The Experts below are selected from a list of 612 Experts worldwide ranked by ideXlab platform
Hein S. Venter - One of the best experts on this subject based on the ideXlab platform.
-
Holistic digital Forensic Readiness framework for IoT-enabled organizations
Forensic Science International: Reports, 2020Co-Authors: Victor R. Kebande, Hein S. Venter, Phathutshedzo P. Mudau, Richard Adeyemi Ikuesan, Kim-kwang Raymond ChooAbstract:Abstract Internet of Things (IoT) are becoming commonplace in homes, buildings, cities, and nations, and IoT networks are also getting more complex and interconnected. The complexity, interconnectivity, and heterogeneity of IoT systems, however, complicate digital (Forensic) investigations. The challenge is compounded due to the lack of holistic and standardized approaches. Hence, building on the ISO/IEC 27043 international standard, we present a holistic digital Forensic Readiness (DFR) framework. We also qualitatively evaluate the utility of the proposed DFR framework.
-
Digital Forensic Readiness Framework for Ransomware Investigation
Digital Forensics and Cyber Crime, 2019Co-Authors: Avinash Singh, Adeyemi Richard Ikuesan, Hein S. VenterAbstract:Over the years there has been a significant increase in the exploitation of the security vulnerabilities of Windows operating systems, the most severe threat being malicious software (malware). Ransomware, a variant of malware which encrypts files and retains the decryption key for ransom, has recently proven to become a global digital epidemic. The current method of mitigation and propagation of malware and its variants, such as anti-viruses, have proven ineffective against most Ransomware attacks. Theoretically, Ransomware retains footprints of the attack process in the Windows Registry and the volatile memory of the infected machine. Digital Forensic Readiness (DFR) processes provide mechanisms for the pro-active collection of digital footprints. This study proposed the integration of DFR mechanisms as a process to mitigate Ransomware attacks. A detailed process model of the proposed DFR mechanism was evaluated in compliance with the ISO/IEC 27043 standard. The evaluation revealed that the proposed mechanism has the potential to harness system information prior to, and during a Ransomware attack. This information can then be used to potentially decrypt the encrypted machine. The implementation of the proposed mechanism can potentially be a major breakthrough in mitigating this global digital endemic that has plagued various organizations. Furthermore, the implementation of the DFR mechanism implies that useful decryption processes can be performed to prevent ransom payment.
-
ICDF2C - Digital Forensic Readiness Framework for Ransomware Investigation
Lecture Notes of the Institute for Computer Sciences Social Informatics and Telecommunications Engineering, 2018Co-Authors: Avinash Singh, Adeyemi Richard Ikuesan, Hein S. VenterAbstract:Over the years there has been a significant increase in the exploitation of the security vulnerabilities of Windows operating systems, the most severe threat being malicious software (malware). Ransomware, a variant of malware which encrypts files and retains the decryption key for ransom, has recently proven to become a global digital epidemic. The current method of mitigation and propagation of malware and its variants, such as anti-viruses, have proven ineffective against most Ransomware attacks. Theoretically, Ransomware retains footprints of the attack process in the Windows Registry and the volatile memory of the infected machine. Digital Forensic Readiness (DFR) processes provide mechanisms for the pro-active collection of digital footprints. This study proposed the integration of DFR mechanisms as a process to mitigate Ransomware attacks. A detailed process model of the proposed DFR mechanism was evaluated in compliance with the ISO/IEC 27043 standard. The evaluation revealed that the proposed mechanism has the potential to harness system information prior to, and during a Ransomware attack. This information can then be used to potentially decrypt the encrypted machine. The implementation of the proposed mechanism can potentially be a major breakthrough in mitigating this global digital endemic that has plagued various organizations. Furthermore, the implementation of the DFR mechanism implies that useful decryption processes can be performed to prevent ransom payment.
-
novel digital Forensic Readiness technique in the cloud environment
Australian Journal of Forensic Sciences, 2018Co-Authors: Victor R. Kebande, Hein S. VenterAbstract:AbstractThis paper examines the design and implementation of a feasible technique for performing Digital Forensic Readiness (DFR) in cloud computing environments. The approach employs a modified obfuscated Non-Malicious Botnet (NMB) whose functionality operates as a distributed Forensic Agent-Based Solution (ABS) in a cloud environment with capabilities of performing Forensic logging for DFR purposes. Under basic Service Level Agreements (SLAs), this proactive technique allows any organization to perform DFR in the cloud without interfering with operations and functionalities of the existing cloud architecture or infrastructure and the collected file metadata. Based on the evaluation discussed, the effectiveness of our approach is presented as the easiest way of conducting DFR in the cloud environment as stipulated in the ISO/IEC 27043: 2015 international standard, which is a standard of information technology, security techniques and incident investigation principles and processes. Through this technique...
-
a digital Forensic Readiness architecture for online examinations
South African Computer Journal, 2018Co-Authors: Ivans Kigwana, Hein S. VenterAbstract:Some institutions provide online courses to students to ease the courses’ workload. Online courses can also be convenient because the online course content management software conducts marking of tests and examinations. However, a few students could be willing to exploit such a system’s weaknesses in a bid to cheat in online examinations because invigilators are absent. Proactive measures are needed and measures have to be implemented in order to thwart unacceptable behaviour in situations where there is little control of students’ conduct. Digital Forensic Readiness (DFR) employs a proactive approach for an organisation to be Forensically prepared for situations where there is little control over people. This can be achieved by gathering, storing and handling incident response data, with the aim of reducing the time and cost that would otherwise be spent in a post-event response process. The problem this paper addresses is that, at the time of writing this paper, there existed no known DFR architecture that can be used to collect relevant information for DFR purposes, specifically in the course of an online examination, as described in the standard published by the International Standards Organisation (ISO) and the International Electrotechnical Commission (IEC) (ISO/IEC 27043:2015) for incident investigation principles and processes. Due to the lack of DFR architecture, the authors propose an Online Examination Digital Forensic Readiness Architecture (OEDFRA) that can be used to achieve DFR when online examinations are conducted. This architecture employs already existing DFR techniques, discussed in the study, to help educational institutions achieve DFR in online examinations. This architecture, (OEDFRA), when implemented, will be tested in future research in order to confirm its contribution to the field of DFR.
Tomas Pitner - One of the best experts on this subject based on the ideXlab platform.
-
verification of Forensic Readiness in software development a roadmap
ACM Symposium on Applied Computing, 2020Co-Authors: Lukas Daubner, Martin Macak, Barbora Buhnova, Tomas PitnerAbstract:Nowadays, a growing need for the Forensic investigation of cybercrimes emerges. It is because of the rising threat of those crimes in cyberspace. Nevertheless, such investigations are highly timeconsuming with delicate supportive processes. The problem of systematic preparation on the potential Forensic investigation during the software development process, called Forensic Readiness, has only been explored since recently. Therefore there are still many open issues and challenges, with missing methods and guidelines that would support software engineers in building software systems that are Forensic ready. One of the essential open challenges is the understanding of the Forensic-Readiness requirements that shall be embedded in the software system early during its design, and then also the techniques to ensure and verify Forensic Readiness and its specific needs along the way. In this paper, we propose a research roadmap towards verification of Forensic Readiness in software design and development, to help the progress of this new research domain. The results of the research based on the roadmap can then support software engineers in designing critical, Forensic-ready systems, together with possible perspective methods of capturing and verifying the specific requirements constituting Forensic Readiness.
-
SAC - Verification of Forensic Readiness in Software Development: A Roadmap
Proceedings of the 35th Annual ACM Symposium on Applied Computing, 2020Co-Authors: Lukas Daubner, Martin Macak, Barbora Buhnova, Tomas PitnerAbstract:Nowadays, a growing need for the Forensic investigation of cybercrimes emerges. It is because of the rising threat of those crimes in cyberspace. Nevertheless, such investigations are highly timeconsuming with delicate supportive processes. The problem of systematic preparation on the potential Forensic investigation during the software development process, called Forensic Readiness, has only been explored since recently. Therefore there are still many open issues and challenges, with missing methods and guidelines that would support software engineers in building software systems that are Forensic ready. One of the essential open challenges is the understanding of the Forensic-Readiness requirements that shall be embedded in the software system early during its design, and then also the techniques to ensure and verify Forensic Readiness and its specific needs along the way. In this paper, we propose a research roadmap towards verification of Forensic Readiness in software design and development, to help the progress of this new research domain. The results of the research based on the roadmap can then support software engineers in designing critical, Forensic-ready systems, together with possible perspective methods of capturing and verifying the specific requirements constituting Forensic Readiness.
-
secure software modeling methods for Forensic Readiness
2020Co-Authors: Lukas Daubner, Tomas PitnerAbstract:Proactive preparation of software systems for Forensic investigation (Forensic Readiness) during the software development process, has been addressed only recently and has many open challenges. Representation of the Forensic concerns and specific requirements of Forensic Readiness is one of them. A common way of representing concepts in software development is modeling. This paper is focused on the possibility of reusing existing secure software modeling methods for the needs of Forensic Readiness.
Deeksha Gupta - One of the best experts on this subject based on the ideXlab platform.
-
ISC2 - Forensic Readiness of smart buildings: Preconditions for subsequent cybersecurity tests
2016 IEEE International Smart Cities Conference (ISC2), 2016Co-Authors: Edita Bajramovic, Karl Waedt, Antonio Ciriello, Deeksha GuptaAbstract:Smart grid and smart buildings are seamlessly interacting together to improve energy usage. Smart buildings accept excess of energy during periods when renewable energy generation is cheap and overflowing. Then, the electric energy is kept for future use and returned to the smart grid when needed. Many advantages exist for smart cities which are focused on the incorporation of smart buildings. The control of smart buildings is supported by dramatically increased embedded systems. This approach is becoming cost-effective and the systems will be almost maintenance-free, involving some or no individuals. Users will also have the ability to simply update settings using their smartphones and other smart devices. However, even with above mentioned advantages, some disadvantages, including cybersecurity risk, are present and therefore, protective measures for a smart world are needed. The consequences of not incorporating cybersecurity and Forensic Readiness in a smart world could have serious impact if cyber-attack was successfully launched. In addition, a broad Knowledge Management (KM) is needed to obtain increasingly better understanding and handling of cybersecurity issues of smart sensors and other extensively configurable devices. This paper addresses the importance of Forensic Readiness, digital evidence preservation and interpretation, and knowledge management in a smart world. The approaches we recommend can be further used for subsequent smart (as model-based) cybersecurity tests.
-
Forensic Readiness of smart buildings: Preconditions for subsequent cybersecurity tests
2016 IEEE International Smart Cities Conference (ISC2), 2016Co-Authors: Edita Bajramovic, Karl Waedt, Antonio Ciriello, Deeksha GuptaAbstract:Smart grid and smart buildings are seamlessly interacting together to improve energy usage. Smart buildings accept excess of energy during periods when renewable energy generation is cheap and overflowing. Then, the electric energy is kept for future use and returned to the smart grid when needed. Many advantages exist for smart cities which are focused on the incorporation of smart buildings. The control of smart buildings is supported by dramatically increased embedded systems. This approach is becoming cost-effective and the systems will be almost maintenance-free, involving some or no individuals. Users will also have the ability to simply update settings using their smartphones and other smart devices. However, even with above mentioned advantages, some disadvantages, including cybersecurity risk, are present and therefore, protective measures for a smart world are needed. The consequences of not incorporating cybersecurity and Forensic Readiness in a smart world could have serious impact if cyber-attack was successfully launched. In addition, a broad Knowledge Management (KM) is needed to obtain increasingly better understanding and handling of cybersecurity issues of smart sensors and other extensively configurable devices. This paper addresses the importance of Forensic Readiness, digital evidence preservation and interpretation, and knowledge management in a smart world. The approaches we recommend can be further used for subsequent smart (as model-based) cybersecurity tests.
Lukas Daubner - One of the best experts on this subject based on the ideXlab platform.
-
verification of Forensic Readiness in software development a roadmap
ACM Symposium on Applied Computing, 2020Co-Authors: Lukas Daubner, Martin Macak, Barbora Buhnova, Tomas PitnerAbstract:Nowadays, a growing need for the Forensic investigation of cybercrimes emerges. It is because of the rising threat of those crimes in cyberspace. Nevertheless, such investigations are highly timeconsuming with delicate supportive processes. The problem of systematic preparation on the potential Forensic investigation during the software development process, called Forensic Readiness, has only been explored since recently. Therefore there are still many open issues and challenges, with missing methods and guidelines that would support software engineers in building software systems that are Forensic ready. One of the essential open challenges is the understanding of the Forensic-Readiness requirements that shall be embedded in the software system early during its design, and then also the techniques to ensure and verify Forensic Readiness and its specific needs along the way. In this paper, we propose a research roadmap towards verification of Forensic Readiness in software design and development, to help the progress of this new research domain. The results of the research based on the roadmap can then support software engineers in designing critical, Forensic-ready systems, together with possible perspective methods of capturing and verifying the specific requirements constituting Forensic Readiness.
-
SAC - Verification of Forensic Readiness in Software Development: A Roadmap
Proceedings of the 35th Annual ACM Symposium on Applied Computing, 2020Co-Authors: Lukas Daubner, Martin Macak, Barbora Buhnova, Tomas PitnerAbstract:Nowadays, a growing need for the Forensic investigation of cybercrimes emerges. It is because of the rising threat of those crimes in cyberspace. Nevertheless, such investigations are highly timeconsuming with delicate supportive processes. The problem of systematic preparation on the potential Forensic investigation during the software development process, called Forensic Readiness, has only been explored since recently. Therefore there are still many open issues and challenges, with missing methods and guidelines that would support software engineers in building software systems that are Forensic ready. One of the essential open challenges is the understanding of the Forensic-Readiness requirements that shall be embedded in the software system early during its design, and then also the techniques to ensure and verify Forensic Readiness and its specific needs along the way. In this paper, we propose a research roadmap towards verification of Forensic Readiness in software design and development, to help the progress of this new research domain. The results of the research based on the roadmap can then support software engineers in designing critical, Forensic-ready systems, together with possible perspective methods of capturing and verifying the specific requirements constituting Forensic Readiness.
-
secure software modeling methods for Forensic Readiness
2020Co-Authors: Lukas Daubner, Tomas PitnerAbstract:Proactive preparation of software systems for Forensic investigation (Forensic Readiness) during the software development process, has been addressed only recently and has many open challenges. Representation of the Forensic concerns and specific requirements of Forensic Readiness is one of them. A common way of representing concepts in software development is modeling. This paper is focused on the possibility of reusing existing secure software modeling methods for the needs of Forensic Readiness.
Raymond Lutui - One of the best experts on this subject based on the ideXlab platform.
-
digital Forensic Readiness in wireless medical systems
2019 29th International Telecommunication Networks and Applications Conference (ITNAC), 2019Co-Authors: Arkar Kyaw, Brian Cusack, Raymond LutuiAbstract:individuals and businesses has become dependent on digital devices. These devices and services are used in the healthcare systems including hospitals as Wireless Medical Networks (WMedSys). Security incidents in the WMedSys have increased over the past few years. This paper reports research into digital Forensic Readiness in wireless medical systems by inserting Forensic Readiness states into the network system and preparing mitigation for security failure. A design is built and tested, and then validated by expert feedback. The contribution of this research is to present a novel conceptual design for a digital Forensic Readiness framework for WMedSys, which can be easily implemented and integrated into existing wireless networks in the healthcare sector.
-
ITNAC - Digital Forensic Readiness In Wireless Medical Systems
2019 29th International Telecommunication Networks and Applications Conference (ITNAC), 2019Co-Authors: Arkar Kyaw, Brian Cusack, Raymond LutuiAbstract:individuals and businesses has become dependent on digital devices. These devices and services are used in the healthcare systems including hospitals as Wireless Medical Networks (WMedSys). Security incidents in the WMedSys have increased over the past few years. This paper reports research into digital Forensic Readiness in wireless medical systems by inserting Forensic Readiness states into the network system and preparing mitigation for security failure. A design is built and tested, and then validated by expert feedback. The contribution of this research is to present a novel conceptual design for a digital Forensic Readiness framework for WMedSys, which can be easily implemented and integrated into existing wireless networks in the healthcare sector.