The Experts below are selected from a list of 23322 Experts worldwide ranked by ideXlab platform
G. Geethakumari - One of the best experts on this subject based on the ideXlab platform.
-
A framework for the identification of suspicious packets to detect anti-Forensic attacks in the cloud environment
Peer-to-Peer Networking and Applications, 2020Co-Authors: Deevi Radha Rani, G. GeethakumariAbstract:Cloud computing is becoming a prominent service model of computing platforms offering resources to all categories of users on-demand. On the other side, cloud environment is vulnerable to many criminal activities too. Investigating the cloud crimes is the need of the hour. Anti-Forensic attack in cloud is an attack which specifically aims to scuttle the cloud Forensic Process. Though many researchers proposed various cloud Forensic approaches, detecting cloud anti-Forensic attack still remains a challenge as it hinders every step of Forensic Process. In this paper, we propose a three stage system for the detection of cloud anti-Forensic attack with a well defined sequence of tasks in which the Process of identifying the suspicious packets plays the major part. Every packet affected with any kind of cloud attack is labeled as suspicious packet and such packets are marked to traceback anti-Forensic attack. The main focus of this paper is to deploy such a mechanism to identify the suspicious packets in cloud environment. To categorize the type of attack that affected the packet, both signature analysis and anomaly detection at cloud layers are applied in our proposed approach. The proposed anomaly detection approach is tested on NSL-KDD dataset. The experimental results show that the accuracy of the proposed approach is high compared to the existing approaches.
-
secure data transmission and detection of anti Forensic attacks in cloud environment using mecc and dlmnn
Computer Communications, 2020Co-Authors: Deevi Radha Rani, G. GeethakumariAbstract:Abstract Anti-Forensics is a set of techniques and measures adopted by an attacker aimed at compromising the digital investigation Process in a computational environment. Cloud computing, which is an environment providing on demand resources to users, is susceptible to anti-Forensic attacks. An anti-Forensic attacker in the cloud can influence the cloud Forensic Process and tamper with evidences, causing damage to the investigation. Though some solutions have been proposed against anti-Forensic attacks in cloud, there is a need to secure the evidences while in transit as well as in storage. In this work, we propose efficient algorithms for secure data (evidence) transmission and early detection of Anti-Forensic Attack (AFA). First, the data packets are compressed using a B-tree Huffman Encoding (BHE) algorithm; next, the packet marking technique is implemented to secure the IP address of the sender. For securely sending the data, we propose the Modified Elliptic curve cryptography (MECC) algorithm which encrypts the data packets and transmits it to a receiver. At the receiver side, the training is done using a Deep Learning Modified Neural Network (DLMNN) classifier, which tests the received data packet IP-address. Based on the IP-address of the sender, DLMNN identifies whether the received packet is an packet attacked or a non-attacked one. After the identification of the data packets, the decryption and de-compression of non-attacked data packets are done to obtain the original information. The original evidence information is further analyzed for investigation purposes. Experimental results shown by the proposed method are weighed against the prevailing techniques for performace comparison.
-
digital Forensic architecture for cloud computing systems methods of evidence identification segregation collection and partial analysis
2016Co-Authors: Digambar Povar, G. GeethakumariAbstract:Various advantages offered by cloud computing business model has made it one of the most significant of current computing trends like personal, mobile, ubiquitous, cluster, grid, and utility computing models. These advantages have created complex issues for Forensic investigators and practitioners for conducting digital Forensic investigation in cloud computing environment. In the past few years, many researchers have contributed in identifying the Forensic challenges, designing Forensic frameworks, data acquisition methods for cloud computing systems. However, to date, there is no unique universally accepted Forensic Process model for cloud computing environment to acquire and analyze data available therein. This paper contributes in three specific areas to expedite research in this emerging field. First is designing a digital Forensic architecture for cloud computing systems; second is evidence source identification, segregation and acquisition; and finally methods for partial analysis of evidence within and outside of a virtual machine (VM).
Mark Scanlon - One of the best experts on this subject based on the ideXlab platform.
-
Deduplicated Disk Image Evidence Acquisition and Forensically-Sound Reconstruction
2018 17th IEEE International Conference On Trust Security And Privacy In Computing And Communications 12th IEEE International Conference On Big Data S, 2018Co-Authors: Xiaoyu Du, Paul Ledwith, Mark ScanlonAbstract:The ever-growing backlog of digital evidence waiting for analysis has become a significant issue for law enforcement agencies throughout the world. This is due to an increase in the number of cases requiring digital Forensic analysis coupled with the increasing volume of data to Process per case. This has created a demand for a paradigm shift in the method that evidence is acquired, stored, and analyzed. The ultimate goal of the research presented in this paper is to revolutionize the current digital Forensic Process through the leveraging of centralized deduplicated acquisition and Processing approach. Focusing on this first step in digital evidence Processing, acquisition, a system is presented enabling deduplicated evidence acquisition with the capability of automated, Forensically-sound complete disk image reconstruction. As the number of cases acquired by the proposed system increases, the more duplicate artifacts will be encountered, and the more efficient the Processing of each new case will become. This results in a time saving for digital investigators, and provides a platform to enable non-expert evidence Processing, alongside the benefits of reduced storage and bandwidth requirements.
-
Evaluation of Digital Forensic Process Models with Respect to Digital Forensics as a Service
arXiv: Cryptography and Security, 2017Co-Authors: Nhien-an Le-khac, Mark ScanlonAbstract:Digital Forensic science is very much still in its infancy, but is becoming increasingly invaluable to investigators. A popular area for research is seeking a standard methodology to make the digital Forensic Process accurate, robust, and efficient. The first digital Forensic Process model proposed contains four steps: Acquisition, Identification, Evaluation and Admission. Since then, numerous Process models have been proposed to explain the steps of identifying, acquiring, analysing, storage, and reporting on the evidence obtained from various digital devices. In recent years, an increasing number of more sophisticated Process models have been proposed. These models attempt to speed up the entire investigative Process or solve various of problems commonly encountered in the Forensic investigation. In the last decade, cloud computing has emerged as a disruptive technological concept, and most leading enterprises such as IBM, Amazon, Google, and Microsoft have set up their own cloud-based services. In the field of digital Forensic investigation, moving to a cloud-based evidence Processing model would be extremely beneficial and preliminary attempts have been made in its implementation. Moving towards a Digital Forensics as a Service model would not only expedite the investigative Process, but can also result in significant cost savings - freeing up digital Forensic experts and law enforcement personnel to progress their caseload. This paper aims to evaluate the applicability of existing digital Forensic Process models and analyse how each of these might apply to a cloud-based evidence Processing paradigm.
-
current challenges and future research areas for digital Forensic investigation
arXiv: Cryptography and Security, 2016Co-Authors: David Lillis, Brett A Becker, Tadhg Osullivan, Mark ScanlonAbstract:Given the ever-increasing prevalence of technology in modern life, there is a corresponding increase in the likelihood of digital devices being pertinent to a criminal investigation or civil litigation. As a direct consequence, the number of investigations requiring digital Forensic expertise is resulting in huge digital evidence backlogs being encountered by law enforcement agencies throughout the world. It can be anticipated that the number of cases requiring digital Forensic analysis will greatly increase in the future. It is also likely that each case will require the analysis of an increasing number of devices including computers, smartphones, tablets, cloud-based services, Internet of Things devices, wearables, etc. The variety of new digital evidence sources pose new and challenging problems for the digital investigator from an identification, acquisition, storage and analysis perspective. This paper explores the current challenges contributing to the backlog in digital Forensics from a technical standpoint and outlines a number of future research topics that could greatly contribute to a more efficient digital Forensic Process.
Benjamin C M Fung - One of the best experts on this subject based on the ideXlab platform.
-
subject based semantic document clustering for digital Forensic investigations
Data and Knowledge Engineering, 2013Co-Authors: Gaby G Dagher, Benjamin C M FungAbstract:Abstract Computers are increasingly used as tools to commit crimes such as unauthorized access (hacking), drug trafficking, and child pornography. The proliferation of crimes involving computers has created a demand for special Forensic tools that allow investigators to look for evidence on a suspect's computer by analyzing communications and data on the computer's storage devices. Motivated by the Forensic Process at Surete du Quebec ( SQ ), the Quebec provincial police, we propose a new subject-based semantic document clustering model that allows an investigator to cluster documents stored on a suspect's computer by grouping them into a set of overlapping clusters, each corresponding to a subject of interest initially defined by the investigator.
Chris Bogen - One of the best experts on this subject based on the ideXlab platform.
-
Triage Process Model
2014Co-Authors: Gary Cantrell, David Dampier, Nan Niu, Yoginder S. Dandass, Chris BogenAbstract:The digital Forensic Process as traditionally laid out begins with the collection, duplication, and authentication of every piece of digital media prior to examination. These first three phases of the digital Forensic Process are by far the most costly. However, complete Forensic duplication is standard practice among digital Forensic laboratories. The time it takes to complete these stages is quickly becoming a serious problem. Digital Forensic laboratories do not have the resources and time to keep up with the growing demand for digital Forensic examinations with the current methodologies. One solution to this problem is the use of pre-examination techniques commonly referred to as digital triage. Pre-examination techniques can assist the examiner with intelligence that can be used to prioritize and lead the examination Process. This work discusses a proposed model for digital triage that is currently under development at Mississippi State University
-
Research toward a Partially-Automated, and Crime Specific Digital Triage Process Model
Computer and Information Science, 2012Co-Authors: Gary Cantrell, David Dampier, Nan Niu, Chris BogenAbstract:The digital Forensic Process as traditionally laid out begins with the collection, duplication, and authentication of every piece of digital media prior to examination. These first three phases of the digital Forensic Process are by far the most costly. However, complete Forensic duplication is standard practice among digital Forensic laboratories. The time it takes to complete these stages is quickly becoming a serious problem. Digital Forensic laboratories do not have the resources and time to keep up with the growing demand for digital Forensic examinations with the current methodologies. One solution to this problem is the use of pre-examination techniques commonly referred to as digital triage. Pre-examination techniques can assist the examiner with intelligence that can be used to prioritize and lead the examination Process. This work discusses a proposed model for digital triage that is currently under development at Mississippi State University.
Thomas Fogwill - One of the best experts on this subject based on the ideXlab platform.
-
selection and ranking of remote hosts for digital Forensic investigation in a cloud environment
Information Security for South Africa, 2013Co-Authors: George Sibiya, Thomas Fogwill, H S VenterAbstract:Cloud computing is a new computing paradigm which presents challenges for digital Forensic investigators. Digital Forensics is a branch of computer security that makes use of electronic evidence to build up a criminal case or for troubleshooting purposes. Advances have been made since the advent of Cloud computing in addressing issues that came with the Cloud including that of security. However, not all aspects of security are advancing. Developments in digital Forensics still leave a lot to be desired in terms of standards and appropriate digital Forensic tools that are applicable in the Cloud. To achieve that, standards as well as standard tools are required for successful evidence collection, preservation, analysis and conviction in case of a criminal case. This paper contributes towards addressing issues in digital Forensics by presenting an algorithm that can be used in the evidence identification phase of a digital Forensic Process. Data in Cloud environments exist in the Internet or in networked environments and data is always accessed remotely. There is therefore at least one connection to a host that exists in a Cloud environment. In a case of a computer system that hosts a Cloud service, the number of connections from clients can be very large. In such a scenario it is very hard to identify an attacker from both active and recently disconnected connections to a host. This may require an investigator to probe all individual IP addresses connected to the host which can be time consuming and costly. There is therefore a need for a mechanism that can identify and rank remote hosts that are connected to a victim host and that may be associated with a malicious activity. In this paper we present an algorithm that uses probabilities to identify and rank suspicious remote hosts connected to a victim host. This algorithm helps minimize the effort required of investigators to probe each IP address that is connected to a victim as connected IP addresses will be prioritized according to their rank.
-
Guidelines for procedures of a harmonised digital Forensic Process in network Forensics
2012 Information Security for South Africa - Proceedings of the ISSA 2012 Conference, 2012Co-Authors: George Sibiya, Sipho Ngobeni, Hein S. Venter, Thomas FogwillAbstract:Cloud computing is a new computing paradigm that presents fresh research issues in the field of digital Forensics. Cloud computing builds upon virtualisation technologies and is distributed in nature. Depending on its implementation, the cloud can span across numerous countries. Its distributed nature and virtualisation introduces digital Forensic research issues that include among others difficulty in identifying and collecting Forensically sound evidence. Even if the evidence may be identified and essential tools for collecting the evidence are acquired, it may be illegal to access computer data residing beyond the jurisdiction of a Forensic investigator. The investigator needs to acquire a search warrant that can be executed in a specific foreign country - which may not be a single country due to the distributed nature of the cloud. Obtaining warrants for numerous countries at once may be costly and time consuming. Some countries may also fail to comply with the demands of cloud Forensics. Since the field of digital Forensics is itself still in its infancy, it lacks standardised Forensic Processes and procedures. Thus, digital Forensic investigators are able to collect evidence, but often fail in following a valid investigation Process that is acceptable in a court of law. In addressing digital Forensic issues such as the above, the authors are writing a series of papers that are aimed at providing guidelines for digital Forensic procedures in a cloud environment. Live Forensics and network Forensics constitute an integral part of cloud Forensics. A paper that deals with guidelines for digital Forensic procedures in live Forensics was submitted elsewhere. The current paper is therefore the second in a series where the authors propose and present guidelines for digital Forensic procedures in network Forensics. The authors eventually aim to have guidelines for digital Forensic procedures in a cloud environment as the last paper in the series.