DocumentCode
2030592
Title
Design and implementation of a network forensics system for Linux
Author
Wang, Hong-Ming ; Yang, Chung-Huang
Author_Institution
Nat. Kaohsiung Normal Univ., Kaohsiung, Taiwan
fYear
2010
fDate
16-18 Dec. 2010
Firstpage
390
Lastpage
395
Abstract
Technological advances of the Internet not only facilitate human life, but also give opportunities to attackers more easily conduct the activities of network intrusion and destruction. Network forensics is a forensic science and an important technology for network security realm. In this paper, we develop a network forensics system for Linux, which is used to collect and protect evidences when the cyber crime occurred. It consists of a live system, a friendly graphical launch menu, strengthen PyFlag software, and integrate required tools of system and network This system can expand its volatile, report presentation functionalities, and provide investigator to perform network forensics work quickly and correctly. The result of the forensics in this system can not only preserve evidences of the cyber crime, but also help organizations and institutions to understand the whole context of network security incidents and to strengthen the network host defense and security policy.
Keywords
Internet; Linux; computer crime; computer forensics; forensic science; Internet; Linux; cyber crime; forensic science; graphical launch menu; network forensics system; network intrusion; network security; security policy; strengthen PyFlag software; Computers; DVD; Forensics; Linux; Security; Software; Universal Serial Bus; Computer Forensics; Digital Evidence; Network Forensics; PyFlag;
fLanguage
English
Publisher
ieee
Conference_Titel
Computer Symposium (ICS), 2010 International
Conference_Location
Tainan
Print_ISBN
978-1-4244-7639-8
Type
conf
DOI
10.1109/COMPSYM.2010.5685481
Filename
5685481
Link To Document