Blog

Network Forensics - Zentachain

Network forensics is defined as the monitoring and analyzing of data on the computer systems. It analyzes concerns the gathering, monitoring, and searching of network activities to uncover the source of attacks, viruses, intrusions or security breaches that occur on a network or in network traffic. It also deals with the analysis of the origins, contents, patterns and transmission paths of e-mail and web pages as well as browser history and web server scripts and header messages. Network forens

August 14, 2020 · 4 min · Zentachain Team
Bold "Network Forensics" lettering over a teal circuit glow, framed by purple and orange blob shapes.

Title card lettered Network Forensics over a glowing teal screen of unreadable log data.

Network forensics is defined as the monitoring and analyzing of data on the computer systems. It analyzes concerns the gathering, monitoring, and searching of network activities to uncover the source of attacks, viruses, intrusions or security breaches that occur on a network or in network traffic. It also deals with the analysis of the origins, contents, patterns and transmission paths of e-mail and web pages as well as browser history and web server scripts and header messages.

Network forensics is a fresh field of forensic science. The growing popularity of the Internet in homes means that computing has become network-centric and data is now available outside of disk-based digital evidence.

Compared to computer forensics where evidence is usually preserved on disk, network data is more volatile and unpredictable. Investigators often only have material to examine if packet filters, firewalls, and intrusion detection systems were set up to anticipate breaches of security.

A forensic analysis follows these steps generally:

Network traffic analysis Assessment of network performance Detection of threats and attacks Determination of network protocols in use Gathering data from sources Presentation providing of conclusions Security investigations and responding to the incident.

What are the network forensics analysis tools?

General-purpose tools; Packet collectors (sniffers), protocol analyzers and Network Forensic Analyzers. dumpcap, pcapdump, and netsniff-ng are packet sniffers, which record packets from the network and store them on files. tcpdump, wireshark/tshark, and tstat are protocol analyzers. These tools are used to inspect recorded traffic. Xplico and NetworkMiner are Network Forensic Analysis (NFAT) tools. They are data-centric which analyzes the traffic content.

Which traffic protocols/network layers are analyzed in network forensics?

The internet provides services such as WWW, email, chat, file transfer, etc. which makes it rich with digital evidence. This is achieved by identifying the logs of servers deployed on the internet. Servers include web servers, email servers, internet relay chat (IRC), and other types of traffic. These servers collect some information, such as browsing history, email accounts, user account information, etc.

Applying forensic methods on the Ethernet layer is done by eavesdropping bitstreams with tools called monitoring tools or sniffers. This can be done using Wireshark or Tcpdump, both of which capture traffic data from a network card interface configured in promiscuous mode. Those tools allow the investigator to filter traffic and reconstruct attachments transmitted over the network. The disadvantage of this method is that it requires a large storage capacity.

Transport and network layer (TCP/IP)

The network layer provides router information based on the routing table present on all routers and also provides authentication log evidence. Investigating this information helps determine compromised packets, identifying the source, and reverse routing and tracking data. Network device logs provide detailed information about network activities. Network administrators configure the devices to send logs to a server and store them for a period of time.

Wireless

This is achieved by collecting and analyzing traffic from wireless networks and devices, such as mobile phones. This extends normal traffic data to include voice communications. The phone location can be also determined. Analysis methods of wireless traffic are similar to wired network traffic but different security issues should be taken into consideration.

TaggedPrivacy
Keep reading

Related articles

An illustrated man with a laptop holds a key up to a giant padlocked phone screen, coins spilling out.
January 9, 2021 · 6 min

I am Zentalk, not Whatsapp and Signal!

WhatsApp wants to share more data with Facebook: The sudden Signal boom is further fueled by WhatsApp's announcement that it will share data directly with Facebook in the future. As of February 8, data from users outside Europe will be shared with Facebook. Even in Europe, you have to give consent to new rules, otherwise, users can no longer use WhatsApp. But due to the General Data Protection Regulation (GDPR), data that is passed on to Facebook may not be used for advertising in this country,

ZentalkPrivacy
The word ZENTALK in dark 3D letters on a grey floor, struck through by a gold brushstroke.
Highlight ·August 21, 2020 · 3 min

WeChat, Signal and Zentalk

The popularity of decentralized apps is growing as centralized apps get stuck and many users become victims. This problem leads to serious threats and violations, especially for messenger applications. This is because centralized apps have serious problems with very important issues such as privacy and data collection. At the same time, because the applications host a server, users' personal data is always open to hacker attacks, so serious problems occur daily. Sometimes some problems between t

ZentalkPrivacy
3D letters spelling TOR VS VPN scattered across a grey floor beside a tall glossy black capsule.
August 14, 2020 · 5 min

Tor Network VS VPN

Tor and VPN are both proxy-based technologies that are designed to provide user privacy and anonymity when using the internet. Both have positive and negative sides. They work in different ways for the same purpose. What is Tor? Tor is a free and open-source software for enabling anonymous communication. Tor encrypts data, including the destination IP address, multiple times and sends it through a virtual circuit of randomly selected relays to hide the user's location and usage from anyone doi

Privacy
Zentachain

Zentachain

Decentralized communication infrastructure. Trust math, not servers. Building the future of privacy, connectivity, and digital sovereignty.

Zentalk

© 2026 Zentachain GmbH

All Rights Reserved