Packet and Protocol Analysis
Packet and Protocol Analysis
Analysis
Section II. Basic Forensic Techniques and
Tools
010101101011110000…
Network trace file
Computer network
Internet
Packets
IP Address
IP Address
Internet
Network Infrastructure
Packets
IP Address
IP Address
Internet
Network Infrastructure
Increasing
network
layer
Increasing
network layer
Increasing
network
layer
IP packet
IP packet
193.136.128.17
IP packet
IP packet
payload
IP packet
Need to know
what’s the
transport
protocol of
the payload
193.136.128.17
TCP flow
switch router
IP packet
146.193.41.201
TCP packet
payload
IP packet
payload
IP packet
Client =>
proxy
Proxy =>
client
IP packet
Link layer
frame
switch router
146.193.41.201
! Primary bibliography
! [Casey11], Chapter 21, 23.2.2