Tools and techniques for Network Forensics
Natarajan Meghanathan, Sumanth Reddy Allam, Loretta A. Moore, (Jackson State University)

TL;DR
This paper reviews various tools and techniques used in network forensics, including data capture, analysis methods, IP traceback, and deception strategies like honeypots, to aid in security incident investigations.
Contribution
It provides a comprehensive survey of existing network forensics tools and techniques, highlighting their applications and effectiveness in security investigations.
Findings
Tools like eMailTrackerPro and Web Historian assist in tracing digital evidence.
IP traceback methods help identify true sources of attacks.
Honeypots and Honeynets gather intelligence on intruders.
Abstract
Network forensics deals with the capture, recording and analysis of network events in order to discover evidential information about the source of security attacks in a court of law. This paper discusses the different tools and techniques available to conduct network forensics. Some of the tools discussed include: eMailTrackerPro to identify the physical location of an email sender; Web Historian to find the duration of each visit and the files uploaded and downloaded from the visited website; packet sniffers like Etherea to capture and analyze the data exchanged among the different computers in the network. The second half of the paper presents a survey of different IP traceback techniques like packet marking that help a forensic investigator to identify the true sources of the attacking IP packets. We also discuss the use of Honeypots and Honeynets that gather intelligence about the…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsNetwork Security and Intrusion Detection · Advanced Malware Detection Techniques · Internet Traffic Analysis and Secure E-voting
