U.S. flag

An official website of the United States government, Department of Justice.

NCJRS Virtual Library

The Virtual Library houses over 235,000 criminal justice resources, including all known OJP works.
Click here to search the NCJRS Virtual Library

Forensic investigation of peer-to-peer file sharing network

NCJ Number
305627
Journal
Digital Investigation Volume: 7 Issue: Supplement Dated: August 2010 Pages: S95-S103
Author(s)
Robert Erdely ; Thomas Kerle; Brian Levine; Marc Liberatore; Clay Shields
Date Published
2010
Length
9 pages
Annotation

Since the investigation of peer-to-peer (P2P) file sharing networks is now of critical interest to law enforcement and P2P networks are extensively used for sharing and distribution of contraband, the authors detail the functionality of two P2P protocols, Gnutella and BitTorrent, and describe the legal issues pertaining to investigating such networks.

Abstract

The authors present an analysis of the protocols focused on the items of particular interest to investigators, such as the value of evidence given its provenance on the network. They also report their development of RoundUp, a tool for Gnutella investigations that follows the principles and techniques the authors detail for networking investigations. RoundUp has experienced rapid acceptance and deployment: it is currently used by 52 Internet Crimes Against Children (ICAC) Task Forces, who each share data from investigations in a central database. Using RoundUp, since October 2009, over 300,000 unique installations of Gnutella have been observed by law enforcement sharing known contraband in the U.S. Using leads and evidence from RoundUp, a total of 558 search warrants have been issued and executed during that time. (Publisher abstract provided)