# Enabling the Non-Expert Analysis of Large Volumes of Intercepted Network Traffic

Canonical URL: https://markscanlon.co/publications/NetworkIntell

CSL-JSON: https://markscanlon.co/publications/NetworkIntell.csl.json
BibTeX: https://markscanlon.co/publications/NetworkIntell.bib
RIS: https://markscanlon.co/publications/NetworkIntell.ris

Authors: Erwin van de Weil; Mark Scanlon; Nhien-An Le-Khac
Venue: Advances in Digital Forensics XIV
Year: 2018
DOI: https://doi.org/10.1007/978-3-319-99277-8_11
PDF: https://markscanlon.co/publications/NetworkIntell.pdf
Full text: https://markscanlon.co/publications/NetworkIntell.full.md

## Contribution Summary

This paper addresses the challenge of analyzing large volumes of intercepted network traffic, which is a common technique used by law enforcement in criminal investigations. The current approach of analyzing data in a chronological manner is labor-intensive and often requires specialized knowledge. The authors propose a novel approach that focuses on network metadata, reducing the complexity of the analysis and providing insights for non-technical investigators. The approach is tested with a large sample of network traffic data and can be used to identify devices and usage behind an internet connection. This research contributes to the field of digital forensics and cybersecurity by providing a new method for analyzing intercepted network traffic, which can be used to support investigations and improve the efficiency of digital investigators.

## Abstract

In criminal investigations, telecommunication wiretaps have become a common technique used by law enforcement. While phone-based wiretapping is well documented and the procedure for their execution are well known, the same cannot be said for Internet taps. Lawfully intercepted network traffic often contains a lot of encrypted traffic making it increasingly difficult to find useful information inside the traffic captured. The advent of Internet-of-Things further complicates the process for non-technical investigators. The current level of complexity of intercepted network traffic is close to a point where data cannot be analysed without supervision of a digital investigator with advanced network knowledge. Current investigations focus on analysing all traffic in a chronological manner and are predominately conducted on the data contents of the intercepted traffic. This approach often becomes overly arduous when the amount of data to be analysed becomes very large. In this paper, we propose a novel approach to analyse large amounts of intercepted network traffic based on network metadata. Our approach significantly reduces the duration of the analysis and also produces an insight view of analysing results for the non-technical investigator. We also test our approach with a large sample of network traffic data.

