Earticle

현재 위치 Home

Improving Distributed Forensics and Incident Response in Loosely Controlled Networked Environments

첫 페이지 보기
  • 발행기관
    보안공학연구지원센터(IJSIA) 바로가기
  • 간행물
    International Journal of Security and Its Applications SCOPUS 바로가기
  • 통권
    Vol.10 No.1 (2016.01)바로가기
  • 페이지
    pp.385-414
  • 저자
    Irvin Homem, Theo Kanter, Rahim Rahmani
  • 언어
    영어(ENG)
  • URL
    https://www.earticle.net/Article/A269908

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

원문정보

초록

영어
Mobile devices and virtualized appliances in the Internet of Things can be end nodes on varying networks owned by different parties over time, while still seamlessly participating in licit or illicit activities. Digital Forensics and Incident Response (DFIR) tools today struggle to perform digital investigations in such loosely controlled networked environments as they face several challenges including: scarcity of resources, availability, trust, privacy, data volumes, velocity and variety. In this paper we analyze the state of research in DFIR in networked environments, identifying the challenges facing DFIR tools particularly in loosely controlled network environments. We present the requirements for a system to address these challenges at the various steps of the typical digital investigation methodology. From this we identify the need for support from Peer to Peer (P2P) overlays and discuss their relative merits and drawbacks in order to identify those that would best support DFIR in loosely controlled networked environments. Finally we incorporate both structured and unstructured P2P overlays in various capacities in our architecture in order to organize devices in loosely controlled networks, using context information, thus enabling efficient capture, analysis and reporting of artifacts of use in digital investigations.

목차

Abstract
 1. Introduction
  1.1. Defining Loosely Controlled Networked Environments
  1.2. Control in Cloud Infrastructures, Mobile Devices and Ad hoc installations
  1.3. The Need for Independently Controlled DFIR Mechanisms
  1.4. Contribution
  1.5. Overview
 2. Background and Related Work
  2.1. Digital Forensics and Incident Response in Networked Environments
  2.2. Incident and Investigation Information Management and Exchange
  2.3. Peer to Peer Architectures
 3. Requirements and Challenges
  3.1. Digital Forensics and Incident Response Functionality
  3.2. Security Considerations Around the Digital Forensics Process
  3.3. Distributed Systems and “Big Data” Concerns
 4. Peer to Peer Overlay Considerations for Supporting DFIR
  4.1. Triage and Evidence Identification
  4.2. Evidence Acquisition
  4.3. Analysis
  4.4. Reporting
  4.5. Remediation
 5. An Architecture for DFIR in Loosely Controlled Environments
  5.1. The LEIA Architecture
  5.2. Support for Loosely Controlled Networked Environments
 6. Conclusions
 7. Future Work
 References

저자

  • Irvin Homem [ Stockholm University, Post Box 7003, 164 07, Kista, Sweden ] Corresponding Author
  • Theo Kanter [ Stockholm University, Post Box 7003, 164 07, Kista, Sweden ]
  • Rahim Rahmani [ Stockholm University, Post Box 7003, 164 07, Kista, Sweden ]

참고문헌

자료제공 : 네이버학술정보

간행물 정보

발행기관

  • 발행기관명
    보안공학연구지원센터(IJSIA) [Science & Engineering Research Support Center, Republic of Korea(IJSIA)]
  • 설립연도
    2006
  • 분야
    공학>컴퓨터학
  • 소개
    1. 보안공학에 대한 각종 조사 및 연구 2. 보안공학에 대한 응용기술 연구 및 발표 3. 보안공학에 관한 각종 학술 발표회 및 전시회 개최 4. 보안공학 기술의 상호 협조 및 정보교환 5. 보안공학에 관한 표준화 사업 및 규격의 제정 6. 보안공학에 관한 산학연 협동의 증진 7. 국제적 학술 교류 및 기술 협력 8. 보안공학에 관한 논문지 발간 9. 기타 본 회 목적 달성에 필요한 사업

간행물

  • 간행물명
    International Journal of Security and Its Applications
  • 간기
    격월간
  • pISSN
    1738-9976
  • 수록기간
    2008~2016
  • 등재여부
    SCOPUS
  • 십진분류
    KDC 505 DDC 605

이 권호 내 다른 논문 / International Journal of Security and Its Applications Vol.10 No.1

    피인용수 : 0(자료제공 : 네이버학술정보)

    함께 이용한 논문 이 논문을 다운로드한 분들이 이용한 다른 논문입니다.

      페이지 저장