forensic investigation framework for tracing and ...

3 downloads 21819 Views 86KB Size Report
Jan 1, 2015 - CRIMES IN COMPUTER NETWORKS. Research Problem. Network ... help in generating a suitable incident response. Forensic tools also ...
1/1/2015

FORENSIC INVESTIGATION FRAMEWORK FOR TRACING AND REPORTING DIGITAL CRIMES IN COMPUTER NETWORKS Research Problem Network forensic analysis frameworks or tools permit administrators and investigators to monitor networks, gather all information about anomalous traffic, assist in network crime investigation and help in generating a suitable incident response. Forensic tools also provide support in analyzing the inside illegal network event and misuse of resources, predict network pattern in near future, executes risk assessment processes, judging the network performance, and thus help in protecting the intellectual propriety. These processes are complex in nature for real time implementation and execution. Network forensics is being researched for decade but it still seems to be a very young science. Here many issues are still an open problem like IP spoofing and other network based malicious activities. Following section provides brief comparison of different Forensic Investigation Frameworks by considering following ideal characteristics. 1) Collection & filtering(C) 2) Correlation and analysis of multiple raw data sources(R) 3) Log file analysis(L) 4) Application layer viewer(A) 5) Stream reassembly(S) 6) Workflow or case management(W) Collection and Filtering This is an important feature of any network forensic investigation tool which acts as source for investigators to identify any malicious activity from any network session. The collection module of the tool should be designed in such a way that the collection must include suspected network

1

Suggest Documents