Digital Forensics Subdomains: The State of the Art and Future Directions

For reliable digital evidence to be admitted in a court of law, it is important to apply scientifically proven digital forensic investigation techniques to corroborate a suspected security incident. Mainly, traditional digital forensics techniques focus on computer desktops and servers. However, rec...

Full description

Bibliographic Details
Main Authors: Arafat Al-Dhaqm, Richard Adeyemi Ikuesan, Victor R. Kebande, Shukor Abd Razak, George Grispos, Kim-Kwang Raymond Choo, Bander Ali Saleh Al-Rimy, Abdulrahman A. Alsewari
Format: Article
Language:English
Published: IEEE 2021-01-01
Series:IEEE Access
Subjects:
Online Access:https://ieeexplore.ieee.org/document/9594835/
_version_ 1811273971671236608
author Arafat Al-Dhaqm
Richard Adeyemi Ikuesan
Victor R. Kebande
Shukor Abd Razak
George Grispos
Kim-Kwang Raymond Choo
Bander Ali Saleh Al-Rimy
Abdulrahman A. Alsewari
author_facet Arafat Al-Dhaqm
Richard Adeyemi Ikuesan
Victor R. Kebande
Shukor Abd Razak
George Grispos
Kim-Kwang Raymond Choo
Bander Ali Saleh Al-Rimy
Abdulrahman A. Alsewari
author_sort Arafat Al-Dhaqm
collection DOAJ
description For reliable digital evidence to be admitted in a court of law, it is important to apply scientifically proven digital forensic investigation techniques to corroborate a suspected security incident. Mainly, traditional digital forensics techniques focus on computer desktops and servers. However, recent advances in digital media and platforms have seen an increased need for the application of digital forensic investigation techniques to other subdomains. This includes mobile devices, databases, networks, cloud-based platforms, and the Internet of Things (IoT) at large. To assist forensic investigators to conduct investigations within these subdomains, academic researchers have attempted to develop several investigative processes. However, many of these processes are domain-specific or describe domain-specific investigative tools. Hence, in this paper, we hypothesize that the literature is saturated with ambiguities. To further synthesize this hypothesis, a digital forensic model-orientated Systematic Literature Review (SLR) within the digital forensic subdomains has been undertaken. The purpose of this SLR is to identify the different and heterogeneous practices that have emerged within the specific digital forensics subdomains. A key finding from this review is that there are process redundancies and a high degree of ambiguity among investigative processes in the various subdomains. As a way forward, this study proposes a high-level abstract metamodel, which combines the common investigation processes, activities, techniques, and tasks for digital forensics subdomains. Using the proposed solution, an investigator can effectively organize the knowledge process for digital investigation.
first_indexed 2024-04-12T23:09:16Z
format Article
id doaj.art-42e5dcde5c244180a3fced59c3e5f64d
institution Directory Open Access Journal
issn 2169-3536
language English
last_indexed 2024-04-12T23:09:16Z
publishDate 2021-01-01
publisher IEEE
record_format Article
series IEEE Access
spelling doaj.art-42e5dcde5c244180a3fced59c3e5f64d2022-12-22T03:12:50ZengIEEEIEEE Access2169-35362021-01-01915247615250210.1109/ACCESS.2021.31242629594835Digital Forensics Subdomains: The State of the Art and Future DirectionsArafat Al-Dhaqm0https://orcid.org/0000-0002-0729-2654Richard Adeyemi Ikuesan1https://orcid.org/0000-0001-7355-2314Victor R. Kebande2https://orcid.org/0000-0003-4071-4596Shukor Abd Razak3https://orcid.org/0000-0002-8824-6069George Grispos4https://orcid.org/0000-0003-3468-0182Kim-Kwang Raymond Choo5https://orcid.org/0000-0001-9208-5336Bander Ali Saleh Al-Rimy6https://orcid.org/0000-0003-3048-5961Abdulrahman A. Alsewari7https://orcid.org/0000-0002-7802-6628Faculty of Engineering, School of Computing, Universiti Teknologi Malaysia (UTM), Johor, MalaysiaDepartment of Cybersecurity and Networking, School of Information Technology, Community College of Qatar, Doha, QatarDepartment of Computer Science (DIDA), Blekinge Institute of Technology, Karlskrona, SwedenFaculty of Engineering, School of Computing, Universiti Teknologi Malaysia (UTM), Johor, MalaysiaSchool of Interdisciplinary Informatics, University of Nebraska at Omaha, Omaha, NE, USADepartment of Information Systems and Cyber Security, The University of Texas at San Antonio, San Antonio, TX, USAFaculty of Engineering, School of Computing, Universiti Teknologi Malaysia (UTM), Johor, MalaysiaIBM Centre of Excellence, Faculty of Computing, Universiti Malaysia Pahang, Pahang, MalaysiaFor reliable digital evidence to be admitted in a court of law, it is important to apply scientifically proven digital forensic investigation techniques to corroborate a suspected security incident. Mainly, traditional digital forensics techniques focus on computer desktops and servers. However, recent advances in digital media and platforms have seen an increased need for the application of digital forensic investigation techniques to other subdomains. This includes mobile devices, databases, networks, cloud-based platforms, and the Internet of Things (IoT) at large. To assist forensic investigators to conduct investigations within these subdomains, academic researchers have attempted to develop several investigative processes. However, many of these processes are domain-specific or describe domain-specific investigative tools. Hence, in this paper, we hypothesize that the literature is saturated with ambiguities. To further synthesize this hypothesis, a digital forensic model-orientated Systematic Literature Review (SLR) within the digital forensic subdomains has been undertaken. The purpose of this SLR is to identify the different and heterogeneous practices that have emerged within the specific digital forensics subdomains. A key finding from this review is that there are process redundancies and a high degree of ambiguity among investigative processes in the various subdomains. As a way forward, this study proposes a high-level abstract metamodel, which combines the common investigation processes, activities, techniques, and tasks for digital forensics subdomains. Using the proposed solution, an investigator can effectively organize the knowledge process for digital investigation.https://ieeexplore.ieee.org/document/9594835/Digital forensicsdatabase forensicsmobile forensicnetwork forensicsIoT forensicsdigital forensic metamodel
spellingShingle Arafat Al-Dhaqm
Richard Adeyemi Ikuesan
Victor R. Kebande
Shukor Abd Razak
George Grispos
Kim-Kwang Raymond Choo
Bander Ali Saleh Al-Rimy
Abdulrahman A. Alsewari
Digital Forensics Subdomains: The State of the Art and Future Directions
IEEE Access
Digital forensics
database forensics
mobile forensic
network forensics
IoT forensics
digital forensic metamodel
title Digital Forensics Subdomains: The State of the Art and Future Directions
title_full Digital Forensics Subdomains: The State of the Art and Future Directions
title_fullStr Digital Forensics Subdomains: The State of the Art and Future Directions
title_full_unstemmed Digital Forensics Subdomains: The State of the Art and Future Directions
title_short Digital Forensics Subdomains: The State of the Art and Future Directions
title_sort digital forensics subdomains the state of the art and future directions
topic Digital forensics
database forensics
mobile forensic
network forensics
IoT forensics
digital forensic metamodel
url https://ieeexplore.ieee.org/document/9594835/
work_keys_str_mv AT arafataldhaqm digitalforensicssubdomainsthestateoftheartandfuturedirections
AT richardadeyemiikuesan digitalforensicssubdomainsthestateoftheartandfuturedirections
AT victorrkebande digitalforensicssubdomainsthestateoftheartandfuturedirections
AT shukorabdrazak digitalforensicssubdomainsthestateoftheartandfuturedirections
AT georgegrispos digitalforensicssubdomainsthestateoftheartandfuturedirections
AT kimkwangraymondchoo digitalforensicssubdomainsthestateoftheartandfuturedirections
AT banderalisalehalrimy digitalforensicssubdomainsthestateoftheartandfuturedirections
AT abdulrahmanaalsewari digitalforensicssubdomainsthestateoftheartandfuturedirections