Forensic Carving of Network Packets and Associated Data Structures
MetadataShow full item record
Using validated carving techniques, we show that popular operating systems (e.g. Windows, Linux, and OSX) frequently have residual IP packets, Ethernet frames, and associated data structures present in system memory from long-terminated network traffic. Such information is useful for many forensic purposes including establishment of prior connection activity and services used; identification of other systems present on the systemÃ Ã Â¢ s LAN or WLAN; geolocation of the host computer system; and cross-drive analysis. We show that network structures can also be recovered from memory that is persisted onto a mass storage medium during the course of system swapping or hibernation. We present our network carving techniques, algorithms and tools, and validate these against both purpose-built memory images and a readily available forensic corpora. These techniques are valuable to both forensics tasks, particularly in analyzing mobile devices, and to cyber-security objectives such as malware analysis.
DFRWS 2011, Aug. 1-3, 2011, New Orleans, LA. BEST PaperR AWARDThe article of record as published may be found at http://dx.doi.org/10.1016/j.diin.2011.05.010Refereed Conference Paper
Showing items related by title, author, creator and subject.
Redmond, Patrick J. (Monterey, California. Naval Postgraduate School, 2007-03);The next generation of military capabilities will hinge on systems of systems technologies, entailing the integration of numerous large scale systems into a complex system of systems whose capability exceeds the capabilities ...
Nagashima, M.; Agrawal, B.N. (2012);For a large Adaptive Optics (AO) system such as a large Segmented Mirror Telescope (SMT), it is often difficult, although not impossible, to directly apply common Multi-Input Multi-Output (MIMO) controller design methods ...
Caffall, Dale Scott (Monterey, California. Naval Postgraduate School, 2005-03);Capturing and realizing the desired system-of-systems behavior in the traditional natural language development documents is a complex issue given that the legacy systems in a system-of-systems exhibit independent behaviors. ...