Digital forensic analysis for voip
Is this your thesis?
This record came from a bulk archive import. If it’s yours, link it to your profile.
Abstract (EN)
Today, communications through various networks are considered as an important indicator for how we conduct our daily lives. This is realized by the massive use of communication applications that require voice, image, video, and data. VoIP technology is regarded as one of the convenient communication services that meet the requirements of individuals and organizations. The growth of electronic devices and VoIP applications have increased the need for a specialized digital investigation. Generally, the digital investigation is creating challenging issues that need to be confronted. Many advanced digital forensic tools have been developed to assist the digital investigation process. Being familiar with the application scope and the limitations of forensic analysis tools is very important for the investigator. This is due to the fact that choosing a random forensic tool might be a waste of time and it may generate misleading results. Essentially, one tool cannot cope with the requirements of digital forensic applications; and with all the available tools, it is difficult to choose the most suitable tool for VoIP applications. It is possible to analyze and recover popular VoIP applications data from the RAM. However, the blind investigation of the digital evidence from unknown VoIP applications can be tedious and time-consuming. In this research, a classification for popular RAM acquisition and digital forensic tools is conducted. The ultimate aim is to help the investigators to properly choose the right RAM acquisition and forensic analysis tools applicable to VoIP. In addition, the research considered the use of unknown VoIP applications during the classification process. The experimental work was achieved by simulating a client-server unknown VoIP communication as well as the use of popular VoIP applications to create the relevant digital trace. The investigation process is made based only on volatile memory analysis. Two RAM sizes are used in this research, namely 4 and 8 GB. Here, RAM artefacts are captured by FTK Imager v3.1, Magnet Capture V1.0, RAM capture.exe, and DumpIt tools. The generated capture files are analyzed by Forensic Explorer, FTK v6.0, X-Way Forensics, Belkasoft, and Magnet IEF 6.8 tools. The obtained results are used for classifying the tools based on analysis duration, interface type and convenience, tool licensing, the ability to present the artefacts, the possible file formats, and the size of output file. The obtained results vary based on the used tool and RAM size, yet the optimal choice will be always case-dependent. Thus, a combination of tools can always be a useful option for VoIP forensic.
Author
Husseın Al_sadaawı
How to Cite
Husseın Al_sadaawı (Master Thesis). Digital forensic analysis for voip, 2017, Fırat University.
Keywords
License
Tüm Hakları Saklıdır
This work is shared under the specified license terms.
More theses from Fırat University
- Using social media as an integrated marketing communication tool(2018)
- Foundation of Dutch East İndia Company and her rising in İndonesia in the 17th century(2013)
- Examination of stress state between Doğanyol (Malatya) and Çelikhan (Adıyaman) on the east Anatolian fault zone(2020)
- Color usage at Turkish Divan of Fuzûlî(2013)
- Yavuzeli (Gaziantep) surrounding volcanic outcropping of rocks petrographic and geochemical features(2014)
- Hizbu?t-Tahrir and the religions and political thoughts of Ercumend Özkan(2008)
