in other schools it would never pay for itself so some may say why bother in the first place. Where I know it's really good is Girls schools. They are not normally so equipment destructive but they can be terrifyingly vicious to each other. This software catches them red handed time and time again. It intercepts slang usage, excellent for identifying the use of messenger type applications and websites. Close them down in seconds. Evidence, when action is required you need evidence and lots of it, this product gives you all you could ever need. Where it's bad, you would probably want to host it on a dedicated box as it could become a massive resource hog. It has a memory overhead at each client. False positives, as said elsewhere innocent webpages are often grabbed as a potential offence because "sex" was detected somewhere on the page as in "Essex". This can make it difficult to seperate the bad from the good and you might spend far too long trying to find something you can't fix! Cost, I beleive the prices are down on last years, but in 2005 they were asking about £25 per seat going down if you had more than 200 seats. Viglen had this product in the classlink NT4 product under another name Im sure. Lastly if you installed a keylogger on all of your systems you would probably be in breach of some human rights treaty of some sort so a highly visible awareness notice needs to conveyed. So once again what might be a wonderful and useful tool to some may be construed as an awful waste of time and money to another. Securus do a similar product but as an appliance i I think. It's your call.
Geoff Posted January 25, 2006 Posted January 25, 2006 Make sure you cover yourself in your Policies/AUP's if your doing big brotherthings like this.
Abaddon Posted March 15, 2006 Posted March 15, 2006 A sample word was 'sh*t' but it did a screen shot of every word containing thse letters ir Mashita. Also for bullying a racist reason we put 'P*ki' in as a word and it picked up screen shots of pakistan etc. In all fairness, it DOES make a difference if you select the word as 'embedded' or not... if it IS embedded then you would get the results you have seen. Otherwise it would only list the individual usage of those words. We've had a SECURUS box here for a while now, and it has been a good deterrent, and also bailed us out of a small number of situations where students have entered 'inappropriate' comments and language on various forums. In those cases, being able to identify the time\date\user has been a real boon. Catching those cases has /significantly/ improved the deterrent value. As an aside, we've been using Teksys here for a number of years now, and it's almost like you guys are describing a different company... I have had nothing but excellent service from them and would have no hesitation in recommending them to anyone. They have been involved in several different projects here, and all the engineers have been efficient and happy to help with any aspect of the projects (as long as it's been reasonably relevant!).
wesleyw Posted March 15, 2006 Posted March 15, 2006 I have to admit I've been trialing the Securus software for about two weeks and it does pick up an awful lot of false positives but I would rather have that than no results at all. As you've said making sure it isn't an embedded word would help cut down these and another feature in the next release is for the program to onlly "Allow" programs you've given in a list unlike the current revision which is a "Deny" programs which as most of you know is a real pain to get on top of! It will also flag up programs people try running (In the new release) which is good! I trialed Forensic Software and this was a very nice program too, but I think Securus may just have a few more useful features both don't go overboard and add features just for the sake of it though so presently both are very nie to use and of course simple to navigate which is a bonus when trying to sift through all of the information presented to you. I would also agree its not for everyone I have to admit I'm not sure it's needed here presently but time will of course tell! Wes
kallack Posted March 18, 2006 Posted March 18, 2006 I can highly recommend Forensic software - it catches EVERYTHING. The incidence of internet/email abuse has gone way down since we started using it. How good you school is at DOING something about violations of your AUP? That's what makes the difference. Forensic's Software (Policy Central) just catches them! Kevin
Mitch Posted March 18, 2006 Posted March 18, 2006 This threadhas taken my intrest, as I have background in forensic computing. To label a piece of software "forensic" it must comply with a number of protocols laid down by a number of governing bodies inluding the law. and the methology of obtaing the "data" also is subject to specific protocols. The ability to monitor activity upon a network does not under any circumstances conform to "forensic investigation" in my work i have had to perform forensic investigations and give evidence in court, and justify every action i do. It is a science in itself and it has taken me years to be respected in this field. Lets have a little question, "you have been called out to sieze a computer that has been used in a crime, you are accomanied by police tothe house where upon entry the pc is on and logged on to the internet. under the ACPO how do you make the PC "safe" for forensic investigation. Ill tel you its a windows XP home edition (depending on the OS depends also whayou do. do you 1. close ie and logoff, then shut down 2. go start>shutdown 3. ask the accused to logoff 4. pull the plug 5. go to the internet temp internet history and record activity straight in you notebook. Mitch
PiqueABoo Posted March 18, 2006 Posted March 18, 2006 I'd pull the plug. Graceful logoff & shutdown will modify the state of the (file) system. It might even be set to secure wipe history, page files and the like. And I can't see how you can do *anything* prior to that without altering the state of the system and being open to claims of tampering etc. I suppose it would be a bit of a downer if the owner/user happened to have their plausibly deniable virtual disk open at that point, but.. Anyway what's the answer (why and why not the others)?
Mitch Posted March 19, 2006 Posted March 19, 2006 PiqueABoo Well Done !. You are correct in saying that a gracefull logoff, will alter the file system, it will also alter many other aspects of the windows architecture too. Wiping history and pagefiles is not a problem to me, Hey ive examined Hard Drives that have been thrown in the bath, formatted and Fdisked numerous times, hard drives with this "washer software" installed. Trying to monitor students is a nightmare there is software out there that does have its merits, the main problem i have found is the amount of false notifications, and the amount of time the technician or network manager has to plod through data. also the possibility of bottlenecks on the network. Its alright having lots of screen shots of possible violations and lots of reports of possible violations. But then the "administrator" has to go through this and can get it wrong. Thats why we take the responcibility of this away from the school. I had a school using another package, we run oursoftware on the system and produced the report, they were impressed but they said what they could not understand is we have banned a pupil for pornographic material and you have not shown him on the this report. I knew exactly the username they were talking about, and we had prepared a report on that user, I showed that the pupil was NOT searching for porn at all, he was actually searching for crackz and serials, and the pornographic material that was being "screenshot" was redirections. Thus the pupil had no control over the content of redirections. Thus the software that had alerted the IT Manager was producing false information with regard to the users actions.The IT manager and Head had the parents of this boy in. the boys parent was a governor of the school. We sorted that problem out and spoke to the parents. everybody is now happy. Yes the boy was using the school network wrongly, but not for PORN. but then we can get onto copywrite issues within the school as pupils download music ect. leaving the school open to prosecution, we stop that too. We also put a stop to the huge problem "its not me sir, someone has my password". Mitch
ChrisH Posted March 19, 2006 Posted March 19, 2006 We also put a stop to the huge problem "its not me sir, someone has my password". Ah yes the standard excuse. So how do you go about stoppping this without the aid of CCTV or Biometric logon?
PiqueABoo Posted March 19, 2006 Posted March 19, 2006 So how do you go about stoppping this without the aid of CCTV or Biometric logon? Don't know what that or any other one does but if I'd built an app centred on key-logging: A user's typing style is a biometric that can be used for authentication. i.e. it has a sufficiently unique signature.
_Bob_ Posted March 20, 2006 Posted March 20, 2006 CCTV would be the only way to be absolutely sure. The next excuse you're going to get is, yes i logged onto that machine but i walked off and forgot to log out. I think at some point you have to say 'It IS your fault that someone knows your password!'. Make them take some responsibility.
Geoff Posted March 20, 2006 Posted March 20, 2006 Realisticaly you should have something in your AUP to cover that.
PiqueABoo Posted March 20, 2006 Posted March 20, 2006 CCTV would be the only way to be absolutely sure True.. if I wanted to do something naughty and knew how I typed was analyzed, I'd deliberately alter my typing style e.g. just use little fingers. It would only really works if a logon depends on both the correct password and how it is typed.. and although you'd then have more ammunition to prove the user's identity, it's definitely not absolute.
E1uSiV3 Posted March 20, 2006 Posted March 20, 2006 We also put a stop to the huge problem "its not me sir, someone has my password". Ah yes the standard excuse. So how do you go about stoppping this without the aid of CCTV or Biometric logon? Make the kids responsible for the security of their own logon details, as Geoff said, put it in the relevant docs to back you up and when an issue occurs, pull out the AUP.
TechMonkey Posted March 20, 2006 Posted March 20, 2006 Make the kids responsible for the security of their own logon details, as Geoff said, put it in the relevant docs to back you up and when an issue occurs, pull out the AUP. Thats the way we do it. It's their account with their potential important coursework on it so they are responsible. We take all possible measures to track down someone if they say it isn't them (we have basic CCTV in nearly all IT rooms) but at the end of the day it is their account and they have to take responsibility for it. If they know someone has their password they should get it changed and let us know. Stops a lot of arguements that way.
tosca925 Posted March 20, 2006 Posted March 20, 2006 We have had installed now for over 2 weeks PCE (Policy Central Enterprise) Forensic software. It works quite well but i have one or two issues with it. I t has stopped Dreamweaver 2004 from launching, if you click on the shortcut the programme launches and then immediately shuts itself down, I have to right click an html file and choose 'edit with Dreamweaver to get it to open correctly. But the worst is i can no longer choose 'Define sites' with out it crashing. I have installed the latest version of Dreaweaver(8) and it does not seem to affect this version. I plan on re-imaging the machines in Easter hols with the new version of Dreamweaver 8 any way so i should be able to stop this. Problem i have now is that staff are complaining that Smartboard software is playing up now. It odes not detect the pens on start up and also orientation does not work. Has any one else got PCE and is having similar problems.
PiqueABoo Posted March 20, 2006 Posted March 20, 2006 Has any one else got PCE and is having similar problems. No, but I can see the potential for conflicts with rootkit-like software. Definitely worth pulling PCE off a machine to see if the problem goes away.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now