The Experts below are selected from a list of 303 Experts worldwide ranked by ideXlab platform

Peter Hannay - One of the best experts on this subject based on the ideXlab platform.

Jill Slay - One of the best experts on this subject based on the ideXlab platform.

  • ios forensics how can we recover deleted image files with timestamp in a Forensically Sound Manner
    Availability Reliability and Security, 2013
    Co-Authors: Aswami Ariffin, Christian Doorazio, Kimkwang Raymond Choo, Jill Slay
    Abstract:

    IOS devices generally allow users to synch their images (pictures) and video files using iTunes between Apple products (e.g. an iPhone and a Mac Book Pro). Recovering deleted images, particularly in a Forensically Sound Manner, from iOS devices can be an expensive and challenging exercise (due to the hierarchical encrypted file system, etc). In this paper, we propose an operational technique that allows digital forensic practitioners to recover deleted image files by referring to iOS journaling file system. Using an iPhone as a case study, we then conduct a forensic analysis to validate our proposed technique.

  • AISC - Digital camcorder forensics
    2013
    Co-Authors: Aswami Ariffin, Kimkwang Raymond Choo, Jill Slay
    Abstract:

    Digital camcorders commonly have an in-built capability to export entire video files or a single image to storage media such as a digital versatile disc (DVD). In the event that a DVD is not properly finalised, its contents might not be easily readable. It is generally accepted that recovering video evidence from an unfinalised DVD in a Forensically Sound Manner is an expensive and a challenging exercise. In this paper, we propose a digital camcorder forensics technique that allows digital forensics examiners to carve video files with timestamps without referring to a file system (file system independent technique). We then conduct a forensic analysis to validate our proposed technique.

  • ARES - iOS Forensics: How Can We Recover Deleted Image Files with Timestamp in a Forensically Sound Manner?
    2013 International Conference on Availability Reliability and Security, 2013
    Co-Authors: Aswami Ariffin, Kimkwang Raymond Choo, Christian D'oorazio, Jill Slay
    Abstract:

    IOS devices generally allow users to synch their images (pictures) and video files using iTunes between Apple products (e.g. an iPhone and a Mac Book Pro). Recovering deleted images, particularly in a Forensically Sound Manner, from iOS devices can be an expensive and challenging exercise (due to the hierarchical encrypted file system, etc). In this paper, we propose an operational technique that allows digital forensic practitioners to recover deleted image files by referring to iOS journaling file system. Using an iPhone as a case study, we then conduct a forensic analysis to validate our proposed technique.

  • NSS - The Design of Real-Time Adaptive Forensically Sound Secure Critical Infrastructure
    2010 Fourth International Conference on Network and System Security, 2010
    Co-Authors: Ray Hunt, Jill Slay
    Abstract:

    Network security design has seen significant advances in recent years. This has been demonstrated by a growing number of new encryption algorithms, more intelligent firewall and intrusion detection techniques, new developments in multifactor authentication, advances in malware protection and many more. During a similar period of time the industry has seen the need for network infrastructure which provides a greater degree of trust which has resulted in the development of forensic analysis tools which meet the requirements of law enforcement agencies. Such tools must provide for commercial intelligence and national security. This paper proposes that application of the common ground between security and forensics has great potential to provide for improvements in the effort to achieve real-time adaptive security. This implies an architecture which can detect security breaches and in real-time record and analyse traffic logs in a Forensically Sound Manner, provide corrective feedback to security devices and attempt to trace back to the source of the attack. In addressing computer security and forensic analysis from a real-time perspective, this paper recognises that some of these processes already exist, but proposes methods whereby the ongoing damage and potential risk to critical infrastructure can be reduced. This requires the implementation of a highly integrated approach to security and forensics such that they can inter-work in real-time in order to address the significant security issues which currently face the industry.

  • HICSS - iPod Forensics: Forensically Sound Examination of an Apple iPod
    2007 40th Annual Hawaii International Conference on System Sciences (HICSS'07), 2007
    Co-Authors: Jill Slay, A. Przibilla
    Abstract:

    This paper reports on the development of a method for extracting and verifying an image of the hard drive of an iPod in a Forensically Sound Manner via a USB2 connection, so as to create a standard operating procedure for Australian Law Enforcement. It also establishes an understanding of the nature of proprietary data stored on the iPod and indicates how this can be used as a guide within a forensic investigation. It also develops a Sound understanding of the nature of any metadata stored on the iPod and reports on how the information gained, and the standard operating procedures developed from this research, may be applied to gain a better understanding of imaging issues in other portable electronic devices, such as music players and memory based devices, and how similar standard operating procedures may be constructed for the analysis of these devices

Ali Dehghantanha - One of the best experts on this subject based on the ideXlab platform.

  • Mobile forensic data acquisition in Firefox OS
    2014 3rd International Conference on Cyber Security Cyber Warfare and Digital Forensic CyberSec 2014, 2014
    Co-Authors: Mohd Najwadi Yusoff, Mohd Taufik Abdullah, Ramlan Mahmod, Ali Dehghantanha
    Abstract:

    Mozilla Corporation has recently released a Linuxbased open source operating system, namely Firefox OS. The arrival of this Firefox OS has created new challenges, concentrations and opportunities for digital investigators. Currently, Firefox OS is still not fully supported by most of the existing mobile forensic tools. Even when the phone is detected as Android, only pictures from removable card was able to be captured. Furthermore, the internal data acquisition is still not working. Therefore, there are very huge opportunities to explore the Firefox OS on every stages of mobile forensic procedures. This paper will present an approach for mobile forensic data acquisition in a Forensically Sound Manner from a Firefox OS running device. This approach will largely use the UNIX dd command to create a forensic image from the Firefox OS running device.

  • CyberSec - An approach for forensic investigation in Firefox OS
    2014 Third International Conference on Cyber Security Cyber Warfare and Digital Forensic (CyberSec), 2014
    Co-Authors: Mohd Najwadi Yusoff, Ramlan Mahmod, Ali Dehghantanha, Mohd Taufik Abdullah
    Abstract:

    The advancement of smartphone technology has attracted many companies in developing mobile operating system. Mozilla Corporation recently released Linux-based open source operating system, named Firefox OS. The emergence of Firefox OS has created new challenges, concentrations and opportunities for digital investigators. In general, Firefox OS is designed to allow smartphones to communicate directly with HTML5 applications using JavaScript and newly introduced WebAPI. However, the used of JavaScript in HTML5 applications and solely no OS restriction might lead to security issues and potential exploits. Therefore, forensic analysis for Firefox OS is urgently needed in order to investigate any criminal intentions. This paper will present an approach and methodology in Forensically Sound Manner for Firefox OS.

  • Advances of mobile forensic procedures in Firefox OS
    International Journal of Cyber-Security and Digital Forensics, 2014
    Co-Authors: Mohd Najwadi Yusoff, Ramlan Mahmod, Ali Dehghantanha, Mohd Taufik Abdullah
    Abstract:

    The advancement of smartphone technology has attracted many companies in developing mobile operating system (OS). Mozilla Corporation recently released Linux-based open source mobile OS, named Firefox OS. The emergence of Firefox OS has created new challenges, concentrations and opportunities for digital investigators. In general, Firefox OS is designed to allow smartphones to communicate directly with HTML5 applications using JavaScript and newly introduced WebAPI. However, the used of JavaScript in HTML5 applications and solely no OS restriction might lead to security issues and potential exploits. Therefore, forensic analysis for Firefox OS is urgently needed in order to investigate any criminal intentions. This paper will present an overview and methodology of mobile forensic procedures in Forensically Sound Manner for Firefox OS.

  • CyberSec - Mobile forensic data acquisition in Firefox OS
    2014 Third International Conference on Cyber Security Cyber Warfare and Digital Forensic (CyberSec), 2014
    Co-Authors: Mohd Najwadi Yusoff, Mohd Taufik Abdullah, Ramlan Mahmod, Ali Dehghantanha
    Abstract:

    Mozilla Corporation has recently released a Linux-based open source operating system, namely Firefox OS. The arrival of this Firefox OS has created new challenges, concentrations and opportunities for digital investigators. Currently, Firefox OS is still not fully supported by most of the existing mobile forensic tools. Even when the phone is detected as Android, only pictures from removable card was able to be captured. Furthermore, the internal data acquisition is still not working. Therefore, there are very huge opportunities to explore the Firefox OS on every stages of mobile forensic procedures. This paper will present an approach for mobile forensic data acquisition in a Forensically Sound Manner from a Firefox OS running device. This approach will largely use the UNIX dd command to create a forensic image from the Firefox OS running device.

  • Performance measurement for mobile forensic data acquisition in Firefox OS
    International Journal of Cyber-Security and Digital Forensics, 2014
    Co-Authors: Mohd Najwadi Yusoof, Ramlan Mahmod, Ali Dehghantanha
    Abstract:

    Mozilla Corporation has recently released a Linux-based open source operating system, namely Firefox OS. The arrival of this Firefox OS has created new challenges, concentrations and opportunities for digital investigators. Currently, Firefox OS is still not fully supported by most of the existing mobile forensic tools. Even when the phone is detected as Android, only pictures from removable memory was able to be captured. Furthermore, the internal data acquisition is still not working. Therefore, there are very huge opportunities to explore the Firefox OS on every stages of mobile forensic procedures. This paper will present an approach for mobile forensic data acquisition in a Forensically Sound Manner from a Firefox OS running device. This approach will largely use the UNIX dd command to create a forensic image from the Firefox OS running device. Apart from that, performance measurement will be made to find the best block size for acquisition process in Firefox OS.

Iain Sutherland - One of the best experts on this subject based on the ideXlab platform.

  • forensic analysis of a sony playstation 4
    Digital Investigation: The International Journal of Digital Forensics & Incident Response archive, 2015
    Co-Authors: Matthew Davies, Huw Read, Konstantinos Xynos, Iain Sutherland
    Abstract:

    The primary function of a games console is that of an entertainment system. However the latest iteration of these consoles has added a number of new interactive features that may prove of value to the digital investigator. This paper highlights the value of these consoles, in particular Sony's latest version of their PlayStation. This console provides a number of features including web browsing, downloading of material and chat functionality; all communication features that will be of interest to forensic investigators. In this paper we undertake an initial investigation of the PlayStation 4 games console. This paper identifies potential information sources of forensic value with the PlayStation 4 and provides a method for acquiring information in a Forensically Sound Manner. In particular issues with the online and offline investigative process are also identified.

  • Forensic analysis of a Sony PlayStation 4: A first look
    Digital Investigation, 2015
    Co-Authors: Matthew Davies, Huw Read, Konstantinos Xynos, Iain Sutherland
    Abstract:

    Abstract The primary function of a games console is that of an entertainment system. However the latest iteration of these consoles has added a number of new interactive features that may prove of value to the digital investigator. This paper highlights the value of these consoles, in particular Sony's latest version of their PlayStation. This console provides a number of features including web browsing, downloading of material and chat functionality; all communication features that will be of interest to forensic investigators. In this paper we undertake an initial investigation of the PlayStation 4 games console. This paper identifies potential information sources of forensic value with the PlayStation 4 and provides a method for acquiring information in a Forensically Sound Manner. In particular issues with the online and offline investigative process are also identified.

Christoph Reich - One of the best experts on this subject based on the ideXlab platform.

  • ARES - A Forensic Acquisition and Analysis System for IaaS: Architectural Model and Experiment
    2016 11th International Conference on Availability Reliability and Security (ARES), 2016
    Co-Authors: Saad Alqahtany, Steven Furnell, Nathan Clarke, Christoph Reich
    Abstract:

    Cloud computing has been advancing at a feverish pace. It has become one of the most important research topics in computer science and information systems. Cloud computing offers enterprise-scale platforms in a short time frame with little effort. Thus, it delivers significant economic benefits to both commercial and public entities. Despite this, the security and subsequent incident management requirements are major obstacles to adopting the cloud. Current cloud architectures do not support digital forensic investigators, nor comply with today's digital forensics procedures – largely due to the dynamic nature of the cloud. When an incident has occurred, an organization-based investigation will seek to provide potential digital evidence while minimizing the cost of investigation. However, all members engaging in digital forensics must rely, to a very significant degree, upon the assistance of cloud providers to present relevant evidence. Unfortunately, providers often lack appropriate tools and features to perform adequate acquisition and analysis. Therefore, dependence on the CSPs is considered one of the most significant challenges when investigators need to acquire evidence in a timely yet Forensically Sound Manner from cloud systems. This paper aims to achieve two objectives: the first objective is the development and validation of a forensic acquisition system in an Infrastructure as a Service (IaaS) model in order to ensure organizations remain in complete control, remove the burden/liability from the CSPs and make it easy to acquire the evidence in a Forensically Sound and timely Manner. Secondly, it is to investigate the technical implications and costs resulting from such a system on the day-to-day operation of a cloud system.

  • a forensic acquisition and analysis system for iaas architectural model and experiment
    Availability Reliability and Security, 2016
    Co-Authors: Saad Alqahtany, Steven Furnell, Nathan Clarke, Christoph Reich
    Abstract:

    Cloud computing has been advancing at a feverish pace. It has become one of the most important research topics in computer science and information systems. Cloud computing offers enterprise-scale platforms in a short time frame with little effort. Thus, it delivers significant economic benefits to both commercial and public entities. Despite this, the security and subsequent incident management requirements are major obstacles to adopting the cloud. Current cloud architectures do not support digital forensic investigators, nor comply with today's digital forensics procedures – largely due to the dynamic nature of the cloud. When an incident has occurred, an organization-based investigation will seek to provide potential digital evidence while minimizing the cost of investigation. However, all members engaging in digital forensics must rely, to a very significant degree, upon the assistance of cloud providers to present relevant evidence. Unfortunately, providers often lack appropriate tools and features to perform adequate acquisition and analysis. Therefore, dependence on the CSPs is considered one of the most significant challenges when investigators need to acquire evidence in a timely yet Forensically Sound Manner from cloud systems. This paper aims to achieve two objectives: the first objective is the development and validation of a forensic acquisition system in an Infrastructure as a Service (IaaS) model in order to ensure organizations remain in complete control, remove the burden/liability from the CSPs and make it easy to acquire the evidence in a Forensically Sound and timely Manner. Secondly, it is to investigate the technical implications and costs resulting from such a system on the day-to-day operation of a cloud system.

  • A forensic acquisition and analysis system for IaaS
    Cluster Computing, 2016
    Co-Authors: Saad Alqahtany, Steven Furnell, Nathan Clarke, Christoph Reich
    Abstract:

    Cloud computing is a promising next-generation computing paradigm that offers significant economic benefits to both commercial and public entities. Furthermore, cloud computing provides accessibility, simplicity, and portability for its customers. Due to the unique combination of characteristics that cloud computing introduces (including on-demand self-service, broad network access, resource pooling, rapid elasticity, and measured service), digital investigations face various technical, legal, and organizational challenges to keep up with current developments in the field of cloud computing. There are a wide variety of issues that need to be resolved in order to perform a proper digital investigation in the cloud environment. This paper examines the challenges in cloud forensics that are identified in the current research literature, alongside exploring the existing proposals and technical solutions addressed in the respective research. The open problems that need further effort are highlighted. As a result of the analysis of literature, it is found that it would be difficult, if not impossible, to perform an investigation and discovery in the cloud environment without relying on cloud service providers (CSPs). Therefore, dependence on the CSPs is ranked as the greatest challenge when investigators need to acquire evidence in a timely yet Forensically Sound Manner from cloud systems. Thus, a fully independent model requires no intervention or cooperation from the cloud provider is proposed. This model provides a different approach to a forensic acquisition and analysis system (FAAS) in an Infrastructure as a Service model. FAAS seeks to provide a richer and more complete set of admissible evidences than what current CSPs provide, with no requirement for CSP involvement or modification to the CSP’s underlying architecture.