100 likes | 126 Views
Learn about P2P investigation, including the overview of P2P, direct vs hearsay evidence, investigation steps, and analysis of the Gnutella protocol.
E N D
P2P Investigation Pedro Gallegos
Topics • Overview of P2P • Direct vs Hearsay • Investigation Steps • Analysis Gnutella Protocol • RoundUp
Overview of P2P • P2P stands for Peer-to-Peer • Way to distribute files • Gnutella • Supports queries • Peers inform each other of files • BitTorrent • Uses torrent files • Trackers inform client of peers
Direct VS Hearsay • Direct • When an investigator has a direct connection, that is,a TCP connection to a process on a remote computer, and receives information about that specific computer, that information is direct • Hearsay • When a process on one remote machine relays information for or about another,different machine.
Investigation Steps • Determine Files of Interest (FOIs) • Use P2P to find candidates • Narrow down the candidates • Attempt to verify possession or distribution
Investigation Steps Cont. • A subpoena to the ISP is obtained • On basis of evidence, obtain search warrant • Perform search
Analysis Gnutella Protocol Overview • Before warrant is obtained, it is important to only gather data that is in public domain through: • Queries • Swarming Information • Browsing Host • File download
RoundUp • RoundUp is a tool for forensically valid investigations of the Gnuetella network
Sources: • Forensic Investigation of Peer-to-Peer File Sharing Network. Robert Erdely, Thomas Kerle, Brian Levine, Marc Liberatore and Clay Shields. http://www.dfrws.org/2010/proceedings/2010-311.pdf