Download PDFOpen PDF in browserImplementation of Network Sniffing Tool with CarvingEasyChair Preprint 36974 pages•Date: June 29, 2020AbstractIn this paper, we introduce a network traffic monitoring tool equipped with a carving module. It collects network traffic through real-time monitoring, saves file data before it is tampered, and recovers files. Therefore, a carving module that can be restored to the original file is developed so that it can be easily used in a small network or a group requiring monitoring and forensic functions. It also proposes a method of recovering files in which files of different extensions are separated in real-time through only network traffic sniffing and recovering files whose end of the file is not clearly known because there is no footer signature. Keyphrases: Implementation of Tool, carving, network sniffing
|