Question

What kind of information is collected in a firewall log? How would this information be used in a network forensics investigation?

What kind of information is collected in a firewall log? How would this information be used in a network forensics investigation?

0 0
Add a comment Improve this question Transcribed image text
Answer #1

Firewall Systems have a Log Tab. It has real time up to date, integrated data of traffic logs generated by firewall system. It is in form of a table.

It may have following fields:

Time : exact time of an event occuring.

Direction : incoming or outgoing traffic

Action : action taken by firewall, namely block, allow, ask and disconnect.

Protocol : type of protocol such as UDP, TCP, ICMP etc used by the specific connection

SRC address : IP address of incoming packet.

SRC host : resolving ID of incoming packet system.

SRC port : port from which incoming packet left.

DST address : outgoing packet destination IP address.

DST host : outgoing packet destination system ID.

DST port : outgoing packet destination port address where packet will be accepted.

Process : The .exe file to which incoming or outgoing packet belongs.

SRC MAC : MAC address of sender system.(Remote)

DST MAC : MAC address of sending system.

Use of Firewall Logs in Network Forensics:

1. Analyse port with which no application or service is connected. Hackers may use backdoor trojans through these.

2. IP addresses refused or dropped can be checked for illegal port access.

3. Looking for unsuccessful access to system firewall.

Add a comment
Know the answer?
Add Answer to:
What kind of information is collected in a firewall log? How would this information be used in a network forensics investigation?
Your Answer:

Post as a guest

Your Name:

What's your source?

Earn Coins

Coins can be redeemed for fabulous gifts.

Not the answer you're looking for? Ask your own homework help question. Our experts will answer your question WITHIN MINUTES for Free.
Similar Homework Help Questions
ADVERTISEMENT
Free Homework Help App
Download From Google Play
Scan Your Homework
to Get Instant Free Answers
Need Online Homework Help?
Ask a Question
Get Answers For Free
Most questions answered within 3 hours.
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT