Download PDFOpen PDF in browser Switch back to the title and the abstract in Korean Implementation of Network Sniffing Tool with CarvingEasyChair Preprint no. 36974 pages•Date: June 29, 2020AbstractIn this paper, we introduce a network traffic monitoring tool equipped with a carving module. It collects network traffic through real-time monitoring, saves file data before it is tampered, and recovers files. Therefore, a carving module that can be restored to the original file is developed so that it can be easily used in a small network or a group requiring monitoring and forensic functions. It also proposes a method of recovering files in which files of different extensions are separated in real-time through only network traffic sniffing and recovering files whose end of the file is not clearly known because there is no footer signature. Keyphrases: carving, Implementation of Tool, network sniffing
|