Design and Implementation of the MSN Network Forensic System on Network Processors

碩士 === 國立中正大學 === 通訊工程研究所 === 94 === There's no way to achieve 100 percent protection. We need digital forensic mechanism to reduce risk. Digital forensic is used to reconstruct the scenario after attacks. Digital forensic give you 5W1H of attack and provide powerful evidence in lawsuit. MSN is...

Full description

Bibliographic Details
Main Authors: Wei-chi Chang, 張維騏
Other Authors: none
Format: Others
Language:zh-TW
Published: 2006
Online Access:http://ndltd.ncl.edu.tw/handle/13125356249741744583
Description
Summary:碩士 === 國立中正大學 === 通訊工程研究所 === 94 === There's no way to achieve 100 percent protection. We need digital forensic mechanism to reduce risk. Digital forensic is used to reconstruct the scenario after attacks. Digital forensic give you 5W1H of attack and provide powerful evidence in lawsuit. MSN is the most popular network application software now. But there are few security devices provide forensic mechanism for MSN. Many network forensic tools (ex. Sniffer or L3/L4 network forensic tools) cannot show the behavior of users in network. We propose a network forensic system solution for MSN-“MSN-shot”. As his name, MSN-shot can take a shot with any MSN activities. When security Incidents occurs, we can propose effective evidence and reconstruct the scenario in the attack time by the strict activity record. This paper presents a MSN-shot network forensic system which is designed and implemented based on Intel IXP425 network processor.