Universiti Teknologi Malaysia Institutional Repository

Comparative analysis of network forensic tools and network forensics processes

M. Ghabban, Fahad and M. Alfadli, Ibrahim and Abu Ali, Amer Nizar and Ameerbakhsh, Omair and Al-Dhaqm, Arafat and Al-Khasawneh, Mahmoud Ahmad (2021) Comparative analysis of network forensic tools and network forensics processes. In: 2nd International Conference on Smart Computing and Electronic Enterprise, ICSCEE 2021, 15 - 16 June 2021, Virtual, Online.

[img]
Preview
PDF
1MB

Official URL: http://dx.doi.org/10.1109/ICSCEE50312.2021.9498226

Abstract

Network Forensics (NFs) is a branch of digital forensics which used to detect and capture potential digital crimes over computer networked environments crime. Network Forensic Tools (NFTs) and Network Forensic Processes (NFPs) have abilities to examine networks, collect all normal and abnormal traffic/data, help in network incident analysis, and assist in creating an appropriate incident detection and reaction and also create a forensic hypothesis that can be used in a court of law. Also, it assists in examining the internal incidents and exploitation of assets, attack goals, executes threat evaluation, also by evaluating network performance. According to existing literature, there exist quite a number of NFTs and NTPs that are used for identification, collection, reconstruction, and analysing the chain of incidents that happen on networks. However, they were vary and differ in their roles and functionalities. The main objective of this paper, therefore, is to assess and see the distinction that exist between Network Forensic Tools (NFTs) and Network Forensic Processes (NFPs). Precisely, this paper focuses on comparing among four famous NFTs: Xplico, OmniPeek, NetDetector, and NetIetercept. The outputs of this paper show that the Xplico tool has abilities to identify, collect, reconstruct, and analyse the chain of incidents that happen on networks than other NF tools.

Item Type:Conference or Workshop Item (Paper)
Uncontrolled Keywords:Comparative analysis, Digital forensics
Subjects:Q Science > QA Mathematics > QA75 Electronic computers. Computer science
Divisions:Computing
ID Code:94562
Deposited By: Widya Wahid
Deposited On:31 Mar 2022 15:47
Last Modified:31 Mar 2022 15:47

Repository Staff Only: item control page