Forensics for multi-stage cyber incidents: Survey and future directions

被引:0
|
作者
Nisioti, Antonia [1 ]
Loukas, George [1 ]
Mylonas, Alexios [2 ]
Panaousis, Emmanouil [1 ]
机构
[1] Univ Greenwich, Internet Things & Secur Ctr, London, England
[2] Univ Hertfordshire, Sch Phys Engn & Comp Sci, Hatfield, England
关键词
Cyber forensics; Digital forensics; Multi -stage attacks; Anti; -forensics; Advanced persistent threats; Survey; Review; ADVANCED PERSISTENT THREATS; ANTI-FORENSICS; FRAMEWORK; MODEL; LOG;
D O I
10.1016/j.fsidi.2022.301480
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The increase in the complexity and sophistication of multi-stage cyber attacks, such as advanced persistent threats, paired with the large volume of data produced by modern systems and networks, have made forensic investigations more demanding in knowledge and resources. Thus, it is essential that cyber forensic investigators are supported to operate more efficiently, in terms of resources and evidence recovery, and cope with a wide range of cyber incidents. This paper presents a comprehensive survey of 49 works that aim to support cyber forensic investigations of modern multi-stage cyber incidents and highlights the need for decision support systems on the field. The works reviewed are compared using 11 criteria, such as their evaluation method, how they optimise the forensic process, or what stage of investigation they study. We also classify the surveyed papers using 8 categories that represent the overall aim of the proposed cyber investigation method or tool. We identify and discuss open issues, arising from this extensive survey, such as the need for realistic evaluation, as well as realistic and representative modelling to increase applicability and performance. Finally, we provide directions for future research on improving the state-of-the-art of cyber forensics. (c) 2022 The Authors. Published by Elsevier Ltd. This is an open access article under the CC BY-NC-ND license (http://creativecommons.org/licenses/by-nc-nd/4.0/).
引用
收藏
页数:16
相关论文
共 50 条
  • [1] A Systematic Survey on Cloud Forensics Challenges, Solutions, and Future Directions
    Manral, Bharat
    Somani, Gaurav
    Choo, Kim-Kwang Raymond
    Conti, Mauro
    Gaur, Manoj Singh
    [J]. ACM COMPUTING SURVEYS, 2020, 52 (06)
  • [2] Introduction to a Network Forensics System for Cyber Incidents Analysis
    Choi, Yangseo
    Lee, Joo-Young
    Choi, Sunoh
    Kim, Jong-Hyum
    Kim, Ikkyun
    [J]. 2016 18TH INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATIONS TECHNOLOGY (ICACT) - INFORMATION AND COMMUNICATIONS FOR SAFE AND SECURE LIFE, 2016, : 50 - 55
  • [3] Evaluating threat assessment for multi-stage cyber attacks
    Yang, Shanchieh Jay
    Holsopple, Jared
    Sudit, Moises
    [J]. MILCOM 2006, VOLS 1-7, 2006, : 1287 - +
  • [4] FUTURE DIRECTIONS FOR FORENSICS EDUCATION
    MCBATH, JH
    [J]. SPEECH TEACHER, 1975, 24 (04): : 365 - 369
  • [5] A comprehensive survey on digital video forensics: Taxonomy, challenges, and future directions
    Javed, Abdul Rehman
    Jalil, Zunera
    Zehra, Wisha
    Gadekallu, Thippa Reddy
    Suh, Doug Young
    Piran, Md Jalil
    [J]. ENGINEERING APPLICATIONS OF ARTIFICIAL INTELLIGENCE, 2021, 106
  • [6] Application of Artificial Intelligence to Network Forensics: Survey, Challenges and Future Directions
    Rizvi, Syed
    Scanlon, Mark
    McGibney, Jimmy
    Sheppard, John
    [J]. IEEE ACCESS, 2022, 10 : 110362 - 110384
  • [7] Adaptive Inference for Multi-Stage Survey Data
    Al-Zou'bi, Loai Mahmoud
    Clark, Robert Graham
    Steel, David G.
    [J]. COMMUNICATIONS IN STATISTICS-SIMULATION AND COMPUTATION, 2010, 39 (07) : 1334 - 1350
  • [8] A Survey on Industrial Control System Digital Forensics: Challenges, Advances and Future Directions
    Cook, Marco
    Marnerides, Angelos
    Johnson, Chris
    Pezaros, Dimitrios
    [J]. IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2023, 25 (03): : 1705 - 1747
  • [9] Multi Task Learning: A Survey and Future Directions
    Lee, Taeho
    Seok, Junhee
    [J]. 2023 INTERNATIONAL CONFERENCE ON ARTIFICIAL INTELLIGENCE IN INFORMATION AND COMMUNICATION, ICAIIC, 2023, : 232 - 235
  • [10] Current approaches and future directions for Cyber Threat Intelligence sharing: A survey
    Alaeifar, Poopak
    Pal, Shantanu
    Jadidi, Zahra
    Hussain, Mukhtar
    Foo, Ernest
    [J]. JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2024, 83