Packet capture infrastructure based on Moloch

Jana Uramová, Pavel Segeč, Marek Moravčík, Jozef Papán, Tomas Mokos, Marek Brodec · 2017

To identify all the hidden details that are left after or during a network incident, the computer forensics is used. The purpose of computer forensic techniques is to search, preserve and analyze information on computer systems to find potential evidence for a trial. Computers are getting more powerful day by day, so the field of computer forensics must rapidly evolve. There exist many computer forensic tools that are used to apply forensic techniques to the computer. We present our investigation with Moloch tool, that is promising for today's computers. We describe components and architecture of Moloch, its application feasibilities and hardware requirements. We present our implementation and experiments with Moloch, our performance tests and statistics and application of useful scripts for Moloch and its components. We focus on integration with other alerting tools, such as IDS, to help speed up analysis.

Read the paper · More papers on PaperTik