Summary
This chapter, though a bit long, has exposed us to three very important components of any network. As network forensic investigators, you learned about the underlying technologies and sources of evidence obtainable from proxies, firewalls, and routers. You also learned the roles they play in the big scheme of things and understood how and where the evidence resides.
We took a look at the Squid proxy server and different log formats that are prevalent for each of these components. We developed an understanding of the different fields in the log file and what each of these fields represent. We also gained an insight into the key role the routers play, the persistent and volatile memory that they have, the logs, as well as the importance of gathering information from both these memories and logs from a network forensic's perspective.
We made interesting progress and as we move on, we will study how data is smuggled through VPN tunnels in the next chapter. We will also see the different...