Forensic Traceback Methods: Designing an Improved Investigation Framework
Date
Authors
Supervisor
Item type
Degree name
Journal Title
Journal ISSN
Volume Title
Publisher
Abstract
The problem of tracing back to the origin of an Internet communication is a challenging task on account of the complexity and instability of computing networks. In this research previous attempts have been reviewed and an innovative theoretical framework developed. The unfortunate misuse of the Internet requires the ability to trace back to an attack origin as an important step in locating evidence that may be used to identify and prosecute those responsible. The innovative method is termed the HC-ICMP method. This is a theoretical and futuristic study to prove in concept the possibility of combining methods. A present empirical study has been published to show the HC Method works in live networks but the ICMP method cannot be proven in real live networks because the routers lack the required protocols for the implementation. This study provides the theoretical tools and future proofing for investigators when the Internet protocols evolve toward the new and predicted capabilities.