Comparative Analysis of Network Forensic Tools and Network Forensics Processes

F. Ghabban, I. Alfadli, O. Ameerbakhsh, A. AbuAli, Arafat Al-dhaqm, M. Al-Khasawneh
{"title":"Comparative Analysis of Network Forensic Tools and Network Forensics Processes","authors":"F. Ghabban, I. Alfadli, O. Ameerbakhsh, A. AbuAli, Arafat Al-dhaqm, M. Al-Khasawneh","doi":"10.1109/ICSCEE50312.2021.9498226","DOIUrl":null,"url":null,"abstract":"Network Forensics (NFs) is a branch of digital forensics which used to detect and capture potential digital crimes over computer networked environments crime. Network Forensic Tools (NFTs) and Network Forensic Processes (NFPs) have abilities to examine networks, collect all normal and abnormal traffic/data, help in network incident analysis, and assist in creating an appropriate incident detection and reaction and also create a forensic hypothesis that can be used in a court of law. Also, it assists in examining the internal incidents and exploitation of assets, attack goals, executes threat evaluation, also by evaluating network performance. According to existing literature, there exist quite a number of NFTs and NTPs that are used for identification, collection, reconstruction, and analysing the chain of incidents that happen on networks. However, they were vary and differ in their roles and functionalities. The main objective of this paper, therefore, is to assess and see the distinction that exist between Network Forensic Tools (NFTs) and Network Forensic Processes (NFPs). Precisely, this paper focuses on comparing among four famous NFTs: Xplico, OmniPeek, NetDetector, and NetIetercept. The outputs of this paper show that the Xplico tool has abilities to identify, collect, reconstruct, and analyse the chain of incidents that happen on networks than other NF tools.","PeriodicalId":252529,"journal":{"name":"2021 2nd International Conference on Smart Computing and Electronic Enterprise (ICSCEE)","volume":"17 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-06-15","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"7","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2021 2nd International Conference on Smart Computing and Electronic Enterprise (ICSCEE)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICSCEE50312.2021.9498226","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 7

Abstract

Network Forensics (NFs) is a branch of digital forensics which used to detect and capture potential digital crimes over computer networked environments crime. Network Forensic Tools (NFTs) and Network Forensic Processes (NFPs) have abilities to examine networks, collect all normal and abnormal traffic/data, help in network incident analysis, and assist in creating an appropriate incident detection and reaction and also create a forensic hypothesis that can be used in a court of law. Also, it assists in examining the internal incidents and exploitation of assets, attack goals, executes threat evaluation, also by evaluating network performance. According to existing literature, there exist quite a number of NFTs and NTPs that are used for identification, collection, reconstruction, and analysing the chain of incidents that happen on networks. However, they were vary and differ in their roles and functionalities. The main objective of this paper, therefore, is to assess and see the distinction that exist between Network Forensic Tools (NFTs) and Network Forensic Processes (NFPs). Precisely, this paper focuses on comparing among four famous NFTs: Xplico, OmniPeek, NetDetector, and NetIetercept. The outputs of this paper show that the Xplico tool has abilities to identify, collect, reconstruct, and analyse the chain of incidents that happen on networks than other NF tools.
网络取证工具与网络取证过程的比较分析
网络取证(NFs)是数字取证的一个分支,用于在计算机网络环境中检测和捕获潜在的数字犯罪。网络取证工具(nft)和网络取证过程(NFPs)具有检查网络、收集所有正常和异常流量/数据、帮助进行网络事件分析、协助创建适当的事件检测和反应以及创建可在法庭上使用的取证假设的能力。此外,它还协助检查内部事件和利用资产、攻击目标、执行威胁评估,也通过评估网络性能。根据现有文献,有相当多的nft和ntp用于识别、收集、重建和分析网络上发生的事件链。但是,它们的作用和功能各不相同。因此,本文的主要目标是评估和了解网络取证工具(nft)和网络取证过程(NFPs)之间存在的区别。具体来说,本文重点比较了四个著名的nft: Xplico、OmniPeek、NetDetector和nettieterept。本文的输出表明,与其他NF工具相比,Xplico工具具有识别、收集、重构和分析网络上发生的事件链的能力。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信