Digital forensic investigation of trojan attacks in network using wireshark, FTK imager and volatility / Muhamad Arif Hashim ... [et al.]

Hashim, Muhamad Arif and Abd Halim, Iman Hazwam and Ismail, Mohammad Hafiz and Mohd Noor, Norfaizalfarid and Mohd Fuzi, Mohd Faris and Mohammed, Abdul Hapes and JM. Gining, Ray Adderley (2017) Digital forensic investigation of trojan attacks in network using wireshark, FTK imager and volatility / Muhamad Arif Hashim ... [et al.]. Journal of Computing Research and Innovation (JCRINN), 2 (2): 8. pp. 60-65. ISSN 2600-8793

Abstract

Trojan attacks are the most common and serious threat to network users. It is a program that appears to be useful program but actually harmful one. It is difficult to detect Trojan attacks because it uses special techniques to conceal its activities from antiviruses and users. Thus, this research intends to retrieve and investigate of Trojan attacks on the network using digital forensic tools namely Wireshark, FTK Imager and Volatility. Two types of Trojan attacks called Remote Access Trojan (RAT) and HTTP Trojan (HT) are created and experimented in this research. These Trojans are sent to the targeted computer in the network through email. Wireshark is used to capture the network packets and then analyze the suspicious packets. FTK Imager is used to capture RAM data on targeted computer. Volatility is used to analyze the captured RAM data and extract suspicious process. This suspicious process is dumped into file and scanned using the Avast antivirus to check whether this process is running Trojan or otherwise. This research may benefit and contribute to the computer security and forensic domain. It can be extends to investigate other Trojan attacks such as Zeus, SubSeven or Back Orifice by using the same digital forensic tools.

Metadata

Item Type: Article
Creators:
Creators
Email / ID Num.
Hashim, Muhamad Arif
UNSPECIFIED
Abd Halim, Iman Hazwam
UNSPECIFIED
Ismail, Mohammad Hafiz
UNSPECIFIED
Mohd Noor, Norfaizalfarid
UNSPECIFIED
Mohd Fuzi, Mohd Faris
UNSPECIFIED
Mohammed, Abdul Hapes
UNSPECIFIED
JM. Gining, Ray Adderley
UNSPECIFIED
Subjects: T Technology > TK Electrical engineering. Electronics. Nuclear engineering > Telecommunication > Computer networks. General works. Traffic monitoring
T Technology > TK Electrical engineering. Electronics. Nuclear engineering > Telecommunication > Computer networks. General works. Traffic monitoring > Intrusion detection systems (Computer security). Computer network security. Hackers
Divisions: Universiti Teknologi MARA, Perlis > Arau Campus > Faculty of Computer and Mathematical Sciences
Journal or Publication Title: Journal of Computing Research and Innovation (JCRINN)
UiTM Journal Collections: UiTM Journal > Journal of Computing Research and Innovation (JCRINN)
ISSN: 2600-8793
Volume: 2
Number: 2
Page Range: pp. 60-65
Keywords: Digital forensic, trojan attack, wireshark, FTK Imager, volatility
Date: 2017
URI: https://ir.uitm.edu.my/id/eprint/54361
Edit Item
Edit Item

Download

[thumbnail of 54361.pdf] Text
54361.pdf

Download (519kB)

ID Number

54361

Indexing

Statistic

Statistic details