Design and Implementation of the MSN Network Forensic System on Network Processors
碩士 === 國立中正大學 === 通訊工程研究所 === 94 === There's no way to achieve 100 percent protection. We need digital forensic mechanism to reduce risk. Digital forensic is used to reconstruct the scenario after attacks. Digital forensic give you 5W1H of attack and provide powerful evidence in lawsuit. MSN is...
Main Authors: | , |
---|---|
Other Authors: | |
Format: | Others |
Language: | zh-TW |
Published: |
2006
|
Online Access: | http://ndltd.ncl.edu.tw/handle/13125356249741744583 |
Summary: | 碩士 === 國立中正大學 === 通訊工程研究所 === 94 === There's no way to achieve 100 percent protection. We need digital forensic mechanism to reduce risk. Digital forensic is used to reconstruct the scenario after attacks. Digital forensic give you 5W1H of attack and provide powerful evidence in lawsuit. MSN is the most popular network application software now. But there are few security devices provide forensic mechanism for MSN. Many network forensic tools (ex. Sniffer or L3/L4 network forensic tools) cannot show the behavior of users in network. We propose a network forensic system solution for MSN-“MSN-shot”. As his name, MSN-shot can take a shot with any MSN activities. When security Incidents occurs, we can propose effective evidence and reconstruct the scenario in the attack time by the strict activity record. This paper presents a MSN-shot network forensic system which is designed and implemented based on Intel IXP425 network processor.
|
---|