{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T15:26:21Z","timestamp":1781105181720,"version":"3.54.1"},"reference-count":25,"publisher":"IGI Global","isbn-type":[{"value":"9781605668369","type":"print"},{"value":"9781605668376","type":"electronic"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2010]]},"abstract":"<jats:p>The community of peer-to-peer (P2P) file-sharing networks has been expanding swiftly since the appearance of the very first P2P application (Napster) in 2001. These networks are famous for their excellent file transfer rates and adversely, the flooding of copyright-infringed digital materials. Recently, a number of documents containing personal data or sensitive information have been shared in an unbridled manner over the Foxy network (a popular P2P network in Chinese regions). These incidents have urged the authors to develop an investigation model for tracing suspicious P2P activities. Unfortunately, hindered by the distributed design and anonymous nature of these networks, P2P investigation can be practically difficult and complicated. In this chapter, the authors briefly review the characteristics of current P2P networks. By observing the behaviors of these networks, they propose some heuristic rules for identifying the first uploader of a shared file. Also, the rules have been demonstrated to be applicable to some simulated cases. The authors believe their findings provide a foundation for future development in P2P file-sharing networks investigation.<\/jats:p>","DOI":"10.4018\/978-1-60566-836-9.ch015","type":"book-chapter","created":{"date-parts":[[2010,5,25]],"date-time":"2010-05-25T17:28:52Z","timestamp":1274808532000},"page":"355-378","source":"Crossref","is-referenced-by-count":4,"title":["Forensic Investigation of Peer-to-Peer Networks"],"prefix":"10.4018","author":[{"given":"Ricci S.C.","family":"Ieong","sequence":"first","affiliation":[{"name":"The University of Hong Kong, Hong Kong"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Pierre K.Y.","family":"Lai","sequence":"additional","affiliation":[{"name":"The University of Hong Kong, Hong Kong"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"K. P.","family":"Chow","sequence":"additional","affiliation":[{"name":"The University of Hong Kong, Hong Kong"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Michael Y.K.","family":"Kwan","sequence":"additional","affiliation":[{"name":"The University of Hong Kong, Hong Kong"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Frank Y.W.","family":"Law","sequence":"additional","affiliation":[{"name":"The University of Hong Kong, Hong Kong"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"2432","reference":[{"key":"978-1-60566-836-9.ch015.-1","unstructured":"Anti-Piracy in Asia Pacific. (n.d.). Retrieved February 20, 2009, from http:\/\/www.mpa-i.org\/piracy_home.html"},{"key":"978-1-60566-836-9.ch015.-2","unstructured":"Bangeman, E. (2007). P2P responsible for as much as 90 percent of all Net traffic. Retrieved February 20, 2009, from http:\/\/arstechnica.com\/news.ars\/post\/20070903-p2p-responsible-for-as-much-as-90-percent-of-all-net-traffic.html"},{"key":"978-1-60566-836-9.ch015.-3","unstructured":"Bin, F., Chiu, D. M., & Lui, J. C. S. (2006). Stochastic Differential Equation Approach to Model BitTorrent-like P2P Systems. In Proceedings of the IEEE International Conference on Communications, Istanbul, Turkey."},{"key":"978-1-60566-836-9.ch015.-4","unstructured":"Cheng, J. (2008). Sandvine: close to half of all bandwidth sucked up by P2P. Retrieved February 20, 2009, from http:\/\/arstechnica.com\/news.ars\/post\/20080623-sandvine-close-to-half-of-all-bandwidth-sucked-up-by-p2p.html"},{"key":"978-1-60566-836-9.ch015.-5","unstructured":"Chesterton, M. (2008). Edison Chen and 7 HK Stars Involved in Sex Photos Scandal, eNews 2.0. Retrieved February 20, 2009, from http:\/\/www.enews20.com\/news_Edison_Chen_and_7_HK_Stars_Involved_in_Sex_Photos_Scandal_05966.html"},{"key":"978-1-60566-836-9.ch015.-6","doi-asserted-by":"crossref","unstructured":"Chow, K. P., Cheng, K. Y., Man, L. Y., Lai, P. K. Y., Hui, L. C. K., Chong, C. F., et al. (2007). BTM \u2013 An Automated Rule-based BT Monitoring System for Piracy Detection. In Proceedings of the Second International Conference on Internet Monitoring and Protection, Silicon Valley, USA.","DOI":"10.1109\/ICIMP.2007.10"},{"key":"978-1-60566-836-9.ch015.-7","unstructured":"Delahunty, J. (2005). BayTSP shows latest weapon against filesharers, AfterDawn.com. Retrieved October 30, 2008, from http:\/\/www.afterdawn.com\/news\/archive\/5963.cfm"},{"key":"978-1-60566-836-9.ch015.-8","doi-asserted-by":"crossref","unstructured":"Fetscherin, M., & Zaugg, S. (2004). Music Piracy on Peer-to-Peer Networks. In Proceedings of the International Conference on e-Technology, e-Commerce and e-Service 2004, Taipei, Taiwan.","DOI":"10.1109\/EEE.2004.1287343"},{"key":"978-1-60566-836-9.ch015.-9","unstructured":"Hendrik, S., & Klaus, M. (2009). Internet Study 2008\/2009. Retrieved February 20, 2009, from http:\/\/www.ipoque.com\/resources\/internet-studies"},{"key":"978-1-60566-836-9.ch015.-10","doi-asserted-by":"crossref","unstructured":"Hughes, D., Walkerdine, J., & Lee, K. (2006). Monitoring Challenges and Approaches for P2P File-Sharing Systems. In Proceedings of Internet Surveillance and Protection.","DOI":"10.1109\/ICISP.2006.22"},{"key":"978-1-60566-836-9.ch015.-11","unstructured":"Interception of Communications and Surveillance Ordinance. (2006). Chapter 589."},{"key":"978-1-60566-836-9.ch015.-12","unstructured":"Internet World Stats. (2008). Retrieved October 30, 2008, from http:\/\/www.internetworldstats.com\/stats.htm"},{"key":"978-1-60566-836-9.ch015.-13","doi-asserted-by":"crossref","unstructured":"Itakura, Y., Yokozawa, M., & Shinohara, T. (2004). Model Analysis of Digital Copyright Piracy on P2P Networks. In Proceedings of the 2004 International Symposium on Applications and the Internet Workshops, Toyko, Japan.","DOI":"10.1109\/SAINTW.2004.1268570"},{"key":"978-1-60566-836-9.ch015.-14","unstructured":"Klang, M. (2006). Disruptive Technology Effects of Technology Regulation on Democracy (Gothenburg Studies in Informatics Report 36).Goeborg University, Department of Applied Information Technology."},{"key":"978-1-60566-836-9.ch015.-15","doi-asserted-by":"crossref","unstructured":"Lioret, J., Diaz, J. R., Jimenez, J. M., & Boronat, F. (2006). Public Domain P2P File-sharing Networks Measurements and Modeling. In Proceedings of The International Conference on Internet Surveillance and Protection, Cap Esterel, C\u00f4te d\u2019Azur, France.","DOI":"10.1109\/ICISP.2006.28"},{"key":"978-1-60566-836-9.ch015.-16","doi-asserted-by":"crossref","unstructured":"Markatos, E. P. (2002). Tracing a large-scale Peer to Peer System: an hour in the life of Gnutella. In Proceedings of the 2nd IEEE\/ACM International Symposium on Cluster Computing and the Grid. Retrieved February 20, 2009, from http:\/\/citeseer.ist.psu.edu\/markatos01tracing.html","DOI":"10.1109\/CCGRID.2002.1017113"},{"key":"978-1-60566-836-9.ch015.-17","unstructured":"Moy, P., & Patel, N. (2008). Covert cops hit by leaks. The Standard."},{"key":"978-1-60566-836-9.ch015.-18","doi-asserted-by":"crossref","unstructured":"Nasraoui, O., Keeling, D. W., Elmaghraby, A., Higgins, G., & Losavio, M. (2008). Node-Based Probing and Monitoring to Investigate Use of Peer-to-Peer Technologies for Distribution of Contraband Material. In Proceedings of the 2008 Third International Workshop on Systematic Approaches to Digital Forensic Engineering, Oakland, California, USA.","DOI":"10.1109\/SADFE.2008.16"},{"key":"978-1-60566-836-9.ch015.-19","doi-asserted-by":"crossref","unstructured":"Pouwelse, J. A., Garbacki, P., Epema, D. H. J., & Sips, H. J. (2005). The BitTorrent p2p file-sharing system: Measurements and Analysis. In Proceedings of International Workshop on Peer-to-Peer Systems.","DOI":"10.1007\/11558989_19"},{"key":"978-1-60566-836-9.ch015.-20","unstructured":"Response to data leakage by Immigration Department. (2008). The Office of the Privacy Commissioner for Personal Data (PCPD). Retrieved February 20, 2009, from http:\/\/www.pcpd.org.hk\/english\/infocentre\/press_20080508b.html"},{"key":"978-1-60566-836-9.ch015.-21","unstructured":"Ripeanu, M., Foster, I., & Iamnitchi, A. (2002). Mapping the gnutella network: Properties of large-scale peer-to-peer systems and implications for system design. IEEE Internet Computing Journal, 6(1). Retrieved February 20, 2009, from http:\/\/citeseer.ist.psu.edu\/ripeanu02mapping.html"},{"key":"978-1-60566-836-9.ch015.-22","doi-asserted-by":"crossref","unstructured":"Ruitenbeek, E. V., & Sanders, W. H. (2008). Modeling Peer-to-Peer Botnets. In Proceedings of the International Conference on Quantitative Evaluation of Systems 2008, France.","DOI":"10.1109\/QEST.2008.43"},{"key":"978-1-60566-836-9.ch015.-23","unstructured":"Scottsdale, A. (2008). The Value of Unlicensed Music \u201cShared\u201d Worldwide on P2P Networks in 2007 was US$ 69 billion. Retrieved February 20, 2009, from http:\/\/www.multimediaintelligence.com\/index.php?option=com_content&view=article&id=142:the-value-of-unlicensed-music-shared-worldwide-on-p2p-networks-in-2007-was-us-69-billion&catid=36:frontage&Itemid=218"},{"key":"978-1-60566-836-9.ch015.-24","unstructured":"Serious leaks of police secrets. (2008). Ming Pao. Retrieved May 28, 2008, from http:\/\/www.mingpaonews.com\/20080528\/ema1.htm"},{"key":"978-1-60566-836-9.ch015.-25","doi-asserted-by":"crossref","unstructured":"Susitaival, R., & Aalto, S. (2007). Analyzing the file availability and download time in a P2P file sharing system. In Proceedings of the 3rd EuroNGI Conference on Next Generation Internet Networks (pp. 88-95).","DOI":"10.1109\/NGI.2007.371202"}],"container-title":["Advances in Digital Crime, Forensics, and Cyber Terrorism","Handbook of Research on Computational Forensics, Digital Crime, and Investigation"],"original-title":[],"link":[{"URL":"https:\/\/www.igi-global.com\/viewtitle.aspx?TitleId=39225","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,9,15]],"date-time":"2021-09-15T19:05:08Z","timestamp":1631732708000},"score":1,"resource":{"primary":{"URL":"http:\/\/services.igi-global.com\/resolvedoi\/resolve.aspx?doi=10.4018\/978-1-60566-836-9.ch015"}},"subtitle":[""],"short-title":[],"issued":{"date-parts":[[2010]]},"ISBN":["9781605668369","9781605668376"],"references-count":25,"URL":"https:\/\/doi.org\/10.4018\/978-1-60566-836-9.ch015","relation":{},"ISSN":["2327-0381","2327-0373"],"issn-type":[{"value":"2327-0381","type":"print"},{"value":"2327-0373","type":"electronic"}],"subject":[],"published":{"date-parts":[[2010]]}}}