Study of Peer-to-Peer Network Based Cybercrime Investigation: Application on Botnet Technologies
Mark Scanlon

TL;DR
This paper presents UP2PNIF, a framework and toolset for efficient investigation of P2P networks, demonstrated on BitTorrent, to aid cybercrime analysis and digital forensics.
Contribution
Introduction of UP2PNIF, a universal framework that accelerates and simplifies P2P network investigations using commonalities and a reference database.
Findings
Developed a proof of concept tool for BitTorrent investigation.
Framework enables faster, less labor-intensive P2P investigations.
Facilitates digital forensic analysis of various P2P applications.
Abstract
The scalable, low overhead attributes of Peer-to-Peer (P2P) Internet protocols and networks lend themselves well to being exploited by criminals to execute a large range of cybercrimes. The types of crimes aided by P2P technology include copyright infringement, sharing of illicit images of children, fraud, hacking/cracking, denial of service attacks and virus/malware propagation through the use of a variety of worms, botnets, malware, viruses and P2P file sharing. This project is focused on study of active P2P nodes along with the analysis of the undocumented communication methods employed in many of these large unstructured networks. This is achieved through the design and implementation of an efficient P2P monitoring and crawling toolset. The requirement for investigating P2P based systems is not limited to the more obvious cybercrimes listed above, as many legitimate P2P based…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAdvanced Malware Detection Techniques · Network Security and Intrusion Detection · Digital and Cyber Forensics
