Digital Fingerprints

Network Event Logs: Painting a Broader Picture

Please sign in to save this to your favorites.

Digital forensics is a vital facet of most fraud examinations today. In certain cases, network event logs will yield more evidence contained within the trail of information left by a user’s online activity than any other technical resource.

Whether we’re analyzing the contents of a hard drive, removable media, or mobile device, electronic evidence provides the fraud examiner with a broader picture of events. (Be sure to work with a certified digital forensics examiner to ensure you won’t nullify or spoil any evidence.)

NETWORK EVENT LOGS 

Network event logs track a user’s Internet activities, such as visited Web sites, communications, and e-mailed documents. Two key pieces of digital information – the timestamp and the Internet Protocol (IP) address – will help the fraud examiner tie events together.

Timestamps on individual log entries denote the time at which the device’s logging system recorded the event. It’s critical to make sure the clock in the system generating the log is synchronized to a centralized time server. Most internal time servers use the Network Time Protocol or a variant of it. Any deviance in time might lead to incorrect assumptions.

Begin Your Free 30-Day Trial

Unlock full access to Fraud Magazine and explore in-depth articles on the latest trends in fraud prevention and detection.