Skip to main navigation Skip to search Skip to main content

Transmitted file extraction and reconstruction from network packets

  • Yangseo Choi
  • , Joo Young Lee
  • , Sunoh Choi
  • , Jong Hyun Kim
  • , Ikkyun Kim
  • Electronics and Telecommunications Research Institute

Research output: Contribution to conferenceConference paperpeer-review

Abstract

When hackers try to attack a target system, their first goal is to install a malware to the target system. It is because hackers can do anything what they want if a malware is installed. In the past, most of the malwares were Microsoft PE files, however they have been changed to various file formats such as pdf, jpg, doc, jar and so on. Under this circumstances some network security systems such as network forensics systems have to reconstruct those malwares from network packets to analyze the malwares. For that, we propose a file type signature and network protocol analysis based transmitted file reconstruction technique which can reconstruct various file types from network packets. In this paper, we show the implementation and file reconstruction results.

Original languageEnglish
Title of host publication2015 World Congress on Internet Security, WorldCIS 2015
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages164-165
Number of pages2
ISBN (Electronic)9781908320506
DOIs
StatePublished - 2015.12.16
EventWorld Congress on Internet Security, WorldCIS 2015 - Dublin, Ireland
Duration: 2015.10.192015.10.21

Publication series

Name2015 World Congress on Internet Security, WorldCIS 2015

Conference

ConferenceWorld Congress on Internet Security, WorldCIS 2015
Country/TerritoryIreland
CityDublin
Period15.10.1915.10.21

Keywords

  • malware collection
  • network forensics
  • Transmitted file reconstruction

Fingerprint

Dive into the research topics of 'Transmitted file extraction and reconstruction from network packets'. Together they form a unique fingerprint.

Cite this