[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-118572-en":3,"doc-seo-118572-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},118572,1374391974564,"Clementine","https://ap-avatar.wpscdn.com/avatar/14000253aa45c000a9e?x-image-process=image/resize,m_fixed,w_180,h_180&k=1779874745381141002",8,"Research & Report","On Machine Learning for Digital Forensics Investigation in Network Traffic - conference paper","Cybercrime increasingly targets individuals and organizations by exploiting the digital infrastructure they rely on for ransom, data theft, fraud, and large financial losses. Network forensics addresses this by collecting and analyzing network traffic to uncover evidence and detect intrusions, yet it must manage large, dynamic, and volatile data that makes manual, rule-based analysis difficult. This work surveys network forensics and machine learning, outlines investigator tools, and reviews recent research results, then discusses open challenges and future directions.","2025 21st International Conference on Distributed Computing in Smart Systems and the Internet of Things (DCOSS-IoT)  \nOn Machine Learning for Digital Forensics Investigation in Network Traffic  \nAndrea Tundis Institute for the Protection of Terrestrial Infrastructures  \nGerman Aerospace Center (DLR) Mornewegstrasse 30, 64293, Darmstadt, Germany [andrea.tundis@dlr.de](andrea.tundis@dlr.de)  \nFrancesco Cauteruccio  \nDIEM University of Salerno Fisciano, Italy [fcauteruccio@unisa.it](fcauteruccio@unisa.it)  \nAbstract—Cybercrime is an ever increasing issue in the modern world. With the growing reliance of individuals, companies and countries on digital infrastructure, more people are exposed to potential attack vectors which cybercriminals can use to extort a ransom, steal data, commit fraud, or cause significant financial damage. To prevent such crimes from occurring, various security measures are being employed. One such measure is network forensics, which focuses on analyzing network traffic data to uncover evidence and information about attacks and detect intrusions. Network forensics has to deal with large, dynamic, and volatile data, which makes performing analysis a challenging task. Machine learning has been proposed to overcome some of the challenges associated with such analysis. This paper aims to give an overview of network forensics and machine learning, present some tools investigators use to perform network forensics, and introduce some results of recent research into the use of machine learning for network forensics. Finally, a brief discussion of current challenges and further research directions is provided.  \nIndex Terms—Digital Forensics Investigation, Network Traffic Analysis, Machine Learning, Artificial Intelligence, Cybersecurity.  \nI. INTRODUCTION  \nAs the digital world evolves toward the Internet of Everything (IoE), an ever-growing number of interconnected devices continuously exchange vast amounts of data. While this hyper-connectivity fosters innovation and efficiency across domains, it also expands the attack surface for malicious actors. Cyberattacks—ranging from Distributed Denial of Service (DDoS) to ransomware and botnet-based intrusions—can target individuals, corporations, and even national infrastructure. These attacks often manifest as anomalous network behavior, leaving behind digital footprints that can be leveraged for detection and investigation. Network forensics (NF) plays a critical role in this context. It involves the collection and analysis of network traffic from potentially compromised systems, aiming to identify ongoing threats, support post-incident investigations, and deter future attacks. Even when attribution is not possible, forensic activities can raise the cost of malicious operations by forcing adversaries to invest more in stealth. However, as the complexity and scale  \nThe research activities related to this work are being conducted in the context of ”urbanModel” and ”Digitaler Atlas 2.0” projects that are funded by the German Aerospace Center (DLR) e.V. This activity has been carried out in cooperation with the LOEWE Zentrum emergenCITY.  \nof IoE systems grow, traditional forensic techniques struggle to keep pace. The high volume, velocity, and dynamic nature of IoE data make manual or rule-based analysis increasingly infeasible. This challenge calls for modern solutions, particularly those based on Machine Learning (ML) and Artificial Intelligence (AI), to support or even automate parts of the forensic process [1] .  \nIn this paper, we provide a concise overview of network forensics and the tools commonly used in investigations, with a particular focus on AI-driven approaches. Particularly, Section II and III provides an overview about network forensic capabilities and tools within the IoE ecosystem. ML approaches are presented in Section IV, whereas a discussion on open research challenges and potential future directions for developing robust, scalable, and adaptive fo","cbCaifALd0ShVncO","https://ap.wps.com/l/cbCaifALd0ShVncO","pdf",246317,1,7,"English","en",105,"# Introduction\n## Background on Network Forensics","[{\"question\":\"What is the role of network forensics in cyber incident handling?\",\"answer\":\"It focuses on collecting and analyzing network traffic to identify threats, support post-incident investigations, and help deter future attacks, even when attribution is not possible.\"},{\"question\":\"Why are traditional forensic techniques insufficient for modern IoE data?\",\"answer\":\"IoE traffic has high volume, velocity, and dynamic behavior, making manual or rule-based analysis increasingly infeasible.\"},{\"question\":\"What two types of network forensics approaches are discussed?\",\"answer\":\"The document contrasts “Catch-it-as-you-can” (continuous monitoring for anomalies) with “Stop, look and listen” (capture and analyze traffic after a potential incident is detected).\"}]","On Machine Learning for Digital Forensics Investigation in Network Traffic - conference paper | PDF",1785684320,18,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"on-machine-learning-for-digital-forensics-investigation-in-network-traffic-conference-paper","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/on-machine-learning-for-digital-forensics-investigation-in-network-traffic-conference-paper/118572/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-02",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What is the role of network forensics in cyber incident handling?","Question",{"text":75,"@type":76},"It focuses on collecting and analyzing network traffic to identify threats, support post-incident investigations, and help deter future attacks, even when attribution is not possible.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"Why are traditional forensic techniques insufficient for modern IoE data?",{"text":80,"@type":76},"IoE traffic has high volume, velocity, and dynamic behavior, making manual or rule-based analysis increasingly infeasible.",{"name":82,"@type":73,"acceptedAnswer":83},"What two types of network forensics approaches are discussed?",{"text":84,"@type":76},"The document contrasts “Catch-it-as-you-can” (continuous monitoring for anomalies) with “Stop, look and listen” (capture and analyze traffic after a potential incident is detected).","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,119,122,127,130,134],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":21,"doc_module":4,"doc_module_name":46,"category_name":116,"show_sort_weight":117,"slug":118},"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":120,"slug":121},30,"research-report",{"id":123,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":106,"slug":137},19,"General","general"]