earticle

논문검색

Improving Distributed Forensics and Incident Response in Loosely Controlled Networked Environments

초록

영어

Mobile devices and virtualized appliances in the Internet of Things can be end nodes on varying networks owned by different parties over time, while still seamlessly participating in licit or illicit activities. Digital Forensics and Incident Response (DFIR) tools today struggle to perform digital investigations in such loosely controlled networked environments as they face several challenges including: scarcity of resources, availability, trust, privacy, data volumes, velocity and variety. In this paper we analyze the state of research in DFIR in networked environments, identifying the challenges facing DFIR tools particularly in loosely controlled network environments. We present the requirements for a system to address these challenges at the various steps of the typical digital investigation methodology. From this we identify the need for support from Peer to Peer (P2P) overlays and discuss their relative merits and drawbacks in order to identify those that would best support DFIR in loosely controlled networked environments. Finally we incorporate both structured and unstructured P2P overlays in various capacities in our architecture in order to organize devices in loosely controlled networks, using context information, thus enabling efficient capture, analysis and reporting of artifacts of use in digital investigations.

목차

Abstract
 1. Introduction
  1.1. Defining Loosely Controlled Networked Environments
  1.2. Control in Cloud Infrastructures, Mobile Devices and Ad hoc installations
  1.3. The Need for Independently Controlled DFIR Mechanisms
  1.4. Contribution
  1.5. Overview
 2. Background and Related Work
  2.1. Digital Forensics and Incident Response in Networked Environments
  2.2. Incident and Investigation Information Management and Exchange
  2.3. Peer to Peer Architectures
 3. Requirements and Challenges
  3.1. Digital Forensics and Incident Response Functionality
  3.2. Security Considerations Around the Digital Forensics Process
  3.3. Distributed Systems and “Big Data” Concerns
 4. Peer to Peer Overlay Considerations for Supporting DFIR
  4.1. Triage and Evidence Identification
  4.2. Evidence Acquisition
  4.3. Analysis
  4.4. Reporting
  4.5. Remediation
 5. An Architecture for DFIR in Loosely Controlled Environments
  5.1. The LEIA Architecture
  5.2. Support for Loosely Controlled Networked Environments
 6. Conclusions
 7. Future Work
 References

저자정보

  • Irvin Homem Stockholm University, Post Box 7003, 164 07, Kista, Sweden
  • Theo Kanter Stockholm University, Post Box 7003, 164 07, Kista, Sweden
  • Rahim Rahmani Stockholm University, Post Box 7003, 164 07, Kista, Sweden

참고문헌

자료제공 : 네이버학술정보

    함께 이용한 논문

      ※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

      0개의 논문이 장바구니에 담겼습니다.