DocumentCode :
3714151
Title :
Transmitted file extraction and reconstruction from network packets
Author :
Yangseo Choi;Joo-Young Lee;Sunoh Choi;Jong-Hyun Kim;Ikkyun Kim
Author_Institution :
Network security research team Electronics and Telecommunications Research Institute Daejeon, South Korea
fYear :
2015
Firstpage :
164
Lastpage :
165
Abstract :
When hackers try to attack a target system, their first goal is to install a malware to the target system. It is because hackers can do anything what they want if a malware is installed. In the past, most of the malwares were Microsoft PE files, however they have been changed to various file formats such as pdf, jpg, doc, jar and so on. Under this circumstances some network security systems such as network forensics systems have to reconstruct those malwares from network packets to analyze the malwares. For that, we propose a file type signature and network protocol analysis based transmitted file reconstruction technique which can reconstruct various file types from network packets. In this paper, we show the implementation and file reconstruction results.
Keywords :
"Protocols","Malware","Image reconstruction","Computer hacking","XML","Internet"
Publisher :
ieee
Conference_Titel :
Internet Security (WorldCIS), 2015 World Congress on
Type :
conf
DOI :
10.1109/WorldCIS.2015.7359436
Filename :
7359436
Link To Document :
بازگشت