Back to Search Start Over

Hadoop‐based analytic framework for cyber forensics.

Authors :
Chhabra, Gurpal Singh
Singh, Varinderpal
Singh, Maninder
Source :
International Journal of Communication Systems. Oct2018, Vol. 31 Issue 15, p1-1. 17p.
Publication Year :
2018

Abstract

Summary: With an exponential increase in the data size and complexity of various documents to be investigated, existing methods of network forensics are found not much efficient with respect to accuracy and detection ratio. The existing techniques for network forensic analysis exhibit inherent limitations while processing a huge volume, variety, and velocity of data. It makes network forensic a time‐consuming and resource‐consuming task. To balance time taken and output delivered, these existing techniques put a limit on the amount of data under analysis, which results in a polynomial time complexity of these solutions. So to mitigate these issues, in this paper, we propose an effective framework to overcome the limitation to handle large volume, variety, and velocity of data. An architectural setup that consists of MapReduce framework on top of Hadoop Distributed File System environment is proposed in this paper. The proposed framework demonstrates its capability to handle issues of storage and processing of big data using cloud computing. Also, in the proposed framework, supervised machine learning (random forest‐based decision tree) algorithm has been implemented to demonstrate better sensitivity. To train and validate the model, online available data set from CAIDA is taken and university network traffic samples, with increasing size, has been taken for experiment. Results thus obtained confirm the superiority of the proposed framework in network forensics, with an average accuracy of 99.34% (malicious and nonmalicious traffic). [ABSTRACT FROM AUTHOR]

Details

Language :
English
ISSN :
10745351
Volume :
31
Issue :
15
Database :
Academic Search Index
Journal :
International Journal of Communication Systems
Publication Type :
Academic Journal
Accession number :
131754697
Full Text :
https://doi.org/10.1002/dac.3772