Article ID Journal Published Year Pages File Type
456548 Digital Investigation 2008 9 Pages PDF
Abstract

Network forensics is an investigation technique looking at the network traffic generated by a system. PyFlag is a general purpose, open source, forensic package which merges disk forensics, memory forensics and network forensics.This paper describes the PyFlag architecture and in particular how that is used in the network forensics context. The novel processing of HTML pages is described and the PyFlag page rendering is demonstrated. PyFlag's novel processing of complex web applications such as Gmail and other web applications is described. Finally PyFlag's report generation capabilities are demonstrated.

Related Topics
Physical Sciences and Engineering Computer Science Computer Networks and Communications
Authors
,