- What is Digital Forensics? Digital Forensics is a branch of forensic science that focuses on the recovery and investigation of material.
- Digital forensics is usually used in a court case and involves a final report of digital evidence by a digital forensic analyst for the purpose of forming a criminal case.
- The need for network forensics is growing, as more and more businesses want to know who, what, when, why, where and how their services and networks were accessed
- The best Forensics tools on the market
- Deep Packet Inspection and Flow analysis are the main analysis techniques
- The most dangerous digital attacks for 2022
This research covers the concept of Digital Forensics and focuses on digital forensics of networks as well as the process model it follows. It also presents basic digital attacks. Its purpose is to introduce the reader to digital forensics and how one can investigate the field.

CRIMINOLOGY ON THE INTERNET
Cybercrime is increasingly on the rise as technology/information technology and especially the Internet are a major part of people's lives and the operation of businesses. Its difference from common criminology is the means used for illegal purposes, where this is none other than the computer. An illegal purpose is defined as an action that is carried out for various reasons: we can define actions such as violating a person's privacy by leaking personal information or encrypting files with the aim of stealing money. However, beyond domestic damage, these criminal actions can have a huge negative effect if they take place in a business. This is usually achieved through a ransomware incident, i.e. the installation of malicious software (malware) that decrypts all the files on a network. Other forms of attacks are: sql injection, ddos attack, brute force attack, etc.

DIGITALFORENSICS
Digital forensics is a branch of forensic science that focuses on the recovery and investigation of material. The main difference from criminal investigation is that in digital forensics, the investigation is done on digital devices.
Depending on the type of device being studied each time, its industry is also determined.
There are four main branches, which are:
- Computer Forensics
- Cloud Forensic
- Network Forensics
- Mobile Forensic
- Database Forensics (SQL Forensic)
Digital forensics is usually used in a court case and involves a final report of digital evidence by a digital forensic analyst for the purpose of forming a criminal case.
It is also used in businesses as a field of investigation and proof of malicious incidents (e.g. digital forensics in a ransomware incident).

DIGITAL NETWORK FORENSIC
The need for network forensics is growing as more and more businesses want to know who, what, when, why, where and how accessed their services and networks. Network forensics is not a way to prevent an attack from occurring, but it can reduce future impact by providing analysis so that companies can respond to a future attack faster.
Digital Network Forensic comes right after network security. More specifically, in order to apply forensics to a network, it must first be secured.
- For example, by installing a firewall and a monitoring system.
- Then, special software is installed that monitors network traffic (network monitoring).
- There, an attempt is made to analyze incoming and outgoing packets and then examine the data in these packets. It is a process through which a digital criminal act is identified as well as the person behind it by examining, in addition to network traffic, log files.
- Then, the researcher is able to present the method and the "path" that a digital criminal followed to reach his final destination.
Network forensics contains the CIA (Capture Identification Analysis) process, which is described as:
- Capture – Capture (network monitoring and packet capture)
- Identification (demonstrates an anomaly in the packets, based on specific criteria such as date and time, resulting in the attack that a network has received becoming apparent)
- Analysis – Analysis (the nature of the attack is determined, extracting information such as client-server conversation, credentials, etc. from the packets).

Finally, the process consists of 5 basic steps.
- Identification – all possible network sources are identified such as PCs, USBs, mobile phones, log files, hard drives, chips, smart home devices, etc. through which information extraction is likely to occur.
- Preservation – an exact copy is created and a policy is placed on it via a device that does not allow any modifications to the copies.
- Collection – using appropriate software and a device, the extraction of data from digital sources that we have collected begins.
- Analysis – in-depth data analysis is performed and evidence of criminal activity is detected in order to draw conclusions.
- Reporting – Based on the previous step, all final conclusions are recorded in a report based on proven techniques.

A critical activity that accompanies the first four steps is note-taking. Documenting the steps taken in sufficient detail for another person to reproduce what is related to an event.
FORENSIC TOOLS
There are many different types of digital forensics tools that can be used to conduct a digital forensic investigation, categorized by the field of digital forensics. The best forensic tools at the given time are the following:

FTK imager
It is a tool for previewing and displaying digital data. It creates unaltered copies of the original digital data that has been acquired. It can also store the image of a hard disk, either in a file or in segments, which can be reconstructed later. Finally, by calculating the MD5 hash value, it validates the integrity of the data.
Network Miner
It supports Windows OS, Linux and Mac OS X and is used to detect operating system, hostname, sessions as well as open ports through packet sniffing and PCAP files.
Belkasoft Live Ram Capturer
It supports Windows OS, and can extract the entire contents of volatile memory even if it is protected by antibugging. Through it, encrypted password files such as login credentials for webmails, websites can be found.
Wireshark
It is a network analyzer, which records and analyzes network traffic in real time.
ANALYSIS TECHNIQUES
For network security, a network diagram is needed first so that the analyst and the IT department can identify potential vulnerabilities. There are two basic techniques that are used:
- Deep Packet Inspection – This is the first technique for analyzing network traffic. It is intended for a thorough analysis of packets routed through the network. It allows the network analyst to obtain entire packets with everything they contain. Programs that deal with deep packet analysis are called analyzers. (e.g. Wireshark)
- Flow analysis – This analysis, unlike deep packet inspection, does not deal with the payload of packets. It analyzes packet headers and categorizes them into flows based on their similar characteristics.

DIGITAL ATTACKS
Since its inception, network forensics has focused on wired environments, specifically Internet Protocol Version 4 (IPV4) and some other related protocols at the network layer of the TCP/IP protocol suite. However, there are some recent trends in this field. Below are some of the most well-known network attacks.
DENIAL OF SERVICE ATTACKS (DoS Attack)
It is an attack carried out by a computer and aims to render the server unable to serve its clients. This is achieved by sending continuous requests to the server, making it unable to serve its clients. A well-known example is the “ping of death” where a host repeatedly sends huge ping requests in order to render it offline.
A variation of the DoS Attack is the DDoS attack in which pings are not sent from one host but from many in parallel.
UNAUTHORIZED ACCESS ( Unauthorized access attacks)
It is an attack in which the attacker gains access to network data without the administrator's permission. This is achieved due to weak passwords and unencrypted networks.
MAN IN THE MIDDLE
The creator of this attack, anonymously interferes in the communication of two parties, as a result of which he can see and manipulate the network traffic. There he starts the handshake process (3 ways handshake) by creating two of his own keys which he uses to encrypt and decrypt packets. He can “poison” the routing table by sending false updates in order to intercept the network traffic.
RANSOMWARE AND ITS TYPES
One of the most current trends in digital forensics is that of the Ransomware Incident. To achieve an attack on a network, the cybercriminal needs to find either an open door in the firewall, or through other techniques such as a phishing e-mail.
Below are some of the most common forms of network attacks.
Ransomware is a special type of malware that makes it impossible for the user to log in to the system and can use encryption techniques to extract various information. The creator of the malware then informs the user that they have been hit by a “ransomware incident” and asks for virtual money (bitcoins, crypto coins) to return the data.
There are many different types but 4 are the most basic.
- Crypto Malware – Encrypts some or all files. To decrypt the files, a decryption key is required, which is given to the victim in exchange for a virtual ransom. There are also new versions of CryptoMalware that can even decrypt network and cloud drives.
- Locker Ransom – poisons the operating system by locking the user out of it, making it impossible to access any file or application on the medium. It uses social engineering techniques to compromise credentials to enter the system. Once installed on the infrastructure, it blocks the user from entering the system until the virtual ransom is paid.
- Double Extorsion Ransom – encrypts files and extracts important data for the user, threatening to publish them if the cybercriminal's terms are not met.
- RaaS – is a business model in which there is a RaaS provider who creates and sells various types of ransomware attacks to subsidiary companies in exchange for virtual currencies.
ROOTKIT
A rootkit is a computer program designed to provide persistent access to a computer while actively hiding its presence. Root refers to the administrator account on Unix and Linux systems, and kit refers to the software components that implement the tool. Today, rootkits are generally associated with malicious software – such as Trojans, worms, viruses – that hide their existence and actions from users and other system processes.
CROSSITE–SCRIPTING/XSS
Cross-site Scripting, or XSS, is a security vulnerability that allows a malicious user to inject JavaScript code into a web page. This code will then be executed in the browser of the user visiting the website.

From the editor-analyst
With the rapid development of technology, network security is becoming an important factor as the value of its data and physical media is great. A network is faced with a huge number of threats every day. Digital forensics plays an important role in dealing with future attacks as it can investigate the network and prevent future attacks. In the event of vulnerabilities and the final collapse of a network, now through digital forensics, someone can implement a series of actions to find the way in which the attack was carried out and prove it.
Author – Researcher: Farougia Eirini
