Network Forensic Acquisition

R. C. Joshi, Emmanuel S. Pilli · Computer communications and networks · 2016

This chapter discusses about the acquisition of packets in the network forensic system. For the same topics such as TCP/IP protocol suite, packet capture format, pcapng dump file format, NetFlow record format, and IPFIX format are discussed. Their relevance with the network forensic system is elaborated. Identification and correlation architecture with all its events are also discussed in the last section of the chapter. These keywords were added by machine and not by the authors. This process is experimental and the keywords may be updated as the learning algorithm improves.

Read the paper · More papers on PaperTik