Retrospective analysis tools of local area network traffic
M. S. Pyr’ev, A. S. Kollerov · Journal of the Ural Federal district Information security · 2019
The article considers the problem of detecting a time-distributed network attack. Reportson the state of information space security from Kaspersky Lab and IBM Security are analyzed, aswell as stages of a retrospective analysis of network traffic based on research in the field of computer forensics are identified. Assumptions were made about possible problems at each stageand solutions were proposed. Existing network traffic analysis systems used to solve the existingproblem are investigated, a comparative description is made and their limitations are revealed