Digital Forensics Subdomains: The State of the Art and Future Directions
For reliable digital evidence to be admitted in a court of law, it is important to apply scientifically proven digital forensic investigation techniques to corroborate a suspected security incident. Mainly, traditional digital forensics techniques focus on computer desktops and servers. However, rec...
Main Authors: | , , , , , , , |
---|---|
Format: | Article |
Language: | English |
Published: |
IEEE
2021-01-01
|
Series: | IEEE Access |
Subjects: | |
Online Access: | https://ieeexplore.ieee.org/document/9594835/ |
_version_ | 1811273971671236608 |
---|---|
author | Arafat Al-Dhaqm Richard Adeyemi Ikuesan Victor R. Kebande Shukor Abd Razak George Grispos Kim-Kwang Raymond Choo Bander Ali Saleh Al-Rimy Abdulrahman A. Alsewari |
author_facet | Arafat Al-Dhaqm Richard Adeyemi Ikuesan Victor R. Kebande Shukor Abd Razak George Grispos Kim-Kwang Raymond Choo Bander Ali Saleh Al-Rimy Abdulrahman A. Alsewari |
author_sort | Arafat Al-Dhaqm |
collection | DOAJ |
description | For reliable digital evidence to be admitted in a court of law, it is important to apply scientifically proven digital forensic investigation techniques to corroborate a suspected security incident. Mainly, traditional digital forensics techniques focus on computer desktops and servers. However, recent advances in digital media and platforms have seen an increased need for the application of digital forensic investigation techniques to other subdomains. This includes mobile devices, databases, networks, cloud-based platforms, and the Internet of Things (IoT) at large. To assist forensic investigators to conduct investigations within these subdomains, academic researchers have attempted to develop several investigative processes. However, many of these processes are domain-specific or describe domain-specific investigative tools. Hence, in this paper, we hypothesize that the literature is saturated with ambiguities. To further synthesize this hypothesis, a digital forensic model-orientated Systematic Literature Review (SLR) within the digital forensic subdomains has been undertaken. The purpose of this SLR is to identify the different and heterogeneous practices that have emerged within the specific digital forensics subdomains. A key finding from this review is that there are process redundancies and a high degree of ambiguity among investigative processes in the various subdomains. As a way forward, this study proposes a high-level abstract metamodel, which combines the common investigation processes, activities, techniques, and tasks for digital forensics subdomains. Using the proposed solution, an investigator can effectively organize the knowledge process for digital investigation. |
first_indexed | 2024-04-12T23:09:16Z |
format | Article |
id | doaj.art-42e5dcde5c244180a3fced59c3e5f64d |
institution | Directory Open Access Journal |
issn | 2169-3536 |
language | English |
last_indexed | 2024-04-12T23:09:16Z |
publishDate | 2021-01-01 |
publisher | IEEE |
record_format | Article |
series | IEEE Access |
spelling | doaj.art-42e5dcde5c244180a3fced59c3e5f64d2022-12-22T03:12:50ZengIEEEIEEE Access2169-35362021-01-01915247615250210.1109/ACCESS.2021.31242629594835Digital Forensics Subdomains: The State of the Art and Future DirectionsArafat Al-Dhaqm0https://orcid.org/0000-0002-0729-2654Richard Adeyemi Ikuesan1https://orcid.org/0000-0001-7355-2314Victor R. Kebande2https://orcid.org/0000-0003-4071-4596Shukor Abd Razak3https://orcid.org/0000-0002-8824-6069George Grispos4https://orcid.org/0000-0003-3468-0182Kim-Kwang Raymond Choo5https://orcid.org/0000-0001-9208-5336Bander Ali Saleh Al-Rimy6https://orcid.org/0000-0003-3048-5961Abdulrahman A. Alsewari7https://orcid.org/0000-0002-7802-6628Faculty of Engineering, School of Computing, Universiti Teknologi Malaysia (UTM), Johor, MalaysiaDepartment of Cybersecurity and Networking, School of Information Technology, Community College of Qatar, Doha, QatarDepartment of Computer Science (DIDA), Blekinge Institute of Technology, Karlskrona, SwedenFaculty of Engineering, School of Computing, Universiti Teknologi Malaysia (UTM), Johor, MalaysiaSchool of Interdisciplinary Informatics, University of Nebraska at Omaha, Omaha, NE, USADepartment of Information Systems and Cyber Security, The University of Texas at San Antonio, San Antonio, TX, USAFaculty of Engineering, School of Computing, Universiti Teknologi Malaysia (UTM), Johor, MalaysiaIBM Centre of Excellence, Faculty of Computing, Universiti Malaysia Pahang, Pahang, MalaysiaFor reliable digital evidence to be admitted in a court of law, it is important to apply scientifically proven digital forensic investigation techniques to corroborate a suspected security incident. Mainly, traditional digital forensics techniques focus on computer desktops and servers. However, recent advances in digital media and platforms have seen an increased need for the application of digital forensic investigation techniques to other subdomains. This includes mobile devices, databases, networks, cloud-based platforms, and the Internet of Things (IoT) at large. To assist forensic investigators to conduct investigations within these subdomains, academic researchers have attempted to develop several investigative processes. However, many of these processes are domain-specific or describe domain-specific investigative tools. Hence, in this paper, we hypothesize that the literature is saturated with ambiguities. To further synthesize this hypothesis, a digital forensic model-orientated Systematic Literature Review (SLR) within the digital forensic subdomains has been undertaken. The purpose of this SLR is to identify the different and heterogeneous practices that have emerged within the specific digital forensics subdomains. A key finding from this review is that there are process redundancies and a high degree of ambiguity among investigative processes in the various subdomains. As a way forward, this study proposes a high-level abstract metamodel, which combines the common investigation processes, activities, techniques, and tasks for digital forensics subdomains. Using the proposed solution, an investigator can effectively organize the knowledge process for digital investigation.https://ieeexplore.ieee.org/document/9594835/Digital forensicsdatabase forensicsmobile forensicnetwork forensicsIoT forensicsdigital forensic metamodel |
spellingShingle | Arafat Al-Dhaqm Richard Adeyemi Ikuesan Victor R. Kebande Shukor Abd Razak George Grispos Kim-Kwang Raymond Choo Bander Ali Saleh Al-Rimy Abdulrahman A. Alsewari Digital Forensics Subdomains: The State of the Art and Future Directions IEEE Access Digital forensics database forensics mobile forensic network forensics IoT forensics digital forensic metamodel |
title | Digital Forensics Subdomains: The State of the Art and Future Directions |
title_full | Digital Forensics Subdomains: The State of the Art and Future Directions |
title_fullStr | Digital Forensics Subdomains: The State of the Art and Future Directions |
title_full_unstemmed | Digital Forensics Subdomains: The State of the Art and Future Directions |
title_short | Digital Forensics Subdomains: The State of the Art and Future Directions |
title_sort | digital forensics subdomains the state of the art and future directions |
topic | Digital forensics database forensics mobile forensic network forensics IoT forensics digital forensic metamodel |
url | https://ieeexplore.ieee.org/document/9594835/ |
work_keys_str_mv | AT arafataldhaqm digitalforensicssubdomainsthestateoftheartandfuturedirections AT richardadeyemiikuesan digitalforensicssubdomainsthestateoftheartandfuturedirections AT victorrkebande digitalforensicssubdomainsthestateoftheartandfuturedirections AT shukorabdrazak digitalforensicssubdomainsthestateoftheartandfuturedirections AT georgegrispos digitalforensicssubdomainsthestateoftheartandfuturedirections AT kimkwangraymondchoo digitalforensicssubdomainsthestateoftheartandfuturedirections AT banderalisalehalrimy digitalforensicssubdomainsthestateoftheartandfuturedirections AT abdulrahmanaalsewari digitalforensicssubdomainsthestateoftheartandfuturedirections |