Proactive System for Digital Forensic Investigation

dc.contributor.authorAlharbi, Soltan Abed
dc.contributor.supervisorWeber, Jens
dc.contributor.supervisorIssa, Traore
dc.date.accessioned2014-04-07T21:25:58Z
dc.date.available2014-04-07T21:25:58Z
dc.date.copyright2014en_US
dc.date.issued2014-04-07
dc.degree.departmentDepartment of Electrical and Computer Engineeringen_US
dc.degree.levelDoctor of Philosophy Ph.D.en_US
dc.description.abstractDigital Forensics (DF) is defined as the ensemble of methods, tools and techniques used to collect, preserve and analyse digital data originating from any type of digital media involved in an incident with the purpose of extracting valid evidence for a court of law. DF investigations are usually performed as a response to a digital crime and, as such, they are termed Reactive Digital Forensic (RDF). An RDF investigation takes the traditional (or post-mortem) approach of investigating digital crimes after incidents have occurred. This involves identifying, preserving, collecting, analyzing, and generating the final report. Although RDF investigations are effective, they are faced with many challenges, especially when dealing with anti-forensic incidents, volatile data and event reconstruction. To tackle these challenges, Proactive Digital Forensic (PDF) is required. By being proactive, DF is prepared for incidents. In fact, the PDF investigation has the ability to proactively collect data, preserve it, detect suspicious events, analyze evidence and report an incident as it occurs. This dissertation focuses on the detection and analysis phase of the proactive investigation system, as it is the most expensive phase of the system. In addition, theories behind such systems will be discussed. Finally, implementation of the whole proactive system will be tested on a botnet use case (Zeus).en_US
dc.description.proquestcode0984en_US
dc.description.proquestcode0537en_US
dc.description.proquestemailsoltanalharbi@hotmail.comen_US
dc.description.scholarlevelGraduateen_US
dc.identifier.bibliographicCitationSoltan Alharbi, Belaid Moa, Jens Weber-Jahnke, and Issa Traore. High performance proactive digital forensics. In Journal of Physics: Conference Series, volume 385, pages 01–15. IOP Publishing, 2012.en_US
dc.identifier.bibliographicCitationSoltan Alharbi, Jens Weber-Jahnke, and Issa Traore. The proactive and reactive digital forensics investigation process: A systematic literature review. In Information Security and Assurance, pages 87–100. Springer, 2011.en_US
dc.identifier.bibliographicCitationS.A. Soltan Alharbi, J.W.J. JensWeber-Jahnke, and I.T. Issa Traore. The proactive and reactive digital forensics investigation process: A systematic literature review. International Journal of Security and Its Applications, 5(4):59–72, 2011.en_US
dc.identifier.urihttp://hdl.handle.net/1828/5237
dc.languageEnglisheng
dc.language.isoenen_US
dc.rights.tempAvailable to the World Wide Weben_US
dc.rights.urihttp://creativecommons.org/publicdomain/zero/1.0/*
dc.subjectDigital Forensicsen_US
dc.subjectReactive Digital Forensicen_US
dc.subjectProactive Digital Forensicen_US
dc.titleProactive System for Digital Forensic Investigationen_US
dc.typeThesisen_US

Files

Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Alharbi_Soltan_PhD_2014.pdf
Size:
4.94 MB
Format:
Adobe Portable Document Format
Description:
License bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
1.74 KB
Format:
Item-specific license agreed upon to submission
Description: