International Journal of Communications, Network and System Sciences

Volume 2, Issue 9 (December 2009)

ISSN Print: 1913-3715   ISSN Online: 1913-3723

Google-based Impact Factor: 1.39  Citations  

Forensic Investigation in Communication Networks Using Incomplete Digital Evidences

HTML  Download Download as PDF (Size: 590KB)  PP. 857-873  
DOI: 10.4236/ijcns.2009.29100    6,630 Downloads   12,425 Views  Citations

Affiliation(s)

.

ABSTRACT

Security incidents targeting information systems have become more complex and sophisticated, and intruders might evade responsibility due to the lack of evidence to convict them. In this paper, we develop a system for Digital Forensic in Networking, called DigForNet, which is useful to analyze security incidents and explain the steps taken by the attackers. DigForNet combines intrusion response team knowledge with formal tools to identify the attack scenarios that have occurred and show how the system behaves for every step in the scenario. The attack scenarios construction is automated and the hypothetical concept is introduced within DigForNet to alleviate missing data related to evidences or investigator knowledge. DigForNet system supports the investigation of attack scenarios that integrate anti-investigation attacks. To exemplify the proposal, a case study is proposed.

Share and Cite:

S. REKHIS, J. KRICHENE and N. BOUDRIGA, "Forensic Investigation in Communication Networks Using Incomplete Digital Evidences," International Journal of Communications, Network and System Sciences, Vol. 2 No. 9, 2009, pp. 857-873. doi: 10.4236/ijcns.2009.29100.

Copyright © 2025 by authors and Scientific Research Publishing Inc.

Creative Commons License

This work and the related PDF file are licensed under a Creative Commons Attribution 4.0 International License.