Answered step by step
Verified Expert Solution
Link Copied!

Question

1 Approved Answer

Please answer all parts (2-3 lines answer only) for Upvote. 1. a) What is Grey Listing? b) Why is important to periodically monitor and provide

Please answer all parts (2-3 lines answer only) for Upvote.

1. a) What is Grey Listing?

b) Why is important to periodically monitor and provide a baseline of the top 5000 domain names being accessed by your organization?

c) Assume that alter the grep command to search the var/log/messages file for the IP address of 5.79.11.202. For example;

image text in transcribed

What type of network forensic evidence can we discover about IP address 5.79.11.202 from the preceding grep example?

d)

Linux will store DNS network forensic evidence in /var/log/messages file. Since Linux stores a lot of evidence, the grep commands is used to filter the message log and will search for www.reddit.com

The following is a sample of one DNS forward lookup.

image text in transcribed

Describe and explain the network forensic evidence for each field of this entry using the following table

image text in transcribed

# grep 5 . 79. 11. 202 /var/log/messages 1457131141.17235911192.168.75.4511192.168.75.111INI Idcs.cb.philips.com. I JA115.79.11.2021119101 11

Step by Step Solution

There are 3 Steps involved in it

Step: 1

blur-text-image

Get Instant Access to Expert-Tailored Solutions

See step-by-step solutions with expert insights and AI powered tools for academic success

Step: 2

blur-text-image

Step: 3

blur-text-image

Ace Your Homework with AI

Get the answers you need in no time with our AI-driven, step-by-step assistance

Get Started

Recommended Textbook for

Practical Issues In Database Management A Refernce For The Thinking Practitioner

Authors: Fabian Pascal

1st Edition

0201485559, 978-0201485554

More Books

Students also viewed these Databases questions

Question

are pro forma statements projections and not guarantees

Answered: 1 week ago