Evidence Collection in Peer-to-Peer Network Investigations - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Communication Dans Un Congrès Année : 2012

Evidence Collection in Peer-to-Peer Network Investigations

Résumé

Peer-to-peer (P2P) file sharing networks are often abused to distribute content that is prohibited by law. Strong evidence of suspicion must be provided to obtain a court order to identify the location of an offender. However, initial evidence collection from a P2P network is a challenge due to the lack of a central point of control and the dynamic nature of the network. This paper describes an initial evidence collection tool for P2P network forensics. The tool performs active and passive monitoring by inserting a modified peer node in a P2P network that records relevant information about nodes that distribute contraband files. It logs data sent by suspicious nodes along with timestamps and unique identification information, which provides a strong, verifiable body of initial evidence.
Fichier principal
Vignette du fichier
978-3-642-33962-2_15_Chapter.pdf (1.39 Mo) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)

Dates et versions

hal-01523704 , version 1 (16-05-2017)

Licence

Paternité

Identifiants

Citer

Teja Myneedu, Yong Guan. Evidence Collection in Peer-to-Peer Network Investigations. 8th International Conference on Digital Forensics (DF), Jan 2012, Pretoria, South Africa. pp.215-230, ⟨10.1007/978-3-642-33962-2_15⟩. ⟨hal-01523704⟩
52 Consultations
738 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More