7Viewes
Forensic Extraction of Network Artifacts A Wireshark-Based Analysis of CTF Scenario
Repository Analytics
Statistic Details
0Downloaded
7Accessed per month
2Countries
Loading...
Date
Authors
Gultom, Josep Lois Castilo
Journal Title
Journal ISSN
Volume Title
Publisher
Politeknik Negeri Batam
Abstract
Network forensics is a branch of digital forensics concerned with monitoring and capturing traffic to uncover digital crime. The purpose of this report is to isolate network forensics artifacts (e.g. covert payload and data exfiltration) from Capture The Flag (CTF) network traffic PCAPs, which will be used to build a complete picture of attack events. Although attackers may hide their malware commands and control in plain sight via network traffic, post-incident forensic analysis may allow investigators to study the captured packet data and identify malicious activity. A post-incident analysis was executed on a simulated CTF network traffic PCAP file with the network packet analyser Wireshark. Post-incident forensic analysis was applied by performing statistical analysis to identify and filter network traffic and reconstructing TCP streams to extract specific malicious packets from network noise, uncover attacks, and the impact of a breach. This analysis involves the usage of Wireshark display filter expressions, statistics capability features, and more. This paper proves that with post-incident forensic analysis techniques, an investigator will be able to identify and isolate the network forensic artifacts, construct an event timeline, and gain an accurate understanding of the incident.
Description
Citation
IEEE
