Exploring the Usability of Open Source Network Forensic Tools
Erik E. Northrop, Heather Richter Lipford · 2014
Network forensics tools are an important class of tool used by network administrators to monitor network performance and by forensics investigators to understand network compromises. Many of the available tools are open source, created and maintained by a community of volunteer developers and freely available to users. Despite their importance, there is little research on the use and usability of such tools. In this paper, we report the results of a small interview study of users of open source network forensics tools. We identify both the benefits and challenges of such tools, and additional unmet design needs. Additionally, we summarize a heuristic evaluation of one very popular tool, Wireshark, to further illustrate the usability challenges of network forensics tools.