Forensic Investigation in Communication Networks Using Incomplete Digital Evidences
- 1
- 2
- 3
Abstract
Security incidents targeting information systems have become more complex and sophisticated, and intruders might evade responsibility due to the lack of evidence to convict them. In this paper, we develop a system for Digital Forensic in Networking, called DigForNet, which is useful to analyze security incidents and explain the steps taken by the attackers. DigForNet combines intrusion response team knowledge with formal tools to identify the attack scenarios that have occurred and show how the system behaves for every step in the scenario. The attack scenarios construction is automated and the hypothetical concept is introduced within DigForNet to alleviate missing data related to evidences or investigator knowledge. DigForNet system supports the investigation of attack scenarios that integrate anti-investigation attacks. To exemplify the proposal, a case study is proposed.
- P. D. Dixon, “An overview of computer forensics,” IEEE Potentials, Vol. 24, No. 5, pp. 7–10, 2005.
- P. Stephenson, “Modeling of post-incident root cause analysis,” International Journal of Digital Evidence, Vol. 2, No. 2, pp. 1–16, 2003.
- T. Stallard and K. Levitt, “Automated analysis for digital forensic science: Semantic integrity checking,” Proceedings of the 19th Annual Computer Security Applications Conference, Las Vegas, USA, 2003.
- P. Gladyshev, “Finite state machine analysis of a blackmail investigation,” International Journal of Digital Evidence, Vol. 4, No. 1, 2005.
- P. Gladyshev and A. Patel, “Finite state machine approach to digital event reconstruction,” Digital Investigation journal, Vol. 1, No. 2, pp. 130–149, 2004.
- B. D. Carrier and E. H. Spafford, “Categories of digital investigation analysis techniques based on the computer history model,” Digital Investigation Journal, 3(S), pp. 121–130, 2006.
- S. Willassen, “Hypothesis-Based investigation of digital timestamps,” Proceedings of Fourth Annual IFIP WG 11.9 International Conference on Digital Forensics, Kyoto, Japan, 2008.
- S. Y. Willassen, “Timestamp evidence correlation by model based clock hypothesis testing,” Proceedings of the 1st International Conference on Forensic Applications and Techniques in Telecommunications, Information, and Multimedia, 2008.
- A. R. Arasteha, M. Debbabi, A. Sakhaa, and M. Saleh, “Analyzing multiple logs for forensic evidence,” Digital Investigation, Vol. 4, No. 1, pp. 82–91, 2007.
- A. Pal, H. T. Sencar, and N. Memon, “Detecting file fragmentation point using sequential hypothesis testing,” Digital Investigation, Vol. 5, No. 1, pp. S2–S13, 2008.
- S. P. Peisert, “A model of forensic analysis using goal- oriented logging,” PhD thesis, University of California, San Diego, 2007.
- A. S. Huff, “Mapping strategic thought,” John Wiley & Sons, 1990.
- J. Krichene, M. Hamdi, and N. Boudriga, “Collective computer incident response using cognitive maps,” IEEE International Conference on Systems, Man and Cybernetics, Hammamet, Tunisia, pp. 1080–1085, 2004.
- S. Rekhis, J. Krichene, and N. Boudriga, “Dig for net: Digital Forensic in networking,” In Proceedings of the 3rd International Information Security Conference (SEC), Milan, Italy, 2008.