Academia.eduAcademia.edu

Cybercrime and Network Traffic Investigations

Traffic analysis consists of capturing network traffic in order to identify and respond to anomalies that could be indicative of security threats or other areas of concern. The communication, network, and technological infrastructures are expanding at a rapid pace and increasingly complex. Moreover, the global community has expanded interconnectedness as routine resulting in extraordinary production of data.   In the event of a cyber attack, the capacity to capture network traffic for analysis is critical to the success of a forensic investigation. Zhou, Yan, Fu, and Yao (2018) determined that the attributes displayed on the slide depict the relevance of capturing network traffic for subsequent analysis. As an analyst, it is important to have the correct tools depending on what is to be done, however if the nucleus is the data and if the rate, type, source, destination and other traffic factors can’t be determined, then you are still ill-equipped. Capturing network data for investigative purposes is necessary not only to initiate investigations, but allows documentation of lessons learned to improve present infrastructure operations. However, for it to be value-added, packets must be captured.

Loading...

Loading Preview

Sorry, preview is currently unavailable. You can download the paper by clicking the button above.