Network forensics helps in tracking down cyber fraudsters by assessing and tracing back network data. The use of various network traffic gathering tools is required. Network forensics is analyzing network traffic to detect intrusions and studying how the crime occurred, i.e., establishing a crime scene for investigation and replays. This study proposes a general network forensic process model and architecture. A secondary data set, KDD CUP of normal...