Toward Automated MAC Spoofer Investigations

Serguei A. Mokhov, Michael J. Assels, Joey Paquet, Mourad Debbabi · 2008

We automate live and dead forensic evidence gathering for MAC spoofer investigations and formalize its encoding in Forensic Lucid for subsequent reasoning. The monitoring covers a Faculty's network focusing on 1000 analyst-managed clients. We describe initial operational deployment of the MAC Spoofer Analyzer's evidence gathering components. We also highlight immediate and future concerns regarding the automation of the reasoning aspects behind the analyzer to aid network system administrators in their daily network security monitoring, management, and maintenance activities.

Read the paper · More papers on PaperTik