Mobile devices and virtualized appliances in the Internet of Things can be end nodes on varying networks owned by different parties over time, while still seamlessly participating in licit or illicit activities. Digital Forensics and Incident Response (DFIR) tools today struggle to perform digital investigations in such loosely controlled networked environments as they face several challenges including: scarcity of resources, availability, trust, privacy, data volumes, velocity and variety. In this paper we analyze the state of research in DFIR in networked environments, identifying the challenges facing DFIR tools particularly in loosely controlled network environments. We present the requirements for a system to address these challenges at the various steps of the typical digital investigation methodology. From this we identify the need for support from Peer to Peer (P2P) overlays and discuss their relative merits and drawbacks in order to identify those that would best support DFIR in loosely controlled networked environments. Finally we incorporate both structured and unstructured P2P overlays in various capacities in our architecture in order to organize devices in loosely controlled networks, using context information, thus enabling efficient capture, analysis and reporting of artifacts of use in digital investigations.
목차
Abstract 1. Introduction 1.1. Defining Loosely Controlled Networked Environments 1.2. Control in Cloud Infrastructures, Mobile Devices and Ad hoc installations 1.3. The Need for Independently Controlled DFIR Mechanisms 1.4. Contribution 1.5. Overview 2. Background and Related Work 2.1. Digital Forensics and Incident Response in Networked Environments 2.2. Incident and Investigation Information Management and Exchange 2.3. Peer to Peer Architectures 3. Requirements and Challenges 3.1. Digital Forensics and Incident Response Functionality 3.2. Security Considerations Around the Digital Forensics Process 3.3. Distributed Systems and “Big Data” Concerns 4. Peer to Peer Overlay Considerations for Supporting DFIR 4.1. Triage and Evidence Identification 4.2. Evidence Acquisition 4.3. Analysis 4.4. Reporting 4.5. Remediation 5. An Architecture for DFIR in Loosely Controlled Environments 5.1. The LEIA Architecture 5.2. Support for Loosely Controlled Networked Environments 6. Conclusions 7. Future Work References
보안공학연구지원센터(IJSIA) [Science & Engineering Research Support Center, Republic of Korea(IJSIA)]
설립연도
2006
분야
공학>컴퓨터학
소개
1. 보안공학에 대한 각종 조사 및 연구
2. 보안공학에 대한 응용기술 연구 및 발표
3. 보안공학에 관한 각종 학술 발표회 및 전시회 개최
4. 보안공학 기술의 상호 협조 및 정보교환
5. 보안공학에 관한 표준화 사업 및 규격의 제정
6. 보안공학에 관한 산학연 협동의 증진
7. 국제적 학술 교류 및 기술 협력
8. 보안공학에 관한 논문지 발간
9. 기타 본 회 목적 달성에 필요한 사업
간행물
간행물명
International Journal of Security and Its Applications
간기
격월간
pISSN
1738-9976
수록기간
2008~2016
등재여부
SCOPUS
십진분류
KDC 505DDC 605
이 권호 내 다른 논문 / International Journal of Security and Its Applications Vol.10 No.1