Forensic Extraction of Network Artifacts A Wireshark-Based Analysis of CTF Scenario

Repository Analytics

Statistic Details

Updated data
7Viewes
0Downloaded
7Accessed per month
2Countries
Loading...
Thumbnail Image

Authors

Gultom, Josep Lois Castilo

Journal Title

Journal ISSN

Volume Title

Publisher

Politeknik Negeri Batam

Abstract

Network forensics is a branch of digital forensics concerned with monitoring and capturing traffic to uncover digital crime. The purpose of this report is to isolate network forensics artifacts (e.g. covert payload and data exfiltration) from Capture The Flag (CTF) network traffic PCAPs, which will be used to build a complete picture of attack events. Although attackers may hide their malware commands and control in plain sight via network traffic, post-incident forensic analysis may allow investigators to study the captured packet data and identify malicious activity. A post-incident analysis was executed on a simulated CTF network traffic PCAP file with the network packet analyser Wireshark. Post-incident forensic analysis was applied by performing statistical analysis to identify and filter network traffic and reconstructing TCP streams to extract specific malicious packets from network noise, uncover attacks, and the impact of a breach. This analysis involves the usage of Wireshark display filter expressions, statistics capability features, and more. This paper proves that with post-incident forensic analysis techniques, an investigator will be able to identify and isolate the network forensic artifacts, construct an event timeline, and gain an accurate understanding of the incident.

Description

Citation

IEEE

Endorsement

Review

Supplemented By

Referenced By