Network forensic frameworks: Survey and research challenges

被引:106
作者
Pilli, Emmanuel S. [1 ]
Joshi, R. C. [1 ]
Niyogi, Rajdeep [1 ]
机构
[1] Indian Inst Technol Roorkee, Dept Elect & Comp Engn, Roorkee 247667, Uttar Pradesh, India
关键词
Network forensics; NFATs; Distributed systems; Soft computing; Honeypots; Data fusion; Attribution; Traceback; Incident response;
D O I
10.1016/j.diin.2010.02.003
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Network forensics is the science that deals with capture, recording, and analysis of network traffic for detecting intrusions and investigating them. This paper makes an exhaustive survey of various network forensic frameworks proposed till date. A generic process model for network forensics is proposed which is built on various existing models of digital forensics. Definition, categorization and motivation for network forensics are clearly stated. The functionality of various Network Forensic Analysis Tools (NFATs) and network security monitoring tools, available for forensics examiners is discussed. The specific research gaps existing in implementation frameworks, process models and analysis tools are identified and major challenges are highlighted. The significance of this work is that it presents an overview on network forensics covering tools, process models and framework implementations, which will be very much useful for security practitioners and researchers in exploring this upcoming and young discipline. (C) 2010 Elsevier Ltd. All rights reserved.
引用
收藏
页码:14 / 27
页数:14
相关论文
共 73 条
[1]   Network Forensics with Neurofuzzy Techniques [J].
Aguirre Anaya, Eleazar ;
Nakano-Miyatake, Mariko ;
Perez Meana, Hector Manuel .
2009 52ND IEEE INTERNATIONAL MIDWEST SYMPOSIUM ON CIRCUITS AND SYSTEMS, VOLS 1 AND 2, 2009, :848-852
[2]  
Almulhem A, 2005, LECT NOTES COMPUT SC, V3391, P62
[3]  
ALMULHEM A, 2009, P 9 IEEE INT S SIGN
[4]  
[Anonymous], P AIAA GUID NAV CONT
[5]  
[Anonymous], SILK
[6]  
[Anonymous], PADS
[7]  
[Anonymous], P0F
[8]  
[Anonymous], 2001, 1 DIG FOR RES WORKSH
[9]  
[Anonymous], TCPFLOW
[10]  
[Anonymous], Infinistream