This week, we are focusing into the analysis of TCP/IP protocols, focusing on how to examine network flows, extract data, and analyze higher-layer traffic.
What is Flow Analysis?
Flow analysis is the "examination of sequences of related packets ('flows')". This process is typically conducted to identify traffic patterns, isolate suspicious activity, analyze higher-layer protocols, or extract data.
According to RFC 3679, a flow is "a sequence of packets sent from a particular source to a particular unicast, anycast, or multicast destination that the source desires to label as a flow". In modern network analysis, the terms "flow" and "stream" are increasingly becoming interchangeable.
Core Flow Analysis Tools
To analyze these flows, investigators rely on several key tools:
- Wireshark: Provides a highly visual "Follow TCP Stream" feature to read conversations.
- Tshark: A command-line network protocol analyzer.
- Tcpflow: Parses non-fragmented IP packets and reassembles the TCP stream into a file.
- Pcapcat: Lists all the streams it sees and can dump individual streams.
- Tcpxtract: Uses file signatures (magic numbers) to extract and reconstruct payload data.
Flow Analysis Techniques
1. Listing Conversations and Flows
You can view packet conversations directly from the command line using Tshark. For example, to view TCP conversations from a capture file:
$ tshark -qn -z conv,tcp -r evidence01.pcap
You can also use Pcapcat to list specific TCP flows to identify IP addresses and ports of interest.
2. Exporting a Flow
Once you identify the conversation containing potential evidence, you can export it. Pcapcat and Tcpflow are highly effective for this.
$ tcpflow -r evidence01.pcap 'host 192.168.1.158 and port 5190'
3. File and Data Carving
Data carving is the process of extracting files directly from the raw data payload.
- Manual Carving: Involves opening the exported flow in a hex editor and looking for "magic numbers" (file signatures). For example, a JPEG file always begins with 0xffd8 and ends with 0xffd9. Once extracted, you should gather hashes (using md5sum or sha256sum) and confirm the file size.
- Automatic Carving: Tools like Tcpxtract automate this process by scanning the packet capture for known file signatures and exporting the discovered files automatically:
$ tcpxtract -f evidence01.pcap
Higher-Layer Traffic Analysis
Beyond raw data extraction, forensic investigators must understand higher-layer protocols to contextualize network activity.
HTTP (Hypertext Transfer Protocol)
Defined in RFC 2616, HTTP uses specific methods for communication:
- GET: Retrieve information identified by a URI.
- POST: Send data to a URI for processing.
- HEAD: Retrieve information without the message body.
- PUT: Upload information to a specified URI.
- DELETE: Delete a specified resource.
- OPTIONS: Obtain information about communication options.
SMTP (Simple Mail Transfer Protocol)
When investigating email traffic, it helps to know the architecture and basic commands:
- Architecture: Mail User Agent (MUA), Mail Submission Agent (MSA), Mail Transfer Agent (MTA), Mail Delivery Agent (MDA), and Mail eXchanger (MX).
- Basic Commands: HELO (opens connection), MAIL (identifies return address), RCPT (identifies recipient address), and DATA (message content).
DNS & DHCP
- DNS (Domain Name System): A query-response protocol where both the client question and the server response are typically sent as single UDP packets.
- DHCP (Dynamic Host Configuration Protocol): Handles the automated assignment of IP addresses and network configurations.
Higher-Layer Analysis Tools
For higher-layer analysis, investigators choose between specialized and multipurpose tools:
- Small Specialized Tools: Great when you have a good idea of what the packet contains. Examples include Oftcat (for protocol summaries of OFT activity and recovered files), Smtpdump (for extracting email information and attachments), and Findsmtpinfo.py (for extracting authentication data and mail headers).
- Multipurpose Tools: Best when a wide range of information is needed. NetworkMiner is an excellent example of a multipurpose traffic analyzer that can sort hosts, extract files, and parse credentials in a highly visual interface.
Works Cited
The contents of this post are based on the week3.pptx presentation by S. Pradono Suryodiningrat.
- Davidoff, S., & Ham, J. (2012). Network Forensics Tracking Hackers Through Cyberspace. Boston: Prentice Hall.
Top comments (0)