The Experts below are selected from a list of 2727 Experts worldwide ranked by ideXlab platform
Nhien-an Le-khac - One of the best experts on this subject based on the ideXlab platform.
-
Smart vehicle Forensics: Challenges and case study
Future Generation Computer Systems, 2020Co-Authors: Nhien-an Le-khac, Daniel Jacobs, John Nijhoff, Karsten Bertens, Kim-kwang Raymond ChooAbstract:Abstract Vehicles are fast becoming another important source of digital evidence in a criminal investigation. Traditionally, when a vehicle is involved in a crime scene (e.g. drink driving) or a terrorist attack, the investigators focus on the Acquisition of DNA, fingerprints and other identifying materials that are usually non digital in nature. However, modern-day cars, particularly smart or driverless cars, store a wealth of digital information, such as recent destinations, favorite locations, routes, and personal data (e.g. call logs, contact lists, SMS messages, pictures, and videos). In this paper, we describe some of the challenges associated with vehicle data Forensics, which is an understudied area. Next, we present our case studies on Forensic Acquisition and data analysis of an entertainment system on a Volkswagen car. We also discuss potential hardware and software solutions that can be used to acquire Forensic artifacts from such vehicles. Finally, we describe and analyze the mobile data traffic from an Audi car, a VW car and a BMW car.
-
Cyber and Digital Forensic Investigations - CCTV Forensics in the Big Data Era: Challenges and Approaches
Studies in Big Data, 2020Co-Authors: Richard Gomm, Kim-kwang Raymond Choo, Nhien-an Le-khac, Ryan Brooks, Kien Wooi HewAbstract:The video security market has seen rapid expansion over the last few years, expanding from the old analogue into new and emerging IP systems whilst running on multiple platform digital video recorders (DVR) of both Open and Proprietary format. Accordingly to the 2017 video surveillance report from IFSEC Global (https://www.ifsecglobal.com/video-surveillance-report-2017), for example, proprietary formats accounted for 56% of their surveyed responses. It is primarily within these proprietary formats that numerous challenges arise with the Forensic Acquisition and analysis of the closed circuit television camera (CCTV) data. Such challenges are expanded when consideration is given to the volume of data and the complexity of data due to the different manufacturers, data formats, file systems, volume storage methods, etc. In this paper, we review current approach on CCTV Forensics in literature, and identify challenges of CCTV Forensics in the context of big data Forensics. Then, we describe a new Forensic process/workflow for acquiring and analysing artefacts from large amounts data from CCTV devices of different models/manufacturers, prior to presenting and analysing three real world case studies.
-
TrustCom/BigDataSE - Framework for the Retrieval of Social Media and Instant Messaging Evidence from Volatile Memory
2019 18th IEEE International Conference On Trust Security And Privacy In Computing And Communications 13th IEEE International Conference On Big Data S, 2019Co-Authors: Ranul Thantilage, Nhien-an Le-khacAbstract:The human society today has had to be confronted by the threat posed by criminals who are taking the advantages of social media and instant-messaging apps to conduct their criminal activities. In literature, there are many approaches for Forensic Acquisition and analysis of these apps. However, most of the approaches mainly focus on non-volatile storage media. Meanwhile, social media and instant-messaging platforms do not usually store information relating to social transactions in non-volatile bases. Hence, in this paper, we propose a framework for volatile memory Forensics that is essential for the ready retrieval of evidence. Our approach is based on the retrieval of social media and instant-messaging evidence through the use of string search mechanism extended by the usage of regular expressions and the functionality of match groups. Our approach has been tested and proved to be effective with different social media apps on two popular operating systems: Windows and Mac.
-
An Automated Live Forensic and Postmortem Analysis Tool for Bitcoin on Windows Systems
IEEE Access, 2019Co-Authors: Stephan Zollner, Kim-kwang Raymond Choo, Nhien-an Le-khacAbstract:Bitcoin is popular not only with consumers, but also with cybercriminals (e.g., in ransomware and online extortion, and commercial online child exploitation). Given the potential of Bitcoin to be involved in a criminal investigation, the need to have an up-to-date and in-depth understanding on the Forensic Acquisition and analysis of Bitcoins is crucial. However, there has been limited Forensic research of Bitcoin in the literature. The general focus of existing research is on postmortem analysis of specific locations (e.g. wallets on mobile devices), rather than a Forensic approach that combines live data Forensics and postmortem analysis to facilitate the identification, Acquisition, and analysis of Forensic traces relating to the use of Bitcoins on a system. Hence, the latter is the focus of this paper where we present an open source tool for live Forensic and postmortem analysing automatically. Using this open source tool, we describe a list of target artifacts that can be obtained from a Forensic investigation of popular Bitcoin clients and Web Wallets on different web browsers installed on Windows 7 and Windows 10 platforms.
-
IFIP Int. Conf. Digital Forensics - Internet of Things Forensics – Challenges and a Case Study
Advances in Digital Forensics XIV, 2018Co-Authors: Saad Alabdulsalam, Kevin Schaefer, M-tahar Kechadi, Nhien-an Le-khacAbstract:During this era of the Internet of Things, millions of devices such as automobiles, smoke detectors, watches, glasses and webcams are being connected to the Internet. The number of devices with the ability of monitor and collect data is continuously increasing. The Internet of Things enhances human comfort and convenience, but it raises serious questions related to security and privacy. It also creates significant challenges for digital investigators when they encounter Internet of Things devices in criminal scenes. In fact, current research focuses on security and privacy in Internet of Things environments as opposed to Forensic Acquisition and analysis techniques for Internet of Things devices. This chapter focuses on the major challenges with regard to Internet of Things Forensics. A Forensic approach for Internet of Things devices is presented using a smartwatch as a case study. Forensic artifacts retrieved from the smartwatch are analyzed and the evidence found is discussed with respect to the challenges facing Internet of Things Forensics.
Kim-kwang Raymond Choo - One of the best experts on this subject based on the ideXlab platform.
-
Smart vehicle Forensics: Challenges and case study
Future Generation Computer Systems, 2020Co-Authors: Nhien-an Le-khac, Daniel Jacobs, John Nijhoff, Karsten Bertens, Kim-kwang Raymond ChooAbstract:Abstract Vehicles are fast becoming another important source of digital evidence in a criminal investigation. Traditionally, when a vehicle is involved in a crime scene (e.g. drink driving) or a terrorist attack, the investigators focus on the Acquisition of DNA, fingerprints and other identifying materials that are usually non digital in nature. However, modern-day cars, particularly smart or driverless cars, store a wealth of digital information, such as recent destinations, favorite locations, routes, and personal data (e.g. call logs, contact lists, SMS messages, pictures, and videos). In this paper, we describe some of the challenges associated with vehicle data Forensics, which is an understudied area. Next, we present our case studies on Forensic Acquisition and data analysis of an entertainment system on a Volkswagen car. We also discuss potential hardware and software solutions that can be used to acquire Forensic artifacts from such vehicles. Finally, we describe and analyze the mobile data traffic from an Audi car, a VW car and a BMW car.
-
Cyber and Digital Forensic Investigations - CCTV Forensics in the Big Data Era: Challenges and Approaches
Studies in Big Data, 2020Co-Authors: Richard Gomm, Kim-kwang Raymond Choo, Nhien-an Le-khac, Ryan Brooks, Kien Wooi HewAbstract:The video security market has seen rapid expansion over the last few years, expanding from the old analogue into new and emerging IP systems whilst running on multiple platform digital video recorders (DVR) of both Open and Proprietary format. Accordingly to the 2017 video surveillance report from IFSEC Global (https://www.ifsecglobal.com/video-surveillance-report-2017), for example, proprietary formats accounted for 56% of their surveyed responses. It is primarily within these proprietary formats that numerous challenges arise with the Forensic Acquisition and analysis of the closed circuit television camera (CCTV) data. Such challenges are expanded when consideration is given to the volume of data and the complexity of data due to the different manufacturers, data formats, file systems, volume storage methods, etc. In this paper, we review current approach on CCTV Forensics in literature, and identify challenges of CCTV Forensics in the context of big data Forensics. Then, we describe a new Forensic process/workflow for acquiring and analysing artefacts from large amounts data from CCTV devices of different models/manufacturers, prior to presenting and analysing three real world case studies.
-
An Automated Live Forensic and Postmortem Analysis Tool for Bitcoin on Windows Systems
IEEE Access, 2019Co-Authors: Stephan Zollner, Kim-kwang Raymond Choo, Nhien-an Le-khacAbstract:Bitcoin is popular not only with consumers, but also with cybercriminals (e.g., in ransomware and online extortion, and commercial online child exploitation). Given the potential of Bitcoin to be involved in a criminal investigation, the need to have an up-to-date and in-depth understanding on the Forensic Acquisition and analysis of Bitcoins is crucial. However, there has been limited Forensic research of Bitcoin in the literature. The general focus of existing research is on postmortem analysis of specific locations (e.g. wallets on mobile devices), rather than a Forensic approach that combines live data Forensics and postmortem analysis to facilitate the identification, Acquisition, and analysis of Forensic traces relating to the use of Bitcoins on a system. Hence, the latter is the focus of this paper where we present an open source tool for live Forensic and postmortem analysing automatically. Using this open source tool, we describe a list of target artifacts that can be obtained from a Forensic investigation of popular Bitcoin clients and Web Wallets on different web browsers installed on Windows 7 and Windows 10 platforms.
-
TrustCom/BigDataSE - A Forensic Investigation Framework for Smart Home Environment
2018 17th IEEE International Conference On Trust Security And Privacy In Computing And Communications 12th IEEE International Conference On Big Data S, 2018Co-Authors: Arnoud Goudbeek, Kim-kwang Raymond Choo, Nhien-an Le-khacAbstract:Increasingly our home environment is a part of the Internet, in the sense that devices in our homes (e.g. intelligent home assistants, sensors and smart meters) are Internet-interconnected. In other words, smart home environment is, and will be, an important source of evidence in the foreseeable future. There has been relatively few research on the Forensic Acquisition and analysis of a home automation system. Therefore, in this paper, we propose a Forensic investigation framework for the smart home environment and evaluate its utility using three case studies. Our framework can also be used as a quick reference guide for digital Forensic investigators working on future home automation systems.
-
a Forensic investigation framework for smart home environment
Trust Security And Privacy In Computing And Communications, 2018Co-Authors: Arnoud Goudbeek, Kim-kwang Raymond Choo, Nhienan LekhacAbstract:Increasingly our home environment is a part of the Internet, in the sense that devices in our homes (e.g. intelligent home assistants, sensors and smart meters) are Internet-interconnected. In other words, smart home environment is, and will be, an important source of evidence in the foreseeable future. There has been relatively few research on the Forensic Acquisition and analysis of a home automation system. Therefore, in this paper, we propose a Forensic investigation framework for the smart home environment and evaluate its utility using three case studies. Our framework can also be used as a quick reference guide for digital Forensic investigators working on future home automation systems.
Jill Slay - One of the best experts on this subject based on the ideXlab platform.
-
wireless Forensic analysis tools for use in the electronic evidence collection process
Hawaii International Conference on System Sciences, 2007Co-Authors: Benjamin Turnbull, Jill SlayAbstract:This paper discusses the need for both a series of electronic tools and procedural changes to the evidence collection process to accommodate the possibilities of wireless technologies. 802.11-based wireless technologies in particular pose an issue to the collection of electronic evidence, as devices that appear isolated may be tirelessly accessed during the collection phase, leading to after-seizure communications and a tampering of evidence in custody. Whilst Forensic Acquisition and analysis procedural guides are yet to discuss the Acquisition of wireless devices, one of the core issues in collecting wireless devices is that there is no indication for the number or type of devices connected to a wireless network, should one exist in an area of interest. It is proposed that a series of Forensic software tools be developed to aid in the detection, analysis and control of wireless networks that are in the process of being seized for Forensic analysis. Through control of the wireless medium, information regarding connected devices may be gathered and methods to prevent communication between devices during and after evidence seizure are also examined
-
HICSS - Wireless Forensic Analysis Tools for Use in the Electronic Evidence Collection Process
2007 40th Annual Hawaii International Conference on System Sciences (HICSS'07), 2007Co-Authors: Benjamin Turnbull, Jill SlayAbstract:This paper discusses the need for both a series of electronic tools and procedural changes to the evidence collection process to accommodate the possibilities of wireless technologies. 802.11-based wireless technologies in particular pose an issue to the collection of electronic evidence, as devices that appear isolated may be tirelessly accessed during the collection phase, leading to after-seizure communications and a tampering of evidence in custody. Whilst Forensic Acquisition and analysis procedural guides are yet to discuss the Acquisition of wireless devices, one of the core issues in collecting wireless devices is that there is no indication for the number or type of devices connected to a wireless network, should one exist in an area of interest. It is proposed that a series of Forensic software tools be developed to aid in the detection, analysis and control of wireless networks that are in the process of being seized for Forensic analysis. Through control of the wireless medium, information regarding connected devices may be gathered and methods to prevent communication between devices during and after evidence seizure are also examined
Benjamin Turnbull - One of the best experts on this subject based on the ideXlab platform.
-
COMPSAC (2) - Acer Aspire One Netbooks: A Forensic Challenge
2009 33rd Annual IEEE International Computer Software and Applications Conference, 2009Co-Authors: Amrit Pal Singh, Michael K. Lavine, Benjamin Turnbull, Trupti ShiralkarAbstract:Netbooks, the smallest laptop devices, are ironically the largest market segment, based on sales in the last year. These are light-weight, cheap, and designed for the limited tasks that rely on the internet. Given the large user base of these devices, it is inevitable that they will be used criminally. This is an extension on the fact that all technologies are able to be used criminally and will be, as they become part of larger society. This work seeks to understand the Forensic implications of the Asus Aspire One, one of the most popular Netbooks, looking at both the Forensic Acquisition and analysis of the device.
-
wireless Forensic analysis tools for use in the electronic evidence collection process
Hawaii International Conference on System Sciences, 2007Co-Authors: Benjamin Turnbull, Jill SlayAbstract:This paper discusses the need for both a series of electronic tools and procedural changes to the evidence collection process to accommodate the possibilities of wireless technologies. 802.11-based wireless technologies in particular pose an issue to the collection of electronic evidence, as devices that appear isolated may be tirelessly accessed during the collection phase, leading to after-seizure communications and a tampering of evidence in custody. Whilst Forensic Acquisition and analysis procedural guides are yet to discuss the Acquisition of wireless devices, one of the core issues in collecting wireless devices is that there is no indication for the number or type of devices connected to a wireless network, should one exist in an area of interest. It is proposed that a series of Forensic software tools be developed to aid in the detection, analysis and control of wireless networks that are in the process of being seized for Forensic analysis. Through control of the wireless medium, information regarding connected devices may be gathered and methods to prevent communication between devices during and after evidence seizure are also examined
-
HICSS - Wireless Forensic Analysis Tools for Use in the Electronic Evidence Collection Process
2007 40th Annual Hawaii International Conference on System Sciences (HICSS'07), 2007Co-Authors: Benjamin Turnbull, Jill SlayAbstract:This paper discusses the need for both a series of electronic tools and procedural changes to the evidence collection process to accommodate the possibilities of wireless technologies. 802.11-based wireless technologies in particular pose an issue to the collection of electronic evidence, as devices that appear isolated may be tirelessly accessed during the collection phase, leading to after-seizure communications and a tampering of evidence in custody. Whilst Forensic Acquisition and analysis procedural guides are yet to discuss the Acquisition of wireless devices, one of the core issues in collecting wireless devices is that there is no indication for the number or type of devices connected to a wireless network, should one exist in an area of interest. It is proposed that a series of Forensic software tools be developed to aid in the detection, analysis and control of wireless networks that are in the process of being seized for Forensic analysis. Through control of the wireless medium, information regarding connected devices may be gathered and methods to prevent communication between devices during and after evidence seizure are also examined
Christoph Reich - One of the best experts on this subject based on the ideXlab platform.
-
A Forensic Acquisition based upon a cluster analysis of non-volatile memory in IaaS
2017 2nd International Conference on Anti-Cyber Crimes (ICACC), 2017Co-Authors: Saad Alqahtany, Nathan Clarke, Steven Furnell, Christoph ReichAbstract:Cloud computing technologies have significantly changed the way in which organizations implement their information technology infrastructure. It is a new paradigm that turned the long-held promises of computing services into reality. It allows organizations to focus on their business with minimal effort placed upon building, managing and maintaining their IT requirements. However, security and incident management requirements are still extremely challenging. Unfortunately, the underlining architecture of cloud computing poses a range of technical and organizational issues for digital investigators. Due to the dynamic nature of cloud computing, current Forensic tools and procedures have ranges of limitations. Such limitations lead to devastating consequences including heavy monetary fines or even forcing the organization out of the business. However, an increasing emphasis has been placed on investigating the issues pertained to data Acquisition - as it is the first and most difficult problem to be solved when conducting cloud based digital investigation. This study identifies the challenges in cloud Forensics related to data Acquisition and proposes a novel technique based upon a cluster analysis of non-volatile memory. The approach achieves Forensically reliable images at the same level of integrity as the traditional computer Forensic Acquisition procedures with the additional capability to restore the virtual hard disk as a Forensic image at any given time.
-
a Forensic Acquisition and analysis system for iaas architectural model and experiment
Availability Reliability and Security, 2016Co-Authors: Saad Alqahtany, Nathan Clarke, Steven Furnell, Christoph ReichAbstract:Cloud computing has been advancing at a feverish pace. It has become one of the most important research topics in computer science and information systems. Cloud computing offers enterprise-scale platforms in a short time frame with little effort. Thus, it delivers significant economic benefits to both commercial and public entities. Despite this, the security and subsequent incident management requirements are major obstacles to adopting the cloud. Current cloud architectures do not support digital Forensic investigators, nor comply with today's digital Forensics procedures – largely due to the dynamic nature of the cloud. When an incident has occurred, an organization-based investigation will seek to provide potential digital evidence while minimizing the cost of investigation. However, all members engaging in digital Forensics must rely, to a very significant degree, upon the assistance of cloud providers to present relevant evidence. Unfortunately, providers often lack appropriate tools and features to perform adequate Acquisition and analysis. Therefore, dependence on the CSPs is considered one of the most significant challenges when investigators need to acquire evidence in a timely yet Forensically sound manner from cloud systems. This paper aims to achieve two objectives: the first objective is the development and validation of a Forensic Acquisition system in an Infrastructure as a Service (IaaS) model in order to ensure organizations remain in complete control, remove the burden/liability from the CSPs and make it easy to acquire the evidence in a Forensically sound and timely manner. Secondly, it is to investigate the technical implications and costs resulting from such a system on the day-to-day operation of a cloud system.
-
ARES - A Forensic Acquisition and Analysis System for IaaS: Architectural Model and Experiment
2016 11th International Conference on Availability Reliability and Security (ARES), 2016Co-Authors: Saad Alqahtany, Nathan Clarke, Steven Furnell, Christoph ReichAbstract:Cloud computing has been advancing at a feverish pace. It has become one of the most important research topics in computer science and information systems. Cloud computing offers enterprise-scale platforms in a short time frame with little effort. Thus, it delivers significant economic benefits to both commercial and public entities. Despite this, the security and subsequent incident management requirements are major obstacles to adopting the cloud. Current cloud architectures do not support digital Forensic investigators, nor comply with today's digital Forensics procedures – largely due to the dynamic nature of the cloud. When an incident has occurred, an organization-based investigation will seek to provide potential digital evidence while minimizing the cost of investigation. However, all members engaging in digital Forensics must rely, to a very significant degree, upon the assistance of cloud providers to present relevant evidence. Unfortunately, providers often lack appropriate tools and features to perform adequate Acquisition and analysis. Therefore, dependence on the CSPs is considered one of the most significant challenges when investigators need to acquire evidence in a timely yet Forensically sound manner from cloud systems. This paper aims to achieve two objectives: the first objective is the development and validation of a Forensic Acquisition system in an Infrastructure as a Service (IaaS) model in order to ensure organizations remain in complete control, remove the burden/liability from the CSPs and make it easy to acquire the evidence in a Forensically sound and timely manner. Secondly, it is to investigate the technical implications and costs resulting from such a system on the day-to-day operation of a cloud system.
-
A Forensic Acquisition and analysis system for IaaS
Cluster Computing, 2016Co-Authors: Saad Alqahtany, Nathan Clarke, Steven Furnell, Christoph ReichAbstract:Cloud computing is a promising next-generation computing paradigm that offers significant economic benefits to both commercial and public entities. Furthermore, cloud computing provides accessibility, simplicity, and portability for its customers. Due to the unique combination of characteristics that cloud computing introduces (including on-demand self-service, broad network access, resource pooling, rapid elasticity, and measured service), digital investigations face various technical, legal, and organizational challenges to keep up with current developments in the field of cloud computing. There are a wide variety of issues that need to be resolved in order to perform a proper digital investigation in the cloud environment. This paper examines the challenges in cloud Forensics that are identified in the current research literature, alongside exploring the existing proposals and technical solutions addressed in the respective research. The open problems that need further effort are highlighted. As a result of the analysis of literature, it is found that it would be difficult, if not impossible, to perform an investigation and discovery in the cloud environment without relying on cloud service providers (CSPs). Therefore, dependence on the CSPs is ranked as the greatest challenge when investigators need to acquire evidence in a timely yet Forensically sound manner from cloud systems. Thus, a fully independent model requires no intervention or cooperation from the cloud provider is proposed. This model provides a different approach to a Forensic Acquisition and analysis system (FAAS) in an Infrastructure as a Service model. FAAS seeks to provide a richer and more complete set of admissible evidences than what current CSPs provide, with no requirement for CSP involvement or modification to the CSP’s underlying architecture.