KEYWORDS: Forensic science, Sensors, Network security, Data storage, Information security, Digital forensics, Data processing, Surface plasmons, Binary data, Control systems
Data collection is the most important stage in network forensics; but under the resource constrained situations, a good
evidence collection mechanism is required to provide effective event collections in a high network traffic environment.
In literatures, a few network forensic tools offer MSN-messenger behavior reconstruction. Moreover, they do not have
classification strategies at the collection stage when the system becomes saturated. The emphasis of this paper is to
address the shortcomings of the above situations and pose a solution to select a better classification in order to ensure the
integrity of the evidences in the collection stage under high-traffic network environments. A system-awareness decision
classifier (SADC) mechanism is proposed in this paper. MSN-shot sensor is able to adjust the amount of data to be
collected according to the current system status and to keep evidence integrity as much as possible according to the file
format and the current system status. Analytical results show that proposed SADC to implement selective collection (SC) consumes less cost than full collection (FC) under heavy traffic scenarios. With the deployment of the proposed SADC mechanism, we believe that MSN-shot is able to reconstruct the MSN-messenger behaviors perfectly in the context of upcoming next generation network.
Access to the requested content is limited to institutions that have purchased or subscribe to SPIE eBooks.
You are receiving this notice because your organization may not have SPIE eBooks access.*
*Shibboleth/Open Athens users─please
sign in
to access your institution's subscriptions.
To obtain this item, you may purchase the complete book in print or electronic format on
SPIE.org.
INSTITUTIONAL Select your institution to access the SPIE Digital Library.
PERSONAL Sign in with your SPIE account to access your personal subscriptions or to use specific features such as save to my library, sign up for alerts, save searches, etc.