The Experts below are selected from a list of 12681 Experts worldwide ranked by ideXlab platform

Hein S. Venter - One of the best experts on this subject based on the ideXlab platform.

  • A natural human language framework for Digital forensic readiness in the public cloud
    Australian Journal of Forensic Sciences, 2020
    Co-Authors: Stacey O. Baror, Hein S. Venter, Richard Adeyemi
    Abstract:

    Currently, about half of all global enterprises are adopting and using some form of cloud computing services. In cloud computing, Potential Digital Evidence is distributed across multiple isolated ...

  • Proactive Forensics: Keystroke Logging from the Cloud as Potential Digital Evidence for Forensic Readiness Purposes
    2020 IEEE International Conference on Informatics IoT and Enabling Technologies (ICIoT), 2020
    Co-Authors: Sheunesu M Makura, Victor R. Kebande, Richard Adeyemi Ikuesan, Hein S. Venter, Nickson M. Karie
    Abstract:

    The relationship between negative and positive connotations with regard to malware in the cloud is rarely investigated according to the prevailing literature. However, there is a significant relationship between the use of positive and negative connotations. A clear distinction between the two emanates when we use the originally considered malicious code, for positive connotation like in the case of capturing keystrokes in a proactive forensic purpose. This is done during the collection of Digital Evidence for Digital Forensic Readiness (DFR) purposes, in preparation of a Digital Forensic Investigation (DFI) process. The paper explores the problem of having to use the keystrokes for positive reasons as a piece of Potential Evidence through extraction and Digitally preserving it as highlighted in ISO/IEC 27037: 2012 (security approaches) and ISO/IEC 27043: 2015 (legal connotations). In this paper, therefore, the authors present a technique of how DFR can be achieved through the collection of Digital information from the originally considered malicious code. This is achieved without modifying the cloud operations or the infrastructure thereof, while preserving the integrity of Digital information and possibly maintain the chain of custody at the same time. The paper proposes that the threshold of malicious code intrusion in the cloud can be transformed to an efficacious process of DFR through logical acquisition and Digitally preserving keystrokes. The experiment-tested keystrokes have shown a significant approach that could achieve proactive forensics.

  • on Digital forensic readiness in the cloud using a distributed agent based solution issues and challenges
    Australian Journal of Forensic Sciences, 2018
    Co-Authors: Victor R. Kebande, Hein S. Venter
    Abstract:

    The need to perform Digital investigations has, over the years, led to the exponential growth of the field of Digital Forensics (DF). However, quite a number of challenges face the act of proving – for purposes of Digital Forensic Readiness (DFR) – that an electronic event has occurred in cyberspace. The problem that this research addresses involves the challenges faced when an Agent-Based Solution (ABS) is used in the cloud to extract Potential Digital Evidence (PDE) for DFR purposes. Throughout the paper the authors have modified the functionality of an initially malicious botnet to act as a distributed forensic agent to conduct this process. The paper focuses on the general, technical and operational challenges that are encountered when trying to achieve DFR in the cloud environment. The authors finally propose a contribution by assessing the possible solutions from a general, technical and operational point of view.

  • user attribution based on keystroke dynamics in Digital forensic readiness process
    2017 IEEE Conference on Application Information and Network Security (AINS), 2017
    Co-Authors: Martha Mohlala, Adeyemi Richard Ikuesan, Hein S. Venter
    Abstract:

    As the development of technology increases, the security risk also increases. This has affected most organizations, irrespective of size, as they depend on the increasingly pervasive technology to perform their daily tasks. However, the dependency on technology has introduced diverse security vulnerabilities in organizations which requires a reliable preparedness for probable forensic investigation of the unauthorized incident. Keystroke dynamics is one of the cost-effective methods for collecting Potential Digital Evidence. This paper presents a keystroke pattern analysis technique suitable for the collection of complementary Potential Digital Evidence for forensic readiness. The proposition introduced a technique that relies on the extraction of reliable behavioral signature from user activity. Experimental validation of the proposition demonstrates the effectiveness of proposition using a multi-scheme classifier. The overall goal is to have forensically sound and admissible keystroke Evidence that could be presented during the forensic investigation to minimize the costs and time of the investigation.

  • user attribution based on keystroke dynamics in Digital forensic readiness process
    2017 IEEE Conference on Application Information and Network Security (AINS), 2017
    Co-Authors: Martha Mohlala, Adeyemi Richard Ikuesan, Hein S. Venter
    Abstract:

    As the development of technology increases, the security risk also increases. This has affected most organizations, irrespective of size, as they depend on the increasingly pervasive technology to perform their daily tasks. However, the dependency on technology has introduced diverse security vulnerabilities in organizations which requires a reliable preparedness for probable forensic investigation of the unauthorized incident. Keystroke dynamics is one of the cost-effective methods for collecting Potential Digital Evidence. This paper presents a keystroke pattern analysis technique suitable for the collection of complementary Potential Digital Evidence for forensic readiness. The proposition introduced a technique that relies on the extraction of reliable behavioral signature from user activity. Experimental validation of the proposition demonstrates the effectiveness of proposition using a multi-scheme classifier. The overall goal is to have forensically sound and admissible keystroke Evidence that could be presented during the forensic investigation to minimize the costs and time of the investigation.

Victor R. Kebande - One of the best experts on this subject based on the ideXlab platform.

  • Proactive Forensics: Keystroke Logging from the Cloud as Potential Digital Evidence for Forensic Readiness Purposes
    2020 IEEE International Conference on Informatics IoT and Enabling Technologies (ICIoT), 2020
    Co-Authors: Sheunesu M Makura, Victor R. Kebande, Richard Adeyemi Ikuesan, Hein S. Venter, Nickson M. Karie
    Abstract:

    The relationship between negative and positive connotations with regard to malware in the cloud is rarely investigated according to the prevailing literature. However, there is a significant relationship between the use of positive and negative connotations. A clear distinction between the two emanates when we use the originally considered malicious code, for positive connotation like in the case of capturing keystrokes in a proactive forensic purpose. This is done during the collection of Digital Evidence for Digital Forensic Readiness (DFR) purposes, in preparation of a Digital Forensic Investigation (DFI) process. The paper explores the problem of having to use the keystrokes for positive reasons as a piece of Potential Evidence through extraction and Digitally preserving it as highlighted in ISO/IEC 27037: 2012 (security approaches) and ISO/IEC 27043: 2015 (legal connotations). In this paper, therefore, the authors present a technique of how DFR can be achieved through the collection of Digital information from the originally considered malicious code. This is achieved without modifying the cloud operations or the infrastructure thereof, while preserving the integrity of Digital information and possibly maintain the chain of custody at the same time. The paper proposes that the threshold of malicious code intrusion in the cloud can be transformed to an efficacious process of DFR through logical acquisition and Digitally preserving keystrokes. The experiment-tested keystrokes have shown a significant approach that could achieve proactive forensics.

  • A Review of Mobile Forensic Investigation Process Models
    IEEE Access, 2020
    Co-Authors: Arafat Al-dhaqm, Victor R. Kebande, Richard Adeyemi Ikuesan, Shukor Abd Razak, Kamran Siddique
    Abstract:

    Mobile Forensics (MF) field uses prescribed scientific approaches with a focus on recovering Potential Digital Evidence (PDE) from mobile devices leveraging forensic techniques. Consequently, increased proliferation, mobile-based services, and the need for new requirements have led to the development of the MF field, which has in the recent past become an area of importance. In this article, the authors take a step to conduct a review on Mobile Forensics Investigation Process Models (MFIPMs) as a step towards uncovering the MF transitions as well as identifying open and future challenges. Based on the study conducted in this article, a review of the literature revealed that there are a few MFIPMs that are designed for solving certain mobile scenarios, with a variety of concepts, investigation processes, activities, and tasks. A total of 100 MFIPMs were reviewed, to present an inclusive and up-to-date background of MFIPMs. Also, this study proposes a Harmonized Mobile Forensic Investigation Process Model (HMFIPM) for the MF field to unify and structure whole redundant investigation processes of the MF field. The paper also goes the extra mile to discuss the state of the art of mobile forensic tools, open and future challenges from a generic standpoint. The results of this study find direct relevance to forensic practitioners and researchers who could leverage the comprehensiveness of the developed processes for investigation.

  • on Digital forensic readiness in the cloud using a distributed agent based solution issues and challenges
    Australian Journal of Forensic Sciences, 2018
    Co-Authors: Victor R. Kebande, Hein S. Venter
    Abstract:

    The need to perform Digital investigations has, over the years, led to the exponential growth of the field of Digital Forensics (DF). However, quite a number of challenges face the act of proving – for purposes of Digital Forensic Readiness (DFR) – that an electronic event has occurred in cyberspace. The problem that this research addresses involves the challenges faced when an Agent-Based Solution (ABS) is used in the cloud to extract Potential Digital Evidence (PDE) for DFR purposes. Throughout the paper the authors have modified the functionality of an initially malicious botnet to act as a distributed forensic agent to conduct this process. The paper focuses on the general, technical and operational challenges that are encountered when trying to achieve DFR in the cloud environment. The authors finally propose a contribution by assessing the possible solutions from a general, technical and operational point of view.

  • on Digital forensic readiness in the cloud using a distributed agent based solution issues and challenges
    Australian Journal of Forensic Sciences, 2018
    Co-Authors: Victor R. Kebande, H.s. Venter
    Abstract:

    The need to perform Digital investigations has, over the years, led to the exponential growth of the field of Digital Forensics (DF). However, quite a number of challenges face the act of proving – for purposes of Digital Forensic Readiness (DFR) – that an electronic event has occurred in cyberspace. The problem that this research addresses involves the challenges faced when an Agent-Based Solution (ABS) is used in the cloud to extract Potential Digital Evidence (PDE) for DFR purposes. Throughout the paper the authors have modified the functionality of an initially malicious botnet to act as a distributed forensic agent to conduct this process. The paper focuses on the general, technical and operational challenges that are encountered when trying to achieve DFR in the cloud environment. The authors finally propose a contribution by assessing the possible solutions from a general, technical and operational point of view.

  • 2
    2016
    Co-Authors: Victor R. Kebande
    Abstract:

    Cloud forensics has become an inexorable and a transformative discipline in the modern world. The need to share a pool of resources and to extract Digital Evidence from the same distributed resources to be presented in a court of law, has become a subject of focus. Forensic readiness is a pro-active process that entails Digital preparedness that an organisation uses to gather, store and handle incident responsive data with the aim of reducing post-event response by Digital forensics investigators. Forensic readiness in the cloud can be achieved by implementing a botnet with non-malicious code as opposed to malicious code. The botnet still infects instances of virtual computers within the cloud, however, with good intentions as opposed to bad intentions. The botnet is, effectively, implemented as a service that harvests Digital information that can be preserved as admissible and submissive Potential Digital Evidence. In this paper, the authors ‟ problem is that there are no techniques that exist for gathering information in the cloud for Digital forensic readiness purposes as described in international standard for Digital forensic investigations (ISO/IEC 27043). The authors proposed a model that allows Digital forensic readiness to be achieved by implementing a Botnet as a service (BaaS) in a cloud environment

H.s. Venter - One of the best experts on this subject based on the ideXlab platform.

  • on Digital forensic readiness in the cloud using a distributed agent based solution issues and challenges
    Australian Journal of Forensic Sciences, 2018
    Co-Authors: Victor R. Kebande, H.s. Venter
    Abstract:

    The need to perform Digital investigations has, over the years, led to the exponential growth of the field of Digital Forensics (DF). However, quite a number of challenges face the act of proving – for purposes of Digital Forensic Readiness (DFR) – that an electronic event has occurred in cyberspace. The problem that this research addresses involves the challenges faced when an Agent-Based Solution (ABS) is used in the cloud to extract Potential Digital Evidence (PDE) for DFR purposes. Throughout the paper the authors have modified the functionality of an initially malicious botnet to act as a distributed forensic agent to conduct this process. The paper focuses on the general, technical and operational challenges that are encountered when trying to achieve DFR in the cloud environment. The authors finally propose a contribution by assessing the possible solutions from a general, technical and operational point of view.

  • a generic Digital forensic readiness model for byod using honeypot technology
    IST-Africa Week Conference, 2016
    Co-Authors: Victor R. Kebande, Nickson M. Karie, H.s. Venter
    Abstract:

    Proliferation and mobility trends on Digital devices has seen a significant realization of Bring Your Own Device (BYOD) which is a phenomenon that allows employees in an organizational enterprise network to access computing resources through their personal mobile devices irrespective of their location. This technology has enabled cost effectiveness in organizations through increased accessibility of Digital devices in daily business activities. However, the development of this technology faces a number of security challenges due to lack of effective proactive security model with Digital forensic capability that is able to plan and prepare before Potential security incidents occur in an organization that has allowed BYOD. It is on this premise that the authors have proposed a generic Digital Forensic Readiness (DFR) model that uses honeypot technology to detect and trap Potential security incidents. In this paper, therefore, a significant security model with DFR capability has been proposed. The model is aimed at harvesting, encrypting and Digitally preserving Potential Digital Evidence (PDE) based on the DFR processes and guidelines that have been highlighted in the ISO/IEC 27043: 2015 international standard for information technology, security techniques, incident investigation principles and processes. Finally, the proposed model is meant to reduce the effort required to conduct Digital Forensic Investigation (DFI) by capturing Potential Digital Evidence and make it available when needed by Digital forensic investigators which eventually saves cost and time. A generic DFR model for BYOD using honeypot technology is the main focus of this paper.

  • Towards a framework for enhancing Potential Digital Evidence presentation
    2013 Information Security for South Africa, 2013
    Co-Authors: Nickson M. Karie, H.s. Venter
    Abstract:

    In the case of Digital forensic investigations, the Potential Digital Evidence captured, the analysis, interpretation, and attribution must ultimately be presented in the form of expert reports, depositions, and testimony in any legal proceedings. If the presentation and interpretation of the Potential Digital Evidence is conducted correctly, it is much easier and useful in apprehending the attacker and stands a much greater chance of being admissible in the event of a prosecution. Wrongly presented and interpreted Potential Digital Evidence data might create loopholes for perpetrators to exploit, thus, making it hard to convict and prosecute them. Existing Digital forensic investigation process models have provided guidelines for identifying and preserving Potential Digital Evidence captured from a crime scene. However, the extent to which such Potential Digital Evidence may be admissible in a court of law remains a challenge to investigators. This is backed up by the fact that there are currently no standardised guidelines for even presenting the most common representations of Digital forensic Evidence. Therefore, in the authors' opinion, methodologies and specifications need to be developed in the field of Digital forensics with the ability to effectively enhance the Potential Digital Evidence presentation and interpretation in any legal proceedings. In this paper, therefore, we present a step-by-step framework in an attempt to propose high-level guidelines for enhancing the Potential Digital Evidence presentation in any legal proceedings. Such a framework will be helpful to Digital forensic experts, for example, in structuring investigation findings as well as in identifying relevant patterns of events to be incorporated during the presentation of Potential Digital Evidence. The framework will also assist law enforcement agencies, for example, to determine, with less effort, the validity, weight and admissibility of any Potential Digital Evidence presented. However, it should be noted that the purpose of this paper is not to replace any of the extensive and known Evidence presentation principles, but serves as a survey of the state of the art of the research area while proposing harmonised and high-level guidelines for enhancing the presentation of Potential Digital Evidence in legal proceedings.

Nickson M. Karie - One of the best experts on this subject based on the ideXlab platform.

  • Proactive Forensics: Keystroke Logging from the Cloud as Potential Digital Evidence for Forensic Readiness Purposes
    2020 IEEE International Conference on Informatics IoT and Enabling Technologies (ICIoT), 2020
    Co-Authors: Sheunesu M Makura, Victor R. Kebande, Richard Adeyemi Ikuesan, Hein S. Venter, Nickson M. Karie
    Abstract:

    The relationship between negative and positive connotations with regard to malware in the cloud is rarely investigated according to the prevailing literature. However, there is a significant relationship between the use of positive and negative connotations. A clear distinction between the two emanates when we use the originally considered malicious code, for positive connotation like in the case of capturing keystrokes in a proactive forensic purpose. This is done during the collection of Digital Evidence for Digital Forensic Readiness (DFR) purposes, in preparation of a Digital Forensic Investigation (DFI) process. The paper explores the problem of having to use the keystrokes for positive reasons as a piece of Potential Evidence through extraction and Digitally preserving it as highlighted in ISO/IEC 27037: 2012 (security approaches) and ISO/IEC 27043: 2015 (legal connotations). In this paper, therefore, the authors present a technique of how DFR can be achieved through the collection of Digital information from the originally considered malicious code. This is achieved without modifying the cloud operations or the infrastructure thereof, while preserving the integrity of Digital information and possibly maintain the chain of custody at the same time. The paper proposes that the threshold of malicious code intrusion in the cloud can be transformed to an efficacious process of DFR through logical acquisition and Digitally preserving keystrokes. The experiment-tested keystrokes have shown a significant approach that could achieve proactive forensics.

  • a generic Digital forensic readiness model for byod using honeypot technology
    IST-Africa Week Conference, 2016
    Co-Authors: Victor R. Kebande, Nickson M. Karie, Hein S. Venter
    Abstract:

    Proliferation and mobility trends on Digital devices has seen a significant realization of Bring Your Own Device (BYOD) which is a phenomenon that allows employees in an organizational enterprise network to access computing resources through their personal mobile devices irrespective of their location. This technology has enabled cost effectiveness in organizations through increased accessibility of Digital devices in daily business activities. However, the development of this technology faces a number of security challenges due to lack of effective proactive security model with Digital forensic capability that is able to plan and prepare before Potential security incidents occur in an organization that has allowed BYOD. It is on this premise that the authors have proposed a generic Digital Forensic Readiness (DFR) model that uses honeypot technology to detect and trap Potential security incidents. In this paper, therefore, a significant security model with DFR capability has been proposed. The model is aimed at harvesting, encrypting and Digitally preserving Potential Digital Evidence (PDE) based on the DFR processes and guidelines that have been highlighted in the ISO/IEC 27043: 2015 international standard for information technology, security techniques, incident investigation principles and processes. Finally, the proposed model is meant to reduce the effort required to conduct Digital Forensic Investigation (DFI) by capturing Potential Digital Evidence and make it available when needed by Digital forensic investigators which eventually saves cost and time. A generic DFR model for BYOD using honeypot technology is the main focus of this paper.

  • a generic Digital forensic readiness model for byod using honeypot technology
    IST-Africa Week Conference, 2016
    Co-Authors: Victor R. Kebande, Nickson M. Karie, H.s. Venter
    Abstract:

    Proliferation and mobility trends on Digital devices has seen a significant realization of Bring Your Own Device (BYOD) which is a phenomenon that allows employees in an organizational enterprise network to access computing resources through their personal mobile devices irrespective of their location. This technology has enabled cost effectiveness in organizations through increased accessibility of Digital devices in daily business activities. However, the development of this technology faces a number of security challenges due to lack of effective proactive security model with Digital forensic capability that is able to plan and prepare before Potential security incidents occur in an organization that has allowed BYOD. It is on this premise that the authors have proposed a generic Digital Forensic Readiness (DFR) model that uses honeypot technology to detect and trap Potential security incidents. In this paper, therefore, a significant security model with DFR capability has been proposed. The model is aimed at harvesting, encrypting and Digitally preserving Potential Digital Evidence (PDE) based on the DFR processes and guidelines that have been highlighted in the ISO/IEC 27043: 2015 international standard for information technology, security techniques, incident investigation principles and processes. Finally, the proposed model is meant to reduce the effort required to conduct Digital Forensic Investigation (DFI) by capturing Potential Digital Evidence and make it available when needed by Digital forensic investigators which eventually saves cost and time. A generic DFR model for BYOD using honeypot technology is the main focus of this paper.

  • Towards a framework for enhancing Potential Digital Evidence presentation
    2013 Information Security for South Africa, 2013
    Co-Authors: Nickson M. Karie, H.s. Venter
    Abstract:

    In the case of Digital forensic investigations, the Potential Digital Evidence captured, the analysis, interpretation, and attribution must ultimately be presented in the form of expert reports, depositions, and testimony in any legal proceedings. If the presentation and interpretation of the Potential Digital Evidence is conducted correctly, it is much easier and useful in apprehending the attacker and stands a much greater chance of being admissible in the event of a prosecution. Wrongly presented and interpreted Potential Digital Evidence data might create loopholes for perpetrators to exploit, thus, making it hard to convict and prosecute them. Existing Digital forensic investigation process models have provided guidelines for identifying and preserving Potential Digital Evidence captured from a crime scene. However, the extent to which such Potential Digital Evidence may be admissible in a court of law remains a challenge to investigators. This is backed up by the fact that there are currently no standardised guidelines for even presenting the most common representations of Digital forensic Evidence. Therefore, in the authors' opinion, methodologies and specifications need to be developed in the field of Digital forensics with the ability to effectively enhance the Potential Digital Evidence presentation and interpretation in any legal proceedings. In this paper, therefore, we present a step-by-step framework in an attempt to propose high-level guidelines for enhancing the Potential Digital Evidence presentation in any legal proceedings. Such a framework will be helpful to Digital forensic experts, for example, in structuring investigation findings as well as in identifying relevant patterns of events to be incorporated during the presentation of Potential Digital Evidence. The framework will also assist law enforcement agencies, for example, to determine, with less effort, the validity, weight and admissibility of any Potential Digital Evidence presented. However, it should be noted that the purpose of this paper is not to replace any of the extensive and known Evidence presentation principles, but serves as a survey of the state of the art of the research area while proposing harmonised and high-level guidelines for enhancing the presentation of Potential Digital Evidence in legal proceedings.

Richard Adeyemi Ikuesan - One of the best experts on this subject based on the ideXlab platform.

  • Proactive Forensics: Keystroke Logging from the Cloud as Potential Digital Evidence for Forensic Readiness Purposes
    2020 IEEE International Conference on Informatics IoT and Enabling Technologies (ICIoT), 2020
    Co-Authors: Sheunesu M Makura, Victor R. Kebande, Richard Adeyemi Ikuesan, Hein S. Venter, Nickson M. Karie
    Abstract:

    The relationship between negative and positive connotations with regard to malware in the cloud is rarely investigated according to the prevailing literature. However, there is a significant relationship between the use of positive and negative connotations. A clear distinction between the two emanates when we use the originally considered malicious code, for positive connotation like in the case of capturing keystrokes in a proactive forensic purpose. This is done during the collection of Digital Evidence for Digital Forensic Readiness (DFR) purposes, in preparation of a Digital Forensic Investigation (DFI) process. The paper explores the problem of having to use the keystrokes for positive reasons as a piece of Potential Evidence through extraction and Digitally preserving it as highlighted in ISO/IEC 27037: 2012 (security approaches) and ISO/IEC 27043: 2015 (legal connotations). In this paper, therefore, the authors present a technique of how DFR can be achieved through the collection of Digital information from the originally considered malicious code. This is achieved without modifying the cloud operations or the infrastructure thereof, while preserving the integrity of Digital information and possibly maintain the chain of custody at the same time. The paper proposes that the threshold of malicious code intrusion in the cloud can be transformed to an efficacious process of DFR through logical acquisition and Digitally preserving keystrokes. The experiment-tested keystrokes have shown a significant approach that could achieve proactive forensics.

  • A Review of Mobile Forensic Investigation Process Models
    IEEE Access, 2020
    Co-Authors: Arafat Al-dhaqm, Victor R. Kebande, Richard Adeyemi Ikuesan, Shukor Abd Razak, Kamran Siddique
    Abstract:

    Mobile Forensics (MF) field uses prescribed scientific approaches with a focus on recovering Potential Digital Evidence (PDE) from mobile devices leveraging forensic techniques. Consequently, increased proliferation, mobile-based services, and the need for new requirements have led to the development of the MF field, which has in the recent past become an area of importance. In this article, the authors take a step to conduct a review on Mobile Forensics Investigation Process Models (MFIPMs) as a step towards uncovering the MF transitions as well as identifying open and future challenges. Based on the study conducted in this article, a review of the literature revealed that there are a few MFIPMs that are designed for solving certain mobile scenarios, with a variety of concepts, investigation processes, activities, and tasks. A total of 100 MFIPMs were reviewed, to present an inclusive and up-to-date background of MFIPMs. Also, this study proposes a Harmonized Mobile Forensic Investigation Process Model (HMFIPM) for the MF field to unify and structure whole redundant investigation processes of the MF field. The paper also goes the extra mile to discuss the state of the art of mobile forensic tools, open and future challenges from a generic standpoint. The results of this study find direct relevance to forensic practitioners and researchers who could leverage the comprehensiveness of the developed processes for investigation.