Professional Documents
Culture Documents
7 NetworkAnalysis
7 NetworkAnalysis
Lecture 7
0011 0010 1010 1101 0001 0100 1011
Network Analysis
This Week’s Presentations
• Investigative Goals
• Investigation Centric Analysis
• Data Centric Analysis
• General Tools and Methods
Module 1
0011 0010 1010 1101 0001 0100 1011
First Steps
Goals
• Collect evidence
0011 0010 1010 1101 0001 0100 1011
• Identify:
– Scope of activity
– Other parties involved
• Support or refute allegation
• Timeline
• Ensure compliance
Types of Network-Based Evidence
• Full content data
0011 0010 1010 1101 0001 0100 1011
• Many locations
– Computer systems
– Network components
• Can be large in size
• Might be encrypted
• Could be fragmented
Tying it Together
• Role is a key factor in all decisions
0011 0010 1010 1101 0001 0100 1011
Setup
• Consider a network diagram to show
0011 0010 1010 1101 0001 0100 1011
– Route diversity
– Switched networks
– Convergence
– Wireless (hidden node problem)
• Difficulties resulting from this
– Incomplete observation
– Difficulty in collecting on a network that’s not
well prepped
– Well trained investigators
– Large data
System Tools
• Used for after-incident collection
0011 0010 1010 1101 0001 0100 1011
– Network device
– Computer network logs
• Statistics
– Protocol
– Conversations
– Time of day
– Flow size
– Number of connections
• Signatures
– Well known crime
Module 4
0011 0010 1010 1101 0001 0100 1011
– ethereal
– tcpdump
– windump
– Limitations
• For example, stream reassembly
• Statistical tools
Tools for Analysis
• tcptrace – identify sessions
0011 0010 1010 1101 0001 0100 1011
• Switches
• SNMP enabled devices
• Firewalls
• DHCP servers
• IDS sensors
• Proxy servers
Routers/Switches
• Caches (Live analysis)
0011 0010 1010 1101 0001 0100 1011
– ARP
– Route tables
• Logs
– Previously setup for capture
Network Computer Information
• Similar to network device commands
0011 0010 1010 1101 0001 0100 1011
Future Needs
Gaps
• What are the features that each role would
0011 0010 1010 1101 0001 0100 1011
enjoy having?
– Home user
– Parent
– Corporate IT investigator
– Criminal investigator
– Counter terrorism authority
More Gaps
• What are the difficult problems?
0011 0010 1010 1101 0001 0100 1011