P2P Investigation PEDRO GALLEGOS
Topics Overview of P2P Direct vs Hearsay Investigation Steps Analysis Gnutella Protocol RoundUp
Overview of P2P P2P stands for Peer-to-Peer Way to distribute files Gnutella Supports queries Peers inform each other of files BitTorrent Uses torrent files Trackers inform client of peers
Direct VS Hearsay Direct When an investigator has a direct connection, that is,a TCP connection to a process on a remote computer, and receives information about that specific computer, that information is direc t Hearsay When a process on one remote machine relays information for or about another,different machine.
Investigation Steps Determine Files of Interest (FOIs) Use P2P to find candidates Narrow down the candidates Attempt to verify possession or distribution
Investigation Steps Cont. A subpoena to the ISP is obtained On basis of evidence, obtain search warrant Perform search
Analysis Gnutella Protocol Overview Before warrant is obtained, it is important to only gather data that is in public domain through: Queries Swarming Information Browsing Host File download
RoundUp RoundUp is a tool for forensically valid investigations of the Gnuetella network
Questions?
Sources: Forensic Investigation of Peer-to-Peer File Sharing Network. Robert Erdely, Thomas Kerle, Brian Levine, Marc Liberatore and Clay Shields.