DEV Community

Timothy Imanuel
Timothy Imanuel

Posted on

Network Forensics: Evidence Acquisition (Week 4)

This week, we fovus on the phase of evidence acquisition, focusing on how investigators capture network traffic using physical interception, acquisition software, and active collection methods.

Physical Interception (Passive Acquisition)

Capturing packets as data is transmitted normally over the wire is known as passive acquisition. Investigators use several hardware methods to achieve this:

  • Inline Network Taps: These are Layer 1 devices inserted between physically connected devices. They cause minor data disruption during installation and physically replicate copies of traffic to separate sniffing ports.
  • Vampire Taps: These puncture the coating on the wire to physically touch the core, and they are standard issue in phone company "butt kits".
  • Radio Frequency (802.11 Wi-Fi): Wireless signals travel through the air as a shared medium, allowing stations to capture RF traffic regardless of whether they are part of the link. Anyone with access to the Pre-Shared Key (PSK) can monitor the traffic. Capturing this traffic requires special hardware, as many standard NICs do not support passive monitor mode.
  • Hubs: These dumb Layer 1 devices transmit all packets to every port, allowing for easy monitoring.
  • Switches: These Layer 2 (and sometimes Layer 3) devices use CAM tables to track port assignments and forward packets accordingly. To intercept traffic, investigators must have administrative access to configure port mirroring.

Traffic Acquisition Software

Once hardware is in place, investigators rely on specialized software libraries and tools to capture and filter the data.

  • Libpcap & WinPcap: Libpcap is a UNIX C library providing an API for capturing and filtering data link-layer frames, while WinPcap is the Windows equivalent. Popular tools like Tcpdump, Wireshark, Snort, and Nmap rely on these libraries.
  • Berkeley Packet Filter (BPF): Included in libpcap, BPF is a powerful filtering language that filters traffic based on comparison values at Layers 2, 3, and 4 (such as host, net, port, or specific byte/bit values).
  • Tcpdump: A UNIX command-line tool (WinDump for Windows) used to capture network traffic bit-by-bit for later analysis.
  • Wireshark Suite: This includes Wireshark (an open-source GUI for capturing and analyzing traffic), tshark (a command-line network protocol analyzer), and dumpcap (a tool specifically designed for packet capturing).

Active Acquisition

Active acquisition modifies the target environment, so investigators must carefully minimize their impact to preserve evidence.

  • Console Access: Connecting directly via a serial port or USB-to-serial adapter is the best practice. Remote connections should be avoided because they create excess traffic and can change CAM tables.
  • SSH & SCP/SFTP: Secure Shell (SSH) replaces insecure telnet by encrypting credentials, while SCP and SFTP handle secure file transfers.
  • Telnet: Telnet transmits credentials and data in plaintext and has limited security. It should be avoided unless it is the only option on older, un-upgradable network devices.
  • SNMP: The Simple Network Management Protocol is used to poll devices (GET, GETNEXT), interrupt via notifications (TRAP, INFORM), and control remote configurations (SET).
  • TFTP: Trivial File Transfer Protocol transfers files without authentication over UDP port 69. Forensic investigators often use it to export files from devices that do not support SCP or SFTP.

Acquisition Strategy & Clean Captures

When securing a scene, investigators must follow a strict methodology to ensure evidence is legally defensible.

  • Prioritize Volatile Data: Do not reboot or power down devices, as you will lose volatile data like ARP tables and the current state of the devices. Collect evidence according to its volatility.
  • Document Everything: Record all system times, check for time skew, record all terminal commands using tools like screen or script, and take screenshots of any GUI activities.
  • Forensically Clean Capture: You must not add any of your own traffic (evidence) to the network. To achieve this, use an acquisition system equipped with two network interface cards (e.g., eth0 and eth1). Run two separate tcpdump sessions: collect incoming traffic on one interface (filtering for the suspect's destination IP) and outgoing traffic on the other interface (filtering for the suspect's source IP). These isolated captures can later be merged and analyzed within Wireshark.

Top comments (0)