Forensic Technology Center of Excellence

Introduction

Network Forensics: Challenges and Tools

Network Forensics: Challenges and Tools

This webinar originally occurred on August 12th, 2020
Duration: 1 hour

In response to criminal investigations involving digital evidence, law enforcement needs forensically sound tools to acquire, evaluate, process, and present the data to the court. In the case of network forensics, challenges arise when the evidence is buried in large volumes of data.

The financial burdens of purchasing and licensing proprietary tools are not sustainable for law enforcement. This webinar reviewed a set of open-source tools, including snort, pcap, TcpDump, wireshark, and NetworkMiner. It also highlighted a recent open-source toolkit, FileTSAR, developed by Purdue University. This user-friendly toolkit can extract digital evidence from large amounts of network traffic and reconstruct unencrypted files, web pages, emails, and VOIP. FileTSAR achieves great performance by leveraging Spark, ElasticSearch, Kafka, and Kibana.

Since existing tools all have their own limitations, the presenters also discussed the challenges in network forensics. Potential workarounds were given for law enforcement and future work was identified for researchers in the field.

Detailed Learning Objectives:
Attendees will learn the:
1.) Definition and value of network forensics.
2.) Challenges in network forensics for researchers and law enforcement.
3.) Network forensics tools, limitations, and workarounds

Presenters:
Dr. Kathryn Seigfried-Spellar | Associate Professor in the Department of Computer and Information Technology at Purdue University
Dr. Baijian "Justin" Yang | Associate Professor of Computer and Information Technology at Purdue University

View Archived Webinar Here


Funding for this Forensic Technology Center of Excellence event has been provided by the National Institute of Justice.

Please contact us at ForensicCOE@rti.org for any questions.

Please subscribe to our newsletter for notifications.


Related Content

US and forensic science disciplines

2021 Forensic Science Research Federal Stakeholders Public Meeting

Overview The National Institute of Justice (NIJ) and the National Institute of Standards and Technology (NIST), in partnership with the Forensic Technology Center of Excellence (FTCoE), held a Forensic Science Research Federal Stakeholders meeting on November 8, 2021 from 9:00AM…
question marks and silhouettes

2021 National Forensic Science Week Practitioner Interviews

← Back to Main Page Overview The FTCoE has conducted a variety of written interviews with forensic professionals in various stages of their careers. From recent graduates to retired professionals, the FTCoE showcases real-world perspectives on the current state of…