Publication Details

Netfox Detective: A novel open-source Network Forensics Analysis Tool

PLUSKAL, J.; BREITINGER, F.; RYŠAVÝ, O. Netfox Detective: A novel open-source Network Forensics Analysis Tool. Forensic Science International: Digital Investigation, 2020, vol. 35, no. 301019, p. 1-13. ISSN: 2666-2825.
Czech title
Netfox Detective:nový open-source nástroj pro síťovou forenzní analýzu
Type
journal article
Language
English
Authors
URL
Keywords

Network forensics, Protocol analysis, Web forensics, Network forensic analysis
tool, Lawful interception

Abstract

Network forensics is a major sub-discipline of digital forensics which becomes
more and more important in an age whereeverything is connected. In order to cope
with the amounts of data and other challenges within networks, practitioners
require powerfultools that support them. In this paper, we highlight a novel
open-source network forensic tool named - Netfox Detective - thatoutperforms
existing tools such as Wireshark or NetworkMiner in certain areas. For instance,
it provides a heuristically based enginefor traffic processing that can be easily
extended. Using robust parsers (we are not solely relying on the RFC description
but useheuristics), our application tolerates malformed or missing conversation
segments. Besides outlining the tools architecture and basicprocessing concepts,
we also explain how it can be extended. Lastly, a comparison with other similar
tools is presented as well as areal-world scenario is discussed.

Published
2020
Pages
1–13
Journal
Forensic Science International: Digital Investigation, vol. 35, no. 301019, ISSN 2666-2825
DOI
UT WoS
000600551900005
EID Scopus
BibTeX
@article{BUT169468,
  author="Jan {Pluskal} and Frank {Breitinger} and Ondřej {Ryšavý}",
  title="Netfox Detective: A novel open-source Network Forensics Analysis Tool",
  journal="Forensic Science International: Digital Investigation",
  year="2020",
  volume="35",
  number="301019",
  pages="1--13",
  doi="10.1016/j.fsidi.2020.301019",
  issn="2666-2825",
  url="https://www.sciencedirect.com/science/article/pii/S2666281720300871"
}
Files
Back to top