Chapter 21
Network Basics for Digital Investigators
– Be aware of the reasons that digital investigators have to have a thorough understanding of
networks.
– Be aware of the hardware and protocols that constitute a network.
– Be aware of the various network technologies a digital investigator is likely to encounter.
– Be aware of the tools that assist in network investigations.
Chapter Guide
All digital investigators require some understanding of networks since most computers we encounter are
connected to one. In fact, computers have become network-centered and it is no longer sufficient to only
think of digital evidence on storage media. To comprehend traces of Internet activities left on personal
computers and to establish continuity of offense, digital investigators require knowledge of evidence that
exists on surrounding networks. These sources include server logs, network devices, and traffic on both
wired and wireless networks.
connect to a remote system such as a backbone router as shown here:
On August 15 at 11:20 EDT, Telnet was used to connect from a Windows machine to a public
Internet router (see www.traceroute.org for a list of route servers).
C:\> telnet route-server.ip.tiscali.net
+———–———-———-———-————–———-—+
| |
| TISCALI International Network – Route Monitor |
| (AS3257) |