Network Forensics in GSE Overlay Networks

The importance of captured network traffic as a data-source for law enforcement crime investigation has increased because many devices are Internet-enabled and the data communication might yield crucial evidence for an investigation. There are many points in the Internet Service Provider's infrastructure where the network traffic might be captured. One of them is a satellite connection, DVB-S2, which use Generic Stream Encapsulation (GSE) protocol that carries IP traffic. Current tools for network traffic forensic analysis do not support GSE. In this paper, we describe principles of GSE, methods for GSE traffic analysis and the extension for an existing network forensic tool that performs GSE traffic processing and extraction of encapsulated communication.