From the course: Data-Driven Network Security Essentials

Unlock the full course today

Join today to access over 22,600 courses taught by industry experts or purchase this course individually.

Network forensics

Network forensics

From the course: Data-Driven Network Security Essentials

Start my 1-month free trial

Network forensics

- Network forensics is a subfield of computer and cyber forensics. Its goal is to preserve and analyze data for evidence to be presented in civil and criminal court cases. The basic mission of network forensics is still the same as that of computer and cyber forensics. However, the difference lies in its focus on the network data exchanged between various hosts, rather than the static data generated and stored locally on each computer. Network forensics leverages all the data sources that make up a computer network, ranging from host firewalls to intrusion detection systems. One of the key aspects of network forensics is to effectively preserve, process, and analyze these disparate types of data. Due to the advent of cloud computing, we have vastly enhanced our capacity to preserve and process raw data for network forensics purposes. In fact, the average size of such data is now quickly reaching the scale of big data. What's even more exciting is that analysis tools designed to take…

Contents