Analysis of Network Forensics System and Its Tools

XU Xiao-qin,GONG Jian,ZHOU Peng
DOI: https://doi.org/10.3969/j.issn.1673-629x.2005.05.046
2005-01-01
Abstract:With the development of Web,the quantities of computer crimes are increasing and computer forensics is becoming more and more important.Computer forensics is divided into post-event investigation and real-time investigation.In the early days,network security tools were used in network forensics.But it is limited and the data that they produced can't be regarded as the evidence in the legal meaning.Network forensics system has made up these deficiencies in real-time investigation.It involves capturing,recording,analyzing and reconstructing network audit trails.The paper discusses the network forensics system and a detailed comparison has been made to these tools.
What problem does this paper attempt to address?