Packet Analysis for Network Forensics
Francis Asiedu · Advances in Multidisciplinary & Scientific Research Journal Publication · 2022
If the packet characteristics acquired are sufficiently detailed, packet analysis is a common forensic approach in network forensics that can replay the whole network traffic for a specified time period. This can be used to find evidence of illicit online activity such as data breaches, unauthorized website access, malware infection, and infiltration attempts, as well as to reproduce image files, documents, email attachments, and other material sent over the network. This paper covers a comprehensive assessment of the usage of packet analysis, including deep packet inspection, in network forensics, as well as a discussion of AI-powered packet analysis methodologies with sophisticated network traffic classification and pattern recognition. Keywords: Cybersecurity; Network Security; Traffic Analysis; Deep Inspection; Intrusion Detection; Network Forensics