ENiAC

Pioneer college of Arts and Science | BSc & BCA Student forum
 
HomeSearchMemberlistUsergroupsRegisterGalleryFAQLog in
Congratulations to University Rank Holders: B.C.A: K.Sathyavaishnavi-I RANK, S.Maheswari-V RANK | M.Sc: S.Samanthadevi-III RANK, T.Ambika-IV RANK, S.Sharmila-VI RANK | M.Com: K.Malathi- V RANK, F.Aseena-VIII RANK, R.Saravanakumar-X RANK.
Latest topics
» NANO TECHNOLOGY
Thu Dec 09, 2010 3:26 am by ARUNTHATHIMOHAN

» Kaspersky 35 years validity key... amazing hack..
Sun Dec 05, 2010 4:06 pm by sarathbabu

» Mobile telephony standards[0G,1G,2G,3G,4G,5G technology]
Sun Dec 05, 2010 11:14 am by sarathbabu

» 3G Technology
Sun Dec 05, 2010 11:09 am by sarathbabu

» Detail about IMEI number
Sun Dec 05, 2010 11:03 am by sarathbabu

» SIM CARD[meaning]
Sun Dec 05, 2010 10:59 am by sarathbabu

» smartphone
Sun Dec 05, 2010 10:55 am by sarathbabu

» Blender [animation] must see.....
Sun Dec 05, 2010 10:49 am by sarathbabu

» Blender [animation]
Sun Dec 05, 2010 10:49 am by sarathbabu

» GPS System Technology
Sun Nov 21, 2010 1:36 am by venkatesh

» கண்களை நம்பாதீர்கள்
Thu Nov 18, 2010 6:06 am by Admin

» CSS – ஆரம்ப வழிகாட்டி தமிழில்.
Thu Nov 18, 2010 5:52 am by Admin

» Top 10 Latest Inventions
Sun Nov 14, 2010 5:24 am by venkatesh

» கணினியை பராமரிக்க எழிய வழிமுறைகள்
Sun Nov 14, 2010 5:18 am by venkatesh

» Easy To Pick The Wndows Xp Key
Sun Nov 14, 2010 5:12 am by venkatesh

Top posters
Admin
 
sarathbabu
 
Divya
 
kanimozhi
 
SUBASRI
 
venkatesh
 
samson
 
manickaraaj
 
Mathivanan
 
ARUNTHATHIMOHAN
 
Poll
Which Internet Browser do you prefer?
Internet Explorer(IE)
8%
 8% [ 1 ]
Netscape
0%
 0% [ 0 ]
Opera
8%
 8% [ 1 ]
mozilla firefox
33%
 33% [ 4 ]
google chrome
17%
 17% [ 2 ]
Epic Browser
25%
 25% [ 3 ]
Other
8%
 8% [ 1 ]
Total Votes : 12
Social bookmarking
Social bookmarking Digg  Social bookmarking Delicious  Social bookmarking Reddit  Social bookmarking Stumbleupon  Social bookmarking Slashdot  Social bookmarking Furl  Social bookmarking Yahoo  Social bookmarking Google  Social bookmarking Blinklist  Social bookmarking Blogmarks  Social bookmarking Technorati  

Bookmark and share the address of ENiAC on your social bookmarking website

Bookmark and share the address of ENiAC on your social bookmarking website
Search
 
 

Display results as :
 
Rechercher Advanced Search

Share | 
 

 Network forensics

View previous topic View next topic Go down 
AuthorMessage
SUBASRI



Posts: 20
Reputation/vote (வாக்கு): 1
Join date: 2010-08-23
Age: 23
Location: COIMBATORE

PostSubject: Network forensics   Tue Aug 24, 2010 5:51 pm

Network forensics


Network forensics is the capture, recording, and analysis of network events in order to discover the source of security attacks or other problem incidents. (The term, attributed to firewall expert Marcus Ranum, is borrowed from the legal and criminology fields where forensics pertains to the investigation of crimes.)

According to Simson Garfinkel, author of several books on security, network forensics systems can be one of two kinds:
• "Catch-it-as-you-can" systems, in which all packets passing through a certain traffic point are captured and written to storage with analysis being done subsequently in batch mode. This approach requires large amounts of storage, usually involving a RAID system.

• "Stop, look and listen" systems, in which each packet is analyzed in a rudimentary way in memory and only certain information saved for future analysis. This approach requires less storage but may require a faster processor to keep up with incoming traffic.
Both approaches require significant storage and the need for occasional erasing of old data to make room for new. The open source programs tcpdump and windump as well as a number of commercial programs can be used for data capture and analysis.
One concern with the "catch-it-as-you-can" approach is one of privacy since all packet information (including user data) is captured.
Internet service providers (ISPs) are expressly forbidden by the Electronic Communications Privacy Act (ECPA) from eavesdropping or disclosing intercepted contents except with user permission, for limited operations monitoring, or under a court order.
• Network forensics products are sometimes known as Network Forensic Analysis Tools (NFATs).



Network Forensic Tools
Tags:
Forensic ToolKit, AccessData Corp., Email Examiner, Encase, Guidance Software, Paraben Corp, ProDiscover, Sleuth Kit, Tech-nology Pathways, chain of custody, dtSearch, dtSearch Corp, evidence, hash, incident investigation, intellectual property theft, le-gal team, network forensics, network penetration, Access and Physical Security, Cyberterrorism, Data Protection, Other, Security Policies and Management, Security and Privacy, Software, Software and Web Development, Threats and Attacks, information security


Stages
Stage 1:
Network-capable initial analysis products for first responders, such as Guidance's EnCase Enterprise Edition and Technology Pathway's ProDiscover. These two products can acquire drive images remotely in a live environment, and their use eliminates the need for the Stage 2 tools.


Stage 2:
Primary analysis and drive-image acquisition. This stage usually entails obtaining the hard disk of a suspect machine and investigating it in a controlled (not live) environment. AccessData Forensic Toolkit, Encase Forensic Edition and the open-source Sleuth Kit fit this stage. Any one can be used as the primary investigative tool in environments that don't require a network-capable acquisition application. All these products can acquire a full sector-by-sector drive image of any hard disk under investigation; additional sleuthing functionality varies by application.


Stage 3:
Fine-grained keyword searches through disk or partition contents, e-mail-specific searches or Internet history analysis. Paraben's NetAnalysis, E-Mail Examiner and Net E-Mail Examiner, and dtSearch's dtSearch excel here. These tools operate on disk images created by any of the applications from Stages 1 or 2.





NetDetector

NetDetector is a full-featured appliance for network security surveillance, signature-based anomaly detection, analytics and forensics. It complements existing network security tools, such as firewalls, intrusion detection/prevention systems and switches/routers, to help provide comprehensive defense of hosted intellectual property, mission-critical network services and infrastructure

NetIntercept

NetIntercept captures whole packets and reassembles up to 999,999 TCP connections at once, reconstructing files that were sent over your network and creating a database of its findings. It recognizes over 100 types of network protocols and file types, including web traffic, multimedia, email, and IM.

NetVCR

NetVCR delivers comprehensive real-time network, service and application performance management. It is an integrated, single-point solution that decisively replaces multiple network performance monitoring and troubleshooting systems. NetVCR’s scalable architecture easily adapts to data centers, core networks, remote branches or central offices for LAN and WAN requirements

NIKSUN

NIKSUN’s Full-Function Appliance combines the value of both NetDetector and NetVCR for complete network performance and security surveillance.

This plug-and-play appliance offers customers a complete range of network security and performance monitoring solutions that identify, capture and analyze the root-cause of any security or network incident the first time!

The unique enterprise-wide network visibility provided by this product is extremely attractive to large enterprises requiring an integrated and proactive solution to combat the constant barrage of security and network incidents such as worms, viruses, Trojan-horse attacks, Denial of Service (DoS) attacks, outages, overload and service slowdown, etc.

NetOmni

NetOmni provides global visibility across the network so IT professionals can manage multiple products and vendors from one central location.

NetOmni streamlines the network management process in a manner conducive to a “best-practices” model that ensures Service Level Agreements (SLA), Quality of Services (QoS) and maximum revenue opportunities.


NISUN (Puma Portable)

NIKSUN's Puma, a portable network monitoring appliance, allows customers to leverage the state-of-the-art network performance, security and compliance monitoring technology as a robust luggable appliance that can be conveniently used in the field.

Deployed in a few short steps, Puma offers with exceptional functionality of NIKSUN's renowned performance and security monitoring technology within minutes to field personnel. Puma, is now capable of monitoring networks at 10G speeds.

The incorporation of real-time 10G monitoring to the Puma feature-set enhances the already excellent value that Puma provides to customers, making it the go-to portable monitoring and forensics tool for network professionals

NetworkMiner is a Network Forensic Analysis Tool (NFAT) for Windows. NetworkMiner can be used as a passive network sniffer/packet capturing tool or to parse PCAP files for off-line analysis.

[u] bom Twisted Evil
Back to top Go down
View user profile
 

Network forensics

View previous topic View next topic Back to top 
Page 1 of 1

 Similar topics

-
» Apa itu network?
» Block Network Staff
» Masters in Network Security
» Network forensics
» The Global Palm Reading Network!

Permissions in this forum:You cannot reply to topics in this forum
ENiAC :: BLOG-