Summary
This chapter, though a bit long, has exposed us to three very important components of any network. As network forensic investigators, you learned about the underlying technologies and sources of evidence obtainable from proxies, firewalls, and routers. You also learned the roles they play in the big scheme of things and understood how and where the evidence resides.
We took a look at the Squid proxy server and different log formats that are prevalent for each of these components. We developed an understanding of the different fields in the log file and what each of these fields represent. We also gained an insight into the key role the routers play, the persistent and volatile memory that they have, the logs, as well as the importance of ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access