• DocumentCode
    2030592
  • Title

    Design and implementation of a network forensics system for Linux

  • Author

    Wang, Hong-Ming ; Yang, Chung-Huang

  • Author_Institution
    Nat. Kaohsiung Normal Univ., Kaohsiung, Taiwan
  • fYear
    2010
  • fDate
    16-18 Dec. 2010
  • Firstpage
    390
  • Lastpage
    395
  • Abstract
    Technological advances of the Internet not only facilitate human life, but also give opportunities to attackers more easily conduct the activities of network intrusion and destruction. Network forensics is a forensic science and an important technology for network security realm. In this paper, we develop a network forensics system for Linux, which is used to collect and protect evidences when the cyber crime occurred. It consists of a live system, a friendly graphical launch menu, strengthen PyFlag software, and integrate required tools of system and network This system can expand its volatile, report presentation functionalities, and provide investigator to perform network forensics work quickly and correctly. The result of the forensics in this system can not only preserve evidences of the cyber crime, but also help organizations and institutions to understand the whole context of network security incidents and to strengthen the network host defense and security policy.
  • Keywords
    Internet; Linux; computer crime; computer forensics; forensic science; Internet; Linux; cyber crime; forensic science; graphical launch menu; network forensics system; network intrusion; network security; security policy; strengthen PyFlag software; Computers; DVD; Forensics; Linux; Security; Software; Universal Serial Bus; Computer Forensics; Digital Evidence; Network Forensics; PyFlag;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Symposium (ICS), 2010 International
  • Conference_Location
    Tainan
  • Print_ISBN
    978-1-4244-7639-8
  • Type

    conf

  • DOI
    10.1109/COMPSYM.2010.5685481
  • Filename
    5685481