Categorizing Tracing Techniques for Network Forensics
摘要
The traceback problem is widely acknowledged as one of the most challenging issues in the field of information security, and it is crucial to find effective solutions to hold attackers accountable for their actions. This research paper aims to provide a comprehensive introduction to the intricate issue of traceback in network forensics. To fully comprehend the problem, the paper delves into the unique characteristics of computer, network, and software forensics. By exploring the distinctive features and challenges of each forensic subfield, a comprehensive understanding of the broader context in which traceback techniques are utilized is established. Furthermore, the paper analyses various traceback mechanisms and categorizes them based on their distinct features and modes of operation. In conclusion, the study proposes a systematic classification system for all traceback techniques, evaluating and integrating their respective advantages. This offers valuable insights for digital forensics investigations and brings us closer to identifying the actual perpetrator.