Deakin University
Browse

File(s) under permanent embargo

Timestamp Analysis for Quality Validation of Network Forensic Data

conference contribution
posted on 2016-01-01, 00:00 authored by Nikolai Hampton, Zubair BaigZubair Baig
Digital forensics is a fast-evolving field of study in contemporary times. One of the challenges of forensic analysis is the quality of evidence captured from computing devices and networks involved in a crime. The credibility of forensic evidence is dependent on the accuracy of established timelines of captured events. Despite the rising orders of magnitude in data volume captured by forensic analysts, the reliability and independence of the timing data source may be questionable due to the underlying network dynamics and the skew in the large number of intermediary system clocks that dictate packet time stamps. Through this paper, we propose a mechanism to verify the accuracy of forensic timing data through collaborative verification of forensic evidence obtained from multiple third party servers. The proposed scheme does analysis of HTTP response headers extracted from network packet capture (PCAP) files and validity testing of third party data through the application of statistical methods. We also develop a proof of concept universal time agreement protocol to independently verify timestamps generated by local logging servers and to provide a mechanism that may be adopted in digital forensics procedures.

History

Event

Network and System Security. Conference(2016 : Taipei, Taiwan)

Series

Lecture Notes in Computer Science; v.9955

Pagination

235 - 248

Publisher

Springer

Location

Taipei, Taiwan

Place of publication

Cham, Switzerland

Start date

2016-09-28

End date

2016-09-30

ISSN

0302-9743

ISBN-13

9783319462974

Language

eng

Publication classification

E1.1 Full written paper - refereed

Editor/Contributor(s)

J Chen, V Piuri, C Su, M Yung

Title of proceedings

NSS 2016 : Proceedings of the International Conference on Network and System Security

Usage metrics

    Research Publications

    Categories

    No categories selected

    Exports