A Method for Solving Problems in Acquiring Communication Logs on End Hosts

Author:

Fukuta Youji1ORCID,Shiraishi Yoshiaki2ORCID,Hirotomo Masanori3ORCID,Mohri Masami1ORCID

Affiliation:

1. Faculty of Science and Engineering, Cyber Informatics Research Institute, Kindai University, Higashiosaka 577-8502, Japan

2. Graduate School of Engineering, Kobe University, Kobe 657-8501, Japan

3. Faculty of Science and Engineering, Saga University, Saga 840-8502, Japan

Abstract

In the process of collecting evidence of activities and events in network devices, there are problems with content and storage, and we aim to solve the problems faced by network devices in network forensics. In this paper, we propose a simple method for solving the problems with content and storage in acquiring communication logs on end hosts, implement a sniffing tool that captures raw packets with communication event control, compare it with existing tools, and conduct experiments and considerations. Through these experiments and considerations, we confirmed that the proposed communication log acquisition method can be implemented on the end host, and that the problem can be solved by using a tool that implements the proposed method. Also, we confirmed that it can be applied to real-world communication log collection scenarios, and that it can coexist with existing systems and tools that collect communication logs.

Funder

Ministry of Internal Affairs and Communications

Publisher

MDPI AG

Reference20 articles.

1. Davidoff, S., and Ham, J. (2012). Network Forensics: Tracking Hackers through Cyberspace, Pearson Education, Inc.

2. (2024, January 10). NIST SP 800-86 Guide to Integrating Forensic Techniques into Incident Response, Available online: https://csrc.nist.gov/pubs/sp/800/86/final.

3. Detection and analysis cerber ransomware based on network forensics behavior;Kurniawan;Int. J. Netw. Secur.,2018

4. Network Forensics: A Comprehensive Review of Tools and Techniques;Qureshi;Int. J. Adv. Comput. Sci. Appl. (IJACSA),2021

5. Li, J., Wu, C., Ye, J., Ding, J., Fu, Q., and Huang, J. (2019, January 5–8). The Comparison and Verification of Some Efficient Packet Capture and Processing Technologies. Proceedings of the 2019 IEEE International Conference on Dependable, Autonomic and Secure Computing, International Conference on Pervasive Intelligence and Computing, International Conference on Cloud and Big Data Computing, International Conference on Cyber Science and Technology Congress (DASC/PiCom/CBDCom/CyberSciTech), Fukuoka, Japan.

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3