Skip to main navigation Skip to search Skip to main content

An improved approach towards network forensic investigation of HTTP and FTP protocols

  • T. Manesh
  • , B. Brijith
  • , Mahendra Prathap Singh

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

Network packet analysis and reconstruction of network sessions are more sophisticated processes in any network forensic and analysis system. Here we introduce an integrated technique which can be used for inspecting, reordering and reconstructing the contents of packets in a network session as part of forensic investigation. Network analysts should be able to observe the stored packet information when a suspicious activity is reported and should collect adequate supporting evidences from stored packet information by recreating the original data/files/messages sent/received by each user. Thus suspicious user activities can be found by monitoring the packets in offline. So we need an efficient method for reordering packets and reconstructing the files or documents to execute forensic investigation and to create necessary evidence against any network crime. The proposed technique can be used for content level analysis of packets passing through the network based on HTTP and FTP protocols and reports deceptive network activities in the enterprise for forensic analysis.
Original languageEnglish
Title of host publicationAdvances in Parallel Distributed Computing
Subtitle of host publicationFirst International Conference on Parallel, Distributed Computing Technologies and Applications, PDCTA 2011, Tirunelveli, Tamil Nadu, India, September 23-25, 2011, Proceedings
Place of PublicationBerlin
PublisherSpringer Berlin
Pages385-292
Number of pages8
ISBN (Electronic)9783642240379
ISBN (Print)9783642240362
DOIs
Publication statusPublished - 14 Sept 2011
Externally publishedYes

Publication series

NameCommunications in Computer and Information Science
ISSN (Print)1865-0929
ISSN (Electronic)1865-0937

Fingerprint

Dive into the research topics of 'An improved approach towards network forensic investigation of HTTP and FTP protocols'. Together they form a unique fingerprint.

Cite this