• DocumentCode
    2130865
  • Title

    Universal Peer-to-Peer Network Investigation Framework

  • Author

    Scanlon, Mark ; Kechadi, M-Tahar

  • Author_Institution
    Sch. of Comput. Sci. & Inf., Univ. Coll. Dublin, Dublin, Ireland
  • fYear
    2013
  • fDate
    2-6 Sept. 2013
  • Firstpage
    694
  • Lastpage
    700
  • Abstract
    Peer-to-Peer (P2P) networking has fast become a useful technological advancement for a vast range of cyber criminal activities. Cyber crimes from copyright infringement and spamming, to serious, high financial impact crimes, such as fraud, distributed denial of service attacks (DDoS) and phishing can all be aided by applications and systems based on the technology. The requirement for investigating P2P based systems is not limited to the more well known cyber crimes listed above, as many more legitimate P2P based applications may also be pertinent to a digital forensic investigation, e.g., VoIP and instant messaging communications, etc. Investigating these networks has become increasingly difficult due to the broad range of network topologies and the ever increasing and evolving range of P2P based applications. This paper introduces the Universal Peer-to-Peer Network Investigation Framework (UP2PNIF), a framework which enables significantly faster and less labour intensive investigation of newly discovered P2P networks through the exploitation of the commonalities in network functionality. In combination with a reference database of known network protocols and characteristics, it is envisioned that any known P2P network can be instantly investigated using the framework. The framework can intelligently determine the best methodology dependant on the focus of the investigation resulting in a significantly expedited evidence gathering process.
  • Keywords
    Internet telephony; computer crime; computer network security; copyright; digital forensics; electronic messaging; fraud; peer-to-peer computing; telecommunication network topology; DDoS; P2P based systems; P2P networking; UP2PNIF; VoIP; copyright infringement; cyber crimes; cyber criminal activities; digital forensic investigation; distributed denial-of-service attacks; fraud; high financial impact crimes; instant messaging communications; network functionality; network protocols; network topologies; phishing; reference database; spamming; universal peer-to-peer network investigation framework; Databases; Forensics; IP networks; Internet; Peer-to-peer computing; Servers; Sociology; Cybercrime; Forensics; Framework; Investigation; Network; P2P; Peer-to-Peer;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Availability, Reliability and Security (ARES), 2013 Eighth International Conference on
  • Conference_Location
    Regensburg
  • Type

    conf

  • DOI
    10.1109/ARES.2013.91
  • Filename
    6657307