Forensics for multi-stage cyber incidents: Survey and future directions

被引:0
|
作者
Nisioti, Antonia [1 ]
Loukas, George [1 ]
Mylonas, Alexios [2 ]
Panaousis, Emmanouil [1 ]
机构
[1] Univ Greenwich, Internet Things & Secur Ctr, London, England
[2] Univ Hertfordshire, Sch Phys Engn & Comp Sci, Hatfield, England
关键词
Cyber forensics; Digital forensics; Multi -stage attacks; Anti; -forensics; Advanced persistent threats; Survey; Review; ADVANCED PERSISTENT THREATS; ANTI-FORENSICS; FRAMEWORK; MODEL; LOG;
D O I
10.1016/j.fsidi.2022.301480
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The increase in the complexity and sophistication of multi-stage cyber attacks, such as advanced persistent threats, paired with the large volume of data produced by modern systems and networks, have made forensic investigations more demanding in knowledge and resources. Thus, it is essential that cyber forensic investigators are supported to operate more efficiently, in terms of resources and evidence recovery, and cope with a wide range of cyber incidents. This paper presents a comprehensive survey of 49 works that aim to support cyber forensic investigations of modern multi-stage cyber incidents and highlights the need for decision support systems on the field. The works reviewed are compared using 11 criteria, such as their evaluation method, how they optimise the forensic process, or what stage of investigation they study. We also classify the surveyed papers using 8 categories that represent the overall aim of the proposed cyber investigation method or tool. We identify and discuss open issues, arising from this extensive survey, such as the need for realistic evaluation, as well as realistic and representative modelling to increase applicability and performance. Finally, we provide directions for future research on improving the state-of-the-art of cyber forensics. (c) 2022 The Authors. Published by Elsevier Ltd. This is an open access article under the CC BY-NC-ND license (http://creativecommons.org/licenses/by-nc-nd/4.0/).
引用
收藏
页数:16
相关论文
共 50 条
  • [21] On using contextual correlation to detect multi-stage cyber attacks in smart grids
    Sen, Oemer
    van der Velde, Dennis
    Wehrmeister, Katharina A.
    Hacker, Immanuel
    Henze, Martin
    Andres, Michael
    [J]. SUSTAINABLE ENERGY GRIDS & NETWORKS, 2022, 32
  • [22] A Multi-Stage Machine Learning and Fuzzy Approach to Cyber-Hate Detection
    Ketsbaia, Lida
    Issac, Biju
    Chen, Xiaomin
    Jacob, Seibu Mary
    [J]. IEEE ACCESS, 2023, 11 : 56046 - 56065
  • [23] Towards an Approach to Contextual Detection of Multi-Stage Cyber Attacks in Smart Grids
    Sen, Oemer
    van der Velde, Dennis
    Wehrmeister, Katharina A.
    Hacker, Immanuel
    Henze, Martin
    Andres, Michael
    [J]. 2021 INTERNATIONAL CONFERENCE ON SMART ENERGY SYSTEMS AND TECHNOLOGIES (SEST), 2021,
  • [24] Supply Chain 4.0: A Survey of Cyber Security Challenges, Solutions and Future Directions
    Sobb, Theresa
    Turnbull, Benjamin
    Moustafa, Nour
    [J]. ELECTRONICS, 2020, 9 (11) : 1 - 31
  • [25] Design of Cyber-Physical Security Testbed for Multi-Stage Manufacturing System
    Coshatt, Stephen J.
    Li, Qi
    Yang, Bowen
    Wu, Shushan
    Shrivastava, Darpan
    Ye, Jin
    Song, WenZhan
    Zahiri, Feraidoon
    [J]. 2022 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM 2022), 2022, : 1978 - 1983
  • [26] Cyber Bullying and Cyber Victimization: Future Directions for Research
    Yoon, Jibe
    [J]. INTERNATIONAL JOURNAL OF PSYCHOLOGY, 2016, 51 : 835 - 836
  • [27] A comparison of periodic survey designs employing multi-stage sampling
    Virginia M. Lesser
    William D. Kalsbeek
    [J]. Environmental and Ecological Statistics, 1997, 4 : 117 - 130
  • [28] A comparison of periodic survey designs employing multi-stage sampling
    Lesser, VM
    Kalsbeek, WD
    [J]. ENVIRONMENTAL AND ECOLOGICAL STATISTICS, 1997, 4 (02) : 117 - 130
  • [29] A Comprehensive Survey on Computer Forensics: State-of-the-Art, Tools, Techniques, Challenges, and Future Directions
    Javed, Abdul Rehman
    Ahmed, Waqas
    Alazab, Mamoun
    Jalil, Zunera
    Kifayat, Kashif
    Gadekallu, Thippa Reddy
    [J]. IEEE Access, 2022, 10 : 11065 - 11089
  • [30] A Comprehensive Survey on Computer Forensics: State-of-the-Art, Tools, Techniques, Challenges, and Future Directions
    Javed, Abdul Rehman
    Ahmed, Waqas
    Alazab, Mamoun
    Jalil, Zunera
    Kifayat, Kashif
    Gadekallu, Thippa Reddy
    [J]. IEEE ACCESS, 2022, 10 : 11065 - 11089