Forensics for multi-stage cyber incidents: Survey and future directions

被引:0
|
作者
Nisioti, Antonia [1 ]
Loukas, George [1 ]
Mylonas, Alexios [2 ]
Panaousis, Emmanouil [1 ]
机构
[1] Univ Greenwich, Internet Things & Secur Ctr, London, England
[2] Univ Hertfordshire, Sch Phys Engn & Comp Sci, Hatfield, England
关键词
Cyber forensics; Digital forensics; Multi -stage attacks; Anti; -forensics; Advanced persistent threats; Survey; Review; ADVANCED PERSISTENT THREATS; ANTI-FORENSICS; FRAMEWORK; MODEL; LOG;
D O I
10.1016/j.fsidi.2022.301480
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The increase in the complexity and sophistication of multi-stage cyber attacks, such as advanced persistent threats, paired with the large volume of data produced by modern systems and networks, have made forensic investigations more demanding in knowledge and resources. Thus, it is essential that cyber forensic investigators are supported to operate more efficiently, in terms of resources and evidence recovery, and cope with a wide range of cyber incidents. This paper presents a comprehensive survey of 49 works that aim to support cyber forensic investigations of modern multi-stage cyber incidents and highlights the need for decision support systems on the field. The works reviewed are compared using 11 criteria, such as their evaluation method, how they optimise the forensic process, or what stage of investigation they study. We also classify the surveyed papers using 8 categories that represent the overall aim of the proposed cyber investigation method or tool. We identify and discuss open issues, arising from this extensive survey, such as the need for realistic evaluation, as well as realistic and representative modelling to increase applicability and performance. Finally, we provide directions for future research on improving the state-of-the-art of cyber forensics. (c) 2022 The Authors. Published by Elsevier Ltd. This is an open access article under the CC BY-NC-ND license (http://creativecommons.org/licenses/by-nc-nd/4.0/).
引用
收藏
页数:16
相关论文
共 50 条
  • [31] Future directions for cyber knowledge and databases
    Kiyoki, Y
    Inakage, M
    Satoh, M
    Tomita, M
    [J]. 2004 INTERNATIONAL SYMPOSIUM ON APPLICATIONS AND THE INTERNET WORKSHOPS, PROCEEDINGS, 2004, : 495 - 500
  • [32] Future directions for cyber knowledge and databases
    [J]. Kiyoki, Y. (kiyoki@mdbl.sfc.keio.ac.jp), IEEE Computer Society; Information Processing Society of Japan, IPSJ; Japan's Telecommunications Advancement Organization, TAO; IEICE (Institute of Electrical and Electronics Engineers Computer Society):
  • [33] A framework for automated multi-stage and multi-step product configuration of cyber-physical systems
    Safdar Aqeel Safdar
    Hong Lu
    Tao Yue
    Shaukat Ali
    Kunming Nie
    [J]. Software and Systems Modeling, 2021, 20 : 211 - 265
  • [34] Dynamic analysis of multi-stage cyber attack based on abstract hidden Markov model
    Tang, Ke
    Zhou, Mingtian
    [J]. Journal of Computational Information Systems, 2010, 6 (12): : 4007 - 4017
  • [35] A framework for automated multi-stage and multi-step product configuration of cyber-physical systems
    Safdar, Safdar Aqeel
    Lu, Hong
    Yue, Tao
    Ali, Shaukat
    Nie, Kunming
    [J]. SOFTWARE AND SYSTEMS MODELING, 2021, 20 (01): : 211 - 265
  • [36] Multi-stage classification
    Senator, TE
    [J]. FIFTH IEEE INTERNATIONAL CONFERENCE ON DATA MINING, PROCEEDINGS, 2005, : 386 - 393
  • [37] Mitigation of attack detection via multi-stage cyber intelligence technique in smart grid
    Muneeswari, G.
    Mabel Rose, R.A.
    Balaganesh, S.
    Jerald Prasath, G.
    Chellam, S.
    [J]. Measurement: Sensors, 2024, 33
  • [38] Evidence and Forensics in the Cloud: Challenges and Future Research Directions
    Choo, Kim-Kwang Raymond
    Esposito, Christian
    Castiglione, Aniello
    [J]. IEEE CLOUD COMPUTING, 2017, 4 (03): : 14 - 19
  • [39] Multi-stage programming
    Taha, W
    Sheard, T
    [J]. ACM SIGPLAN NOTICES, 1997, 32 (08) : 321 - 321
  • [40] Cyber-coordinated Simulation Models for Multi-stage Additive Manufacturing of Energy Products
    Sun, Hongyue
    Pedrielli, Giulia
    Zhao, Guanglei
    Bragagnolo, Andrea
    Zhou, Chi
    Pan, Rong
    Xu, Wenyao
    [J]. 2018 IEEE 14TH INTERNATIONAL CONFERENCE ON AUTOMATION SCIENCE AND ENGINEERING (CASE), 2018, : 893 - 898