vix.ing · top · new · best · stats · spec

Comparative Analysis of Network Forensic Tools and Network Forensics\n Processes

2021/08/12 by Fahad Ghabban, Ghabban, Fahad M, Ibrahim Alfadli +9
Computer Science · #Advanced Malware Detection Techniques #Cryptography and Security (cs.CR) #Digital and Cyber Forensics #FOS: Computer and information sciences #Internet Traffic Analysis and Secure E-voting

paper · pdf · doi:10.48550/arxiv.2108.05579

openalex publication_date 2021/08/12 · openalex created_date 2022/07/25 · openalex updated_date 2026/07/28

Abstract

Network Forensics (NFs) is a branch of digital forensics which used to detect\nand capture potential digital crimes over computer networked environments\ncrime. Network Forensic Tools (NFTs) and Network Forensic Processes (NFPs) have\nabilities to examine networks, collect all normal and abnormal traffic/data,\nhelp in network incident analysis, and assist in creating an appropriate\nincident detection and reaction and also create a forensic hypothesis that can\nbe used in a court of law. Also, it assists in examining the internal incidents\nand exploitation of assets, attack goals, executes threat evaluation, also by\nevaluating network performance. According to existing literature, there exist\nquite a number of NFTs and NTPs that are used for identification, collection,\nreconstruction, and analysing the chain of incidents that happen on networks.\nHowever, they were vary and differ in their roles and functionalities. The main\nobjective of this paper, therefore, is to assess and see the distinction that\nexist between Network Forensic Tools (NFTs) and Network Forensic Processes\n(NFPs). Precisely, this paper focuses on comparing among four famous NFTs:\nXplico, OmniPeek, NetDetector, and NetIetercept. The outputs of this paper show\nthat the Xplico tool has abilities to identify, collect, reconstruct, and\nanalyse the chain of incidents that happen on networks than other NF tools.\n

Citations

Related