193Forensics Management
• The ability to bypass rewalls, IDSs, and other security devices through
route changes
• The capability to act as a sniffer on network monitor
• The capability to intercept and modify trafc
The evidence available on the vast majority of routers is volatile in nature. This
means that evidence will be lost if any number of events occur. This can be anything
from a loss of power through to timeouts and natural system purges. Information
contained in the active physical memory of the router will be lost on a power-down.
Additionally, static memory sources (such as ash memory) may be overwritten
if an orderly shutdown is allowed to occur. Much of the information contained
within a router that is related to a forensic ...