TY - JOUR
T1 - Communications reconstruction for a network security analysis
AU - Sisniega-Gonzalez, J.
AU - Aguirre-Anaya, E.
AU - Nakano-Miyatake, M.
AU - Perez-Meana, H.
PY - 2010/7/1
Y1 - 2010/7/1
N2 - The influence of computer technology on the human activities has greatly increased during the last three decades, which has generated considerable increase of computer crimes in computer networks. Besides that the increase of network traffic is huge, doing the analysis of traffic data complicated. In this paper a forensics network model is proposed, which allows to obtain the existing evidence in an involved TCP/IP network storage. The network flows had been subjected to attacks and intrusions and therefore an analysis will be necessary to determinate when data constitutes evidence and as consequence it can be presented to a court. Evaluation results show the desirables features of proposed scheme to reconstruct the data flow for network analysis purposes. © 2010 by Begell House, Inc.
AB - The influence of computer technology on the human activities has greatly increased during the last three decades, which has generated considerable increase of computer crimes in computer networks. Besides that the increase of network traffic is huge, doing the analysis of traffic data complicated. In this paper a forensics network model is proposed, which allows to obtain the existing evidence in an involved TCP/IP network storage. The network flows had been subjected to attacks and intrusions and therefore an analysis will be necessary to determinate when data constitutes evidence and as consequence it can be presented to a court. Evaluation results show the desirables features of proposed scheme to reconstruct the data flow for network analysis purposes. © 2010 by Begell House, Inc.
UR - https://www.scopus.com/inward/record.uri?partnerID=HzOxMe3b&scp=77954005116&origin=inward
UR - https://www.scopus.com/inward/citedby.uri?partnerID=HzOxMe3b&scp=77954005116&origin=inward
U2 - 10.1615/TelecomRadEng.v69.i7.50
DO - 10.1615/TelecomRadEng.v69.i7.50
M3 - Article
SP - 629
EP - 638
JO - Telecommunications and Radio Engineering (English translation of Elektrosvyaz and Radiotekhnika)
JF - Telecommunications and Radio Engineering (English translation of Elektrosvyaz and Radiotekhnika)
SN - 0040-2508
ER -