Generalizing sources of live network evidence

  • Authors:
  • Bruce J. Nikkel

  • Affiliations:
  • Risk Control, UBS AG, P.O. Box, CH-8098 Zurich, Switzerland

  • Venue:
  • Digital Investigation: The International Journal of Digital Forensics & Incident Response
  • Year:
  • 2005

Quantified Score

Hi-index 0.00

Visualization

Abstract

This paper suggests combining the capture of network traffic and the collection of data from remote network services into a more general acquisition category of live network evidence sources. These two evidence sources exhibit many similarities, collected data share the same basic characteristics, and the acquisition architectures used for collection are very similar. When viewed from a more abstract perspective they can be described in the same terms. The OSI model's layered approach to networking can be used to help bring these two branches of network evidence together, organizing and reducing the complexity found in live network acquisition. The concept of an acquisition window is also introduced as a fundamental variable in live network acquisition.