Embedded Statistical Profiling
Abstract
Embedded Statistical Profiling is an initiative to support both offensive and defensive computer network applications. The basis for the effort comprises the development of an environment framework known as Simplified Protocol Capture (SIMPCAP). The environment comprises a collection of tools manifested from SIMPCAP including a SQLite based packet querying engine, virtual file abstraction for seamless multi-file processing, and a complete packet capture / decoding Application Programming Interface (API). Together, these tools automatically integrate with existing LIBPCAP based tools, resulting in a highly tunable and robust environment for 1st level and 2nd level forensic analysts working in network centric operations.
Document Details
- Document Type
- Technical Report
- Publication Date
- May 01, 2007
- Accession Number
- ADA470076
Entities
People
- Michael J. Corley