COMP6064 - Network Forensics Investigation and Memory Forensics

Download Solution Order New Solution

Assignment Task

1. PCAP Analysis

This task focuses on your knowledge of network forensics. As a forensic investigator, you are given a network traffic capture PCAP file to identify various malicious activities between an attacker's device and a server. You should follow the standard forensic procedure (e.g. examination and analysis) and use appropriate forensic tools (e.g. Wireshark) to locate potential evidence containers within the given PCAP file. In particular you need to:

1. Explain the type of incident and how it happened (Executive summary).

2. Identify details of the attacker and victim (e.g. IP address, MAC address).

3. Enumerate attacker's activities.

4. Provide recommendations on how the incident could be avoided.

2. Memory Forensics Analysis 

This task focuses on your understanding of memory forensics. A memory dump was created after the user clicked on an unknown executable file. As a forensic investigator, you follow the standard forensic procedure (e.g. examination and analysis) and use appropriate forensic tools (e.g. Volatility) to tackle the supplied memory dump file and provide a report on your findings. A thorough analysis of the memory dump file is required. In particular you need to:

1. Explain the type of incident and how it happened (Executive summary).

2. Identify details of the victim's machine (e.g. user name, IP addresses, running applications etc.).

3. Identify both attacker's and victim's activities.

4. Provide recommendations on how the incident could be avoided.

This COMP6064 - IT Computer Science Assignment Help has been solved by our IT Computer Science Experts at My Uni Paper.

Get It Done! Today

Country
Applicable Time Zone is AEST [Sydney, NSW] (GMT+11)
+

Every Assignment. Every Solution. Instantly. Deadline Ahead? Grab Your Sample Now.