IT Forensics · Linux

Forensic reconstruction of network connections (ss/netstat) – Analysing active and historical connections

Tools such as `ss` or the older `netstat` display active network connections and listening ports on a running system, drawing on information within the kernel that is available only at runtime.

Enquire without obligation

As this information cannot be reconstructed once a system has been shut down, it can only be captured whilst the system is still running, as part of a live capture.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.

Our services

For running systems, we monitor active network connections and listening ports and correlate these with the associated processes in order to identify unusual or unauthorised communication channels.

Typical areas of application

Monitoring active network connections during live investigations
Identification of unauthorised eavesdropping services
Correlation between network connections and triggering processes
Support for acute incident response procedures
Incident Response on Linux Systems
Judicial and non-judicial expert reports

This is how a network connection analysis works

For a system that is still running, active connections and listening ports are recorded and assigned to their respective processes. Suspicious connections to unknown or unexpected destination addresses are investigated separately and cross-referenced with other data, such as firewall configurations and process lists.

Why is this analysis relevant from a forensic perspective?

Active network connections can provide direct evidence of an ongoing compromise, such as a connection to a known command-and-control server or an unexpected listening service.

As this information is only available at runtime, it is particularly important to decide early on to carry out live monitoring if an active compromise is suspected.

Frequently Asked Questions

Can network connections be reconstructed retrospectively?+
Only to a limited extent via logs or network protocols, but not with the same level of detail as with live monitoring of the running system.
What does a correlation between connection and process indicate?+
Which specific process is responsible for a particular network connection, which makes it considerably easier to identify suspicious communication.
Can a rootkit hide network connections?+
Yes, which is why, where there is reasonable suspicion, additional independent testing methods – such as packet capture at network level – are used.

LanCologne – Linux Forensics Cologne

Do you require a professional forensic investigation into „forensically reconstructing network connections (ss/netstat)"? LanCologne can assist you in securing digital evidence to a standard that stands up in court, as well as in the transparent analysis of relevant Linux artefacts.

Get in touch now