Forensic Network Traffic Analysis
Proceeding: Second International Conference on Digital Security and Forensics (DigitalSec2015)Publication Date: 2015-11-15
Authors : Noora Al Khater; Richard E Overill;
Page : 1-9
Keywords : Digital Forensics; Cyber Security; Network Traffic Classification; Digital Evidence; Network Analysis;
Abstract
The nature of information in a network is volatile and dynamic, some precious evidence might be missed. The real-world situations need a quick classification decision before the flow finishes, especially for security and network forensic purposes. Therefore, monitoring network traffic requires a real-time and continuous analysis, to collect valuable evidence such as instant evidences that might be missed with post-mortem analysis (dead forensics). Network traffic classification is considered the first line of defence where a malicious activity can be filtered, identified and detected. In addition, it is the core component in evidence collection and analysis that uses filtered evidence and helps to reduce redundancy. However, most of the existing approaches that deal with collecting evidence from networks are based on post- mortem analysis. Therefore, this research investigates different classification techniques using Machine Learning (ML) algorithms, seeking to identify ways to improve classification methods from a forensic investigator standpoint.
Other Latest Articles
- Linguistic-philosophical understanding of stereotype
- The concept of "dialect" in the east slavic dialectological tradition and in western european languages
- Social culture in media intertext
- Evaluasi Pelaksanaan Corporate Social Responsibility di PT Bank Rakyat Indonesia (Persero) Tbk
- Pengaruh Job Involvement dan Job Satisfaction terhadap Organizational Citizenship Behaviour serta Dampaknya pada Knowledge Sharing di PT Indolift Sukses Abadi
Last modified: 2015-11-18 00:13:11