首页    期刊浏览 2024年12月01日 星期日
登录注册

文章基本信息

  • 标题:Improving Distributed Forensics and Incident Response in Loosely Controlled Networked Environments
  • 本地全文:下载
  • 作者:Irvin Homem ; Theo Kanter ; Rahim Rahmani
  • 期刊名称:International Journal of Security and Its Applications
  • 印刷版ISSN:1738-9976
  • 出版年度:2016
  • 卷号:10
  • 期号:1
  • 页码:385-414
  • DOI:10.14257/ijsia.2016.10.1.35
  • 出版社:SERSC
  • 摘要:Mobile devices and virtualized appliances in the Internet of Things can be end nodes on varying networks owned by different parties over time, while still seamlessly participating in licit or illicit activities. Digital Forensics and Incident Response (DFIR) tools today struggle to perform digital investigations in such loosely controlled networked environments as they face several challenges including: scarcity of resources, availability, trust, privacy, data volumes, velocity and variety. In this paper we analyze the state of research in DFIR in networked environments, identifying the challenges facing DFIR tools particularly in loosely controlled network environments. We present the requirements for a system to address these challenges at the various steps of the typical digital investigation methodology. From this we identify the need for support from Peer to Peer (P2P) overlays and discuss their relative merits and drawbacks in order to identify those that would best support DFIR in loosely controlled networked environments. Finally we incorporate both structured and unstructured P2P overlays in various capacities in our architecture in order to organize devices in loosely controlled networks, using context information, thus enabling efficient capture, analysis and reporting of artifacts of use in digital investigations.
  • 关键词:Digital Forensics; Incident Response; P2P Overlays; Open Distributed Systems; ; Uncontrolled Environment; Internet of Things
国家哲学社会科学文献中心版权所有