首页> 美国政府科技报告 >Passive TCP Reconstruction and Forensic Analysis with tcpflow.
【24h】

Passive TCP Reconstruction and Forensic Analysis with tcpflow.

机译:使用tcpflow进行被动TCp重建和取证分析。

获取原文

摘要

Passive TCP session reconstruction essential for many kinds of network forensics and law enforcement operations, but it is complicated by packet loss, retransmissions, and possible attacks by adversaries. The key problem is that participants in the TCP session may observe the TCP segments differently than the monitor. An Added complication is the lack of familiarity with network protocols by many forensic analysts, resulting in the need for tools that are easy-to-use and able to tolerate a wide range of data. To address these issues we rewrote the open source network forensics tool tcpflow, making it more robust to anomalies that had been reported to us by users. We also improved the program s usability and performance on large packet captures, and added simple visualization that produces a one-page summary PDF for packet captures of any size.

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号