A Comprehensive and Harmonized Digital Forensic Investigation Process Model

被引:25
|
作者
Valjarevic, Aleksandar [1 ]
Venter, Hein S. [1 ]
机构
[1] Univ Pretoria, Dept Comp Sci, ZA-0002 Pretoria, South Africa
关键词
forensic science; digital forensics; digital evidence; investigation; process; model; harmonization; standardization;
D O I
10.1111/1556-4029.12823
中图分类号
DF [法律]; D9 [法律]; R [医药、卫生];
学科分类号
0301 ; 10 ;
摘要
Performing a digital forensic investigation (DFI) requires a standardized and formalized process. There is currently neither an international standard nor does a global, harmonized DFI process (DFIP) exist. The authors studied existing state-of-the-art DFIP models and concluded that there are significant disparities pertaining to the number of processes, the scope, the hierarchical levels, and concepts applied. This paper proposes a comprehensive model that harmonizes existing models. An effort was made to incorporate all types of processes proposed by the existing models, including those aimed at achieving digital forensic readiness. The authors introduce a novel class of processes called concurrent processes. This is a novel contribution that should, together with the rest of the model, enable more efficient and effective DFI, while ensuring admissibility of digital evidence. Ultimately, the proposed model is intended to be used for different types of DFI and should lead to standardization.
引用
收藏
页码:1467 / 1483
页数:17
相关论文
共 50 条
  • [41] Forensic Recovery of File System Metadata for Digital Forensic Investigation
    Oh, Junghoon
    Lee, Sangjin
    Hwang, Hyunuk
    IEEE ACCESS, 2022, 10 : 111591 - 111606
  • [42] IMPLEMENTING THE HARMONIZED MODEL FOR DIGITAL EVIDENCE ADMISSIBILITY ASSESSMENT
    Antwi-Boasiako, Albert
    Venter, Hein
    ADVANCES IN DIGITAL FORENSICS XV, 2019, 569 : 19 - 36
  • [43] A log correlation model to support the evidence search process in a forensic investigation
    Herrerias, Jorge
    Gomez, Roberto
    SADFE 2007: SECOND INTERNATIONAL WORKSHOP ON SYSTEMATIC APPROACHES TO DIGITAL FORENSIC ENGINEERING, PROCEEDINGS, 2007, : 31 - 39
  • [44] Evaluation and Analysis of a Software Prototype for Guidance and Implementation of a Standardized Digital Forensic Investigation Process
    Ingels, Melissa
    Valjarevic, Aleksandar
    Venter, Hein S.
    2015 INFORMATION SECURITY FOR SOUTH AFRICA - PROCEEDINGS OF THE ISSA 2015 CONFERENCE, 2015,
  • [45] ON THE ISSUE OF CREATING A DIGITAL FORENSIC MODEL FOR COLLECTING ELECTRONIC EVIDENCE IN THE INVESTIGATION OF CYBERCRIMES
    Musaeva, Ulduz A.
    Nguyen, Thi Binh
    Nguyen, Thi Huen Chang
    Svetlichny, Alexander A.
    Tolstukhina, Tatyana V.
    Tew, Van Hung
    RUSSIAN JOURNAL OF CRIMINOLOGY, 2024, 18 (04): : 398 - 411
  • [46] The Case for Validating ADDIE Model as a Digital Forensic Model for Peer-to-Peer Network Investigation
    Musa, Ahmad Sanda
    Awan, Irfan-Ullah
    Zahrah, Fatima
    INFORMATION SYSTEMS FRONTIERS, 2022, 26 (6) : 2305 - 2321
  • [47] TRACEMAP: A Traceability Model for the Digital Forensics Investigation Process
    Selamat, Siti Rahayu
    Ahmad, Sharifah Sakinah Syed
    Masud, Mohd Zaki
    Hassan, Nor Hafeizah
    Sahib, Shahrin
    2017 IEEE CONFERENCE ON APPLICATION, INFORMATION AND NETWORK SECURITY (AINS), 2017, : 25 - 30
  • [48] Prototyping SMS Forensic Tool Application Based On Digital Forensic Research Workshop 2001 (DFRWS) Investigation Model
    Rahaditya, Jordi
    Gde, A. A.
    Sasmita, Arya
    Made, Gusti
    Pratama, Eka
    Agus, I. Putu
    PROCEEDINGS OF 2016 INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY SYSTEMS AND INNOVATION (ICITSI), 2016,
  • [49] Towards a Model for Characterizing Potential Digital Evidence in the Cloud Environment During Digital Forensic Readiness Process
    Kebande, Victor
    Venter, Hein
    PROCEEDINGS OF THE 3RD INTERNATIONAL CONFERENCE ON CLOUD SECURITY AND MANAGEMENT (ICCSM-2015), 2015, : 151 - 166
  • [50] Maximizing Investigation Effectiveness in Digital Forensic Cases
    Kalaimannan, Ezhil
    Gupta, Jatinder N. D.
    Yoo, Seong-Moo
    2013 ASE/IEEE INTERNATIONAL CONFERENCE ON SOCIAL COMPUTING (SOCIALCOM), 2013, : 618 - 623