<?xml version="1.0" encoding="UTF-8"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
<title>P140 - IMF 2008 – IT-Incident Management &amp; IT Forensics</title>
<link href="http://dl.gi.de/handle/20.500.12116/23586" rel="alternate"/>
<subtitle/>
<id>http://dl.gi.de/handle/20.500.12116/23586</id>
<updated>2026-07-21T13:39:36Z</updated>
<dc:date>2026-07-21T13:39:36Z</dc:date>
<entry>
<title>File type analysis using signal processing techniques and machine learning vs. file Unix Utility for forensic analysis</title>
<link href="http://dl.gi.de/handle/20.500.12116/23599" rel="alternate"/>
<author>
<name>Mokhov, Serguei A.</name>
</author>
<author>
<name>Debbabi, Mourad</name>
</author>
<id>http://dl.gi.de/handle/20.500.12116/23599</id>
<updated>2019-06-04T11:30:43Z</updated>
<published>2008-01-01T00:00:00Z</published>
<summary type="text">File type analysis using signal processing techniques and machine learning vs. file Unix Utility for forensic analysis
Mokhov, Serguei A.; Debbabi, Mourad
Göbel, Oliver; Frings, Sandra; Günther, Detlef; Nedon, Jens; Schadt, Dirk
The Unix file utility determines file types of regular files by examining usually the first 512 bytes of the file that often contain some magic header information or typical header information for binary files or common text file fragments; otherwise, it defers to the OS-dependent stat () system call. It combines that heuristics with the common file extensions to give the final result of classification. While file is fast and small, and its magic database is "serviceable" by expert users, for it to recognize new file types, perhaps with much finer granularity it requires code and/or magic database updates and a patch release from the core developers to recognize new file types correctly. We propose an alternative file-like utility in determining file types with much greater flexibility that can learn new types on the user's side and be integrated into forensic toolkits as a plug-in that relies on the file-like utility and uses signal processing techniques to compute the "spectral signatures" of file types. We present the work-in-progress of the design and implementation of such a tool based on MARF's collection of algorithms and the selection of the best combination and the integration of the tool into a forensic toolkit to enhance the tool, called fileType with the automatic machine learning capabilities of the new file types. We compare the advantages and disadvantages of our approach with the file utility in terms of various metrics and apply the new tool to learn known stego files to attempt to classify potential unknown stego files and compare the results with stegdetect.
</summary>
<dc:date>2008-01-01T00:00:00Z</dc:date>
</entry>
<entry>
<title>Live forensic acquisition as alternative to traditional forensic processes</title>
<link href="http://dl.gi.de/handle/20.500.12116/23601" rel="alternate"/>
<author>
<name>Lessing, Marthie</name>
</author>
<author>
<name>Solms, Basie von</name>
</author>
<id>http://dl.gi.de/handle/20.500.12116/23601</id>
<updated>2019-06-04T11:30:43Z</updated>
<published>2008-01-01T00:00:00Z</published>
<summary type="text">Live forensic acquisition as alternative to traditional forensic processes
Lessing, Marthie; Solms, Basie von
Göbel, Oliver; Frings, Sandra; Günther, Detlef; Nedon, Jens; Schadt, Dirk
The development of live forensic acquisition in general presents a remedy for some of the problems introduced by traditional forensic acquisition. However, this live forensic acquisition introduces a variety of additional problems, unique to this discipline. This paper presents current research with regards to the forensic soundness of evidence retrieved through live forensic acquisition. The research is based on work done for a PhD Computer Science at the University of Johannesburg.
</summary>
<dc:date>2008-01-01T00:00:00Z</dc:date>
</entry>
<entry>
<title>Attaking test and online forensics in IPv6 networks</title>
<link href="http://dl.gi.de/handle/20.500.12116/23600" rel="alternate"/>
<author>
<name>Wu, Liu</name>
</author>
<author>
<name>Hai-Xin, Duan</name>
</author>
<author>
<name>Tao, Lin</name>
</author>
<author>
<name>Xing, Li</name>
</author>
<author>
<name>Jian-Ping, Wu</name>
</author>
<id>http://dl.gi.de/handle/20.500.12116/23600</id>
<updated>2019-06-04T11:30:43Z</updated>
<published>2008-01-01T00:00:00Z</published>
<summary type="text">Attaking test and online forensics in IPv6 networks
Wu, Liu; Hai-Xin, Duan; Tao, Lin; Xing, Li; Jian-Ping, Wu
Göbel, Oliver; Frings, Sandra; Günther, Detlef; Nedon, Jens; Schadt, Dirk
Although IPv6 protocol has considered and implemented more security mechanisms compared with IPv4, there are still many security threatens in Ipv6 Networks. Being one of the key protocols in IPv6, the Internet Control Message Protocol (ICMPv6) suffers from severe security risks. In this paper we construct an IPv6 attacking test system ATS_ICMP_6 exploiting the ICMPv6 Unreachable Message, which shows that the security of IPv6 protocol is still very weak. In the other hand, we has designed and implemented a network forensics prototype 6Foren in IPv6 environment based on the protocol analysis technology, its functions include packet capture, data reconstruct and messages replay etc. the 6Foren can be used as the online digital forensics which support the online forensic of HTTP, FTP, SMTP and POP3 protocols.
</summary>
<dc:date>2008-01-01T00:00:00Z</dc:date>
</entry>
<entry>
<title>Network infrastructure forensics</title>
<link href="http://dl.gi.de/handle/20.500.12116/23596" rel="alternate"/>
<author>
<name>Lindner, Felix</name>
</author>
<id>http://dl.gi.de/handle/20.500.12116/23596</id>
<updated>2019-06-04T11:30:42Z</updated>
<published>2008-01-01T00:00:00Z</published>
<summary type="text">Network infrastructure forensics
Lindner, Felix
Göbel, Oliver; Frings, Sandra; Günther, Detlef; Nedon, Jens; Schadt, Dirk
Incident identification, response and forensic analysis depend on the ability to extract meaningful evidence from the suspected system. Such tools do not exist for network infrastructure equipment. The significantly increased attack resilience of common general purpose operating systems poses a surprising new challenge to forensics, as attackers will likely shift their attention back towards network infrastructure control. The paper discusses the importance of network equipment forensics, the anatomy of devices and the attack types encountered. Finally a method for performing forensics on a widely used type of network equipment is presented.
</summary>
<dc:date>2008-01-01T00:00:00Z</dc:date>
</entry>
</feed>
