Network Forensics and Log Files Analysis : A Novel Approach to Building a Digital Evidence Bag and Its Own Processing Tool

dc.contributor.authorQaisi, Ahmed Abdulrheem Jerribi
dc.date.accessioned2011-12-13T02:26:39Z
dc.date.available2011-12-13T02:26:39Z
dc.date.issued2011en
dc.description.abstractIntrusion Detection Systems (IDS) tools are deployed within networks to monitor data that is transmitted to particular destinations such as MySQL,Oracle databases or log files. The data is normally dumped to these destinations without a forensic standard structure. When digital evidence is needed, forensic specialists are required to analyse a very large volume of data. Even though forensic tools can be utilised, most of this process has to be done manually, consuming time and resources. In this research, we aim to address this issue by combining several existing tools to archive the original IDS data into a new container (Digital Evidence Bag) that has a structure based upon standard forensic processes. The aim is to develop a method to improve the current IDS database function in a forensic manner. This database will be optimised for future, forensic, analysis. Since evidence validity is always an issue, a secondary aim of this research is to develop a new monitoring scheme. This is to provide the necessary evidence to prove that an attacker had surveyed the network prior to the attack. To achieve this, we will set up a network that will be monitored by multiple IDSs. Open source tools will be used to carry input validation attacks into the network including SQL injection. We will design a new tool to obtain the original data in order to store it within the proposed DEB. This tool will collect the data from several databases of the different IDSs. We will assume that the IDS will not have been compromised.en
dc.identifier.urihttp://hdl.handle.net/10092/5999
dc.identifier.urihttp://dx.doi.org/10.26021/6078
dc.language.isoen
dc.publisherUniversity of Canterbury. Computer Science and Software Engineeringen
dc.relation.isreferencedbyNZCUen
dc.rightsCopyright Ahmed Abdulrheem Jerribi Qaisien
dc.rights.urihttps://canterbury.libguides.com/rights/thesesen
dc.subjectIDSen
dc.subjectsnorten
dc.subjectbarnyarden
dc.subjectsnorbyen
dc.subjectmysqlen
dc.subjectintrusion detection systemsen
dc.subjectmultiple IDSsen
dc.subjectforensicsen
dc.subjectdigital evidence bagsen
dc.titleNetwork Forensics and Log Files Analysis : A Novel Approach to Building a Digital Evidence Bag and Its Own Processing Toolen
dc.typeTheses / Dissertations
thesis.degree.disciplineComputer Scienceen
thesis.degree.grantorUniversity of Canterburyen
thesis.degree.levelMastersen
thesis.degree.nameMaster of Scienceen
uc.bibnumber1735946en
uc.collegeFaculty of Scienceen
Files
Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
thesis_fulltext.pdf
Size:
2.92 MB
Format:
Adobe Portable Document Format