Indexing Architecture for File Extraction from Network Traffic

Pei-Ting Lee, Baijian Yang · 2017

As crimes, along with nearly every aspect of life, continue to transit into cyberspace, network traffic becomes an increasingly important source of evidence for forensic investigators. Network forensics is most commonly used in analyzing network traffic, identifying suspicious patterns and tracing the source of attack. This paper takes a different approach and views network traffic not as a means to an end, but the source from which evidence can be extracted. When criminals take extra measures to wipe evidence from all physical servers and disks, carving the files from network traffic may become critical to investigations. However, with limitations in current computing power, analyzing each packet for extractable evidence is impractical. This study proposes an architecture for file extraction that incorporates network flow aggregation and indexing for faster, more efficient packet and file extraction.

Read the paper · More papers on PaperTik