Dissertation > Excellent graduate degree dissertation topics show

The Network Forensics models and related technology research

Author: DuanLing
Tutor: WangFeng;DengHui
School: Kunming University of Science and Technology
Course: Applied Computer Technology
Keywords: Network Forensics Network forensics model WinPcap Protocol analysis
CLC: TP393.08
Type: Master's thesis
Year: 2010
Downloads: 102
Quote: 0
Read: Download Dissertation

Abstract


Computer forensics is a powerful tool to combat computer crime and means traditional computer forensic post-mortem analysis of the static forensics technology, there is the evidence collected is not timely, comprehensive, recovery of the data may have been tampered with, the legal effect of the evidence, the evidence analysis and lower extraction efficiency. This is an urgent need for network forensics technology. More perfect, has a relatively stable, the right model can reference, from forensics steps to ensure true network forensics, credible, professional and non-professional staff, a measure of the availability of computer network crime investigation standards, guidance in order to make the network forensics system The current network forensics process, to promote the theory and methods of network forensics gradually matured, this paper presents the point of view of the computer network forensics model specification. Network forensics model designed according to the common needs of network forensics practice, the use of online and offline data collection, to ensure the integrity of network data acquisition. This article from simple into the deep, in-depth analysis of the technical difficulty of the current domestic and international network forensics, emerging solutions and the cutting edge of technology trends, given the definition of network forensics, and discuss the concepts and the research status of network forensics analysis The limitations of the study at this stage. Compared stage forensics model based on network forensics model gives a specific description of the model and compared with other models. Due to the presence of large amounts of network data network forensics investigation, the investigation difficult for potential digital evidence of a crime. The study of crime in the traditional criminal forensics research outline the basic ideas and methods of construction techniques used in network forensics analysis, forensic analysis ideas \established a focused range of investigation and evidence collection, and analysis of the massive amounts of data as quickly as possible to narrow the scope of analysis to find the network the evidence put forward in a new direction. Finally, based on this model, detailed network data acquisition, evidence analysis, intrusion detection module to achieve. Design of a packet capture program based on Windows platform, and access to network packets based on the analysis methods of digital evidence analysis, using a combination of protocol analysis and pattern matching to extract the intrusion evidence. The experimental results show that the network data acquisition module can capture network underlying the packet, and the evidence analysis module can correctly decode Ethernet, ARP, IP, ICMP, TCP and UDP variety of network protocols, and can meet the requirements of network forensics. The domestic network forensics fledgling this study was to further explore the basic methods of network forensics, established a foundation to build a practical and effective network forensics system.

Related Dissertations

  1. Automated Fuzz Testing network protocol vulnerabilities mining method,TP393.08
  2. Research on Data-stream State Management Mechanism for Network Forensics,TP399-C2
  3. The Application Research on Network Security Forensics,TP393.08
  4. WiMAX protocol analysis software design and implementation,TP311.52
  5. Research and Application of embedded platform network packet capture,TP393.08
  6. The Design and Implementation of SIP Capture and Analysis Tool Based on MFC,TN915.04
  7. Research on Digital Protection Devices Test System Based on IEC61850,TM769
  8. Signaling Monitoring GSM-A port business analytics software design and development,TN929.532
  9. Research and Applications of Key Technologies of In-depth Computer Forensics,TP399-C2
  10. Design and Implementation of Network Sniffer Based on WinPcap,TP393.08
  11. Research of the Network Intrusion Detection Model on Rules and Behaviors,TP393.08
  12. Research on Optimization of DFA in Regular Expression Matching,TP393.08
  13. A Research on Intrusion Detection System Based on Snort Rules Optimization,TP393.08
  14. Kind of database mining method based on vulnerability,TP311.13
  15. THP Coordination Protocol Formal Analysis and Verification,TP311.52
  16. High-speed network intrusion detection system design and implementation,TP393.08
  17. Network data acquisition and agreement to restore the system design and implementation,TP393.09
  18. Web content analysis and restore the system design and implementation,TP393.09
  19. BitTorrent traffic monitoring and replacement system design and implementation,TP393.093
  20. Research and application of network monitoring,TP393.08

CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > Computer applications > Computer network > General issues > Computer Network Security
© 2012 www.DissertationTopic.Net  Mobile