U.S. flag

An official website of the United States government, Department of Justice.

NCJRS Virtual Library

The Virtual Library houses over 235,000 criminal justice resources, including all known OJP works.
Click here to search the NCJRS Virtual Library

Incident Response Tools (From Handbook of Computer Crime Investigation: Forensic Tools and Technology, P 73-92, 2002, Eoghan Casey, ed, -- See NCJ-195111)

NCJ Number
195114
Author(s)
Steve Romig
Date Published
2002
Length
20 pages
Annotation
This chapter describes two sets of tools that have been developed by the Network Security Group at Ohio State University for investigating network incidents.
Abstract
The author of this chapter, describes two sets of tools that have been developed by the Network Security Group at Ohio State University for investigating incidents on their network. The first set of tools is called flow-tools and they utilize NetFlow records from Cisco routers. The second set of tools, called review, is useful in examining network traffic that has been captured using tcpdump. This chapter describes these tools as well as the underlying technology of NetFlow and tcpdump. Several case studies are presented to assist in the explanation of the capabilities and appropriate use of these tools. Additionally, illustrations are presented as figures within this chapter to show what the computer screen looks like when using flow-tools and review. Figures, references