In English

Network Forensics: Following the Digital Trail in a Virtual Environment

Konstantinos Samalekas
Göteborg : Chalmers tekniska högskola, 2010. 64 s.
[Examensarbete på avancerad nivå]

The objective of this project is to examine all important aspects of network forensics, and apply incident response methods and investigation techniques in practice. The subject is twofold and begins by introducing the reader to the major network forensic topics. The second section discusses issues raised when working on a virtual context and presents a demonstration network. In particular, it is attempted to create a simplified model that simulates, to some extent, the operation of an ISP network. In this virtual infrastructure, several attack scenarios of email abuse are performed against two corporate hosts. Then, a network forensic investigation is conducted and results are reported.

