A Game Theoretic Approach for Digital Forensic Tool Selection <sup>†</sup>

Digital forensic investigations are getting harder and more time consuming everyday because of various problems including rapid advances in technology, wide variety of available devices in investigations, and large amount of data to be analyzed. In order to tackle with these issues, digital forensic...

Full description

Bibliographic Details
Main Authors: Umit Karabiyik, Tugba Karabiyik
Format: Article
Language:English
Published: MDPI AG 2020-05-01
Series:Mathematics
Subjects:
Online Access:https://www.mdpi.com/2227-7390/8/5/774
_version_ 1797568246490071040
author Umit Karabiyik
Tugba Karabiyik
author_facet Umit Karabiyik
Tugba Karabiyik
author_sort Umit Karabiyik
collection DOAJ
description Digital forensic investigations are getting harder and more time consuming everyday because of various problems including rapid advances in technology, wide variety of available devices in investigations, and large amount of data to be analyzed. In order to tackle with these issues, digital forensic tools are developed by open-source communities and software companies. These software products are released as a complete toolkit or standalone tools targeting specific tasks. In either case, digital forensic investigators use these tools based on their familiarity because of previous training experiences, available funding from their agencies/businesses, tool’s ease of use, etc. Moreover, using additional tools to verify the findings is a common practice in digital forensic investigations. This is particularly common when the previously selected tools do not generate an expected output. In this paper, we propose a game theoretic approach to the tool selection problem in order to help investigators to make a decision on which digital forensic tool to use. We particularly focused on file carving tool usage when building and analyzing our model because of the available data on these tools. Our results show how important it is to investigate the dynamics of strategy changes between the tools during an investigation to increase the efficiency of the investigation using game theoretic modeling.
first_indexed 2024-03-10T19:53:43Z
format Article
id doaj.art-91e369a90b4d4eeda685e5c3e7700200
institution Directory Open Access Journal
issn 2227-7390
language English
last_indexed 2024-03-10T19:53:43Z
publishDate 2020-05-01
publisher MDPI AG
record_format Article
series Mathematics
spelling doaj.art-91e369a90b4d4eeda685e5c3e77002002023-11-20T00:08:35ZengMDPI AGMathematics2227-73902020-05-018577410.3390/math8050774A Game Theoretic Approach for Digital Forensic Tool Selection <sup>†</sup>Umit Karabiyik0Tugba Karabiyik1Department of Computer and Information Technology, Purdue University, 01 N. Grant St. West Lafayette, IN 47907, USAPolytechnic Institute, Purdue University, 01 N. Grant St. West Lafayette, IN 47907, USADigital forensic investigations are getting harder and more time consuming everyday because of various problems including rapid advances in technology, wide variety of available devices in investigations, and large amount of data to be analyzed. In order to tackle with these issues, digital forensic tools are developed by open-source communities and software companies. These software products are released as a complete toolkit or standalone tools targeting specific tasks. In either case, digital forensic investigators use these tools based on their familiarity because of previous training experiences, available funding from their agencies/businesses, tool’s ease of use, etc. Moreover, using additional tools to verify the findings is a common practice in digital forensic investigations. This is particularly common when the previously selected tools do not generate an expected output. In this paper, we propose a game theoretic approach to the tool selection problem in order to help investigators to make a decision on which digital forensic tool to use. We particularly focused on file carving tool usage when building and analyzing our model because of the available data on these tools. Our results show how important it is to investigate the dynamics of strategy changes between the tools during an investigation to increase the efficiency of the investigation using game theoretic modeling.https://www.mdpi.com/2227-7390/8/5/774game theorygame theoretic modelingdigital forensic toolsdigital investigationsdecision making
spellingShingle Umit Karabiyik
Tugba Karabiyik
A Game Theoretic Approach for Digital Forensic Tool Selection <sup>†</sup>
Mathematics
game theory
game theoretic modeling
digital forensic tools
digital investigations
decision making
title A Game Theoretic Approach for Digital Forensic Tool Selection <sup>†</sup>
title_full A Game Theoretic Approach for Digital Forensic Tool Selection <sup>†</sup>
title_fullStr A Game Theoretic Approach for Digital Forensic Tool Selection <sup>†</sup>
title_full_unstemmed A Game Theoretic Approach for Digital Forensic Tool Selection <sup>†</sup>
title_short A Game Theoretic Approach for Digital Forensic Tool Selection <sup>†</sup>
title_sort game theoretic approach for digital forensic tool selection sup † sup
topic game theory
game theoretic modeling
digital forensic tools
digital investigations
decision making
url https://www.mdpi.com/2227-7390/8/5/774
work_keys_str_mv AT umitkarabiyik agametheoreticapproachfordigitalforensictoolselectionsupsup
AT tugbakarabiyik agametheoreticapproachfordigitalforensictoolselectionsupsup
AT umitkarabiyik gametheoreticapproachfordigitalforensictoolselectionsupsup
AT tugbakarabiyik gametheoreticapproachfordigitalforensictoolselectionsupsup