Network Forensics (NFs) is a branch of digital forensics which used to detect and capture potential digital crimes over computer networked environments crime. Network Forensic Tools (NFTs) and Network Forensic Processes (NFPs) have abilities to examine networks, collect all normal and abnormal traffic/data, help in network incident analysis, and assist in creating an appropriate incident detection and reaction and also create a forensic hypothesis that can be used in a court of law. Also, it assists in examining the internal incidents and exploitation of assets, attack goals, executes threat evaluation, also by evaluating network performance. According to existing literature, there exist quite a number of NFTs and NTPs that are used for identification, collection, reconstruction, and analysing the chain of incidents that happen on networks. However, they were vary and differ in their roles and functionalities. The main objective of this paper, therefore, is to assess and see the distinction that exist between Network Forensic Tools (NFTs) and Network Forensic Processes (NFPs). Precisely, this paper focuses on comparing among four famous NFTs: Xplico, OmniPeek, NetDetector, and NetIetercept. The outputs of this paper show that the Xplico tool has abilities to identify, collect, reconstruct, and analyse the chain of incidents that happen on networks than other NF tools.
翻译:法医网络是一个数字法证分支,用来探测和捕捉在计算机网络环境犯罪中潜在的数字犯罪; 法医工具网络和法医程序网络有能力检查网络,收集所有正常和异常的交通/数据,帮助进行网络事故分析,协助创造适当的事故探测和反应,并创造法院可以使用的法医假设; 此外,它还协助审查内部事件和资产剥削、攻击目标、执行威胁评价,以及评价网络业绩。 根据现有文献,有相当多的国家反恐工具和国家贸易点用于识别、收集、重建和分析网络上发生的一系列事件。然而,它们的作用和功能各不相同,因此,本文件的主要目的是评估和观察网络法医工具与网络法医程序之间的区别。 准确地说,本文侧重于对四个著名的国家反恐工具进行比较:Xplico、OmniPeek、NetServeor和NetIteresty。