Network Forensics (2019)
2h 16mIntermediate2019-03-26
Authors

Jungwoo Ryoo
Teaches IT, cybersecurity, and risk analysis at Penn State
Course details
Network forensics is used to find legal evidence in network devices. In this course, Jungwoo Ryoo covers all of the major concepts and tools in this growing technical field. Jungwoo begins by reviewing the basics: the goals of network forensics, a network forensic investigator's typical toolset, and the legal implications of this type of work. Then, he shows how to prepare for an investigation; acquire network logs and investigate network events; collect and investigate network traffic; and leverage various network forensics tools, such as Wireshark, Splunk, and tcpdump. Along the way, he uses a combination of open-source and commercial software, so you can uncover the information you need with tools that are in your budget.
Learning objectives
Goals of network forensics
Using a syslog and Microsoft Log Parser
Investigating network traffic
How protocol analysis works
ARP and DNS poisoning
Working with network forensics tools
Using packet sniffers
Learning objectives
Goals of network forensics
Using a syslog and Microsoft Log Parser
Investigating network traffic
How protocol analysis works
ARP and DNS poisoning
Working with network forensics tools
Using packet sniffers
Skills covered
WiresharkLinuxNetwork SecurityCybersecurityOpen SourceDeep Dive (X:Y)
Concepts
0. Introduction
- 01 - Learning network forensics
- 02 - What you should know
1. Understanding Network Forensics
- 03 - Goals of network forensics
- 04 - Tools
- 05 - Legal implications
- 06 - Current and future trends
- 07 - Anti-network forensics techniques
2. Preparing for a Network Forensics Investigation
- 08 - Network forensics investigation hardware
- 09 - Network forensics investigation software
- 10 - Understanding computer networking
- 11 - Understanding networking devices
- 12 - Understanding network data sources
3. Investigating Network Events
- 13 - Network logs
- 14 - Intrusion and security events
- 15 - Network logs as evidence
- 16 - Network logs and compliance
- 17 - Audit logs
- 18 - Firewall logs
- 19 - syslog
- 20 - syslog-ng
- 21 - Kiwi Syslog Server
- 22 - Microsoft Log Parser
4. Investigating Network Traffic
- 23 - Fundamentals
- 24 - Network models
- 25 - Subnets, subnet ID, and subnet mask
- 26 - Protocol analysis
- 27 - ARP
- 28 - ARP poisoning
- 29 - DNS
- 30 - DNS poisoning
5. Network Forensics Tools
- 31 - tcpdump and WinDump
- 32 - tcpdump and WinDump hands-on
- 33 - Wireshark
- 34 - Wireshark hands-on
- 35 - HTTP proxies
- 36 - HTTP proxies hands-on
- 37 - Splunk
- 38 - Splunk hands-on
Conclusion
- 39 - Next steps