GUIDELINES FOR COLLECTING AND CENTRALIZING NETWORK DIGITAL EVIDENCES
Mohammed Azman Abbas, Elfadil Sabeil Azizah Abdul Manaf · 2011
Network forensic investigators have stated the significance of network digital evidences due to digital crimes science and depicted its ability to come up with rare solutions that limited to network forensic and meanwhile system (computer) forensic cannot. Normally, researchers and experts suggest and propose many different solutions such as Firewall's Logs, IDS/IPD Logs, Switches and Router's Logs and eventually incorporate more advanced systems like Honeywall Architecture to effectively help to investigate network digital evidences. Actually, Honeynet Architecture basically is built to simplify network forensic investigation operations through key features that help to collect and capture network inbound and outbound packets [1][2]. Honeynet Architecture is unique in terms of builtin and well configured tools and utilities which help to achieve the mission. A Honeynet is an architecture which its purpose is basically to build a highly controlled network that control and ABSTRACT