E-mail forensics: tracing and mapping digital evidence from IP address

aut.embargoNoen
aut.thirdpc.containsYes
aut.thirdpc.permissionYes
aut.thirdpc.removedNo
dc.contributor.advisorCusack, Brian
dc.contributor.authorHo, Wan Chung Cary
dc.date.accessioned2011-09-06T02:47:11Z
dc.date.available2011-09-06T02:47:11Z
dc.date.copyright2010
dc.date.issued2010
dc.date.updated2011-09-06T01:47:47Z
dc.description.abstractThe purpose of the thesis is to search for a suitable traceback method for use in email forensics when the source IP address is spoofed. To provide a simple and fast traceback method in email forensics, the hop count distance method is proposed in the thesis. This method has a simple architecture with only three operation blocks: the packet signature identification, default hop count estimation & validation and the hop count distance calculation block. Since the hop count distance method depends only on the Time-To-Live field of the packet to calculate the hop count distance, it is totally independent of the source IP address. Also, from capturing the attacking packet to calculating the hop count distance between the source and destination, the traceback process takes less than a minute.
dc.identifier.urihttps://hdl.handle.net/10292/1997
dc.language.isoenen_NZ
dc.publisherAuckland University of Technology
dc.rights.accessrightsOpenAccess
dc.subjectEmail forensic
dc.subjectIP traceback
dc.titleE-mail forensics: tracing and mapping digital evidence from IP address
dc.typeThesis
thesis.degree.grantorAuckland University of Technology
thesis.degree.levelMasters Theses
thesis.degree.nameMaster of Forensic Information Technology
Files
Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
HoWCC.pdf
Size:
3.03 MB
Format:
Adobe Portable Document Format
Description:
Whole thesis
License bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
897 B
Format:
Item-specific license agreed upon to submission
Description:
Collections