Master'sOpen Access

Digital forensic analysis for voip

Is this your thesis?

This record came from a bulk archive import. If it’s yours, link it to your profile.

2017
0 views
0 downloads

Abstract (EN)

Today, communications through various networks are considered as an important indicator for how we conduct our daily lives. This is realized by the massive use of communication applications that require voice, image, video, and data. VoIP technology is regarded as one of the convenient communication services that meet the requirements of individuals and organizations. The growth of electronic devices and VoIP applications have increased the need for a specialized digital investigation. Generally, the digital investigation is creating challenging issues that need to be confronted. Many advanced digital forensic tools have been developed to assist the digital investigation process. Being familiar with the application scope and the limitations of forensic analysis tools is very important for the investigator. This is due to the fact that choosing a random forensic tool might be a waste of time and it may generate misleading results. Essentially, one tool cannot cope with the requirements of digital forensic applications; and with all the available tools, it is difficult to choose the most suitable tool for VoIP applications. It is possible to analyze and recover popular VoIP applications data from the RAM. However, the blind investigation of the digital evidence from unknown VoIP applications can be tedious and time-consuming. In this research, a classification for popular RAM acquisition and digital forensic tools is conducted. The ultimate aim is to help the investigators to properly choose the right RAM acquisition and forensic analysis tools applicable to VoIP. In addition, the research considered the use of unknown VoIP applications during the classification process. The experimental work was achieved by simulating a client-server unknown VoIP communication as well as the use of popular VoIP applications to create the relevant digital trace. The investigation process is made based only on volatile memory analysis. Two RAM sizes are used in this research, namely 4 and 8 GB. Here, RAM artefacts are captured by FTK Imager v3.1, Magnet Capture V1.0, RAM capture.exe, and DumpIt tools. The generated capture files are analyzed by Forensic Explorer, FTK v6.0, X-Way Forensics, Belkasoft, and Magnet IEF 6.8 tools. The obtained results are used for classifying the tools based on analysis duration, interface type and convenience, tool licensing, the ability to present the artefacts, the possible file formats, and the size of output file. The obtained results vary based on the used tool and RAM size, yet the optimal choice will be always case-dependent. Thus, a combination of tools can always be a useful option for VoIP forensic.

Author

Husseın Al_sadaawı

How to Cite

Husseın Al_sadaawı (Master Thesis). Digital forensic analysis for voip, 2017, Fırat University.

Keywords

License

Tüm Hakları Saklıdır

This work is shared under the specified license terms.

More theses from Fırat University