TY - JOUR T1 - A comparison of machine learning techniques for file system forensics analysis AU - Mohammad, Rami Mustafa A. AU - Alqahtani, Mohammed JO - Journal of Information Security and Applications VL - 46 SP - 53 EP - 61 PY - 2019 DA - 2019/06/01/ SN - 2214-2126 DO - https://doi.org/10.1016/j.jisa.2019.02.009 UR - https://www.sciencedirect.com/science/article/pii/S2214212618307579 KW - Digital forensic KW - File system KW - Computer crimes KW - Machine Learning KW - Log file AB - With the remarkable increase in computer crimes – particularly Internet related crimes – digital forensics become an urgent and a timely issue to study. Normally, digital forensics investigation aims to preserve any evidence in its most original form by identifying, collecting, and validating the digital information for the purpose of reconstructing past events. Most digital evidence is stored within the computer's file system. This research investigates and evaluates the applicability of several machine learning techniques in identifying incriminating evidence by tracing historical file system activities in order to determine how these files can be manipulated by different application programs. A dataset defined by a matrix/vector of features related to file system activity during a specific period of time has been collected. Such dataset has been used to train several machine learning techniques. Overall, the considered machine learning techniques show good results when they have been evaluated using a testing dataset containing unseen evidence. However, all algorithms encountered an essential obstacle that could be the main reason as why the experimental results were less than expectation that is the overlaps among the file system activities. ER - TY - JOUR T1 - Advancing coordinated cyber-investigations and tool interoperability using a community developed specification language AU - Casey, Eoghan AU - Barnum, Sean AU - Griffith, Ryan AU - Snyder, Jonathan AU - van Beek, Harm AU - Nelson, Alex JO - Digital Investigation VL - 22 SP - 14 EP - 45 PY - 2017 DA - 2017/09/01/ SN - 1742-2876 DO - https://doi.org/10.1016/j.diin.2017.08.002 UR - https://www.sciencedirect.com/science/article/pii/S1742287617301007 KW - Cyber-investigation KW - Digital forensics KW - Specification language KW - Standard representation KW - Unified cyber ontology KW - Information sharing KW - Digital evidence exchange KW - Evidence provenance KW - DFAX KW - DFXML KW - CybOX AB - Any investigation can have a digital dimension, often involving information from multiple data sources, organizations and jurisdictions. Existing approaches to representing and exchanging cyber-investigation information are inadequate, particularly when combining data sources from numerous organizations or dealing with large amounts of data from various tools. To conduct investigations effectively, there is a pressing need to harmonize how this information is represented and exchanged. This paper addresses this need for information exchange and tool interoperability with an open community-developed specification language called Cyber-investigation Analysis Standard Expression (CASE). To further promote a common structure, CASE aligns with and extends the Unified Cyber Ontology (UCO) construct, which provides a format for representing information in all cyber domains. This ontology abstracts objects and concepts that are not CASE-specific, so that they can be used across other cyber disciplines that may extend UCO. This work is a rational evolution of the Digital Forensic Analysis eXpression (DFAX) for representing digital forensic information and provenance. CASE is more flexible than DFAX and can be utilized in any context, including criminal, corporate and intelligence. CASE also builds on the Hansken data model developed and implemented by the Netherlands Forensic Institute (NFI). CASE enables the fusion of information from different organizations, data sources, and forensic tools to foster more comprehensive and cohesive analysis. This paper includes illustrative examples of how CASE can be implemented and used to capture information in a structured form to advance sharing, interoperability and analysis in cyber-investigations. In addition to capturing technical details and relationships between objects, CASE provides structure for representing and sharing details about how cyber-information was handled, transferred, processed, analyzed, and interpreted. CASE also supports data marking for sharing information at different levels of trust and classification, and for protecting sensitive and private information. Furthermore, CASE supports the sharing of knowledge related to cyber-investigations, including distinctive patterns of activity/behavior that are common across cases. This paper features a proof-of-concept Application Program Interface (API) to facilitate implementation of CASE in tools. Community members are encouraged to participate in the development and implementation of CASE and UCO. ER - TY - JOUR T1 - A machine learning framework for investigating data breaches based on semantic analysis of adversary’s attack patterns in threat intelligence repositories AU - Noor, Umara AU - Anwar, Zahid AU - Malik, Asad Waqar AU - Khan, Sharifullah AU - Saleem, Shahzad JO - Future Generation Computer Systems VL - 95 SP - 467 EP - 487 PY - 2019 DA - 2019/06/01/ SN - 0167-739X DO - https://doi.org/10.1016/j.future.2019.01.022 UR - https://www.sciencedirect.com/science/article/pii/S0167739X18306708 KW - Cyber threat intelligence KW - Data breach investigation KW - Tactics Techniques and Procedures KW - Indicators of compromise KW - Belief network KW - Latent Semantic Indexing AB - With the ever increasing cases of cyber data breaches, the manual process of sifting through tons of security logs to investigate cyber-attacks is error-prone and time-consuming. Signature-based deep search solutions only give accurate results if the threat artifacts are precisely provided. With the burgeoning variety of sophisticated cyber threats having common attack patterns and utilizing the same attack tools, a timely investigation is nearly impossible. There is a need to automate the threat analysis process by mapping adversary’s Tactics, Techniques and Procedures (TTPs) to attack goals and detection mechanisms. In this paper, a novel machine learning based framework is proposed that identifies cyber threats based on observed attack patterns. The framework semantically relates threats and TTPs extracted from well-known threat sources with associated detection mechanisms to form a semantic network. This network is then used to determine threat occurrences by forming probabilistic relationships between threats and TTPs. The framework is trained using a TTP taxonomy dataset and the performance is evaluated with threat artifacts reported in threat reports. The framework efficiently identifies attacks with 92% accuracy and low false positives even in the case of lost and spurious TTPs. The average detection time of a data breach incident is 0.15 s for a network trained with 133 TTPs from 45 threat families. ER - TY - JOUR T1 - Age-appropriate password “best practice” ontologies for early educators and parents AU - Prior, Suzanne AU - Renaud, Karen JO - International Journal of Child-Computer Interaction VL - 23-24 SP - 100169 PY - 2020 DA - 2020/06/01/ SN - 2212-8689 DO - https://doi.org/10.1016/j.ijcci.2020.100169 UR - https://www.sciencedirect.com/science/article/pii/S2212868920300040 AB - Many mobile apps are developed specifically for use by children. As a consequence, children become actors in world where they use passwords to authenticate themselves from a very young age. As such, there is a need for guidance to inform educators and parents about how to prepare children for responsible password practice. Very little attention has been paid to determining which password-related principles young children should know, and the age at which this information should be imparted. To address this deficiency, we commenced by deriving an ontology of “best practice” password principles from official sources. These password principles encode essential knowledge for password users of all ages and provide a benchmark that can be used to ground a set of age-appropriate ontologies. We compared this benchmark “good practice” ontology to the advice provided by a wide-ranging snapshot of password-related children’s books and parents’ online resources. We then consulted the research literature to identify the skills required to understand and apply each principle, and removed those that were unsuitable for young children. We then consulted parents of young children to help us to confirm the classification of the ontology’s principles in terms of age appropriateness. Parents also helped us to rephrase each principle to maximise accessibility and understandability for each age group. We conclude with our final set of three age-appropriate password best practice ontologies as a helpful resource for early education professionals and parents. ER - TY - JOUR T1 - D4I - Digital forensics framework for reviewing and investigating cyber attacks AU - Dimitriadis, Athanasios AU - Ivezic, Nenad AU - Kulvatunyou, Boonserm AU - Mavridis, Ioannis JO - Array VL - 5 SP - 100015 PY - 2020 DA - 2020/03/01/ SN - 2590-0056 DO - https://doi.org/10.1016/j.array.2019.100015 UR - https://www.sciencedirect.com/science/article/pii/S2590005619300153 KW - Digital forensics framework KW - Artifacts categorization and mapping KW - Examination and analysis KW - Digital reviewing and investigation AB - Many companies have cited lack of cyber-security as the main barrier to Industrie 4.0 or digitalization. Security functions include protection, detection, response and investigation. Cyber-attack investigation is important as it can support the mitigation of damages and maturing future prevention approaches. Nowadays, the investigation of cyber-attacks has evolved more than ever leveraging combinations of intelligent tools and digital forensics processes. Intelligent tools (e.g., YARA rules and Indicators of Compromise) are effective only when there is prior knowledge about software and mechanisms used in the cyber-attack, i.e., they are not attack-agnostic. Therefore, the effectiveness of these intelligent tools is inversely proportional to the number of the never-seen-before software and mechanisms utilized. Digital forensic processes, while not suffering from such issue, lack the ability to provide in-depth support to a cyber-attack investigation mainly due to insufficient detailed instructions in the examination and analysis phases. This paper proposes a digital forensics framework for reviewing and investigating cyber-attacks, called D4I, which focuses on enhancing the examination and analysis phases. First, the framework proposes a digital artifacts categorization and mapping to the Cyber-Kill-Chain steps of attacks. Second, it provides detailed instructing steps for the examination and analysis phases. The applicability of D4I is demonstrated with an application example that concerns a typical case of a spear phishing attack. ER - TY - JOUR T1 - An ontology-based approach for the reconstruction and analysis of digital incidents timelines AU - Chabot, Yoan AU - Bertaux, Aurélie AU - Nicolle, Christophe AU - Kechadi, Tahar JO - Digital Investigation VL - 15 SP - 83 EP - 100 PY - 2015 DA - 2015/12/01/ T2 - Special Issue: Big Data and Intelligent Data Analysis SN - 1742-2876 DO - https://doi.org/10.1016/j.diin.2015.07.005 UR - https://www.sciencedirect.com/science/article/pii/S1742287615000869 KW - Digital forensics KW - Event reconstruction KW - Forensic ontology KW - Knowledge extraction KW - Ontology population KW - Timeline analysis AB - Due to the democratisation of new technologies, computer forensics investigators have to deal with volumes of data which are becoming increasingly large and heterogeneous. Indeed, in a single machine, hundred of events occur per minute, produced and logged by the operating system and various software. Therefore, the identification of evidence, and more generally, the reconstruction of past events is a tedious and time-consuming task for the investigators. Our work aims at reconstructing and analysing automatically the events related to a digital incident, while respecting legal requirements. To tackle those three main problems (volume, heterogeneity and legal requirements), we identify seven necessary criteria that an efficient reconstruction tool must meet to address these challenges. This paper introduces an approach based on a three-layered ontology, called ORD2I, to represent any digital events. ORD2I is associated with a set of operators to analyse the resulting timeline and to ensure the reproducibility of the investigation. ER - TY - JOUR T1 - Identify trademark legal case precedents - Using machine learning to enable semantic analysis of judgments AU - Trappey, Charles V. AU - Trappey, Amy J.C. AU - Liu, Bo-Hung JO - World Patent Information VL - 62 SP - 101980 PY - 2020 DA - 2020/09/01/ SN - 0172-2190 DO - https://doi.org/10.1016/j.wpi.2020.101980 UR - https://www.sciencedirect.com/science/article/pii/S0172219019300638 KW - Trademark infringement KW - Clustering KW - Latent dirichlet allocation KW - Precedence analysis KW - Recommendation platform AB - Legal case precedents have a considerable impact on the development of litigation strategies. This research uses the neural network language modeling (NNLM) approach to analyze and identify judgment documents of US trademark (TM) litigation cases as precedents of a given target case. In this research, the NNLM has been trained using 4835 TM litigation documents. There are more than 800,000 words in the entire training text set including more than 150,000 vocabularies. The words in TM legal documents are vectorized to train the NN model for e-discovery of semantically correlated precedents and their features. Specifically, non-supervised machine learning (ML) methods, including clustering and Latent Dirichlet Allocation (LDA), are applied to form the TM legal document clusters, topics, and key terminologies used to characterize the TM case descriptions and precedents. The definition of the clusters, topics and corresponding key terms enhance the ability of the system to recommend and explain similar case judgments for any given TM case of interest or a cease and desist letter with detailed claims of infringement. Further, the intelligent approach provides macro and micro views for companies to research TM litigation trends as a means to better protect their brand equity. ER - TY - JOUR T1 - A semantic framework for noise addition with nominal data AU - Rodriguez-Garcia, Mercedes AU - Batet, Montserrat AU - Sánchez, David JO - Knowledge-Based Systems VL - 122 SP - 103 EP - 118 PY - 2017 DA - 2017/04/15/ SN - 0950-7051 DO - https://doi.org/10.1016/j.knosys.2017.01.032 UR - https://www.sciencedirect.com/science/article/pii/S0950705117300473 KW - Noise addition KW - Nominal data KW - Semantics KW - Ontologies KW - Medical ontologies AB - Noise addition is a data distortion technique widely used in data intensive applications. For example, in machine learning tasks it helps to reduce overfitting, whereas in data privacy protection it adds uncertainty to personally identifiable information. Yet, due to its mathematical operating principle, noise addition is a method mainly intended for continuous numerical data. In fact, despite the large amount of nominal data that are being currently compiled and used in data analysis, only a few alternative techniques have been proposed to distort nominal data in a similar way as standard noise addition does for numerical data. Furthermore, all these alternative methods rely on the distribution of the data rather than on the semantics of nominal values, which negatively affects the utility of the distorted outcomes. To tackle this issue, in this paper we present a semantically-grounded alternative to numerical noise suitable for nominal data, which we name semantic noise. By means of semantic noise, and by exploiting structured knowledge sources such as ontologies, we are able to distort nominal data while preserving better their semantics and thus, their analytical utility. To that end, we provide semantically and mathematically coherent versions of the statistical operators required in the noise addition process, which include the difference, the mean, the variance and the covariance. Then, we propose semantic noise addition algorithms that cope with the finite, discrete and non-ordinal nature of nominal data. The proposed algorithms cover both uncorrelated noise addition, which is suited to independent attributes, and correlated noise addition, which can cope with multivariate datasets with dependent attributes. Empirical results show that our proposals offer general and configurable mechanisms to distort nominal data while preserving data semantics better than baseline methods based only on the distribution of the data. ER - TY - JOUR T1 - A survey of information security incident handling in the cloud AU - Ab Rahman, Nurul Hidayah AU - Choo, Kim-Kwang Raymond JO - Computers & Security VL - 49 SP - 45 EP - 69 PY - 2015 DA - 2015/03/01/ SN - 0167-4048 DO - https://doi.org/10.1016/j.cose.2014.11.006 UR - https://www.sciencedirect.com/science/article/pii/S0167404814001680 KW - Capability Maturity Model For Services (CMMI-SVC) KW - Cloud computing KW - Cloud response KW - Incident handling KW - Incident management KW - Incident response AB - Incident handling strategy is one key strategy to mitigate risks to the confidentiality, integrity and availability (CIA) of organisation assets, as well as minimising loss (e.g. financial, reputational and legal) particularly as organisations move to the cloud. In this paper, we surveyed existing incident handling and digital forensic literature with the aims of contributing to the knowledge gap(s) in handling incidents in the cloud environment. 139 English language publications between January 2009 and May 2014 were located by searching various sources including the websites of standard bodies (e.g. National Institute of Standards and Technology) and academic databases (e.g. Google Scholar, IEEEXplore, ACM Digital Library, Springer and ScienceDirect). We then propose a conceptual cloud incident handling model that brings together incident handling, digital forensic and the Capability Maturity Model for Services to more effectively handle incidents for organisations using the cloud. A discussion of open research issues concludes this survey. ER - TY - JOUR T1 - Impacts of increasing volume of digital forensic data: A survey and future research challenges AU - Quick, Darren AU - Choo, Kim-Kwang Raymond JO - Digital Investigation VL - 11 IS - 4 SP - 273 EP - 294 PY - 2014 DA - 2014/12/01/ SN - 1742-2876 DO - https://doi.org/10.1016/j.diin.2014.09.002 UR - https://www.sciencedirect.com/science/article/pii/S1742287614001066 KW - Data mining KW - Data volume KW - Digital forensics KW - Evidence discovery KW - Forensic computer analysis KW - Intelligence analysis KW - Knowledge management AB - A major challenge to digital forensic analysis is the ongoing growth in the volume of data seized and presented for analysis. This is a result of the continuing development of storage technology, including increased storage capacity in consumer devices and cloud storage services, and an increase in the number of devices seized per case. Consequently, this has led to increasing backlogs of evidence awaiting analysis, often many months to years, affecting even the largest digital forensic laboratories. Over the preceding years, there has been a variety of research undertaken in relation to the volume challenge. Solutions posed range from data mining, data reduction, increased processing power, distributed processing, artificial intelligence, and other innovative methods. This paper surveys the published research and the proposed solutions. It is concluded that there remains a need for further research with a focus on real world applicability of a method or methods to address the digital forensic data volume challenge. ER - TY - JOUR T1 - Industrial espionage – A systematic literature review (SLR) AU - Hou, Tie AU - Wang, Victoria JO - Computers & Security VL - 98 SP - 102019 PY - 2020 DA - 2020/11/01/ SN - 0167-4048 DO - https://doi.org/10.1016/j.cose.2020.102019 UR - https://www.sciencedirect.com/science/article/pii/S0167404820302923 KW - Industrial espionage KW - Systematic literature review (SLR) KW - Key features KW - Challenges KW - Trends AB - Industrial Espionage (IE) is an umbrella term covering a complicated range of activities performed to gain competitive advantages, resulting in a huge amount of financial loss annually. Currently, techniques generated by rapid developments of Internet of Things (IOTs) and Data Science are enabling a massive increase of both frequency and power of IE related activities in our increasingly challenging global commercial environment. Thus, an in-depth understanding of IE is necessary. In this paper, we report a comprehensive Systematic Literature Review (SLR) of current English literature on IE. Particularly, we systematically: i) identify key features of IE by analysing its current definitions, and coin our own working definition; ii) discuss the current state of research on IE from different academic disciplines; iii) highlight some key challenges in the current state of research on IE; and iv) identify some possible trends in its future development. Further, based on our findings, we call for more multi-disciplinary/multi-agency research on IE in order to construct a comprehensive framework to combat IE. ER - TY - JOUR T1 - Requirements capture and comparative analysis of open source versus proprietary service oriented architecture AU - Bamhdi, Alwi JO - Computer Standards & Interfaces VL - 74 SP - 103468 PY - 2021 DA - 2021/02/01/ SN - 0920-5489 DO - https://doi.org/10.1016/j.csi.2020.103468 UR - https://www.sciencedirect.com/science/article/pii/S0920548920303548 KW - SOA KW - Open source KW - Closed source proprietary KW - Requirements capture KW - Advanced technologies KW - Web services access KW - Web 1.0/2.0/3.0/4./5.0/6.0 AB - Service Oriented Architecture (SOA) integrates information systems towards an agile and reusable service-based connectivity. It is an approach amalgamating large scale private/public computer systems and other resources with continuous phenomenal advent evolution and leveraging of the World Wide Web (WWW, commonly referred to as the Web) social media, mobile communications, Big Data (BD), data analytics, Machine Learning (ML) based optimisation, Cloud Computing (CC) and Internet of Things (IoT), commonly known as Advanced Technologies (AT). Implementing SOA, whether Open Source Software (OSS) or proprietary or absolute freeware is a choice to be made which depends on the organisation's requirements in light of AT as well as a host of delivery and security concerns. In this paper, a comparative analysis of an open source vs. proprietary SOA for large scale computer systems servicing AT is presented by examining their main efficacies, features, advantages and disadvantages and capturing their generic technical functional and non-functional requirements in a unified manner. Furthermore, the SOA evaluation criteria, recommendations and conclusions are also presented. ER - TY - JOUR T1 - Data warehousing and OLAP (DOLAP’08) AU - Abello, Alberto AU - Song, Il-Yeol JO - Data & Knowledge Engineering VL - 69 IS - 1 SP - 1 EP - 2 PY - 2010 DA - 2010/01/01/ T2 - Including Special Section: 11th ACM International Workshop on Data Warehousing and OLAP (DOLAP’08) - Five selected and extended papers SN - 0169-023X DO - https://doi.org/10.1016/j.datak.2009.08.011 UR - https://www.sciencedirect.com/science/article/pii/S0169023X09001244 ER - TY - JOUR T1 - Timeline2GUI: A Log2Timeline CSV parser and training scenarios AU - Debinski, Mark AU - Breitinger, Frank AU - Mohan, Parvathy JO - Digital Investigation VL - 28 SP - 34 EP - 43 PY - 2019 DA - 2019/03/01/ SN - 1742-2876 DO - https://doi.org/10.1016/j.diin.2018.12.004 UR - https://www.sciencedirect.com/science/article/pii/S1742287618303232 KW - Log2Timeline KW - Timeline KW - Timestamps KW - Parser KW - Timeline2GUI KW - Training cases AB - Crimes involving digital evidence are getting more complex due to the increasing storage capacities and utilization of devices. Event reconstruction (i.e., understanding the timeline) is an essential step for investigators to understand a case where a prominent tool is Log2Timeline (a tool that creates super timelines which is a combination of several log files and events throughout a system). While these timelines provide great evidence and help to understand a case, they are complex and require tools as well as training scenarios. In this paper we present Timeline2GUI an easy-to-use python implementation to analyze CSV log files create by Log2Timeline. Additionally, we present three training scenarios – beginner, intermediate and advanced – to practice timeline analysis skills as well as familiarity with visualization tools. Lastly, we provide a comprehensive overview of tools. ER - TY - JOUR T1 - Internet of Things applications: A systematic review AU - Asghari, Parvaneh AU - Rahmani, Amir Masoud AU - Javadi, Hamid Haj Seyyed JO - Computer Networks VL - 148 SP - 241 EP - 261 PY - 2019 DA - 2019/01/15/ SN - 1389-1286 DO - https://doi.org/10.1016/j.comnet.2018.12.008 UR - https://www.sciencedirect.com/science/article/pii/S1389128618305127 KW - Application-based services KW - Internet of things KW - Systematic literature review KW - Smart objects KW - Quality of service AB - Internet of Things (IoT) is considered as an ecosystem that contains smart objects equipped with sensors, networking and processing technologies integrating and working together to provide an environment in which smart services are taken to the end users. The IoT is leading numerous benefits into the human life through the environment wherein smart services are provided to utilize every activity anywhere and anytime. All these facilities and services are conveyed through the diverse applications which are performed in the IoT environment. The most important utilities that are achieved by the IoT applications are monitoring and consequently immediate decision making for efficient management. In this paper, we intend to survey in divers IoT application domains to comprehend the different approaches in IoT applications which have been recently presented based on the Systematic Literature Review (SLR) method. The aim of this paper is to categorize analytically and statistically, and analyze the current research techniques on IoT applications approaches published from 2011 to 2018. A technical taxonomy is presented for the IoT applications approaches according to the content of current studies that are selected with SLR process in this study including health care, environmental monitoring, smart city, commercial, industrial and general aspects in IoT applications. IoT applications are compared with each other according to some technical features such as Quality of Service (QoS), proposed case study and evaluation environments. The achievements and disadvantages of each study is discussed as well as presenting some hints for addressing their weaknesses and highlighting the future research challenges and open issues in IoT applications. ER - TY - JOUR T1 - Analyse digital forensic evidences through a semantic-based methodology and NLP techniques AU - Amato, F. AU - Cozzolino, G. AU - Moscato, V. AU - Moscato, F. JO - Future Generation Computer Systems VL - 98 SP - 297 EP - 307 PY - 2019 DA - 2019/09/01/ SN - 0167-739X DO - https://doi.org/10.1016/j.future.2019.02.040 UR - https://www.sciencedirect.com/science/article/pii/S0167739X19301906 KW - Digital forensics KW - Text analysis KW - Log analysis KW - Correlation KW - Cybersecurity AB - The increasing adoption of digital technologies to manage and process information used in everyday life, results in an increase in the demand for digital data analysis for investigative purposes. In fact, the reconstruction of computer and telematic crimes, or, in general, of crimes committed with computer systems, require the adoption of Computer Forensics best practices in order to extract relevant evidences from electronic devices, guaranteeing the integrity of data and their admissibility during a trial. The process of extraction, conservation, analysis and documentation of a forensic investigation can be enhanced by a framework that support investigators during their work, correlating evidences collected by different forensic tools. So, in this work we propose a semantic methodology and a system architecture for evidences correlation aiming to provide enhanced retrieval and reasoning capabilities. ER - TY - JOUR T1 - Packet analysis for network forensics: A comprehensive survey AU - Sikos, Leslie F. JO - Forensic Science International: Digital Investigation VL - 32 SP - 200892 PY - 2020 DA - 2020/03/01/ SN - 2666-2817 DO - https://doi.org/10.1016/j.fsidi.2019.200892 UR - https://www.sciencedirect.com/science/article/pii/S1742287619302002 KW - Packet analysis KW - Deep packet inspection KW - Network forensics KW - Packet sniffer KW - Wireshark KW - Pcap KW - Digital evidence KW - Network monitoring KW - Intrusion detection AB - Packet analysis is a primary traceback technique in network forensics, which, providing that the packet details captured are sufficiently detailed, can play back even the entire network traffic for a particular point in time. This can be used to find traces of nefarious online behavior, data breaches, unauthorized website access, malware infection, and intrusion attempts, and to reconstruct image files, documents, email attachments, etc. sent over the network. This paper is a comprehensive survey of the utilization of packet analysis, including deep packet inspection, in network forensics, and provides a review of AI-powered packet analysis methods with advanced network traffic classification and pattern identification capabilities. Considering that not all network information can be used in court, the types of digital evidence that might be admissible are detailed. The properties of both hardware appliances and packet analyzer software are reviewed from the perspective of their potential use in network forensics. ER - TY - JOUR T1 - On the suitability of blockchain platforms for IoT applications: Architectures, security, privacy, and performance AU - Brotsis, Sotirios AU - Limniotis, Konstantinos AU - Bendiab, Gueltoum AU - Kolokotronis, Nicholas AU - Shiaeles, Stavros JO - Computer Networks VL - 191 SP - 108005 PY - 2021 DA - 2021/05/22/ SN - 1389-1286 DO - https://doi.org/10.1016/j.comnet.2021.108005 UR - https://www.sciencedirect.com/science/article/pii/S1389128621001225 KW - Blockchain KW - Consensus protocols KW - Cyber-attacks KW - Fault tolerance KW - Internet of things KW - Security KW - Smart contracts KW - Smart homes KW - Performance KW - Privacy AB - Blockchain and distributed ledger technologies have received significant interest in various areas beyond the financial sector, with profound applications in the Internet of Things (IoT), providing the means for creating truly trustless and secure solutions for IoT applications. Taking into account the weak security defences that the majority of IoT devices have, it is critical that a blockchain-based solution targeting the IoT is not only capable of addressing the many challenges IoT is facing, but also does not introduce other defects, e.g. in terms of performance, making its adoption hard to achieve. This paper aims at addressing the above needs by providing a comprehensive and coherent review of the available blockchain solutions to determine their ability to meet the requirements and tackle the challenges of the IoT, using the smart home as the reference domain. Key architectural aspects of blockchain solutions, like the platforms’ software and network setups, the consensus protocols used, as well as smart contracts, are examined in terms of their ability to withstand various types of common IoT and blockchain attacks, deliver enhanced privacy features, and assure adequate performance levels while processing large amounts of transactions being generated in an IoT environment. The analysis carried out identified that the defences currently provided by blockchain platforms are not sufficient to thwart all the prominent attacks against blockchains, with blockchain 1.0 and 2.0 platforms being susceptible to the majority of them. On the other side, privacy related mechanisms are being supported, to varying degrees, by all platforms investigated; however, each of the them tackles specific only privacy aspects, thus rendering the overall privacy evaluation a challenging task which needs to be considered in an ad-hoc basis. If the underlying consensus protocols’ performance and fault tolerance is also considered, then only a small number of platforms meet the requirements of our reference IoT domain. ER - TY - JOUR T1 - Evidence collection and forensics on social networks: Research challenges and directions AU - Arshad, Humaira AU - Jantan, Aman AU - Omolara, Esther JO - Digital Investigation VL - 28 SP - 126 EP - 138 PY - 2019 DA - 2019/03/01/ SN - 1742-2876 DO - https://doi.org/10.1016/j.diin.2019.02.001 UR - https://www.sciencedirect.com/science/article/pii/S1742287618302937 KW - Social Media forensic acquisition KW - Forensic preservation KW - Social Media as Evidence KW - Admissibility KW - Research Goals AB - Social Media (SM) evidence is a new and rapidly emerging frontier in digital forensics. The trail of digital information on social media, if explored correctly, can offer remarkable support in criminal investigations. However, exploring social media for potential evidence and presenting these proofs in court is not a straightforward task. Social media evidence must be collected by a legally and scientifically appropriate forensic process and also coincide with the privacy rights of individuals. Following the legal process is a challenging task for legal practitioners and investigators due to the highly dynamic and heterogeneous nature of social media. Forensic investigators can conduct effective investigations and collect legally sound evidence efficiently if they are provided with sophisticated tools to manage the diversity and size of social media content. This article explains the current state of evidence acquisition, admissibility, and jurisdiction in social media forensics. It also describes the immediate challenges for the collection, analysis, presentation, and validation of social media evidence in legal proceedings. Furthermore, the research gaps in the domain and few research objectives with potential research directions are presented. ER - TY - JOUR T1 - A complete formalized knowledge representation model for advanced digital forensics timeline analysis AU - Chabot, Yoan AU - Bertaux, Aurélie AU - Nicolle, Christophe AU - Kechadi, M-Tahar JO - Digital Investigation VL - 11 SP - S95 EP - S105 PY - 2014 DA - 2014/08/01/ T2 - Fourteenth Annual DFRWS Conference SN - 1742-2876 DO - https://doi.org/10.1016/j.diin.2014.05.009 UR - https://www.sciencedirect.com/science/article/pii/S1742287614000528 KW - Digital forensics KW - Timeline analysis KW - Event reconstruction KW - Knowledge management KW - Ontology AB - Having a clear view of events that occurred over time is a difficult objective to achieve in digital investigations (DI). Event reconstruction, which allows investigators to understand the timeline of a crime, is one of the most important step of a DI process. This complex task requires exploration of a large amount of events due to the pervasiveness of new technologies nowadays. Any evidence produced at the end of the investigative process must also meet the requirements of the courts, such as reproducibility, verifiability, validation, etc. For this purpose, we propose a new methodology, supported by theoretical concepts, that can assist investigators through the whole process including the construction and the interpretation of the events describing the case. The proposed approach is based on a model which integrates knowledge of experts from the fields of digital forensics and software development to allow a semantically rich representation of events related to the incident. The main purpose of this model is to allow the analysis of these events in an automatic and efficient way. This paper describes the approach and then focuses on the main conceptual and formal aspects: a formal incident modelization and operators for timeline reconstruction and analysis. ER - TY - JOUR T1 - Toward a cybercrime classification ontology: A knowledge-based approach AU - Donalds, Charlette AU - Osei-Bryson, Kweku-Muata JO - Computers in Human Behavior VL - 92 SP - 403 EP - 418 PY - 2019 DA - 2019/03/01/ SN - 0747-5632 DO - https://doi.org/10.1016/j.chb.2018.11.039 UR - https://www.sciencedirect.com/science/article/pii/S0747563218305740 KW - Cybercrime KW - Ontology KW - Classification KW - Knowledge-based approach KW - Design science AB - In recent years there has been an increase in cybercrimes and its negative impacts on the lives of individuals, organizations, and governments. It has been argued that a better understanding of cybercrime is a necessary condition to develop appropriate legal and policy responses to cybercrime. While a universally agreed-upon classification scheme would facilitate the development of such understanding and also collaborations, current classification schemes are insufficient, fragmented and often incompatible since each focuses on different perspectives (e.g., role of the computer, attack, attacker's or defender's viewpoint), or uses varying terminologies to refer to the same thing, making consistent cybercrime classifications improbable. In this paper we present and illustrate a new cybercrime ontology that incorporates multiple perspectives and offers a more holistic viewpoint for cybercrime classification than prior works. It should therefore prove to be a more useful tool for cybercrime stakeholders. ER - TY - JOUR T1 - A hybrid anomaly-based intrusion detection system to improve time complexity in the Internet of Energy environment AU - Rose, Thomas AU - Kifayat, Kashif AU - Abbas, Sohail AU - Asim, Muhammad JO - Journal of Parallel and Distributed Computing VL - 145 SP - 124 EP - 139 PY - 2020 DA - 2020/11/01/ SN - 0743-7315 DO - https://doi.org/10.1016/j.jpdc.2020.06.012 UR - https://www.sciencedirect.com/science/article/pii/S0743731520303191 KW - Intrusion detection KW - Anomaly-based intrusion detection KW - Machine learning KW - Smart grid KW - Internet of Energy AB - The technological evolution of the smart grids is going to take its shape in the form of a new paradigm called the Internet of Energy (IoE); which is considered to be the convergence of internet, communication, and energy. Like other evolved technologies, the IoE inherits security vulnerabilities from its constituents that need to be addressed. Intrusion Detection Systems (IDS) have been used to counteract malicious attacks. Among the types of IDS, anomaly-based IDS that employ mostly machine learning algorithms are considered to be the promising one, owing to their capability of detecting zero-day attacks. However, using complex algorithms to detect attacks, the existing anomaly-based IDS designed for IoE require considerable amount of time. It is tempting to reduce the training and testing time in order to make the IDS feasible for the IoE architecture. In this paper, we propose a hybrid anomaly-based IDS that can be installed at any networked site of the IoE architecture, such as Advanced Metering Infrastructure (AMI), to counteract security attacks. Our proposed system reduces the overall classification time of detection compared to the existing hybrid methods. The proposed solution uses a combination of K-means and Support Vector Machine, where the K-means centroids are used in a unique training method that reduces the training and testing times of the Support Vector Machine without compromising classification performance. We choose the best value of “k” and fine-tuned the SVM for best anomaly detection. Our approach achieves the highest accuracy of 99.9% in comparison with the existing approaches. ER - TY - JOUR T1 - CuFA: A more formal definition for digital forensic artifacts AU - Harichandran, Vikram S. AU - Walnycky, Daniel AU - Baggili, Ibrahim AU - Breitinger, Frank JO - Digital Investigation VL - 18 SP - S125 EP - S137 PY - 2016 DA - 2016/08/07/ SN - 1742-2876 DO - https://doi.org/10.1016/j.diin.2016.04.005 UR - https://www.sciencedirect.com/science/article/pii/S1742287616300366 KW - Forensic artifact KW - Digital forensics KW - CybOX KW - Curated forensic artifact KW - CuFA KW - Artifact definition KW - Survey KW - Cyber forensics KW - Taxonomy KW - Ontology AB - The term “artifact” currently does not have a formal definition within the domain of cyber/digital forensics, resulting in a lack of standardized reporting, linguistic understanding between professionals, and efficiency. In this paper we propose a new definition based on a survey we conducted, literature usage, prior definitions of the word itself, and similarities with archival science. This definition includes required fields that all artifacts must have and encompasses the notion of curation. Thus, we propose using a new term – curated forensic artifact (CuFA) – to address items which have been cleared for entry into a CuFA database (one implementation, the Artifact Genome Project, abbreviated as AGP, is under development and briefly outlined). An ontological model encapsulates these required fields while utilizing a lower-level taxonomic schema. We use the Cyber Observable eXpression (CybOX) project due to its rising popularity and rigorous classifications of forensic objects. Additionally, we suggest some improvements on its integration into our model and identify higher-level location categories to illustrate tracing an object from creation through investigative leads. Finally, a step-wise procedure for researching and logging CuFAs is devised to accompany the model. ER - TY - JOUR T1 - A nifty collaborative intrusion detection and prevention architecture for Smart Grid ecosystems AU - Patel, Ahmed AU - Alhussian, Hitham AU - Pedersen, Jens Myrup AU - Bounabat, Bouchaib AU - Júnior, Joaquim Celestino AU - Katsikas, Sokratis JO - Computers & Security VL - 64 SP - 92 EP - 109 PY - 2017 DA - 2017/01/01/ SN - 0167-4048 DO - https://doi.org/10.1016/j.cose.2016.07.002 UR - https://www.sciencedirect.com/science/article/pii/S0167404816300748 KW - Smart Grid (SG) KW - Intrusion Detection and Prevention System (IDPS) KW - Intelligent Collaborative Autonomic Management KW - Risk assessment management KW - Soft computing KW - SCADA AB - Smart Grid (SG) systems are critical, intelligent infrastructure utility services connected through open networks that are potentially susceptible to cyber-attacks with very acute security risks of shutdown, loss of life, and loss of revenue. Traditional intrusion detection systems based on signature and anomaly techniques are no longer sufficient to protect SGs due to their new connectivity and management challenges, the ever-rapidly-evolving masquerades, and cyber criminality levied against them. SGs require cyber-security systems to render them resilient and protected through advanced Intrusion Detection and Prevention System (IDPS) techniques and mechanisms. This paper proposes a smart collaborative advanced IDPS to provide the best possible protection of SGs with a fully distributed management structure that supports the network and host based detections and the prevention of attacks. By facilitating a reliable, scalable, and flexible design, the specific requirements of IDPS for SGs can be more easily met via a fuzzy risk analyzer, an independent and ontology knowledge-based inference engine module. These can work collaboratively by managing functions across multiple IDPS domains. A set of extensive and intensive simulated experiments shows that with its smart advanced components incorporating soft computing machine-learning techniques and a rich ontology knowledge base with fuzzy logic analysis, it detects and prevents intrusions more efficiently. The multi-faceted results of the simulation also show that the proposed Collaborative Smart IDPS (CSIDPS) system increases the intrusion detection accuracy and decreases the false positive alarms when compared to traditional IDPSs. This is epitomized by the skillful use of the confusion matrix technique for organizing classifiers, visualizing their performance, and assessing their overall behavior. In the final analysis, the CSIDPS architecture is designed toward contributing to de facto norms for SG ecosystems. ER - TY - JOUR T1 - DESO: Addressing volume and variety in large-scale criminal cases AU - Brady, Owen AU - Overill, Richard AU - Keppens, Jeroen JO - Digital Investigation VL - 15 SP - 72 EP - 82 PY - 2015 DA - 2015/12/01/ T2 - Special Issue: Big Data and Intelligent Data Analysis SN - 1742-2876 DO - https://doi.org/10.1016/j.diin.2015.10.002 UR - https://www.sciencedirect.com/science/article/pii/S1742287615001061 KW - Big data KW - Cyber forensics KW - Digital evidence KW - Ontology KW - Criminal investigation KW - Digital investigation KW - Artefacts AB - This paper proposes a mechanism for dealing with the growing variety and volume of digital evidence in a criminal investigation. The challenges posed by this growth have been long recognised and documented. There have been solutions aimed at processing bulk data and others based on event correlation or time lines. Instead we examine if there is an alternate method: to classify digital evidence artefacts in a way that assists selection of the potentially relevant evidence before processing any material. In so doing we wish to avoid generating bulk data and instead start viewing digital evidence from an investigative perspective – not a technological one. This paper details the continuing development of an ontology for this purpose – the Digital Evidence Semantic Ontology (DESO). This provides an index to a repository of known digital evidence artefacts which are classified according to the location that they are found and the information they represent. Further, this paper also demonstrates how DESO can be applied to criminal investigations to assist lines of enquiry. ER - TY - JOUR T1 - Formal knowledge model for online social network forensics AU - Arshad, Humaira AU - Jantan, Aman AU - Hoon, Gan Keng AU - Abiodun, Isaac Oludare JO - Computers & Security VL - 89 SP - 101675 PY - 2020 DA - 2020/02/01/ SN - 0167-4048 DO - https://doi.org/10.1016/j.cose.2019.101675 UR - https://www.sciencedirect.com/science/article/pii/S0167404819302160 KW - Forensic automation KW - Knowledge model KW - Formal model KW - Forensic ontology KW - Online social network forensics AB - Currently, examining social media networks is an integral part of most investigations. However, getting a clear view of the events relevant to the incident from a large set of data, such as social media, is a challenging task. Automation of the forensic and analysis process is the only solution to manage large data sets and get useful information. However, automation in digital forensics is a technical issue with legal implications. The legal system accepts only those automated processes that are reproducible, explainable, and rigorously testable. Therefore, automated forensic processes must be based on formal theories, which are rare in digital forensics. This article explains a theoretical and formal knowledge model for forensic automation on online social networks. This model consists of an event-based knowledge model, which provides theoretical concepts that can assist in the construction and interpretation of the events related to the incident under investigation. The proposed model is implemented through an ontology to provide semantically rich and formal representation to the concepts. This article also describes the feasibility of legally acceptable automated analysis operators, based on a formal theory, for online social network forensics. ER - TY - JOUR T1 - Contents JO - Procedia Computer Science VL - 109 SP - iii EP - xi PY - 2017 DA - 2017/01/01/ T2 - 8th International Conference on Ambient Systems, Networks and Technologies, ANT-2017 and the 7th International Conference on Sustainable Energy Information Technology, SEIT 2017, 16-19 May 2017, Madeira, Portugal SN - 1877-0509 DO - https://doi.org/10.1016/S1877-0509(17)31154-7 UR - https://www.sciencedirect.com/science/article/pii/S1877050917311547 ER - TY - JOUR T1 - Cyber resilience protection for industrial internet of things: A software-defined networking approach AU - Babiceanu, Radu F. AU - Seker, Remzi JO - Computers in Industry VL - 104 SP - 47 EP - 58 PY - 2019 DA - 2019/01/01/ SN - 0166-3615 DO - https://doi.org/10.1016/j.compind.2018.10.004 UR - https://www.sciencedirect.com/science/article/pii/S0166361517306954 KW - Software-defined networking KW - Cybersecurity-resilience mechanisms KW - Manufacturing logical control KW - Industrial internet of things AB - In addition to productivity and quality output, for many years, manufacturing systems were also designed with reliability and safety requirements in mind. In the recent decade or so, the approach seems not adequate anymore. The current manufacturing global operations ask for more stringent requirements than ever before, which include privacy and security of transactions, among others. Manufacturing control is not new, but the use of cloud environments to integrate distributed manufacturing facilities and entirely control the production processes across those facilities is an active research area denoted in terms such as: virtual factory, cloud manufacturing, Industry 4.0, Industrial Internet of Things (IIoT), and more recently, software-defined networking-based (SDN-based) manufacturing. In computer networking domain, SDN is known as a network architecture that decouples the network data and control mechanisms. SDN architecture assigns the entire data control to a logically centralized control plane that can be software-programmed based on specific application needs. From the security point of view, this translates in the fact that anyone with access to the computers that run the network control software could potentially get control over the entire network. This paper proposes an integrated modeling environment that addresses the virtual manufacturing system assurance through cybersecurity and resilience mechanisms for SDN applications. First, the paper proposes a SDN-based manufacturing testbed and a combined cybersecurity-resilience ontology to be used for the requirements capture of the virtual manufacturing network design stages. Then, the paper outlines the framework for SDN-based cybersecurity-resilience protection mechanisms for virtual manufacturing applications, and ends with the envisioned future research needed for implementing the proposed framework. ER - TY - JOUR T1 - TeknoRoadmap, an approach for depicting emerging technologies AU - Bildosola, Iñaki AU - Río-Bélver, Rosa María AU - Garechana, Gaizka AU - Cilleruelo, Ernesto JO - Technological Forecasting and Social Change VL - 117 SP - 25 EP - 37 PY - 2017 DA - 2017/04/01/ SN - 0040-1625 DO - https://doi.org/10.1016/j.techfore.2017.01.015 UR - https://www.sciencedirect.com/science/article/pii/S0040162516304310 KW - Technology forecasting KW - Bibliometrics KW - Technology roadmapping KW - Data mining KW - Web content mining KW - Cloud computing AB - One of the biggest challenges for current enterprises is the adoption of emerging technologies as soon as these provide competitive improvements. In this sense, several types of technology forecasting and surveillance activities are present in their daily activity. From the academic point of view, technology forecasting activities involve the combination of methods of a diverse nature, with which the technology is depicted and its potential future paths are discussed. Within this conceptual framework, the present work aims at describing a novel approach, known as TeknoRoadmap, which combines bibliometrics and technology forecasting methods to depict emerging technologies. Thus, this contribution aims to widen the scope compared to those provided by previous works within the field, and to that end, the depiction of emerging technologies is provided based on two main elements, namely: the profile of the research activity; and a complete technology roadmap. The approach combines consolidated methods such as text mining and roadmapping, and novel ones such as web content mining, with special attention given to forecasting activities. The work provides a detailed description of the steps on which the approach is structured, as well as the results of one specific application to a cutting edge emerging technology: cloud computing. ER - TY - JOUR T1 - A survey on forensic investigation of operating system logs AU - Studiawan, Hudan AU - Sohel, Ferdous AU - Payne, Christian JO - Digital Investigation VL - 29 SP - 1 EP - 20 PY - 2019 DA - 2019/06/01/ SN - 1742-2876 DO - https://doi.org/10.1016/j.diin.2019.02.005 UR - https://www.sciencedirect.com/science/article/pii/S1742287618303980 KW - Operating system logs KW - Event logs KW - Log forensics KW - Log tamper detection KW - Event correlation KW - Event reconstruction KW - Event anomaly AB - Event logs are one of the most important sources of digital evidence for forensic investigation because they record essential activities on the system. In this paper, we present a comprehensive literature survey of the forensic analysis on operating system logs. We present a taxonomy of various techniques used in this area. Additionally, we discuss the tools that support the examination of the event logs. This survey also gives a review of the publicly available datasets that are used in operating system log forensics research. Finally, we suggest potential future directions on the topic of operating system log forensics. ER - TY - JOUR T1 - Visualisation of fuzzy systems: requirements, techniques and framework AU - Pham, Binh AU - Brown, Ross JO - Future Generation Computer Systems VL - 21 IS - 7 SP - 1199 EP - 1212 PY - 2005 DA - 2005/07/01/ SN - 0167-739X DO - https://doi.org/10.1016/j.future.2004.04.007 UR - https://www.sciencedirect.com/science/article/pii/S0167739X04000512 KW - Fuzzy data KW - Ontologies KW - Framework KW - Visualisation AB - Complex fuzzy systems exist in many applications and effective visualisation is required to gain insights into the nature and working of these systems, especially in the implication of imprecision, its propagation and impacts on the quality and reliability of the outcomes. This paper presents a holistic approach towards the design of a visualisation system for fuzzy systems. We firstly analyse the requirements for such a visualisation system by articulating fundamental ontologies that underpin the structure and operations of fuzzy systems. A software framework using a multi-agent approach is then presented with the aim to facilitate the organisation and flow of complex tasks, their inter-relationships and their interactions with users. Finally, we discuss visualisation techniques for fuzzy data and fuzzy rules, and introduce methods to extend and improve some existing techniques. ER - TY - JOUR T1 - Design and Evaluation of COFELET-based Approaches for Cyber Security Learning and Training AU - KATSANTONIS, Menelaos N. AU - MAVRIDIS, Ioannis AU - GRITZALIS, Dimitris JO - Computers & Security VL - 105 SP - 102263 PY - 2021 DA - 2021/06/01/ SN - 0167-4048 DO - https://doi.org/10.1016/j.cose.2021.102263 UR - https://www.sciencedirect.com/science/article/pii/S0167404821000870 KW - Cyber security education KW - Serious games KW - Design KW - Evaluation KW - Ontology KW - eLearning KW - Training KW - COFELET AB - Cyber security game-based learning is a new field that lacks design standards and common methodologies. To this end, the Conceptual Framework for eLearning and Training (COFELET) and the COFELET ontology have been proposed. COFELET is a framework that can be used as a guide for the design and evaluation of effective cyber security learning and training approaches, whereas the COFELET ontology describes the key elements that such approaches should embrace to assimilate well known cyber security threat analysis and modeling standards as the means to create interesting educational experiences. Aiming at providing insights on how COFELET compliant approaches can be developed, we propose the life-cycle of a COFELET game, a blueprint illustrating the design aspects and the course of phases for the development of COFELET compliant games (COFELET games). Besides, an extension of the COFELET ontology is also proposed describing the appropriate elements utilized to develop the learning and the instructional aspects of COFELET games. Based on the life-cycle of a COFELET game and the extended COFELET ontology, we elaborate the design of a prototype hacking simulator COFELET game, called HackLearn. An excerpt of the HackLearn's design is methodically presented along with the analysis elaborated according to the Activity Theory Model for Serious Games (ATMSG) and a set of instances of the COFELET ontology objects. Finally, the HackLearn's game design is put on the test of a preliminary evaluation scheme elaborated for the assessment of new cyber security game-based learning approaches. The results of the evaluation show that HackLearn embraces several features of cyber security game-based learning approaches and they also provide reasons to be optimistic about the effectiveness of the cyber security learning and training that it will deliver. ER - TY - JOUR T1 - A unified framework for cloud security transparency and audit AU - Ismail, Umar Mukhtar AU - Islam, Shareeful JO - Journal of Information Security and Applications VL - 54 SP - 102594 PY - 2020 DA - 2020/10/01/ SN - 2214-2126 DO - https://doi.org/10.1016/j.jisa.2020.102594 UR - https://www.sciencedirect.com/science/article/pii/S2214212620307626 KW - Security audit KW - Cloud security transparency KW - Cloud audit KW - Security requirements AB - The paradigm of cloud computing has elevated IT to new heights by offering the elasticity to match customer needs, while also reducing capital expenditure on procuring IT infrastructure. Despite the apparent benefits provided by cloud computing, organisations are slow in embracing the technology due to numerous issues that are associated with the lack of security transparency such as trust and accountability. Several contributions have been proposed to address these issues. However, most of the contributions have not provided a definite method by which security transparency can be achieved based on user requirements, and particularly, by probing or auditing cloud service providers. In this paper, we propose a framework for addressing a pressing challenge of cloud security transparency. Our approach includes a process and a supporting auditing tool for vetting cloud service providers and enabling security transparency based on predefined user requirements. The paper builds on our previous work on security transparency framework by incorporating an implementation process. In addition, we have developed a Security Transparency and Audit Tool through which users can collect and analyze evidence from cloud service providers for determining conformity to requirements, as well as for the specification of remedial actions. The tool is designed to be a supplementary component of the proposed framework that enables continuous probing and vetting of cloud provider meets user requirements, thereby enhancing security transparency. The work is novel in its approach because it consolidates various elements to provide a simplified method for organizations to attain security transparency. We also believe that the contributions are significant towards solving the issues and challenges of cloud security transparency in general. ER - TY - JOUR T1 - Study of identifying and managing the potential evidence for effective Android forensics AU - Kim, Dohyun AU - Lee, Sangjin JO - Forensic Science International: Digital Investigation VL - 33 SP - 200897 PY - 2020 DA - 2020/06/01/ SN - 2666-2817 DO - https://doi.org/10.1016/j.fsidi.2019.200897 UR - https://www.sciencedirect.com/science/article/pii/S1742287619301367 KW - Mobile forensics KW - Android forensics KW - Data grouping KW - Potential evidence identification KW - Data classification KW - Mobile data analysis KW - Evidence management KW - Data taxonomy KW - Android forensics XML AB - Since the advent of various IoT devices, the need for digital forensics for mobile devices that people use most closely in their daily lives has continued to grow. Besides, as Bring Your Own Device (BYOD) becomes the trend, devices store business-related information as well as privacy. Thus, mobile devices are becoming the most critical evidence of digital forensics. For practical mobile forensics, it is necessary to identify crime-related items among the many files inside the device accurately. Also, various user information for user behavior analysis from these files should be effectively extracted and managed as potential evidence to ensure integrity. This paper proposes an efficient forensics investigation method for mobile devices with Android OS, which holds the highest share in the world among mobile devices. In this paper, we studied data pre-processing (classification and identification of data), data analysis, evidence management, and Android data Taxonomy. ER - TY - JOUR T1 - Experience constructing the Artifact Genome Project (AGP): Managing the domain's knowledge one artifact at a time AU - Grajeda, Cinthya AU - Sanchez, Laura AU - Baggili, Ibrahim AU - Clark, Devon AU - Breitinger, Frank JO - Digital Investigation VL - 26 SP - S47 EP - S58 PY - 2018 DA - 2018/07/01/ SN - 1742-2876 DO - https://doi.org/10.1016/j.diin.2018.04.021 UR - https://www.sciencedirect.com/science/article/pii/S1742287618302007 KW - Forensics KW - Artifacts KW - Applications KW - Education AB - While various tools have been created to assist the digital forensics community with acquiring, processing, and organizing evidence and indicating the existence of artifacts, very few attempts have been made to establish a centralized system for archiving artifacts. The Artifact Genome Project (AGP) has aimed to create the largest vetted and freely available digital forensics repository for Curated Forensic Artifacts (CuFAs). This paper details the experience of building, implementing, and maintaining such a system by sharing design decisions, lessons learned, and future work. We also discuss the impact of AGP in both the professional and academic realms of digital forensics. Our work shows promise in the digital forensics academic community to champion the effort in curating digital forensic artifacts by integrating AGP into courses, research endeavors, and collaborative projects. ER - TY - JOUR T1 - Network security assessment using a semantic reasoning and graph based approach AU - Wu, Songyang AU - Zhang, Yong AU - Cao, Wei JO - Computers & Electrical Engineering VL - 64 SP - 96 EP - 109 PY - 2017 DA - 2017/11/01/ SN - 0045-7906 DO - https://doi.org/10.1016/j.compeleceng.2017.02.001 UR - https://www.sciencedirect.com/science/article/pii/S0045790617302409 KW - Network security KW - Security ontology KW - Attack graph KW - Semantic reasoning AB - Owing to the high value of business data, sophisticated cyber-attacks targeting enterprise networks have become more prominent, with attackers trying to penetrate deeper into and reach wider from the compromised machines. An important security requirement is that domain experts and network administrators have a common vocabulary to share security knowledge and quickly help each other respond to new threats. We propose an innovative ontology and graph-based approach for security assessment. An ontology is designed to represent security knowledge such as that of assets, vulnerabilities, and attacks in a common form. Using the inference abilities of the ontological model, an efficient system framework is proposed to generate attack graphs and assess network security. The performance of the proposed system is evaluated on test networks of differing sizes and topologies. ER - TY - JOUR T1 - Modern art challenges face detection AU - Wechsler, Harry AU - Toor, Andeep S. JO - Pattern Recognition Letters VL - 126 SP - 3 EP - 10 PY - 2019 DA - 2019/09/01/ T2 - Robustness, Security and Regulation Aspects in Current Biometric Systems SN - 0167-8655 DO - https://doi.org/10.1016/j.patrec.2018.02.014 UR - https://www.sciencedirect.com/science/article/pii/S0167865518300576 KW - Modern art KW - Biometrics KW - Face detection KW - Forensics KW - Visual Turing test KW - Interoperability AB - There is a widely held belief that computer vision, in general, and face authentication, in particular, are to a large extent solved problems. This paper challenges this belief regarding face authentication using examples from modern art that significantly confound face detection. The challenges are made concrete using a new MAFD-150 dataset (Modern Art Face Detection) composed mostly of modern art examples that cover much diversity in style and artists. MAFD-150 challenges the belief that singleton and crowd face detection is an almost solved problem, and provides baselines and preliminary results that highlight the inadequacy of current expertise and methods to address face detection. In particular, we show that well-known face detection algorithms are only able to achieve an F1 score of less than 35% overall across the new dataset. Additionally, we discuss the performance of the selected face detectors on varying art categories (such as Impressionism, Pop Art, et al.) to show how style and face representation may impact these algorithms. The paper concludes with suggestions on how to advance face processing by leveraging the complementarity between Show-and-Tell-like methods and a context and cooperative driven visual question answering framework using relevance-based triage. The very challenges detailed throughout are then shown to be helpful with developing novel, robust, and secure access protocols that combine text and modern art images using the visual question answering framework. ER - TY - CHAP T1 - Chapter 4 - Metadata Management and the Semantic Web AU - Yang, Sharon Q. AU - Li, Lili A2 - Yang, Sharon Q. A2 - Li, Lili BT - Emerging Technologies for Librarians PB - Chandos Publishing SP - 41 EP - 55 PY - 2016 DA - 2016/01/01/ SN - 978-1-84334-788-0 DO - https://doi.org/10.1016/B978-1-84334-788-0.00004-5 UR - https://www.sciencedirect.com/science/article/pii/B9781843347880000045 KW - Metadata KW - BIBFRAME KW - RDA KW - RDF KW - URI KW - Semantic Web KW - Linked Data AB - Metadata is defined as data about data and information about information. Librarians have been involved with metadata creation and discovery since the pre-AACR2 and MARC era. In the digital age, the concept about metadata management has changed drastically. The modern library metadata should display entity relationships among data elements. They must be released from silos and be accessible through popular Internet search engines. The Semantic Web is the chosen technology to accomplish the above goal. FRBR, RDA, BIBFRAME, and Linked Data are a series of standards and technologies that will facilitate this process. Among many challenges ahead, libraries must reconcile the requirements of search engines and library metadata schemas and vocabularies. ER - TY - JOUR T1 - An optimized approach for massive web page classification using entity similarity based on semantic network AU - Li, Huakang AU - Xu, Zheng AU - Li, Tao AU - Sun, Guozi AU - Raymond Choo, Kim-Kwang JO - Future Generation Computer Systems VL - 76 SP - 510 EP - 518 PY - 2017 DA - 2017/11/01/ SN - 0167-739X DO - https://doi.org/10.1016/j.future.2017.03.003 UR - https://www.sciencedirect.com/science/article/pii/S0167739X17303321 KW - Web page classification KW - Semantic network KW - Kinship-relation association KW - Entity class probability KW - Hereditary weight AB - With the development of mobile technology, the users browsing habits are gradually shifted from only information retrieval to active recommendation. The classification mapping algorithm between users interests and web contents has been become more and more difficult with the volume and variety of web pages. Some big news portal sites and social media companies hire more editors to label these new concepts and words, and use the computing servers with larger memory to deal with the massive document classification, based on traditional supervised or semi-supervised machine learning methods. This paper provides an optimized classification algorithm for massive web page classification using semantic networks, such as Wikipedia, WordNet. In this paper, we used Wikipedia data set and initialized a few category entity words as class words. A weight estimation algorithm based on the depth and breadth of Wikipedia network is used to calculate the class weight of all Wikipedia Entity Words. A kinship-relation association based on content similarity of entity was therefore suggested optimizing the unbalance problem when a category node inherited the probability from multiple fathers. The keywords in the web page are extracted from the title and the main text using N-gram with Wikipedia Entity Words, and Bayesian classifier is used to estimate the page class probability. Experimental results showed that the proposed method obtained good scalability, robustness and reliability for massive web pages. ER - TY - JOUR T1 - DIALOG: A framework for modeling, analysis and reuse of digital forensic knowledge AU - Kahvedžić, Damir AU - Kechadi, Tahar JO - Digital Investigation VL - 6 SP - S23 EP - S33 PY - 2009 DA - 2009/09/01/ T2 - The Proceedings of the Ninth Annual DFRWS Conference SN - 1742-2876 DO - https://doi.org/10.1016/j.diin.2009.06.014 UR - https://www.sciencedirect.com/science/article/pii/S174228760900036X KW - Windows KW - Registry KW - Digital KW - Investigation KW - Ontology AB - This paper presents DIALOG (Digital Investigation Ontology); a framework for the management, reuse, and analysis of Digital Investigation knowledge. DIALOG provides a general, application independent vocabulary that can be used to describe an investigation at different levels of detail. DIALOG is defined to encapsulate all concepts of the digital forensics field and the relationships between them. In particular, we concentrate on the Windows Registry, where registry keys are modeled in terms of both their structure and function. Registry analysis software tools are modeled in a similar manner and we illustrate how the interpretation of their results can be done using the reasoning capabilities of ontology. ER - TY - JOUR T1 - Subject-based semantic document clustering for digital forensic investigations AU - Dagher, Gaby G. AU - Fung, Benjamin C.M. JO - Data & Knowledge Engineering VL - 86 SP - 224 EP - 241 PY - 2013 DA - 2013/07/01/ SN - 0169-023X DO - https://doi.org/10.1016/j.datak.2013.03.005 UR - https://www.sciencedirect.com/science/article/pii/S0169023X13000360 KW - Clustering KW - Classification KW - Data mining KW - Information retrieval KW - Forensic analysis KW - Crime investigation AB - Computers are increasingly used as tools to commit crimes such as unauthorized access (hacking), drug trafficking, and child pornography. The proliferation of crimes involving computers has created a demand for special forensic tools that allow investigators to look for evidence on a suspect's computer by analyzing communications and data on the computer's storage devices. Motivated by the forensic process at Sûreté du Québec (SQ), the Québec provincial police, we propose a new subject-based semantic document clustering model that allows an investigator to cluster documents stored on a suspect's computer by grouping them into a set of overlapping clusters, each corresponding to a subject of interest initially defined by the investigator. ER - TY - JOUR T1 - Editorial for big data issue AU - Geradts, Zeno J. AU - Franke, Katrin JO - Digital Investigation VL - 15 SP - 18 EP - 19 PY - 2015 DA - 2015/12/01/ T2 - Special Issue: Big Data and Intelligent Data Analysis SN - 1742-2876 DO - https://doi.org/10.1016/j.diin.2015.10.003 UR - https://www.sciencedirect.com/science/article/pii/S1742287615001073 ER - TY - JOUR T1 - Table of Contents JO - Procedia Computer Science VL - 141 SP - iii EP - vii PY - 2018 DA - 2018/01/01/ T2 - The 9th International Conference on Emerging Ubiquitous Systems and Pervasive Networks (EUSPN-2018) / The 8th International Conference on Current and Future Trends of Information and Communication Technologies in Healthcare (ICTH-2018) / Affiliated Workshops SN - 1877-0509 DO - https://doi.org/10.1016/S1877-0509(18)32249-X UR - https://www.sciencedirect.com/science/article/pii/S187705091832249X ER - TY - JOUR T1 - A critical review of 7 years of Mobile Device Forensics AU - Barmpatsalou, Konstantia AU - Damopoulos, Dimitrios AU - Kambourakis, Georgios AU - Katos, Vasilios JO - Digital Investigation VL - 10 IS - 4 SP - 323 EP - 349 PY - 2013 DA - 2013/12/01/ SN - 1742-2876 DO - https://doi.org/10.1016/j.diin.2013.10.003 UR - https://www.sciencedirect.com/science/article/pii/S1742287613001096 KW - Mobile Device Forensics KW - Smartphone KW - Security KW - Forensic acquisition KW - Mobile OS AB - Mobile Device Forensics (MF) is an interdisciplinary field consisting of techniques applied to a wide range of computing devices, including smartphones and satellite navigation systems. Over the last few years, a significant amount of research has been conducted, concerning various mobile device platforms, data acquisition schemes, and information extraction methods. This work provides a comprehensive overview of the field, by presenting a detailed assessment of the actions and methodologies taken throughout the last seven years. A multilevel chronological categorization of the most significant studies is given in order to provide a quick but complete way of observing the trends within the field. This categorization chart also serves as an analytic progress report, with regards to the evolution of MF. Moreover, since standardization efforts in this area are still in their infancy, this synopsis of research helps set the foundations for a common framework proposal. Furthermore, because technology related to mobile devices is evolving rapidly, disciplines in the MF ecosystem experience frequent changes. The rigorous and critical review of the state-of-the-art in this paper will serve as a resource to support efficient and effective reference and adaptation. ER - TY - JOUR T1 - Beyond ubiquitous computing: The Malaysian HoneyBee project for Innovative Digital Economy AU - Patel, Ahmed AU - Nordin, Rosdiadee AU - Al-Haiqi, Ahmed JO - Computer Standards & Interfaces VL - 36 IS - 5 SP - 844 EP - 854 PY - 2014 DA - 2014/09/01/ SN - 0920-5489 DO - https://doi.org/10.1016/j.csi.2014.01.003 UR - https://www.sciencedirect.com/science/article/pii/S0920548914000063 KW - Ad-hoc network KW - Decentralized network KW - Ensemble computing KW - HoneyBee KW - Security KW - Safety KW - Performance statistics AB - In the proposed advanced computing environment, known as the HoneyBee Platform, various computing devices using single or multiple interfaces and technologies/standards need to communicate and cooperate efficiently with a certain level of security and safety measures. These computing devices may be supported by different types of operating systems with different features and levels of security support. In order to ensure that all operations within the environment can be carried out seamlessly in an ad-hoc manner, there is a need for a common mobile platform to be developed. The purpose of this long-term project is to investigate and implement a new functional layered model of the common mobile platform with secured and trusted ensemble computing architecture for an innovative Digital Economic Environment in the Malaysian context. This mobile platform includes a lightweight operating system to provide a common virtual environment, a middleware for providing basic functionalities of routing, resource and network management, as well as to provide security, privacy and a trusted environment. A generic application programming interface is provided for application developers to access underlying resources. The aim is for the developed platform to act as the building block for an ensemble environment, upon which higher level applications could be built. Considered as the most essential project in a series of related projects towards a more digital socio-economy in Malaysia, this article presents the design of the target computational platform as well as the conceptual framework for the HoneyBee project. ER - TY - JOUR T1 - Domain Ontology of Hand-drawn Avatars as Online Self-representations for Cyber Forensics AU - Mei, Cheong Lee AU - Jamaludin, Nor Adzlan JO - Procedia Computer Science VL - 20 SP - 163 EP - 168 PY - 2013 DA - 2013/01/01/ T2 - Complex Adaptive Systems SN - 1877-0509 DO - https://doi.org/10.1016/j.procs.2013.09.255 UR - https://www.sciencedirect.com/science/article/pii/S1877050913010557 KW - ontology KW - avatar KW - self-representation KW - document retrieval KW - hand-drawn avatars AB - The idea of concepts and relationships in the organization of hand-drawn avatars can be defined and identified with ontology. Hand-drawn avatars as online self-representation can be used for criminal investigation in cyber space. These iconic self- representations are important as supporting evidence for other physical evidence in forensic investigation. Informal knowledge about avatars as online self-representation is acquired by considering the broadest possible categories of hand-drawn avatars among 210 participants of ages between 21 and 22 years old with no prior knowledge of readily available online avatars. An analysis of an earlier research yields nine categories of the avatars: inanimate object, cartoon, humanoid, male figure, female figure, insect, animal, plant, and hybrid form. The common goal in information retrieval is to retrieve as many documents as possible from a collection that are closely related to an investigator's query. In this paper, we propose a model to support cyber forensics by utilizing an AvatarDrawn Ontological Knowledge Base (AOKB) in a document retrieval system. An advantage of this approach is that the AOKB can be progressively improved through definitions of new entities to expand its domain knowledge. An algorithm for semantic hand-drawn image retrieval is written to provide comprehensive and objective information. ER - TY - JOUR T1 - AFF4-L: A Scalable Open Logical Evidence Container AU - Schatz, Bradley L. JO - Digital Investigation VL - 29 SP - S143 EP - S149 PY - 2019 DA - 2019/07/01/ SN - 1742-2876 DO - https://doi.org/10.1016/j.diin.2019.04.016 UR - https://www.sciencedirect.com/science/article/pii/S1742287619301653 KW - Logical image KW - AFF4 KW - Deduplication AB - With the proliferation of cloud-based evidence and locked down physical storage logical imaging is increasingly necessary in digital forensics. In practice closed formats are commonly used, however they lack extensibility and expressiveness, are poorly defined, and suffer from limited interoperability. This work proposes and implements an open logical imaging format based on the AFF4 evidence container, supporting scalable arbitrary metadata storage and deduplicated logical image storage. ER - TY - JOUR T1 - Identifying 3D printer residual data via open-source documentation AU - Miller, Daniel Bradford AU - Glisson, William Bradley AU - Yampolskiy, Mark AU - Choo, Kim-Kwang Raymond JO - Computers & Security VL - 75 SP - 10 EP - 23 PY - 2018 DA - 2018/06/01/ SN - 0167-4048 DO - https://doi.org/10.1016/j.cose.2018.01.011 UR - https://www.sciencedirect.com/science/article/pii/S0167404818300324 KW - Additive manufacturing KW - 3D printer KW - Residual data KW - Digital forensics KW - Open Source Intelligence KW - Embedded systems AB - Additive manufacturing, also known as 3D printing, is a rapidly growing technology that enables the production of customized complex objects. Its proliferation into both industrial and consumer markets, combined with the potential for misuse, raises questions about how to investigate an incident involving 3D printers. A survey of product documentation acquired from Open Source Intelligence (OSINT) sources reveals patterns in the processes used to print objects with consumer 3D printer models used by 3D object printing services. Both the ability to operate without an attached controlling computer and the methods by which G-code instructions move to the device are identified as features relevant to the potential presence of residual data. The implications of this residual data are discussed within the contexts of digital forensics, intellectual property protection, and privacy. It is concluded that classes of 3D printers are predisposed to containing residual data based on the functionality offered to the user. Additionally, investigations of 3D printers should involve not only the printer itself, but also any devices used in the production or transport of the object design and G-code files in order to develop a comprehensive picture of the events leading to the production of an object. ER - TY - JOUR T1 - Taming the logs - Vocabularies for semantic security analysis AU - Ekelhart, Andreas AU - Kiesling, Elmar AU - Kurniawan, Kabul JO - Procedia Computer Science VL - 137 SP - 109 EP - 119 PY - 2018 DA - 2018/01/01/ T2 - Proceedings of the 14th International Conference on Semantic Systems 10th – 13th of September 2018 Vienna, Austria SN - 1877-0509 DO - https://doi.org/10.1016/j.procs.2018.09.011 UR - https://www.sciencedirect.com/science/article/pii/S1877050918316156 KW - semantic extraction KW - log vocabularies KW - log analysis KW - security analysis AB - Due to the growing complexity of information systems and the increasing prevalence and sophistication of threats, security management has become an enormously challenging task. To identify suspicious activities, security analysts need to monitor their systems constantly, which involves coping with high volumes of heterogeneous log data from various sources. Processes to aggregate these disparate logs and trigger alerts when particular events occur are often automated today. However, these methods are typically based on regular expressions and statistical correlations and do not involve any interpretation of the context in which an event occurred and do not allow for inference or sophisticated rules. Inspection and in-depth analysis of log information to link events from various sources (e.g., firewall, syslog, web server log, database log) and establish causal chains has therefore largely remained a tedious manual search process that scales poorly with a growing number of heterogeneous log sources, log volumes, and the increasing complexity of attacks. In this paper, we make the case for a semantic approach to tackle these challenges. By lifting raw log data and modeling their context, events can be linked to rich background knowledge, integrated based on causal relations, and interpreted in a context-specific manner. This builds a foundation for more comprehensive extraction of the meaning of events from unstructured log messages. Based on the results, we envision a platform to partly automate security monitoring and support analysts in coping with fast evolving threat landscapes, alleviate alert fatigue, improve situational awareness, and expedite incidence response. ER - TY - CHAP T1 - Chapter 7 - Standard operating procedures for cybercrime investigations: a systematic literature review AU - Jeffries, Stephen AU - Apeh, Edward A2 - Benson, Vladlena A2 - Mcalaney, John BT - Emerging Cyber Threats and Cognitive Vulnerabilities PB - Academic Press SP - 145 EP - 162 PY - 2020 DA - 2020/01/01/ SN - 978-0-12-816203-3 DO - https://doi.org/10.1016/B978-0-12-816203-3.00007-1 UR - https://www.sciencedirect.com/science/article/pii/B9780128162033000071 KW - Cybercrime KW - Cybercrime investigations KW - Evidence-based policing KW - Policing cybercrime KW - Standard operating procedures KW - Systematic literature review AB - Traditional policing involves the identification of a victim and the establishment of an offender via way of an investigation. The investigation seeks to obtain the necessary evidence through the overt or covert collection of the evidence to support a prosecution of the offender. Overt recovery of evidence involves the obtaining of statements from victims and witnesses, CCTV recovery, photographs or videos and the forensic examination of materials for fingerprints or DNA. The covert methods involve the gathering of intelligence through Covert Human Intelligence Sources (CHIS), interception of telecommunications, infiltration of crimes groups and the use of surveillance. These approaches are inherent in policing investigative procedures and have been instilled in police officers from basic training and throughout their policing careers. The advancement in cyberspace has created new challenges for policing. Crime in cyberspace operates in a nontraditional way, and the threats and the vulnerabilities of cyberspace tend to make the use of such traditional techniques in police investigation ineffective when applied against cybercrime and cybercriminals. For example, in offences of incitement and radicalization, the victims are often so far removed from each other that traditional reactive police investigations are likely to fail to identify an offender, their location and those victims before any offences being committed and thereby any potential interventions would be too late to prevent any offences being completed. Therefore, policing needs to consider new procedures that take into account the differences in the cyber landscape and how crime is committed online. This chapter performs a systematic literature review of traditional policing with a view of identifying and proposing new procedures that can be adapted to investigate and gather evidence of cybercrimes. ER - TY - JOUR T1 - Interpol review of digital evidence 2016 - 2019 AU - Reedy, Paul JO - Forensic Science International: Synergy VL - 2 SP - 489 EP - 520 PY - 2020 DA - 2020/01/01/ SN - 2589-871X DO - https://doi.org/10.1016/j.fsisyn.2020.01.015 UR - https://www.sciencedirect.com/science/article/pii/S2589871X20300152 KW - Digital forensics KW - Digital evidence KW - Network forensics AB - This review paper covers the forensic-relevant literature in digital evidence from 2016 to 2019 as a part of the 19th Interpol International Forensic Science Managers Symposium. The review papers are also available at the Interpol website at: https://www.interpol.int/content/download/14458/file/Interpol Review Papers 2019.pdf ER - TY - JOUR T1 - Digital forensics as a service: Stepping up the game AU - van Beek, H.M.A. AU - van den Bos, J. AU - Boztas, A. AU - van Eijk, E.J. AU - Schramp, R. AU - Ugen, M. JO - Forensic Science International: Digital Investigation VL - 35 SP - 301021 PY - 2020 DA - 2020/12/01/ SN - 2666-2817 DO - https://doi.org/10.1016/j.fsidi.2020.301021 UR - https://www.sciencedirect.com/science/article/pii/S2666281720300706 KW - Digital forensics KW - Digital forensics as a service KW - DFaaS KW - Hansken AB - After providing Digital Forensics as a Service (DFaaS) implementations to law enforcement agencies for close to a decade, we present our view from an inside-out perspective. We share the lessons learned from an organizational, operational and development perspective in a forensic and legal context. We conclude with our vision on how to bring the DFaaS concept to the next level for both investigative and innovative purposes. ER - TY - JOUR T1 - Snapchat Analysis to Discover Digital Forensic Artifacts on Android Smartphone AU - Alyahya, Tadani AU - Kausar, Firdous JO - Procedia Computer Science VL - 109 SP - 1035 EP - 1040 PY - 2017 DA - 2017/01/01/ T2 - 8th International Conference on Ambient Systems, Networks and Technologies, ANT-2017 and the 7th International Conference on Sustainable Energy Information Technology, SEIT 2017, 16-19 May 2017, Madeira, Portugal SN - 1877-0509 DO - https://doi.org/10.1016/j.procs.2017.05.421 UR - https://www.sciencedirect.com/science/article/pii/S1877050917311006 KW - Android KW - Smartphone KW - Forensic analysis KW - Autopsy KW - Magent Axiom KW - Snapchat AB - Abstract: Smartphones play an important role in our lives. With the advent of applications for smartphones, the more functionalities and services are offered to users. Online social networks (OSN) applications are the most popular applications worldwide. OSN applications, such as Facebook and Twitter, allow users to share personal information such as posts, age, gender, location, photos and videos. This valuable information saved on smartphones’ internal memory and could be used as evidence during forensic investigation. Snapchat is a popular OSN application that is available for Android and iOS devices. It allows users to share photos and videos called Snaps with predetermined time to view. Once the time expired, snaps are automatically deleted. This paper analyses artifacts saved by Snapchat application on Android smartphones and identifies their significance to the forensic investigation process. ER - TY - JOUR T1 - Knowledge Representation Model for Crime Analysis AU - Abdul Jalil, Masita @ Masila AU - Ling, Chia Pui AU - Mohamad Noor, Noor Maizura AU - Mohd., Fatihah JO - Procedia Computer Science VL - 116 SP - 484 EP - 491 PY - 2017 DA - 2017/01/01/ T2 - Discovery and innovation of computer science technology in artificial intelligence era: The 2nd International Conference on Computer Science and Computational Intelligence (ICCSCI 2017) SN - 1877-0509 DO - https://doi.org/10.1016/j.procs.2017.10.067 UR - https://www.sciencedirect.com/science/article/pii/S1877050917321178 KW - Correlation KW - crime analysis KW - knowledge representation KW - ontology KW - TopBraid AB - The knowledge representation model is a particular way in representing knowledge by using the knowledge and reasoning mechanism. Ontology is a kind of knowledge representation model that represents knowledge as a set of concepts within a domain and the relationship between these concepts. It is important to solve the problem of large amount of data in the crime investigation domain which is not well defined in a proper relation. The problems exist currently are how to develop an ontology model to represent the crime investigation information and how to make good use of the information represented by the model. These problems could be solved by developing an ontological-based case matching model, named CrimeAnalysis as a study prototype. In this study, an ontology model is developed using the selected semantic modelling tool, named TopBraid Composer Standard Edition in order to represent the crime information with the well-defined classes and relationships. This would help to save the investigation officer’s effort in aiming and targeting the possible suspect within the shortest time interval. ER - TY - JOUR T1 - A comparative study of support vector machine and neural networks for file type identification using n-gram analysis AU - Sester, Joachim AU - Hayes, Darren AU - Scanlon, Mark AU - Le-Khac, Nhien-An JO - Forensic Science International: Digital Investigation VL - 36 SP - 301121 PY - 2021 DA - 2021/04/01/ T2 - DFRWS 2021 EU - Selected Papers and Extended Abstracts of the Eighth Annual DFRWS Europe Conference SN - 2666-2817 DO - https://doi.org/10.1016/j.fsidi.2021.301121 UR - https://www.sciencedirect.com/science/article/pii/S2666281721000184 KW - File type identification KW - n-grams analysis KW - Forensic analysis KW - Neural networks KW - Support vector machine AB - File type identification (FTI) has become a major discipline for anti-virus developers, firewall designers and for forensic cybercrime investigators. Over the past few years, research has seen the introduction of several classifiers and features. One of these advances is the so-called n-grams analysis, which is an interpretation of statistical counting in classified fragments. Recently, n-grams based approaches were already successfully combined with computational intelligence classifiers. However, the academic body of literature is scant when it comes to a comprehensive explanation of machine learning based approaches such as neural networks (NN) or support vector machines (SVM). For example, how the input parameters, including learning rate, different values of n for n-grams, etc. influence the results. In addition, very few studies have compared the scalability of NN vs. SVM approaches. Therefore, a systematic research in comparing different approaches is needed to address these questions. Hence, this paper investigates this type of comparison, by focusing on the n-gram analysis as a feature for the two different classifiers: SVMs and NNs. This paper details our experiments with two NNs and four SVMs, using linear kernels and RBF kernels on RealDC datasets. In general, we found that SVM-based approaches performed better than the NN, but their scalability is still a challenge. ER - TY - JOUR T1 - CHIS: A big data infrastructure to manage digital cultural items AU - Castiglione, Aniello AU - Colace, Francesco AU - Moscato, Vincenzo AU - Palmieri, Francesco JO - Future Generation Computer Systems VL - 86 SP - 1134 EP - 1145 PY - 2018 DA - 2018/09/01/ SN - 0167-739X DO - https://doi.org/10.1016/j.future.2017.04.006 UR - https://www.sciencedirect.com/science/article/pii/S0167739X17305605 KW - Big data KW - Cultural heritage KW - Resource management KW - Big data analytics KW - SOA KW - NoSQL AB - In this paper, we describe CHIS (Cultural Heritage Information System), a big data infrastructure that can be used to query, browse, analyze and process digital contents related to cultural heritage from a set of heterogeneous and distributed repositories. CHIS is characterized by the following technical features: capability to gather information from distributed and heterogeneous data sources (e.g., Sensor Networks, Social Media Networks, Digital Libraries and Archives, Multimedia Collections, Web Data Services, etc.); advanced data management techniques and technologies; ability to provide useful and personalized data to users based on their preferences and context; advanced information retrieval facilities, data analytics and other utilities/services, according to the SOA paradigm. By means of a set of ad-hoc APIs, and value-added data processing and analytics services, our system can support several applications: mobile multimedia guides for cultural environments, web portals to promote the cultural heritage of a given organization, multimedia recommender and storytelling systems and so on. We discuss the main ideas that characterize the system, showing its use for several applications. ER - TY - JOUR T1 - Contents JO - Procedia Computer Science VL - 159 SP - iii EP - xvii PY - 2019 DA - 2019/01/01/ T2 - Knowledge-Based and Intelligent Information & Engineering Systems: Proceedings of the 23rd International Conference KES2019 SN - 1877-0509 DO - https://doi.org/10.1016/S1877-0509(19)31644-8 UR - https://www.sciencedirect.com/science/article/pii/S1877050919316448 ER - TY - JOUR T1 - Contents JO - Procedia Computer Science VL - 176 SP - iii EP - xxiii PY - 2020 DA - 2020/01/01/ T2 - Knowledge-Based and Intelligent Information & Engineering Systems: Proceedings of the 24th International Conference KES2020 SN - 1877-0509 DO - https://doi.org/10.1016/S1877-0509(20)32261-4 UR - https://www.sciencedirect.com/science/article/pii/S1877050920322614 ER - TY - JOUR T1 - The role of big data analytics in Internet of Things AU - Ahmed, Ejaz AU - Yaqoob, Ibrar AU - Hashem, Ibrahim Abaker Targio AU - Khan, Imran AU - Ahmed, Abdelmuttlib Ibrahim Abdalla AU - Imran, Muhammad AU - Vasilakos, Athanasios V. JO - Computer Networks VL - 129 SP - 459 EP - 471 PY - 2017 DA - 2017/12/24/ T2 - Special Issue on 5G Wireless Networks for IoT and Body Sensors SN - 1389-1286 DO - https://doi.org/10.1016/j.comnet.2017.06.013 UR - https://www.sciencedirect.com/science/article/pii/S1389128617302591 KW - Internet of Things KW - Big data KW - Analytics KW - Distributed computing KW - Smart city AB - The explosive growth in the number of devices connected to the Internet of Things (IoT) and the exponential increase in data consumption only reflect how the growth of big data perfectly overlaps with that of IoT. The management of big data in a continuously expanding network gives rise to non-trivial concerns regarding data collection efficiency, data processing, analytics, and security. To address these concerns, researchers have examined the challenges associated with the successful deployment of IoT. Despite the large number of studies on big data, analytics, and IoT, the convergence of these areas creates several opportunities for flourishing big data and analytics for IoT systems. In this paper, we explore the recent advances in big data analytics for IoT systems as well as the key requirements for managing big data and for enabling analytics in an IoT environment. We taxonomized the literature based on important parameters. We identify the opportunities resulting from the convergence of big data, analytics, and IoT as well as discuss the role of big data analytics in IoT applications. Finally, several open challenges are presented as future research directions. ER - TY - CHAP T1 - Chapter 4 - Archival and recordkeeping research: Past, present and future AU - Gilliland, Anne J. AU - McKemmish, Sue A2 - Williamson, Kirsty A2 - Johanson, Graeme BT - Research Methods (Second Edition) PB - Chandos Publishing SP - 85 EP - 125 PY - 2018 DA - 2018/01/01/ SN - 978-0-08-102220-7 DO - https://doi.org/10.1016/B978-0-08-102220-7.00004-2 UR - https://www.sciencedirect.com/science/article/pii/B9780081022207000042 KW - Research in archival multiverse KW - archival research infrastructure KW - research design KW - archival research methodologies KW - archival research methods ER - TY - JOUR T1 - Risk media and the end of anonymity AU - Hoskins, Andrew JO - Journal of Information Security and Applications VL - 34 SP - 2 EP - 7 PY - 2017 DA - 2017/06/01/ T2 - Human-Centred Cyber Security SN - 2214-2126 DO - https://doi.org/10.1016/j.jisa.2017.01.005 UR - https://www.sciencedirect.com/science/article/pii/S2214212617300091 KW - Media KW - Anonymity KW - Risk KW - Decay time KW - Emergence KW - Memory AB - Whereas threats from twentieth century 'broadcast era' media were characterised in terms of ideology and ‘effects', today the greatest risks posed by media are informational. This paper argues that digital participation as the condition for the maintenance of today's self identity and basic sociality has shaped a new principal media risk of the loss of anonymity. I identify three interrelated key features of this new risk. Firstly, basic communicational acts are archival. Secondly, there is a diminishment of the predictable 'decay time' of media. And, thirdly, both of these shape a new individual and organizational vulnerability of 'emergence' – the haunting by our digital trails. This article places these media risks in the context of the shifting nature and function of memory and the potential uses and abuses of digital pasts. ER - TY - JOUR T1 - Contents List JO - Digital Investigation VL - 13 SP - iii PY - 2015 DA - 2015/06/01/ SN - 1742-2876 DO - https://doi.org/10.1016/S1742-2876(15)00066-3 UR - https://www.sciencedirect.com/science/article/pii/S1742287615000663 ER - TY - JOUR T1 - Digital forensics research: The next 10 years AU - Garfinkel, Simson L. JO - Digital Investigation VL - 7 SP - S64 EP - S73 PY - 2010 DA - 2010/08/01/ T2 - The Proceedings of the Tenth Annual DFRWS Conference SN - 1742-2876 DO - https://doi.org/10.1016/j.diin.2010.05.009 UR - https://www.sciencedirect.com/science/article/pii/S1742287610000368 KW - Forensics KW - Human subjects research KW - Corpora KW - Real data corpus KW - Realistic data AB - Today’s Golden Age of computer forensics is quickly coming to an end. Without a clear strategy for enabling research efforts that build upon one another, forensic research will fall behind the market, tools will become increasingly obsolete, and law enforcement, military and other users of computer forensics products will be unable to rely on the results of forensic analysis. This article summarizes current forensic research directions and argues that to move forward the community needs to adopt standardized, modular approaches for data representation and forensic processing. ER - TY - JOUR T1 - Validation and verification of computer forensic software tools—Searching Function AU - Guo, Yinghua AU - Slay, Jill AU - Beckett, Jason JO - Digital Investigation VL - 6 SP - S12 EP - S22 PY - 2009 DA - 2009/09/01/ T2 - The Proceedings of the Ninth Annual DFRWS Conference SN - 1742-2876 DO - https://doi.org/10.1016/j.diin.2009.06.015 UR - https://www.sciencedirect.com/science/article/pii/S1742287609000358 KW - Electronic evidence KW - Computer forensics KW - Validation KW - Verification KW - Searching AB - The process of using automated software has served law enforcement and the courts very well, and experienced detectives and investigators have been able to use their well-developed policing skills, in conjunction with the automated software, so as to provide sound evidence. However, the growth in the computer forensic field has created a demand for new software (or increased functionality to existing software) and a means to verify that this software is truly “forensic” i.e. capable of meeting the requirements of the ‘trier of fact’. In this work, we present a scientific and systemical description of the computer forensic discipline through mapping fundamental functions required in the computer forensic investigation process. Based on the function mapping, we propose a more detailed functionality orientated validation and verification framework of computer forensic tools. We focus this paper on the searching function. We specify the requirements and develop a corresponding reference set to test any tools that possess the searching function. ER - TY - JOUR T1 - Focused digital evidence analysis and forensic distinguishers AU - Casey, Eoghan JO - Digital Investigation VL - 18 SP - A1 EP - A3 PY - 2016 DA - 2016/09/01/ SN - 1742-2876 DO - https://doi.org/10.1016/j.diin.2016.08.004 UR - https://www.sciencedirect.com/science/article/pii/S1742287616300895 ER - TY - CHAP T1 - Chapter 3 - Electronic Discovery AU - Holley, James O. AU - Luehr, Paul H. AU - Smith, Jessica Reust AU - Schwerha, Joseph J. A2 - Casey, Eoghan A2 - Altheide, Cory A2 - Daywalt, Christopher A2 - de Donno, Andrea A2 - Forte, Dario A2 - Holley, James O. A2 - Johnston, Andy A2 - van der Knijff, Ronald A2 - Kokocinski, Anthony A2 - Luehr, Paul H. A2 - Maguire, Terrance A2 - Pittman, Ryan D. A2 - Rose, Curtis W. A2 - Schwerha, Joseph J. A2 - Shaver, Dave A2 - Smith, Jessica Reust BT - Handbook of Digital Forensics and Investigation PB - Academic Press CY - San Diego SP - 63 EP - 133 PY - 2010 DA - 2010/01/01/ SN - 978-0-12-374267-4 DO - https://doi.org/10.1016/B978-0-12-374267-4.00003-3 UR - https://www.sciencedirect.com/science/article/pii/B9780123742674000033 AB - Publisher Summary This chapter elaborates the role of digital forensic examiners throughout these phases of e-discovery, particularly in large-scale cases involving disputes between organizations. It addresses the legal framework for e-discovery as well as unique forensic questions that arise around case management, identification and collection of ESI, and culling and production of data. This chapter also describes common pitfalls in the complex, high-stakes field of e-discovery, with the goal of helping both new and experienced forensic examiners safely navigate this potential minefield. Electronic discovery or “e-discovery” is the exchange of data between parties in civil or criminal litigation. The process is largely controlled by attorneys who determine what data should be produced based on relevance or withheld based on claims of privilege. Forensic examiners play crucial roles as technical advisors, hands-on collectors, and analysts. The e-discovery field is complex, and the technical and logistical challenges routinely found in large e-discovery projects can test even the most experienced digital forensic examiner. The high stakes nature of most e-discovery projects leave little room for error at any stage of the process—from initial identification and preservation of evidence sources to the final production and presentation of results—and to be successful an examiner must understand and be familiar with their role at each stage. The size and scope of e-discovery projects require effective case management, and essential to effective case management is establishing a strategic plan at the outset, and diligently implementing constructive and documented quality assurance measures throughout each step of the process. ER - TY - CHAP T1 - Index A2 - Al-Turjman, Fadi A2 - Deebak, B.D. BT - Security in IoT Social Networks PB - Academic Press SP - 247 EP - 252 PY - 2021 DA - 2021/01/01/ T2 - Intelligent Data-Centric Systems SN - 978-0-12-821599-9 DO - https://doi.org/10.1016/B978-0-12-821599-9.20001-0 UR - https://www.sciencedirect.com/science/article/pii/B9780128215999200010 ER - TY - JOUR T1 - Associative retrieval in spatial big data based on spreading activation with semantic ontology AU - Sun, Shengtao AU - Song, Weijing AU - Zomaya, Albert Y. AU - Xiang, Yang AU - Choo, Kim-Kwang Raymond AU - Shah, Tejal AU - Wang, Lizhe JO - Future Generation Computer Systems VL - 76 SP - 499 EP - 509 PY - 2017 DA - 2017/11/01/ SN - 0167-739X DO - https://doi.org/10.1016/j.future.2016.10.018 UR - https://www.sciencedirect.com/science/article/pii/S0167739X16304137 KW - Big data KW - Associative retrieval KW - Spreading activation KW - Ontology model KW - Semantic inference AB - The opportunities associated with big data have helped generate significant interest, and big data analytics has emerged as an important area of study for both practitioners and researchers. For example, traditional cause–effect analysis and conditional retrieval fall short in dealing with data that are so large and complex. Associative retrieval, on the other hand, has been identified as a potential technique for big data. In this paper, we integrate the spreading activation (SA) algorithm and the ontology model in order to promote the associative retrieval of big data. In our approach, constraints based on variant weights of semantic links are considered with the aim of improving the spreading-activation process and ensuring the accuracy of search results. Semantic inference rules are also introduced to the SA algorithm to find latent spreading path and help obtain results which are more relevant. Our theoretical and experimental analysis demonstrate the utility of this approach. ER - TY - JOUR T1 - A multilayered semantic framework for integrated forensic acquisition on social media AU - Arshad, Humaira AU - Jantan, Aman AU - Hoon, Gan Keng AU - Butt, Anila Sahar JO - Digital Investigation VL - 29 SP - 147 EP - 158 PY - 2019 DA - 2019/06/01/ SN - 1742-2876 DO - https://doi.org/10.1016/j.diin.2019.04.002 UR - https://www.sciencedirect.com/science/article/pii/S1742287618303785 KW - Online social network forensics KW - Hybrid Ontology model KW - Social network analysis KW - Social network forensic automation AB - In recent years, examination of the social media networks has become an integral part of investigations. Law enforcement agencies and legal practitioners frequently utilize social networks to quickly access the information related to the participants of any illicit incident. However, the forensic process needs collection and analysis of the information which is immense, heterogeneous, and spread across multiple social networks. This process is technically intricate due to heterogeneous and unstructured online social networks (OSNs). Hence, creating cognitive challenges and massive workloads for the investigators. Therefore, it is imperative to develop automated and reliable solutions to assist investigators. Capturing the forensic information in the structured form is crucial for automation, sharing, and interoperability. This paper introduces the design of a multi-layer framework; from collection to evidence analysis. The central component of this framework is a hybrid ontology approach that involves multiple ontologies to manage the unstructured data and integrate various social media data collections. This approach aims to find the evidence by automated methods that are trustworthy and therefore admissible in a court of law. ER - TY - JOUR T1 - Safeguarding the evidential value of forensic cryptocurrency investigations AU - Fröwis, Michael AU - Gottschalk, Thilo AU - Haslhofer, Bernhard AU - Rückert, Christian AU - Pesch, Paulina JO - Forensic Science International: Digital Investigation VL - 33 SP - 200902 PY - 2020 DA - 2020/06/01/ SN - 2666-2817 DO - https://doi.org/10.1016/j.fsidi.2019.200902 UR - https://www.sciencedirect.com/science/article/pii/S1742287619302567 KW - Digital forensics KW - Cryptocurrencies KW - Digital evidence KW - Safeguards KW - Legal AB - Analyzing cryptocurrency payment flows has become a key forensic method in law enforcement and is nowadays used to investigate a wide spectrum of criminal activities. However, despite its widespread adoption, the evidential value of obtained findings in court is still largely unclear. In this paper, we focus on the key ingredients of modern cryptocurrency analytics techniques, which are clustering heuristics and attribution tags. We identify internationally accepted standards and rules for substantiating suspicions and providing evidence in court and project them onto current cryptocurrency forensics practices. By providing an empirical analysis of CoinJoin transactions, we illustrate possible sources of misinterpretation in algorithmic clustering heuristics. Eventually, we derive a set of legal key requirements and translate them into a technical data sharing framework that fosters compliance with existing legal and technical standards in the realm of cryptocurrency forensics. Integrating the proposed framework in modern cryptocurrency analytics tools could allow more efficient and effective investigations, while safeguarding the evidential value of the analysis and the fundamental rights of affected persons. ER - TY - JOUR T1 - Context-aware service roaming for heterogeneous embedded devices over cloud AU - Jing, Lei AU - Zhou, Yinghui AU - Cheng, Zixue AU - Yen, Neil Y. AU - Park, James J. JO - Journal of Systems Architecture VL - 59 IS - 9 SP - 776 EP - 784 PY - 2013 DA - 2013/10/01/ SN - 1383-7621 DO - https://doi.org/10.1016/j.sysarc.2013.02.006 UR - https://www.sciencedirect.com/science/article/pii/S1383762113000246 KW - Cloud computing KW - Embedded device KW - Network programming KW - Reprogramming KW - Data dissemination KW - Over The Air Programming KW - Magic Ring AB - Cloud computing advocates a promising paradigm that facilitates the access within heterogeneous services, platforms, and end users. However, platforms (or host servers) have confined to devices which require a considerable computing resources. In this case, solutions concerning the efficient use of pervasive devices with constrained resources become an open issue. This study investigates the seamless connection between embedded devices and cloud resources to enhance the capability of computing and furthermore provide context-aware services. A method for wireless program dissemination and boot loading is proposed to transfer necessary information and resources between service and target device(s). The experiment results on time delay and energy cost demonstrate the feasibility and performance. ER - TY - JOUR T1 - Leveraging CybOX™ to standardize representation and exchange of digital forensic information AU - Casey, Eoghan AU - Back, Greg AU - Barnum, Sean JO - Digital Investigation VL - 12 SP - S102 EP - S110 PY - 2015 DA - 2015/03/01/ T2 - DFRWS 2015 Europe SN - 1742-2876 DO - https://doi.org/10.1016/j.diin.2015.01.014 UR - https://www.sciencedirect.com/science/article/pii/S1742287615000158 KW - Digital forensics KW - Standard representation KW - Digital forensic ontology KW - Digital forensic XML KW - CybOX KW - DFXML KW - DFAX AB - With the growing number of digital forensic tools and the increasing use of digital forensics in various contexts, including incident response and cyber threat intelligence, there is a pressing need for a widely accepted standard for representing and exchanging digital forensic information. Such a standard representation can support correlation between different data sources, enabling more effective and efficient querying and analysis of digital evidence. This work summarizes the strengths and weaknesses of existing schemas, and proposes the open-source CybOX schema as a foundation for storing and sharing digital forensic information. The suitability of CybOX for representing objects and relationships that are common in forensic investigations is demonstrated with examples involving digital evidence. The capability to represent provenance by leveraging CybOX is also demonstrated, including specifics of the tool used to process digital evidence and the resulting output. An example is provided of an ongoing project that uses CybOX to record the state of a system before and after an event in order to capture cause and effect information that can be useful for digital forensics. An additional open-source schema and associated ontology called Digital Forensic Analysis eXpression (DFAX) is proposed that provides a layer of domain specific information overlaid on CybOX. DFAX extends the capability of CybOX to represent more abstract forensic-relevant actions, including actions performed by subjects and by forensic examiners, which can be useful for sharing knowledge and supporting more advanced forensic analysis. DFAX can be used in combination with other existing schemas for representing identity information (CIQ), and location information (KML). This work also introduces and leverages initial steps of a Unified Cyber Ontology (UCO) effort to abstract and express concepts/constructs that are common across the cyber domain. ER - TY - JOUR T1 - A Scaling Robust Copy-Paste Tampering Detection for Digital Image Forensics AU - Warbhe, Anil Dada AU - Dharaskar, R.V. AU - Thakare, V.M. JO - Procedia Computer Science VL - 79 SP - 458 EP - 465 PY - 2016 DA - 2016/01/01/ T2 - Proceedings of International Conference on Communication, Computing and Virtualization (ICCCV) 2016 SN - 1877-0509 DO - https://doi.org/10.1016/j.procs.2016.03.059 UR - https://www.sciencedirect.com/science/article/pii/S1877050916001903 KW - Digital Image Forensics KW - Image Forgery Detection KW - Image Tampering KW - Image Authentication AB - It is crucial in image forensics to prove the authenticity of the digital images. Due to the availability of the using sophisticated image editing software programs, anyone can manipulate the images easily. There are various types of digital image manipulation or tampering possible; like image compositing, splicing, copy-paste, etc. In this paper, we propose a passive scaling robust algorithm for the detection of Copy-Paste tampering. Sometimes the copied region of an image is scaled before pasting to some other location in the image. In such cases, the normal Copy-Paste detection algorithm fails to detect the forgeries. We have implemented and used an improved customized Normalized Cross Correlation for detecting highly correlated areas from the image and the image blocks, thereby detecting the tampered regions from an image. The experimental results demonstrate that the proposed approach can be effectively used to detect copy-paste forgeries accurately and is scaling robust. ER - TY - JOUR T1 - Contents List JO - Digital Investigation VL - 15 SP - iii PY - 2015 DA - 2015/12/01/ T2 - Special Issue: Big Data and Intelligent Data Analysis SN - 1742-2876 DO - https://doi.org/10.1016/S1742-2876(15)00114-0 UR - https://www.sciencedirect.com/science/article/pii/S1742287615001140 ER - TY - JOUR T1 - Provenance-based reproducibility in the Semantic Web AU - Moreau, Luc JO - Journal of Web Semantics VL - 9 IS - 2 SP - 202 EP - 221 PY - 2011 DA - 2011/07/01/ T2 - Provenance in the Semantic Web SN - 1570-8268 DO - https://doi.org/10.1016/j.websem.2011.03.001 UR - https://www.sciencedirect.com/science/article/pii/S1570826811000163 KW - Provenance KW - Reproducibility KW - Denotational semantics KW - Primitive environment AB - Reproducibility is a crucial property of data since it allows users to understand and verify how data were derived, and therefore allows them to put their trust in such data. Reproducibility is essential for science, because the reproducibility of experimental results is a tenet of the scientific method, but reproducibility is also beneficial in many other fields, including automated decision making, visualization, and automated data feeds. To achieve the vision of reproducibility, the workflow-based community has strongly advocated the use of provenance as an underpinning mechanism for reproducibility, since a rich representation of provenance allows steps to be reproduced and all intermediary and final results checked and validated. Concurrently, multiple ontology-based representations of provenance have been devised, to be able to describe past computations, uniformly across a variety of technologies. However, such Semantic Web representations of provenance do not have any formal link with execution. Even assuming a faithful and non-malicious environment, how can we claim that an ontology-based representation of provenance enables reproducibility, since it has not been given any execution semantics, and therefore has no formal way of expressing the reproduction of computations? This is the problem that this paper tackles by defining a denotational semantics for the Open Provenance Model, which is referred to as the reproducibility semantics. This semantics is used to implement a reproducibility service, leveraging multiple Semantic Web technologies, and offering a variety of reproducibility approaches, found in the literature. A series of empirical experiments were designed to exhibit the range of reproducibility capabilities of our approach; in particular, we demonstrate the ability to reproduce computations involving multiple technologies, as is commonly found on the Web. ER - TY - JOUR T1 - Engineering an online computer forensic service AU - Bhoedjang, R.A.F. AU - van Ballegooij, A.R. AU - van Beek, H.M.A. AU - van Schie, J.C. AU - Dillema, F.W. AU - van Baar, R.B. AU - Ouwendijk, F.A. AU - Streppel, M. JO - Digital Investigation VL - 9 IS - 2 SP - 96 EP - 108 PY - 2012 DA - 2012/11/01/ SN - 1742-2876 DO - https://doi.org/10.1016/j.diin.2012.10.001 UR - https://www.sciencedirect.com/science/article/pii/S1742287612000655 KW - XIRAF KW - Online service KW - Computer forensics KW - Digital forensics KW - SAAS AB - XIRAF is a second-generation forensic analysis system developed at the Netherlands Forensic Institute. XIRAF automates the collection of millions of forensic artefacts and organizes these artefacts such that they can be searched in effective ways through a web interface. This paper describes the design of version 1.2 of XIRAF and describes the lessons we learned from implementing and deploying it. Today, a number of Dutch law enforcement organizations are using the XIRAF service offered by the Netherlands Forensic Institute. Our experience with this service indicates that XIRAF allows investigative teams of dozens of investigators with varying technical background to collaborate effectively and allows them to obtain results from amounts of digital evidence that were infeasible to handle in a cost-effective way before. ER - TY - CHAP T1 - The State of the Art in Digital Forensics AU - Forte, Dario A2 - Zelkowitz, M.V. BT - Advances in Computers PB - Elsevier VL - 67 SP - 253 EP - 300 PY - 2006 DA - 2006/01/01/ SN - 0065-2458 DO - https://doi.org/10.1016/S0065-2458(05)67006-4 UR - https://www.sciencedirect.com/science/article/pii/S0065245805670064 AB - We are in an historical moment where computing is part of the social life. It does mean that computers are also part of crimes, both physical and virtual. In this an idea of the state of the art of the digital forensic will be provided, with special emphasis on UNIX operating systems and log file management. Included will also be an overview of current scientific research on the topic and illustrations of a number of potential issues that are often the subject of discussions in courtrooms the world over. ER - TY - JOUR T1 - An Argumentation-Based Reasoner to Assist Digital Investigation and Attribution of Cyber-Attacks AU - Karafili, Erisa AU - Wang, Linna AU - Lupu, Emil C. JO - Forensic Science International: Digital Investigation VL - 32 SP - 300925 PY - 2020 DA - 2020/04/01/ SN - 2666-2817 DO - https://doi.org/10.1016/j.fsidi.2020.300925 UR - https://www.sciencedirect.com/science/article/pii/S2666281720300202 KW - Cyber-attacks KW - Digital investigation KW - Attribution KW - Argumentation reasoning AB - We expect an increase in the frequency and severity of cyber-attacks that comes along with the need for efficient security countermeasures. The process of attributing a cyber-attack helps to construct efficient and targeted mitigating and preventive security measures. In this work, we propose an argumentation-based reasoner (ABR) as a proof-of-concept tool that can help a forensics analyst during the analysis of forensic evidence and the attribution process. Given the evidence collected from a cyber-attack, our reasoner can assist the analyst during the investigation process, by helping him/her to analyze the evidence and identify who performed the attack. Furthermore, it suggests to the analyst where to focus further analyses by giving hints of the missing evidence or new investigation paths to follow. ABR is the first automatic reasoner that can combine both technical and social evidence in the analysis of a cyber-attack, and that can also cope with incomplete and conflicting information. To illustrate how ABR can assist in the analysis and attribution of cyber-attacks we have used examples of cyber-attacks and their analyses as reported in publicly available reports and online literature. We do not mean to either agree or disagree with the analyses presented therein or reach attribution conclusions. ER - TY - JOUR T1 - Educating judges, prosecutors and lawyers in the use of digital forensic experts AU - Henseler, Hans AU - van Loenhout, Sophie JO - Digital Investigation VL - 24 SP - S76 EP - S82 PY - 2018 DA - 2018/03/01/ SN - 1742-2876 DO - https://doi.org/10.1016/j.diin.2018.01.010 UR - https://www.sciencedirect.com/science/article/pii/S1742287618300422 KW - Digital forensics KW - Registration requirements KW - Standards KW - Court experts AB - Recent years have seen an exponential growth of evidence in digital forensic investigations. Digital Forensics (DF) experts are predicting, amongst others, a ’digital explosion’ of ransomware in the coming years. The legal community must be prepared to deal with an increase of digital evidence in both volume and complexity. In cooperation with experts in the field, the Netherlands Register of Court Experts (NRGD) has recently developed standards and registration requirements for DF experts in the Netherlands. This article describes how these standards were established and provides insight into the requirements that a DF expert should meet to qualify as an NRGD registered expert. Registration is now open to all DF experts, both Dutch and non-Dutch. Furthermore, this article can be used by DF experts worldwide to educate judges, prosecutors and lawyers that make use of their reports. It illustrates what the legal community can expect from DF court experts, it provides a demarcation of the DF field based on DF literature and it presents examples of relevant questions that can or should be asked to a DF expert. ER - TY - JOUR T1 - A cyber forensics ontology: Creating a new approach to studying cyber forensics AU - Brinson, Ashley AU - Robinson, Abigail AU - Rogers, Marcus JO - Digital Investigation VL - 3 SP - 37 EP - 43 PY - 2006 DA - 2006/09/01/ T2 - The Proceedings of the 6th Annual Digital Forensic Research Workshop (DFRWS '06) SN - 1742-2876 DO - https://doi.org/10.1016/j.diin.2006.06.008 UR - https://www.sciencedirect.com/science/article/pii/S1742287606000703 KW - Ontology KW - Model KW - Cyber forensics KW - Curriculum KW - Certification KW - Specialization AB - The field of cyber forensics, still in its infancy, possesses a strong need for direction and definition. Areas of specialty within a professional environment, certifications, and/or curriculum development are still questioned. With the continued need to standardize parts of the field, methodologies need to be created that will allow for uniformity and direction. This paper focuses on creating an ontological for the purpose of finding the correct layers for specialization, certification, and education within the cyber forensics domain. There is very little information available on this topic and what is present, seems to be somewhat varied. This underscores the importance of creating a method for defining the correct levels of education, certification and specialization. This ontology can also be used to develop curriculum and educational materials. This paper is meant to spark discussion and further research into the topic. ER - TY - JOUR T1 - Study of digital textual watermarking distortions under Internet attacks in high resolution videos AU - Zotin, Alexandr AU - Favorskaya, Margarita AU - Proskurin, Alexandr AU - Pakhirka, Andrey JO - Procedia Computer Science VL - 176 SP - 1633 EP - 1642 PY - 2020 DA - 2020/01/01/ T2 - Knowledge-Based and Intelligent Information & Engineering Systems: Proceedings of the 24th International Conference KES2020 SN - 1877-0509 DO - https://doi.org/10.1016/j.procs.2020.09.187 UR - https://www.sciencedirect.com/science/article/pii/S1877050920320895 KW - Textual watermark KW - video watermarking KW - attacks KW - robustness KW - high resolution videos AB - Multimedia content transmitted through the unprotected channels include several types of information, such as text messages, audio, images, and video sequences. Each type of embedded information can be distorted under various attacks with unknown parameters. In this paper, we study a special issue of textual watermarking distortions in videos under the simulated intentional and accidental attacks. Three approaches for textual messages embedding are exploited considering text as the sequence of binary codes, ordinary image, and barcode image. The experiments were conducted using test video sequences with high resolution compressed by x264 (H.264/AVC) codec in order to obtain the dependences between the robustness, capacity, and imperceptibility for blind watermarking schemes. We formulate the recommendations for hiding of textual information depending on a goal of embedding. ER - TY - JOUR T1 - Stitcher: Correlating digital forensic evidence on internet-of-things devices AU - Tok, Yee Ching AU - Wang, Chundong AU - Chattopadhyay, Sudipta JO - Forensic Science International: Digital Investigation VL - 35 SP - 301071 PY - 2020 DA - 2020/12/01/ SN - 2666-2817 DO - https://doi.org/10.1016/j.fsidi.2020.301071 UR - https://www.sciencedirect.com/science/article/pii/S2666281720303681 KW - IoT digital forensics KW - User study KW - Evidence classification KW - Evidence correlation KW - AB - The increasing adoption of Internet-of-Things (IoT) devices present new challenges to digital forensic investigators and law enforcement agencies when investigation into cybercrime on these new platforms are required. However, there has been no formal study to document actual challenges faced by investigators and whether existing tools help them in their work. Prior issues such as the correlation and consistency problem in digital forensic evidence have also become a pressing concern in light of numerous evidence sources from IoT devices. Motivated by these observations, we conduct a user study with 39 digital forensic investigators from both public and private sectors to document the challenges they faced in traditional and IoT digital forensics. We also created a tool, Stitcher, that addresses the technical challenges faced by investigators when handling IoT digital forensics investigation. We simulated an IoT crime that mimics sophisticated cybercriminals and invited our user study participants to utilize Stitcher to investigate the crime. The efficacy of Stitcher is confirmed by our study results where 96.2% of users indicated that Stitcher assisted them in handling the crime, and 61.5% of users who used Stitcher with its full features solved the crime completely. ER - TY - JOUR T1 - Leveraging ontologies and machine-learning techniques for malware analysis into Android permissions ecosystems AU - Navarro, Luiz C. AU - Navarro, Alexandre K.W. AU - Grégio, André AU - Rocha, Anderson AU - Dahab, Ricardo JO - Computers & Security VL - 78 SP - 429 EP - 453 PY - 2018 DA - 2018/09/01/ SN - 0167-4048 DO - https://doi.org/10.1016/j.cose.2018.07.013 UR - https://www.sciencedirect.com/science/article/pii/S0167404818302311 KW - Malware KW - Android permissions KW - Ontology KW - Bags of graphs KW - Machine learning KW - Discriminant features AB - Smartphones form a complex application ecosystem with a myriad of components, properties, and interfaces that produce an intricate relationship network. Given the intrinsic complexity of this system, we hereby propose two main contributions. First, we devise a methodology to systematically determine and analyze the complex relationship network among components, properties, and interfaces associated with the permission mechanism in Android ecosystems. Second, we investigate whether it is possible to identify characteristics shared by malware samples at this high level of abstraction that could be leveraged to unveil their presence. We propose an ontology-based framework to model the relationships between application and system elements, together with a machine-learning approach to analyze the complex network that arises therefrom. We represent the ontological model for the considered Android ecosystem with 4570 apps through a graph with some 55,000 nodes and 120,000 edges. Experiments have shown that a classifier operating on top of this complex representation can achieve an accuracy of 88% and precision of 91% and is capable of identifying and determining 24 features that correspond to 70 important graph nodes related to malware activity, which is a remarkable feat for security. ER - TY - JOUR T1 - The future decisions of RoboJudge HHJ Arthur Ian Blockchain: Dread, delight or derision?, AU - Castell, Stephen JO - Computer Law & Security Review VL - 34 IS - 4 SP - 739 EP - 753 PY - 2018 DA - 2018/08/01/ SN - 0267-3649 DO - https://doi.org/10.1016/j.clsr.2018.05.011 UR - https://www.sciencedirect.com/science/article/pii/S026736491830195X KW - Intelligence KW - Blockchain KW - Robot KW - Ethic KW - Algorithm KW - Crypto AB - Steve Saxby's prescient founding of CLSR, two hundred issues ago, encouraged and resonated with my own digital visionary thinking and professional activity in the evolving field of ICT and the Law. From Infolex, the UK's first commercially-available computer-assisted legal information retrieval service, and my APPEAL Report (on the admissibility of computer evidence in court and the legal reliability/security of IT systems), via my Forensic Systems Analysis expert methodology, to the nascent CryptoBlockTV, Steve's scholarly foresight in promoting adventurous exploration of ‘digilaw’ high-ground topics and issues has presented me with opportunities to generate a stream of prescient material, for which I am immensely grateful. And what is beyond prescient today is that the Coming of the Robots is unstoppable. The Artificial Intelligence (AI) Age is upon us; RoboJudge has all but already arrived. While many are concerned about defining and developing Machine Ethics, Castell's Second Dictum: “You cannot construct an algorithm that will reliably decide whether or not any algorithm is ethical” reveals that this is a futile exercise. Algorithms are also pivotal to the current mania for Crypto-Algorithmic Blockchain Technology Initial Coin Offerings (ICOs), with a ‘Crypto Tribe’ of Millennials relentlessly raising billions in real money thereby, to the extent that I have dubbed Crypto the Millennials’ Rock'n’Roll. The seasoned ICT expert professional however bears in mind that there are as yet no ISO standards for blockchain, and there is far more to creating and delivering a complete quality-assured system than just the blockchain component. Furthermore, the legal status of cryptocurrency, smart contract and distributed ledger technology is not clear or uncontentious – and there is already ICO litigation on foot. Nevertheless, taking my limerick-writing Castell GhostWriteBot’s advice, it is perhaps time for my own asset-linked ICO, to launch my CapChere.com concept designed to reboot Capitalism and achieve ubiquitous universal share and wealth ownership. Look out for Castell GhostWriteBot’s account (with or without limericks) of how I fared, in the 400th issue of CLSR. ER - TY - JOUR T1 - A case-based reasoning method for locating evidence during digital forensic device triage AU - Horsman, Graeme AU - Laing, Christopher AU - Vickers, Paul JO - Decision Support Systems VL - 61 SP - 69 EP - 78 PY - 2014 DA - 2014/05/01/ SN - 0167-9236 DO - https://doi.org/10.1016/j.dss.2014.01.007 UR - https://www.sciencedirect.com/science/article/pii/S0167923614000086 KW - Digital forensics KW - Triage KW - Case based reasoning KW - Bayesian reasoning KW - Knowledge reuse AB - The role of triage in digital forensics is disputed, with some practitioners questioning its reliability for identifying evidential data. Although successfully implemented in the field of medicine, triage has not established itself to the same degree in digital forensics. This article presents a novel approach to triage for digital forensics. Case-Based Reasoning Forensic Triager (CBR-FT) is a method for collecting and reusing past digital forensic investigation information in order to highlight likely evidential areas on a suspect operating system, thereby helping an investigator to decide where to search for evidence. The CBR-FT framework is discussed and the results of twenty test triage examinations are presented. CBR-FT has been shown to be a more effective method of triage when compared to a practitioner using a leading commercial application. ER - TY - JOUR T1 - Empirical analysis of solid state disk data retention when used with contemporary operating systems AU - King, Christopher AU - Vidas, Timothy JO - Digital Investigation VL - 8 SP - S111 EP - S117 PY - 2011 DA - 2011/08/01/ T2 - The Proceedings of the Eleventh Annual DFRWS Conference SN - 1742-2876 DO - https://doi.org/10.1016/j.diin.2011.05.013 UR - https://www.sciencedirect.com/science/article/pii/S1742287611000375 KW - Solid state disks KW - Digital forensics KW - Data recovery KW - Hard drive technology AB - Data recovery techniques for platter-based disk drives have remained rather static due to the dominance of the hard disk for the last two decades. Solid State Disk drives have differing storage and recall functionality from platter-based disks and require special care when attempting data recovery. Manufacturers have varying implementations of garbage collection in each drive, which affects the amount of data retained on the disk. This paper presents an analysis of solid state disk data retention based off of empirical evidence of 16 different disks. It also discusses the data recovery problem faced by forensic examiners due to the ATA8 TRIM command, which can sanitize disks in seconds. The experiment shows that without TRIM, nearly all data is recoverable, but with TRIM enabled only up to 27% of blocks were recoverable dependent on the controller manufacturer. ER - TY - JOUR T1 - Automated event and social network extraction from digital evidence sources with ontological mapping AU - Turnbull, Benjamin AU - Randhawa, Suneel JO - Digital Investigation VL - 13 SP - 94 EP - 106 PY - 2015 DA - 2015/06/01/ SN - 1742-2876 DO - https://doi.org/10.1016/j.diin.2015.04.004 UR - https://www.sciencedirect.com/science/article/pii/S1742287615000444 KW - Artificial intelligence KW - Big data KW - Digital forensics KW - Digital evidence KW - Event representation KW - Forensic tool development KW - Knowledge representation KW - Ontology KW - Software engineering KW - Triage AB - The sharp rise in consumer computing, electronic and mobile devices and data volumes has resulted in increased workloads for digital forensic investigators and analysts. The number of crimes involving electronic devices is increasing, as is the amount of data for each job. This is becoming unscaleable and alternate methods to reduce the time trained analysts spend on each job are necessary. This work leverages standardised knowledge representations techniques and automated rule-based systems to encapsulate expert knowledge for forensic data. The implementation of this research can provide high-level analysis based on low-level digital artefacts in a way that allows an understanding of what decisions support the facts. Analysts can quickly make determinations as to which artefacts warrant further investigation and create high level case data without manually creating it from the low-level artefacts. Extraction and understanding of users and social networks and translating the state of file systems to sequences of events are the first uses for this work. A major goal of this work is to automatically derive ‘events’ from the base forensic artefacts. Events may be system events, representing logins, start-ups, shutdowns, or user events, such as web browsing, sending email. The same information fusion and homogenisation techniques are used to reconstruct social networks. There can be numerous social network data sources on a single computer; internet cache can locate Facebook, LinkedIn, Google Plus caches; email has address books and copies of emails sent and received; instant messenger has friend lists and call histories. Fusing these into a single graph allows a more complete, less fractured view for an investigator. Both event creation and social network creation are expected to assist investigator-led triage and other fast forensic analysis situations. ER - TY - JOUR T1 - An application of case-based reasoning with machine learning for forensic autopsy AU - Yeow, Wei Liang AU - Mahmud, Rohana AU - Raj, Ram Gopal JO - Expert Systems with Applications VL - 41 IS - 7 SP - 3497 EP - 3505 PY - 2014 DA - 2014/06/01/ SN - 0957-4174 DO - https://doi.org/10.1016/j.eswa.2013.10.054 UR - https://www.sciencedirect.com/science/article/pii/S0957417413008713 KW - Case-based reasoning KW - Naïve Bayes KW - Autopsy report system KW - Decision-support system KW - Feature-weight learning AB - Case-based reasoning (CBR) is one of the matured paradigms of artificial intelligence for problem solving. CBR has been applied in many areas in the commercial sector to assist daily operations. However, CBR is relatively new in the field of forensic science. Even though forensic personnel have consciously used past experiences in solving new cases, the idea of applying machine intelligence to support decision-making in forensics is still in its infancy and poses a great challenge. This paper highlights the limitation of the methods used in forensics compared with a CBR method in the analysis of forensic evidences. The design and development of an Intelligent Forensic Autopsy Report System (I-AuReSys) basing on a CBR method along with the experimental results are presented. Our system is able to extract features by using an information extraction (IE) technique from the existing autopsy reports; then the system analyzes the case similarities by coupling the CBR technique with a Naïve Bayes learner for feature-weights learning; and finally it produces an outcome recommendation. Our experimental results reveal that the CBR method with the implementation of a learner is indeed a viable alternative method to the forensic methods with practical advantages. ER - TY - JOUR T1 - ARES 2012 special issue JO - Information Security Technical Report VL - 17 IS - 4 SP - 129 EP - 130 PY - 2013 DA - 2013/05/01/ T2 - Special Issue: ARES 2012 7th International Conference on Availability, Reliability and Security SN - 1363-4127 DO - https://doi.org/10.1016/j.istr.2013.04.001 UR - https://www.sciencedirect.com/science/article/pii/S1363412713000216 ER - TY - JOUR T1 - Contents JO - Procedia Computer Science VL - 35 SP - iii EP - ix PY - 2014 DA - 2014/01/01/ T2 - Knowledge-Based and Intelligent Information & Engineering Systems 18th Annual Conference, KES-2014 Gdynia, Poland, September 2014 Proceedings SN - 1877-0509 DO - https://doi.org/10.1016/S1877-0509(14)01235-6 UR - https://www.sciencedirect.com/science/article/pii/S1877050914012356 ER - TY - JOUR T1 - Achieving security scalability and flexibility using Fog-Based Context-Aware Access Control AU - Kayes, A.S.M. AU - Rahayu, Wenny AU - Watters, Paul AU - Alazab, Mamoun AU - Dillon, Tharam AU - Chang, Elizabeth JO - Future Generation Computer Systems VL - 107 SP - 307 EP - 323 PY - 2020 DA - 2020/06/01/ SN - 0167-739X DO - https://doi.org/10.1016/j.future.2020.02.001 UR - https://www.sciencedirect.com/science/article/pii/S0167739X19323349 KW - Access control KW - Fog computing KW - Cloud computing KW - Security KW - Privacy KW - Cybercrime KW - Internet of Things AB - In the cyberspace environment, access control is one of the foremost fundamental safeguards used to prevent unauthorized access and to minimize the impact from security breaches. Fog computing preserves many benefits for the integration of both internet of things (IoT) and cloud computing platforms. Security in Fog computing environment remains a significant concern among practitioners from academia and industry. The current existing access control models, like the traditional Context-Aware Access Control (CAAC), are limited to access data from centralized sources, and not robust due to lack of semantics and cloud-based service. This major concern has not been addressed in the literature, also literature still lacks a practical solution to control fog data view from multiple sources. This paper critically reviews and investigates the limitations of current fog-based access control. It considers the trade-off between latency and processing overheads which has not been thoroughly studied before. In this paper, a new generation of Fog-Based Context-Aware Access Control (FB-CAAC) framework is proposed to enable flexible access control data from multiple sources. To fill the gap in the literature this paper introduces (i) a general data model and its associated mapping model to collate data from multiple sources. (ii) a data view model to provide an integrated result to the users, dealing with the privacy requirements of the associated stakeholders, (iii) a unified set of CAAC policies with an access controller to reduce both administrative and processing overheads, and (iv) a data ontology to represent the common classes in the relevant data sets. The applicability of FB-CAAC proposal is demonstrated via a walkthrough of the entire mechanism along with several case studies and a prototype testing. The results show the efficiency, flexibility, effectiveness, and practicality of FB-CAAC for data access control in fog computing environment. ER - TY - JOUR T1 - A semantic-based methodology for digital forensics analysis AU - Amato, Flora AU - Castiglione, Aniello AU - Cozzolino, Giovanni AU - Narducci, Fabio JO - Journal of Parallel and Distributed Computing VL - 138 SP - 172 EP - 177 PY - 2020 DA - 2020/04/01/ SN - 0743-7315 DO - https://doi.org/10.1016/j.jpdc.2019.12.017 UR - https://www.sciencedirect.com/science/article/pii/S0743731519300644 KW - Digital forensics KW - Text analysis KW - Log analysis KW - Correlation KW - Cybersecurity AB - Nowadays, more than ever, digital forensics activities are involved in any criminal, civil or military investigation and represent a fundamental tool to support cyber-security. Investigators use a variety of techniques and proprietary software forensics applications to examine the copy of digital devices, searching hidden, deleted, encrypted, or damaged files or folders. Any evidence found is carefully analysed and documented in a “finding report” in preparation for legal proceedings that involve discovery, depositions, or actual litigation. The aim is to discover and analyse patterns of fraudulent activities. In this work, a new methodology is proposed to support investigators during the analysis process, correlating evidence found through different forensics tools. The methodology was implemented through a system able to add semantic assertion to data generated by forensics tools during extraction processes. These assertions enable more effective access to relevant information and enhanced retrieval and reasoning capabilities. ER - TY - JOUR T1 - DeepUAge: Improving Underage Age Estimation Accuracy to Aid CSEM Investigation AU - Anda, Felix AU - Le-Khac, Nhien-An AU - Scanlon, Mark JO - Forensic Science International: Digital Investigation VL - 32 SP - 300921 PY - 2020 DA - 2020/04/01/ SN - 2666-2817 DO - https://doi.org/10.1016/j.fsidi.2020.300921 UR - https://www.sciencedirect.com/science/article/pii/S2666281720300160 KW - Child Sexual Exploitation Material (CSEM) KW - Age estimation KW - Underage facial age dataset KW - Child sexual abuse investigations KW - Deep learning AB - Age is a soft biometric trait that can aid law enforcement in the identification of victims of Child Sexual Exploitation Material (CSEM) creation/distribution. Accurate age estimation of subjects can classify explicit content possession as illegal during an investigation. Automation of this age classification has the potential to expedite content discovery and focus the investigation of digital evidence through the prioritisation of evidence containing CSEM. In recent years, artificial intelligence based approaches for automated age estimation have been created, and many public cloud service providers offer this service on their platforms. The accuracy of these algorithms have been improving over recent years. These existing approaches perform satisfactorily for adult subjects, but perform wholly inadequately for underage subjects. To this end, the largest underage facial age dataset, VisAGe, has been used in this work to train a ResNet50 based deep learning model, DeepUAge, that achieved state-of-the-art beating performance for age estimation of minors. This paper describes the design and implementation of this model. An evaluation, validation and comparison of the proposed model is performed against existing facial age classifiers resulting in the best overall performance for underage subjects. ER - TY - JOUR T1 - Design and verification of a mobile robot based on the integrated model of cyber-Physical systems AU - Levshun, Dmitry AU - Chevalier, Yannick AU - Kotenko, Igor AU - Chechulin, Andrey JO - Simulation Modelling Practice and Theory VL - 105 SP - 102151 PY - 2020 DA - 2020/12/01/ SN - 1569-190X DO - https://doi.org/10.1016/j.simpat.2020.102151 UR - https://www.sciencedirect.com/science/article/pii/S1569190X20300903 KW - Security by design KW - Cyber-physical system KW - Integrated model KW - Attacker model KW - Attack actions model KW - Access control system KW - Mobile robot AB - The paper describes the new model, which is a key element of the design and verification methodology for secure cyber-physical systems. The proposed model represents cyber-physical systems as a set of building blocks with properties and connections between them, while each building block is the projection of the integrated model. The models of attacker and attack actions are an external models that are connected with an integrated model: attack actions impact is modelled through changes in the properties of the system or its elements while the number of possible attack actions is reduced according to the attacker possibilities. The novelty of the proposed model lies in the strong focus on security and possibilities of direct (from the projections to the integrated model) and reverse (from the integrated model to the projections) transformations. Verification process is an integral part of the proposed solution. Verification provides the formal check of the system creation possibility in accordance with the requirements and limitations as well as that designed system is secured against an attacker of certain level of knowledge which is connected from certain access point and has certain amount of resources. During the experiments SPASS theorem prover, the Maude system and daTac were used. As an example of the proposed model application, firstly, an access control system was considered. This system contains Arduino microcontrollers, software agents, web-servers and different sensors. To provide an additional example an use case about mobile robot for perimeter monitoring was also presented. For the experiments, it was decided to use the LEGO 9797 Mindstorms NXT. ER - TY - JOUR T1 - An Enhanced Multiclass Support Vector Machine Model and its Application to Classifying File Systems Affected by a Digital Crime AU - Mohammad, Rami Mustafa A. JO - Journal of King Saud University - Computer and Information Sciences PY - 2019 DA - 2019/10/30/ SN - 1319-1578 DO - https://doi.org/10.1016/j.jksuci.2019.10.010 UR - https://www.sciencedirect.com/science/article/pii/S1319157819309632 KW - Digital-forensics KW - File-systems KW - SVM KW - Log-Files KW - Digital-evidence AB - The digital revolution we are witnessing nowadays goes hand in hand with a revolution in cybercrime. This irrefutable fact has been a major reason for making digital forensic (DF) a pressing and timely topic to investigate. Thanks to the file system which is a rich source of digital evidence that may prove or deny a digital crime. Yet, although there are many tools that can be used to extract potentially conclusive evidence from the file system, there is still a need to develop effective techniques for evaluating the extracted evidence and link it directly to a digital crime. Machine learning can be posed as a possible solution looming in the horizon. This article proposes an Enhanced Multiclass Support Vector Machine (EMSVM) model that aims to improve the classification performance. The EMSVM suggests a new technique in selecting the most effective set of parameters when building a SVM model. In addition, since the DF is considered a multiclass classification problem duo to the fact that a file system might be accecced by more than one application, the EMSVM enhances the class assignment mechanism by supporting multi-class classification. The article then investigates the applicability of the proposed model in analysing incriminating digital evidence by inspecting the historical activities of file systems to realize if a malicious program manipulated them. The results obtained from the proposed model were promising when compared to several machine-learning algorithms. ER - TY - JOUR T1 - Towards a conceptual model for promoting digital forensics experiments AU - OliveiraJr, Edson AU - Zorzo, Avelino F. AU - Neu, Charles Varlei JO - Forensic Science International: Digital Investigation VL - 35 SP - 301014 PY - 2020 DA - 2020/12/01/ SN - 2666-2817 DO - https://doi.org/10.1016/j.fsidi.2020.301014 UR - https://www.sciencedirect.com/science/article/pii/S2666281720301530 KW - Concept map KW - Conceptual model KW - Digital forensics KW - Experimentation KW - Knowledge semantic-based model AB - Experimentation is one of the foundations for scientific evolution from the empirical point of view. Conducting experiments contributes to strengthen evidence of a given field mainly based on provided data and results, corroborated by repetitions, replications or reproducibility of an experiment, which altogether confirms or rejects pre-established hypotheses. Therefore, the proper conduction, documentation and dissemination of such experiments are essential to enable reproducibility. In this paper, we present ExperDF-CM, a conceptual model that aims to assist Digital Forensics researchers on planning, executing, analyzing and disseminating experiments. Such conceptual model was built based on almost two hundred analyzed Digital Forensics experiment papers and is mainly organized in five elements: Planning, Pre-Operation, Operation, Analysis and Interpretation, and Dissemination. We evaluated the conceptual model based on an evaluation survey and the Technology Acceptance Model (TAM) with researchers and practitioners of the Digital Forensics area. Results point out that our conceptual model is feasible for promoting reproducibility of Digital Forensics experiments, as well as it is easy to use and useful. Thus, our proposed conceptual model can contribute significantly to improve Digital Forensics experimentation and make them repeatable, replicable, and/or reproducible. ER - TY - JOUR T1 - The architecture of a digital forensic readiness management system AU - Reddy, K. AU - Venter, H.S. JO - Computers & Security VL - 32 SP - 73 EP - 89 PY - 2013 DA - 2013/02/01/ SN - 0167-4048 DO - https://doi.org/10.1016/j.cose.2012.09.008 UR - https://www.sciencedirect.com/science/article/pii/S0167404812001447 KW - Digital forensic readiness KW - Management of digital forensic readiness KW - Digital forensic management system KW - Forensic readiness KW - Management of forensics KW - Organisational forensic readiness AB - A coordinated approach to digital forensic readiness (DFR) in a large organisation requires the management and monitoring of a wide variety of resources, both human and technical. The resources involved in DFR in large organisations typically include staff from multiple departments and business units, as well as network infrastructure and computing platforms. The state of DFR within large organisations may therefore be adversely affected if the myriad human and technical resources involved are not managed in an optimal manner. This paper contributes to DFR by proposing the novel concept of a digital forensic readiness management system (DFRMS). The purpose of a DFRMS is to assist large organisations in achieving an optimal level of management for DFR. In addition to this, we offer an architecture for a DFRMS. This architecture is based on requirements for DFR that we ascertained from an exhaustive review of the DFR literature. We describe the architecture in detail and show that it meets the requirements set out in the DFR literature. The merits and disadvantages of the architecture are also discussed. Finally, we describe and explain an early prototype of a DFRMS. ER - TY - JOUR T1 - Semantic Representation and Integration of Digital Evidence AU - Dosis, Spyridon AU - Homem, Irvin AU - Popov, Oliver JO - Procedia Computer Science VL - 22 SP - 1266 EP - 1275 PY - 2013 DA - 2013/01/01/ T2 - 17th International Conference in Knowledge Based and Intelligent Information and Engineering Systems - KES2013 SN - 1877-0509 DO - https://doi.org/10.1016/j.procs.2013.09.214 UR - https://www.sciencedirect.com/science/article/pii/S1877050913010077 KW - Digital evidence KW - Ontology KW - Semantic Web KW - Evidence Integration KW - Knowledge Representation AB - The ever-increasing complexity and sophistication of computer and network attacks challenge society's dependability on digital infrastructure. Digital investigations recover and reconstruct the digital trails of such events and may employ practices from various subfields (computer, network forensics), each with its own set of techniques and tools. Integration of evidence from heterogeneous sources of data (e.g. disk images, network packet captures, logs) is often a manual and time- consuming process relying significantly on the investigator's expertise. In this paper, we propose and develop an approach, based on the Semantic Web framework, for ontologically representing and integrating digital evidence. The presented approach enhances existing forensic analysis techniques by providing partial and eventually full automation of the investigative process. ER - TY - JOUR T1 - Social engineering attack examples, templates and scenarios AU - Mouton, Francois AU - Leenen, Louise AU - Venter, H.S. JO - Computers & Security VL - 59 SP - 186 EP - 209 PY - 2016 DA - 2016/06/01/ SN - 0167-4048 DO - https://doi.org/10.1016/j.cose.2016.03.004 UR - https://www.sciencedirect.com/science/article/pii/S0167404816300268 KW - Bidirectional communication KW - Indirect communication KW - Mitnick's attack cycle KW - Social engineering KW - Social engineering attack detection model KW - Social engineering attack examples KW - Social engineering attack framework KW - Social engineering attack scenario KW - Social engineering attack templates KW - Unidirectional communication AB - The field of information security is a fast-growing discipline. Even though the effectiveness of security measures to protect sensitive information is increasing, people remain susceptible to manipulation and thus the human element remains a weak link. A social engineering attack targets this weakness by using various manipulation techniques to elicit sensitive information. The field of social engineering is still in its early stages with regard to formal definitions, attack frameworks and templates of attacks. This paper proposes detailed social engineering attack templates that are derived from real-world social engineering examples. Current documented examples of social engineering attacks do not include all the attack steps and phases. The proposed social engineering attack templates attempt to alleviate the problem of limited documented literature on social engineering attacks by mapping the real-world examples to the social engineering attack framework. Mapping several similar real-world examples to the social engineering attack framework allows one to establish a detailed flow of the attack whilst abstracting subjects and objects. This mapping is then utilised to propose the generalised social engineering attack templates that are representative of real-world examples, whilst still being general enough to encompass several different real-world examples. The proposed social engineering attack templates cover all three types of communication, namely bidirectional communication, unidirectional communication and indirect communication. In order to perform comparative studies of different social engineering models, processes and frameworks, it is necessary to have a formalised set of social engineering attack scenarios that are fully detailed in every phase and step of the process. The social engineering attack templates are converted to social engineering attack scenarios by populating the template with both subjects and objects from real-world examples whilst still maintaining the detailed flow of the attack as provided in the template. Furthermore, this paper illustrates how the social engineering attack scenarios are applied to verify a social engineering attack detection model. These templates and scenarios can be used by other researchers to either expand on, use for comparative measures, create additional examples or evaluate models for completeness. Additionally, the proposed social engineering attack templates can also be used to develop social engineering awareness material. ER - TY - JOUR T1 - Data Aggregation Mechanisms on the Internet of Things: A Systematic Literature Review AU - Yousefi, Shamim AU - Karimipour, Hadis AU - Derakhshan, Farnaz JO - Internet of Things SP - 100427 PY - 2021 DA - 2021/06/26/ SN - 2542-6605 DO - https://doi.org/10.1016/j.iot.2021.100427 UR - https://www.sciencedirect.com/science/article/pii/S2542660521000718 KW - Centralized KW - Cluster-based aggregation KW - Data aggregation KW - Internet of Things KW - Mobile Agent KW - Tree-based aggregation AB - Nowadays, the Internet of Things (IoT) has gained considerable attention in different academic and real-world research domains. Due to the data-driven nature of IoT, the data aggregation process in such systems is significantly challenging. The main goal of data aggregation mechanisms is to achieve high Quality of Services (QoS), including optimal data transmission delay, reliability, and energy consumption. Despite various types of available review papers on this particular topic, we feel that the existing literature does not satisfy the requirements of being up to date and comprehensive. This paper presents a systematic literature review for data aggregation mechanisms on IoT that illustrates the critical challenges in the context design issues. Further, the data aggregation mechanisms are divided into two main categories: client-server-based and mobile agent-based ones. The client-server-based data aggregation mechanisms are also presented in three groups: cluster-based, tree-based, and centralized methods. Finally, we outline possible future research trends in data aggregation on IoT. ER - TY - JOUR T1 - SoNeUCONABC, an expressive usage control model for Web-Based Social Networks AU - González-Manzano, Lorena AU - González-Tablas, Ana I. AU - de Fuentes, José M. AU - Ribagorda, Arturo JO - Computers & Security VL - 43 SP - 159 EP - 187 PY - 2014 DA - 2014/06/01/ SN - 0167-4048 DO - https://doi.org/10.1016/j.cose.2014.03.009 UR - https://www.sciencedirect.com/science/article/pii/S0167404814000480 KW - Web Based Social Networks KW - Access control KW - Access control model KW - Expressive power KW - Access control policy AB - In the era of hyper-connectivity Web-Based Social Networks (WBSNs) are demanding applications. They facilitate the interaction of huge amounts of users and the development of appropriate Access Control Models (ACMs) is an arising necessity. Particularly, the development of WBSNs ACMs with expressive power and capable of managing access control along the whole usage process is the challenge pursued. To contribute on this issue, first, 23 proposals have been analysed and second, SoNeUCONABC, an expressive usage control model for WBSNs, is proposed. It extends UCONABC (Park, 2003) including relationships management and it is formally defined, specifying entities and elements involved and an access control policy language. Moreover, policy construction is carefully detailed by using regular expressions and access control enforcement functions are described. Finally, the evaluation shows, theoretically, the significant expressive power of SoNeUCONABC and, empirically, the feasibility of its implementation by the development of a proof of concept system. ER - TY - JOUR T1 - A Formal Model Based Automated Decision Making AU - Avram, Calin AU - Gligor, Adrian AU - Avram, Laura JO - Procedia Manufacturing VL - 46 SP - 573 EP - 579 PY - 2020 DA - 2020/01/01/ T2 - 13th International Conference Interdisciplinarity in Engineering, INTER-ENG 2019, 3–4 October 2019, Targu Mures, Romania SN - 2351-9789 DO - https://doi.org/10.1016/j.promfg.2020.03.083 UR - https://www.sciencedirect.com/science/article/pii/S2351978920309616 KW - formal model KW - formal language KW - decision making KW - maintenance KW - optimization AB - Given the challenges related to implementing and operating efficiently the today’s manufacturing systems, methodologies for controlling the technical processes that governs these systems are of a real interest for engineers, business owners or managers. This tends to be even more relevant in the context of widespread Industry 4.0 adoption where instrumentation through communications systems leverages the adoption the automation and intelligence technologies. One of the key of optimal production in manufacturing systems is the proper maintenance for continuous and longer operation of the involved equipment and devices. In the context of large and complex systems, the automation of maintenance could employ real benefits through the quality of the production and the reduction of the related costs. The current paper explores and proposes an approach based on formal models employed in the automation of maintenance decisions processes for Industry 4.0 integrated manufacturing applications. The description and the design of the proposed methodology are presented, followed by discussions, a case study and conclusions. ER - TY - JOUR T1 - Text mining and semantic triples: Spatial analyses of text in applied humanitarian forensic research AU - Miranker, Molly AU - Giordano, Alberto JO - Digital Geography and Society VL - 1 SP - 100005 PY - 2020 DA - 2020/01/01/ SN - 2666-3783 DO - https://doi.org/10.1016/j.diggeo.2020.100005 UR - https://www.sciencedirect.com/science/article/pii/S2666378320300052 KW - GIScience KW - Corpus linguistics KW - Qualitative spatial representation KW - Applied forensics KW - Humanitarian GIS AB - The methods and tools of Geographic Information Sciences (GIScience)—spatial analysis, spatial statistics, and geographic information technologies—are increasingly being used in forensic humanitarian projects. In this article we explore ways to parse and analyze social and media releases from the United States Customs and Border Patrol (CBP) to gain an understanding of the death of migrants at the Texas-Mexico border. The methods we used include corpus linguistic (CL)/natural language processing (NLP) and Qualitative Spatial Representation (QSR) and Semantic Triples (ST). Our results indicate that CL/NLP and QSR/ST have the potential to increase and improve deceased migrant case identification by providing a framework for searching for key terms or themes throughout multiple textual sources. In the specific case examined, however, CL/NLP showed that CBP social media focused on drug confiscation and general patrolling activities and were of limited use for tabulating incidences of migrant death. On the other hand, QSR/ST visualizations showed which CBP Stations most frequently reported deceased migrant recoveries (i.e., search and collection of human remains) and with whom they collaborated. We believe these methods are part of the methodological toolkit needed to lay the ground for what we call Humanitarian GIS—the application of spatial analytical perspectives and tools to genocide studies, spatial forensics, and, in general, human rights topics and events. Within this toolkit, CL/NLP and QSR/ST highlight spatial relationships that are not necessarily mappable in a traditional GIS setting and allow researchers to detect patterns across large corpora of heterogeneous information. The mixing of methodologies and the combination of qualitative and quantitative data in Humanitarian GIS may change our understanding of an ongoing humanitarian crisis and aid in improving and increasing response to such crises. ER - TY - JOUR T1 - A cyber-crime investigation framework AU - Katos, Vasilios AU - Bednar, Peter M. JO - Computer Standards & Interfaces VL - 30 IS - 4 SP - 223 EP - 228 PY - 2008 DA - 2008/05/01/ T2 - Special Issue on Frameworks for Secure, Forensically Safe and Auditable Applications SN - 0920-5489 DO - https://doi.org/10.1016/j.csi.2007.10.003 UR - https://www.sciencedirect.com/science/article/pii/S0920548907000888 KW - Strategic systems thinking KW - Dempster–Shafer Theory KW - Cyber-crime scene AB - Epistemic uncertainty is an unavoidable attribute which is present in criminal investigations and could affect negatively the effectiveness of the process. A cyber-crime investigation involves a potentially large number of individuals and groups who need to communicate, share and make decisions across many levels and boundaries. This paper presents an approach adopting elements of the Strategic Systems Thinking Framework (SST) by which conflicting information due to the unavoidable uncertainty can be captured and processed, in support of the investigation process. A formal description of this approach is proposed as a basis for developing a cyber-crime investigation support system. ER - TY - JOUR T1 - The rise of “malware”: Bibliometric analysis of malware study AU - Razak, Mohd Faizal Ab AU - Anuar, Nor Badrul AU - Salleh, Rosli AU - Firdaus, Ahmad JO - Journal of Network and Computer Applications VL - 75 SP - 58 EP - 76 PY - 2016 DA - 2016/11/01/ SN - 1084-8045 DO - https://doi.org/10.1016/j.jnca.2016.08.022 UR - https://www.sciencedirect.com/science/article/pii/S1084804516301904 KW - Malware KW - Bibliometric analysis KW - Malware analysis KW - Intrusion detection system KW - Mobile malware AB - Malicious software (malware) is a computer program designed to create harmful and undesirable effects. It considered as one of the many dangerous threats for Internet users. Rootkit, botnet, worm, spyware and Trojan horse are the most common types of malware. Most malware studies aim to investigate novel approaches of preventing, detecting and responding to malware threats. However, despite the many articles published to support the research activities, there is still no trace of any bibliometric report that demonstrates the research trends. This paper aims to fill in that gap by presenting a comprehensive evaluation of malware research practices. It begins by looking at a pool of over 4000 articles that are published between 2005 and 2015 in the ISI Web of Science database. Using bibliometric analysis, this paper discusses the research activities done in both North America, Asia and other continents. This paper performed a detailed analysis by looking at the number of articles published, citations, research area, keywords, institutions, terms, and authors. A summary of the research activities continues by listing the terms into a classification of malware detection system which underlines the important area of malware research. From the analysis, it was concluded that there are several significant impacts of research activities in Asia, in comparison to other continents. In particular, this paper discusses the number of papers published by Asian countries such as China, Korea, India, Singapore and Malaysia in relation to the Middle East and North America. ER - TY - JOUR T1 - Current state of research on cross-site scripting (XSS) – A systematic literature review AU - Hydara, Isatou AU - Sultan, Abu Bakar Md. AU - Zulzalil, Hazura AU - Admodisastro, Novia JO - Information and Software Technology VL - 58 SP - 170 EP - 186 PY - 2015 DA - 2015/02/01/ SN - 0950-5849 DO - https://doi.org/10.1016/j.infsof.2014.07.010 UR - https://www.sciencedirect.com/science/article/pii/S0950584914001700 KW - Systematic literature review KW - Cross-site scripting KW - Security KW - Web applications AB - Context Cross-site scripting (XSS) is a security vulnerability that affects web applications. It occurs due to improper or lack of sanitization of user inputs. The security vulnerability caused many problems for users and server applications. Objective To conduct a systematic literature review on the studies done on XSS vulnerabilities and attacks. Method We followed the standard guidelines for systematic literature review as documented by Barbara Kitchenham and reviewed a total of 115 studies related to cross-site scripting from various journals and conference proceedings. Results Research on XSS is still very active with publications across many conference proceedings and journals. Attack prevention and vulnerability detection are the areas focused on by most of the studies. Dynamic analysis techniques form the majority among the solutions proposed by the various studies. The type of XSS addressed the most is reflected XSS. Conclusion XSS still remains a big problem for web applications, despite the bulk of solutions provided so far. There is no single solution that can effectively mitigate XSS attacks. More research is needed in the area of vulnerability removal from the source code of the applications before deployment. ER - TY - JOUR T1 - Integrating blockchain technology into the energy sector — from theory of blockchain to research and application of energy blockchain AU - Wang, Qiang AU - Su, Min JO - Computer Science Review VL - 37 SP - 100275 PY - 2020 DA - 2020/08/01/ SN - 1574-0137 DO - https://doi.org/10.1016/j.cosrev.2020.100275 UR - https://www.sciencedirect.com/science/article/pii/S1574013720300241 KW - Blockchain KW - Energy blockchain KW - Systematic literature review KW - Bibliometrics KW - Cluster analysis AB - Blockchain technology has been ushering in nothing short of a decentralized revolution. Distributed/decentralized energy is recognized the best way to ensure energy sustainability in the future. An open question is what promise the integration of blockchain and energy hold for energy future. This paper systematically reviews the theory of blockchain and explores the current status of energy blockchain research and applications using a visual bibliometric analysis method and the Scopus database from 2014 to 2020. The results show that the number of publications about blockchain technology in the energy sector have been skyrocketing, especially since 2018, which indicates the combining blockchain technology with energy sector is a new cross-cutting research area with increasing attention. At the national level, developing countries begin to move to the world stage, catching up or even surpassing several traditional developed countries in the field of energy blockchain. Cluster analysis results show that the existing energy blockchain research focuses on renewable energy, trying to solve the bottlenecks in its development process, and providing better solutions for the replacement of fossil energy by renewable energy. We therefore contend that blockchain may be fueling the renewable energy and powering our energy sustainability. Finally, the possible future development trend of energy blockchain is offered. ER - TY - JOUR T1 - Cognitive security: A comprehensive study of cognitive science in cybersecurity AU - Andrade, Roberto O AU - Yoo, Sang Guun JO - Journal of Information Security and Applications VL - 48 SP - 102352 PY - 2019 DA - 2019/10/01/ SN - 2214-2126 DO - https://doi.org/10.1016/j.jisa.2019.06.008 UR - https://www.sciencedirect.com/science/article/pii/S2214212618307804 KW - Cognitive security KW - Cognitive science KW - Situation awareness KW - Cyber operations AB - Nowadays, IoT, cloud computing, mobile and social networks are generating a transformation in social processes. Nevertheless, this technological change rise to new threats and security attacks that produce new and complex cybersecurity scenarios with large volumes of data and different attack vectors that can exceeded the cognitive skills of security analysts. In this context, cognitive sciences can enhance the cognitive processes, which can help to security analysts to establish actions in less time and more efficiently within cybersecurity operations. This works presents a cognitive security model that integrates technological solutions such as Big Data, Machine Learning, and Support Decision Systems with the cognitive processes of security analysts used to generate knowledge, understanding and execution of security response actions. The model considers alternatives to establish the automation process in the execution of cognitive tasks defined in the cyber operations processes and includes the analyst as the central axis in the processes of validation and decision making through the use of MAPE-K, OODA and Human in the Loop. ER - TY - JOUR T1 - The thematic and citation landscape of Data and Knowledge Engineering (1985–2007) AU - Chen, Chaomei AU - Song, Il-Yeol AU - Yuan, Xiaojun AU - Zhang, Jian JO - Data & Knowledge Engineering VL - 67 IS - 2 SP - 234 EP - 259 PY - 2008 DA - 2008/11/01/ T2 - Special Jubilee Issue: DKE 25 Years SN - 0169-023X DO - https://doi.org/10.1016/j.datak.2008.05.004 UR - https://www.sciencedirect.com/science/article/pii/S0169023X08000700 KW - Structural and temporal patterns KW - Domain analysis KW - Scientometrics KW - CiteSpace KW - Thematic analysis KW - DKE AB - The thematic and citation structures of Data and Knowledge Engineering (DKE) (1985–2007) are identified based on text analysis and citation analysis of the bibliographic records of full papers published in the journal. Temporal patterns are identified by detecting abrupt increases of frequencies of noun phrases extracted from titles and abstracts of DKE papers over time. Conceptual structures of the subject domain are identified by clustering analysis. Concept maps and network visualizations are presented to illustrate salient patterns and emerging thematic trends. A variety of statistics are reported to highlight key contributors and DKE papers that have made profound impacts. ER - TY - CHAP T1 - 1 - Category Definitions AU - Sittig, Dean F. A2 - Sittig, Dean F. BT - Clinical Informatics Literacy PB - Academic Press SP - 1 EP - 170 PY - 2017 DA - 2017/01/01/ SN - 978-0-12-803206-0 DO - https://doi.org/10.1016/B978-0-12-803206-0.00001-8 UR - https://www.sciencedirect.com/science/article/pii/B9780128032060000018 ER - TY - CHAP T1 - Subject Index A2 - Williamson, Kirsty A2 - Johanson, Graeme BT - Research Methods (Second Edition) PB - Chandos Publishing SP - 603 EP - 644 PY - 2018 DA - 2018/01/01/ SN - 978-0-08-102220-7 DO - https://doi.org/10.1016/B978-0-08-102220-7.00036-4 UR - https://www.sciencedirect.com/science/article/pii/B9780081022207000364 ER - TY - JOUR T1 - Corrigendum to ‘Advancing coordinated cyber-investigations and tool interoperability using a community developed specification language’ [Digital Investigation 22C (2017) 14–45] AU - Casey, Eoghan AU - Barnum, Sean AU - Griffith, Ryan AU - Snyder, Jonathan AU - van Beek, Harm AU - Nelson, Alex JO - Digital Investigation VL - 28 SP - 183 EP - 187 PY - 2019 DA - 2019/03/01/ SN - 1742-2876 DO - https://doi.org/10.1016/j.diin.2018.10.001 UR - https://www.sciencedirect.com/science/article/pii/S1742287618303839 ER - TY - JOUR T1 - A cybercrime incident architecture with adaptive response policy AU - Tsakalidis, George AU - Vergidis, Kostas AU - Petridou, Sophia AU - Vlachopoulou, Maro JO - Computers & Security VL - 83 SP - 22 EP - 37 PY - 2019 DA - 2019/06/01/ SN - 0167-4048 DO - https://doi.org/10.1016/j.cose.2019.01.011 UR - https://www.sciencedirect.com/science/article/pii/S0167404818308150 KW - Cybercrime incident KW - Offence classification system KW - Cyber-security KW - Threat severity KW - Security and privacy KW - Investigation techniques KW - Social engineering attacks KW - Malware/spyware crime AB - Handling and mitigating the cybercrime incidents (CIs) have attracted significant research attention, over the last years, due to their increasing frequency of occurrence. However, the term cybercrime is often used interchangeably with other technology-linked malicious acts, such as cyberwarfare, and cyberterrorism, leading to misconceptions. In addition, there does not exist a management framework which would classify CIs, qualitatively and quantitatively evaluate their occurrence and promptly align them with appropriate measures and policies. This work introduces a Cybercrime Incident Architecture that enables a comprehensive cybercrime embodiment through feature identification, offence classification mechanisms, threats’ severity labeling and a completely novel Adaptive Response Policy (ARP) that identifies and interconnects the relevant stakeholders with preventive measures and response actions. The proposed architecture consists of four separate complementary components that lead to a manually – and in the future automatically – generated ARP. The idea is to build a holistic framework toward automated cybercrime handling. A criminal case study is selected to validate the introduced framework and highlight its potentiality to evolve into a CI expert system. ER - TY - CHAP T1 - Index A2 - Sittig, Dean F. BT - Clinical Informatics Literacy PB - Academic Press SP - 171 EP - 231 PY - 2017 DA - 2017/01/01/ SN - 978-0-12-803206-0 DO - https://doi.org/10.1016/B978-0-12-803206-0.18001-0 UR - https://www.sciencedirect.com/science/article/pii/B9780128032060180010 ER - TY - JOUR T1 - A focused crawler combinatory link and content model based on T-Graph principles AU - Seyfi, Ali AU - Patel, Ahmed JO - Computer Standards & Interfaces VL - 43 SP - 1 EP - 11 PY - 2016 DA - 2016/01/01/ SN - 0920-5489 DO - https://doi.org/10.1016/j.csi.2015.07.001 UR - https://www.sciencedirect.com/science/article/pii/S0920548915000732 KW - Focused Web crawler KW - T-Graph KW - HTML data KW - Information retrieval KW - Search engine AB - The two significant tasks of a focused Web crawler are finding relevant documents and prioritizing them for effective download. For the first task, we propose an algorithm to fetch and analyze the most effective HTML elements of the page to predict and elicit the topical focus of each unvisited page with high accuracy. For the second task, we propose a scoring function of the relevant URLs through the use of T-Graph to prioritize each unvisited link. Thus, our novel method uniquely combines these approaches, giving precision and recall values close to 50%, which indicate the significance of the proposed architecture. ER - TY - JOUR T1 - domRBAC: An access control model for modern collaborative systems AU - Gouglidis, Antonios AU - Mavridis, Ioannis JO - Computers & Security VL - 31 IS - 4 SP - 540 EP - 556 PY - 2012 DA - 2012/06/01/ SN - 0167-4048 DO - https://doi.org/10.1016/j.cose.2012.01.010 UR - https://www.sciencedirect.com/science/article/pii/S0167404812000144 KW - Access control KW - Cross-domain authorization KW - Grid computing KW - RBAC KW - Resource usage management KW - Secure inter-operation AB - Modern collaborative systems such as the Grid computing paradigm are capable of providing resource sharing between users and platforms. These collaborations need to be done in a transparent way among the participants of a virtual organization (VO). A VO may consist of hundreds of users and heterogeneous resources. In order to have a successful collaboration, a list of vital importance requirements should be fulfilled, viz. collaboration among domains, to ensure a secure environment during a collaboration, the ability to enforce usage constraints upon resources, and to manage the security policies in an easy and efficient way. In this article, we propose an enhanced role-based access control model entitled domRBAC for collaborative applications, which is based on the ANSI INCITS 359-2004 access control model. The domRBAC is capable of differentiating the security policies that need to be enforced in each domain and to support collaboration under secure inter-operation. Cardinality constraints along with context information are incorporated to provide the ability of applying simple usage management of resources for the first time in a role-based access control model. Furthermore, secure inter-operation is assured among collaborating domains during role assignment automatically and in real-time. Yet, domRBAC, as an RBAC approach, intrinsically inherits all of its virtues such as ease of management, and separation of duty relationships with the latter also being supported in multiple domains. As a proof of concept, we implement a simulator based on the definitions of our proposed access control model and conduct experimental studies to demonstrate the feasibility and performance of our approach. ER - TY - JOUR T1 - The Internet of Things – The future or the end of mechatronics AU - Bradley, David AU - Russell, David AU - Ferguson, Ian AU - Isaacs, John AU - MacLeod, Allan AU - White, Roger JO - Mechatronics VL - 27 SP - 57 EP - 74 PY - 2015 DA - 2015/04/01/ SN - 0957-4158 DO - https://doi.org/10.1016/j.mechatronics.2015.02.005 UR - https://www.sciencedirect.com/science/article/pii/S0957415815000215 KW - Internet of Things KW - Mechatronics KW - Design KW - Education KW - System security KW - Participatory systems AB - The advent and increasing implementation of user configured and user oriented systems structured around the use of cloud configured information and the Internet of Things is presenting a new range and class of challenges to the underlying concepts of integration and transfer of functionality around which mechatronics is structured. It is suggested that the ways in which system designers and educators in particular respond to and manage these changes and challenges is going to have a significant impact on the way in which both the Internet of Things and mechatronics develop over time. The paper places the relationship between the Internet of Things and mechatronics into perspective and considers the issues and challenges facing systems designers and implementers in relation to managing the dynamics of the changes required. ER - TY - JOUR T1 - Towards a web payment framework: State-of-the-art and challenges AU - Ruiz-Martínez, Antonio JO - Electronic Commerce Research and Applications VL - 14 IS - 5 SP - 345 EP - 350 PY - 2015 DA - 2015/09/01/ T2 - Contemporary Research on Payments and Cards in the Global Fintech Revolution SN - 1567-4223 DO - https://doi.org/10.1016/j.elerap.2015.08.003 UR - https://www.sciencedirect.com/science/article/pii/S1567422315000587 KW - Electronic commerce KW - Electronic payment systems KW - Web payment framework AB - In the Internet era, through the web, and access to content, products and services has evolved in a spectacular way. At the same time, different business models have been developed for access and consumption. Many of these business models are based on making a payment via the web. The use of electronic payments in the web is a complex issue since it involves the support of multiple payment instruments, the secure exchange of payment information, receipts, and so on. A proposed solution approach to web payments is the development of a web payment framework based on a layered approach. This article analyzes the functionality this framework should provide, what solutions may be used, and what issues still need to be addressed so that a web payment framework can make e-payments more widespread. ER - TY - JOUR T1 - Security assurance assessment methodology for hybrid clouds AU - Hudic, Aleksandar AU - Smith, Paul AU - Weippl, Edgar R. JO - Computers & Security VL - 70 SP - 723 EP - 743 PY - 2017 DA - 2017/09/01/ SN - 0167-4048 DO - https://doi.org/10.1016/j.cose.2017.03.009 UR - https://www.sciencedirect.com/science/article/pii/S0167404817300627 KW - Assurance KW - Cloud computing KW - Security assessment KW - Security metric KW - Openstack AB - The emergence of the cloud computing paradigm has altered the delivery models for ICT services. Unfortunately, the widespread use of the cloud has a cost, in terms of reduced transparency and control over a user's information and services. In addition, there are a number of well-understood security and privacy challenges that are specific to this environment. These drawbacks are particularly problematic to operators of critical information infrastructures that want to leverage the benefits of cloud. To improve transparency and provide assurances that measures are in place to ensure security, novel approaches to security evaluation are needed. To evaluate the security of services that are deployed in the cloud requires an evaluation of complex multi-layered systems and services, including their interdependencies. This is a challenging task that involves significant effort, in terms of both computational and human resources. With these challenges in mind, we propose a novel security assessment methodology for analysing the security of critical services that are deployed in cloud environments. Our methodology offers flexibility, in that tailored policy-driven security assessments can be defined based on a user's requirements, relevant standards, policies, and guidelines. We have implemented and evaluated a system that supports online assessments using our methodology, which acquires and processes large volumes of security-related data without affecting the performance of the services in a cloud environment. ER - TY - JOUR T1 - Big Data and virtualization for manufacturing cyber-physical systems: A survey of the current status and future outlook AU - Babiceanu, Radu F. AU - Seker, Remzi JO - Computers in Industry VL - 81 SP - 128 EP - 137 PY - 2016 DA - 2016/09/01/ T2 - Emerging ICT concepts for smart, safe and sustainable industrial systems SN - 0166-3615 DO - https://doi.org/10.1016/j.compind.2016.02.004 UR - https://www.sciencedirect.com/science/article/pii/S0166361516300471 KW - Sensor-based real-time monitoring KW - Big Data KW - Internet of things KW - Cloud computing KW - Manufacturing cyber-physical systems AB - The recent advances in sensor and communication technologies can provide the foundations for linking the physical manufacturing facility and machine world to the cyber world of Internet applications. The coupled manufacturing cyber-physical system is envisioned to handle the actual operations in the physical world while simultaneously monitor them in the cyber world with the help of advanced data processing and simulation models at both the manufacturing process and system operational levels. Moreover, a sensor-packed manufacturing system in which each process or piece of equipment makes available event and status information, coupled with market research for true advanced Big Data analytics, seem to be the right ingredients for event response selection and operation virtualization. As a drawback, the resulting manufacturing cyber-physical system will be vulnerable to the inevitable cyber-attacks, unfortunately, so common for the software and Internet-based systems. This reality makes cybersecurity penetration within the manufacturing domain a need that goes uncontested across researchers and practitioners. This work provides a review of the current status of virtualization and cloud-based services for manufacturing systems and of the use of Big Data analytics for planning and control of manufacturing operations. Building on already developed cloud business solutions, cloud manufacturing is expected to offer improved enterprise manufacturing and business decision support. Based on the current state-of-the-art cloud manufacturing solutions and Big Data applications, this work also proposes a framework for the development of predictive manufacturing cyber-physical systems that include capabilities for attaching to the Internet of Things, and capabilities for complex event processing and Big Data algorithmic analytics. ER - TY - JOUR T1 - Constraint verification failure recovery in web service composition AU - Laleh, Touraj AU - Paquet, Joey AU - Mokhov, Serguei AU - Yan, Yuhong JO - Future Generation Computer Systems VL - 89 SP - 387 EP - 401 PY - 2018 DA - 2018/12/01/ SN - 0167-739X DO - https://doi.org/10.1016/j.future.2018.06.037 UR - https://www.sciencedirect.com/science/article/pii/S0167739X17320629 KW - Web service composition KW - Service constraints KW - Service failure recovery AB - Automated service composition aims at fulfilling complex tasks by combining different existing elementary web services in a workflow and creating value-added services. Many approaches have been proposed for automatic web service composition. Most of these approaches are based on the matching of input/output parameters across different elementary services. However, in addition to input/output parameters, many real-world services have applicable conditions and usage restrictions (i.e., service constraints) that are imposed by their providers. The constraints of a service should be verified prior to service call to ensure its correct execution. However, constraint verification of a composite service is different, as verification of some of the elementary services’ constraints might require execution of other elementary services inside the composite plan. In addition, failure during verification of constraints inside a composite plan results in the failure of execution of the whole composite service, which requires failure recovery for the composite service to continue execution. Composite service failure recovery implies the rollback of certain service transactions during the recovery of the composite plan. Current composite service failure recovery approaches are not adapted to the minimization of service rollbacks due to constraint verification failures. In this paper, a constraint-aware failure recovery approach is proposed to predict failures inside a composite service. Then, a method is proposed to do failure recovery based on those predictions and minimize the number of service rollbacks upon failure resulting from constraint verification. The proposed solution includes a planning-based algorithm and a novel constraint-processing method for service failure prediction and recovery. A publicly available test set generator is used to evaluate and analyze the proposed solution. ER - TY - JOUR T1 - Distributed machine learning cloud teleophthalmology IoT for predicting AMD disease progression AU - Das, Arun AU - Rad, Paul AU - Choo, Kim-Kwang Raymond AU - Nouhi, Babak AU - Lish, Jonathan AU - Martel, James JO - Future Generation Computer Systems VL - 93 SP - 486 EP - 498 PY - 2019 DA - 2019/04/01/ SN - 0167-739X DO - https://doi.org/10.1016/j.future.2018.10.050 UR - https://www.sciencedirect.com/science/article/pii/S0167739X18317941 KW - Internet of Medical Things (IoMT) KW - Deep learning KW - Telemedicine KW - Teleophthalmology KW - Macular degeneration KW - Mobile-cloud teleophthalmology KW - Wearable IoMT AB - The ability to perform screening of potential vision-impairing diseases remotely with an Ophthalmologist-in-the-loop is crucial in serving the Medically Underserved Areas/Population (MUA/P) and in acute medical settings, such as emergency departments. With an estimated 217 million individuals affected by moderate to severe vision-impairing diseases worldwide and an increasing number of new patients with such diseases, the need for access to faster (or real-time) diagnosis on a large scale is imperative. It is evident that early diagnosis of chronic diseases such as diabetic retinopathy and age-related macular degeneration (AMD) could better prevent vision loss. In this paper, a scalable cloud based teleophthalmology architecture via the Internet of Medical Things (IoMT) for diagnosis of AMD is presented. In the proposed architecture, patients wear a head-mounted camera (OphthoAI IoMT headset) to send their retinal fundus images to their secure and private cloud drive storage for personalized disease severity detection and predictive progression analysis. A proposed AMD-ResNet convolution neural network with 152 layers will then analyze the images to identify and determine AMD disease severity. The algorithm is trained with AREDS (age related eye disease study) images from the National Institute of Health (NIH) with over 130,000 fundus images captured over 12 years, and for determining AMD severity, we achieve a sensitivity and specificity of 94.97 ± 0.5% and 98.32 ± 0.1% respectively. A temporal Long–Short Term Memory (LSTM) deep neural network for precision medicine and AMD predictive progression is also proposed. Patient personalization allows better targeted care, lesser side effects, and a greater likelihood of responding to treatments by tailoring healthcare on a per-patient basis. ER - TY - JOUR T1 - Challenges and research directions for heterogeneous cyber–physical system based on IEC 61850: Vulnerabilities, security requirements, and security architecture AU - Yoo, Hyunguk AU - Shon, Taeshik JO - Future Generation Computer Systems VL - 61 SP - 128 EP - 136 PY - 2016 DA - 2016/08/01/ SN - 0167-739X DO - https://doi.org/10.1016/j.future.2015.09.026 UR - https://www.sciencedirect.com/science/article/pii/S0167739X15003064 KW - IEC 61850 KW - DNP3 KW - IEC 61970 KW - Cyber–physical system KW - Cybersecurity AB - IEC 61850, an international standard for communication networks, is becoming prevalent in the cyber–physical system (CPS) environment, especially with regard to the electrical grid. Recently, since cyber threats in the CPS environment have increased, security matters for individual protocols used in this environment are being discussed at length. However, there have not been many studies on the types of new security vulnerabilities and the security requirements that are required in a heterogeneous protocol environment based on IEC 61850. In this paper, we examine the electrical grid in Korea, and discuss security vulnerabilities, security requirements, and security architectures in such an environment. ER - TY - JOUR T1 - Enhancing random forest classification with NLP in DAMEH: A system for DAta Management in eHealth Domain AU - Amato, Flora AU - Coppolino, Luigi AU - Cozzolino, Giovanni AU - Mazzeo, Giovanni AU - Moscato, Francesco AU - Nardone, Roberto JO - Neurocomputing VL - 444 SP - 79 EP - 91 PY - 2021 DA - 2021/07/15/ SN - 0925-2312 DO - https://doi.org/10.1016/j.neucom.2020.08.091 UR - https://www.sciencedirect.com/science/article/pii/S0925231221001302 KW - Big data processing KW - E-health KW - Machine learning KW - Random forests KW - Multi-classification schema AB - The use of pervasive IoT devices in Smart Cities, have increased the Volume of data produced in many and many field. Interesting and very useful applications grow up in number in E-health domain, where smart devices are used in order to manage huge amount of data, in highly distributed environments, in order to provide smart services able to collect data to fill medical records of patients. The problem here is to gather data, to produce records and to analyze medical records depending on their contents. Since data gathering involve very different devices (not only wearable medical sensors, but also environmental smart devices, like weather, pollution and other sensors) it is very difficult to classify data depending their contents, in order to enable better management of patients. Data from smart devices couple with medical records written in natural language: we describe here an architecture that is able to determine best features for classification, depending on existent medical records. The architecture is based on pre-filtering phase based on Natural Language Processing, that is able to enhance Machine learning classification based on Random Forests. We carried on experiments on about 5000 medical records from real (anonymized) case studies from various health-care organizations in Italy. We show accuracy of the presented approach in terms of Accuracy-Rejection curves. ER - TY - JOUR T1 - Literary writing style recognition via a minimal spanning tree-based approach AU - Shalymov, Dmitry AU - Granichin, Oleg AU - Klebanov, Lev AU - Volkovich, Zeev JO - Expert Systems with Applications VL - 61 SP - 145 EP - 153 PY - 2016 DA - 2016/11/01/ SN - 0957-4174 DO - https://doi.org/10.1016/j.eswa.2016.05.032 UR - https://www.sciencedirect.com/science/article/pii/S0957417416302573 KW - Writing style determination KW - Two-sample spanning Tree-based test AB - In this paper, we address the problem of literary writing style determination using a comparison of the randomness of two given texts. We attempt to comprehend if these texts are generated from distinct probability sources that can reveal a difference between the literary writing styles of the corresponding authors. We propose a new approach based on the incorporation of the known Friedman-Rafsky two-sample test into a multistage procedure with the aim of stabilizing the process. A sampling procedure constructed by applying the N-grams methodology is applied to simulate samples drawn from the pooled text with the aim of evaluating the null hypothesis distribution that appears after the writing styles coincide. Next, samples from different files are selected, and the p-values of the test statistics are calculated. An empirical distribution of these values is compared numerous times with the uniform one on the interval [0, 1], and the writing styles are recognized as different if the rejection fraction in this comparison’s sequence is significantly greater than 0.5. The offered approach is language independent in the community of alphabetic languages and does not involve the use of linguistics. In comparison with most existing methods our approach does not deal with any authorship attribute determination. A text itself, more precisely speaking, the distribution of sequential text templates and their mutual occurrences essentially identifies the style. Experiments demonstrate the strong capability of the proposed method. ER - TY - JOUR T1 - Expanded cloud plumes hiding Big Data ecosystem AU - Sharma, Sugam JO - Future Generation Computer Systems VL - 59 SP - 63 EP - 92 PY - 2016 DA - 2016/06/01/ SN - 0167-739X DO - https://doi.org/10.1016/j.future.2016.01.003 UR - https://www.sciencedirect.com/science/article/pii/S0167739X16000054 KW - Cloud KW - Big Data KW - Smart Data and Lakes KW - IoT KW - XCLOUDX KW - as-a-Service AB - Today, a paradigm shift is being observed in science, where the focus is gradually shifting away from operation to data, which is greatly influencing the decision making also. The data is being inundated proactively from several sources in various forms; especially social media and in modern data science vocabulary is being recognized as Big Data. Today, Big Data is permeating through the bigger aspect of human life for scientific and commercial dependencies, especially for massive scale data analytics of beyond the exabyte magnitude. As the footprint of Big Data applications is continuously expanding, the reliability on cloud environments is also increasing to obtain appropriate, robust and affordable services to deal with Big Data challenges. Cloud computing avoids any need to locally maintain the overly scaled computing infrastructure that include not only dedicated space, but the expensive hardware and software also. Several data models to process Big Data are already developed and a number of such models are still emerging, potentially relying on heterogeneous underlying storage technologies, including cloud computing. In this paper, we investigate the growing role of cloud computing in Big Data ecosystem. Also, we propose a novel XCLOUDX {XCloudX, X…X}classification to zoom in to gauge the intuitiveness of the scientific name of the cloud-assisted NoSQL Big Data models and analyze whether XCloudX always uses cloud computing underneath or vice versa. XCloudX symbolizes those NoSQL Big Data models that embody the term “cloud” in their name, where X is any alphanumeric variable. The discussion is strengthen by a set of important case studies. Furthermore, we study the emergence of as-a-Service era, motivated by cloud computing drive and explore the new members beyond traditional cloud computing stack, developed in the past couple of years. ER - TY - JOUR T1 - An integrated framework for analyzing multilingual content in Web 2.0 social media AU - Dang, Yan AU - Zhang, Yulei AU - Hu, Paul Jen-Hwa AU - Brown, Susan A. AU - Ku, Yungchang AU - Wang, Jau-Hwang AU - Chen, Hsinchun JO - Decision Support Systems VL - 61 SP - 126 EP - 135 PY - 2014 DA - 2014/05/01/ SN - 0167-9236 DO - https://doi.org/10.1016/j.dss.2014.02.004 UR - https://www.sciencedirect.com/science/article/pii/S0167923614000372 KW - Social media KW - Web portal KW - User evaluation AB - The growth of Web 2.0 has produced enormous amounts of user-generated content that contains important information about individuals' attitudes, perceptions, and opinions toward products, social events, and political issues. The volume of such content is increasing exponentially, making its search, analysis, and use more difficult and thus favoring advanced tools that aid in information search and processing. We propose an integrated framework that offers an infrastructure necessary for accessing, integrating, and analyzing multilingual user-generated content from different social media sites. Building on this framework, we develop the Dark Web Forum Portal (DWFP) that supports the gathering and analyses of social media content concerning security. Our evaluation results show that users supported by DWFP complete tasks better and faster than those using the benchmark forum. Participants consider DWFP to be better in terms of system quality, usefulness, ease of use, satisfaction and intention to use. ER - TY - CHAP T1 - Chapter 19 - The territories of indigenous people of Baja California, Mexico: Semiotic dimensions in the study of landscapes AU - Parás Fernández, M. Margarita AU - Domínguez Núñez, Martin C. AU - Morales Gamas, Amilcar A2 - Taylor, D.R. Fraser A2 - Anonby, Erik A2 - Murasugi, Kumiko BT - Modern Cartography Series PB - Academic Press VL - 9 SP - 331 EP - 348 PY - 2019 DA - 2019/01/01/ T2 - Further Developments in the Theory and Practice of Cybercartography SN - 1363-0814 DO - https://doi.org/10.1016/B978-0-444-64193-9.00019-1 UR - https://www.sciencedirect.com/science/article/pii/B9780444641939000191 KW - Semiotics KW - Language KW - Meanings KW - Landscape KW - Cybercartographic Atlas KW - Pa Ipai people of Baja California AB - Indigenous communities of Baja California like the Pa Ipai and Koal base their traditions on oral processes, including chants and narratives. Some of these indigenous communities are reaching the brink of extinction. Our research focuses on the semiotic dimensions related to the transformation of cultural landscapes. Of particular interest is the elucidation of meaning and representations associated with astronomical knowledge and worldviews. An important goal is to identify the names of mountains, canyons, and rivers, along with the sacred stories linked to local geo-forms. With these goals in mind an international team of researchers with community participation put together a pilot project for the development of a Cybercartographic Atlas of the Pa Ipai people. Through the Nunaliit Framework, we intend to explore and communicate the traditional knowledge and meanings embedded in the linguistic and sociocultural landscapes in northern Baja California. ER - TY - JOUR T1 - Computer based testing – Bolls v. W. Scott Street, Sec'y of Va. Bd. of Bar Exmnrs., August 11, 2009, case no. 090915 AU - Bolls, Jonathan AU - Castell, Stephen JO - Computer Law & Security Review VL - 29 IS - 4 SP - 446 EP - 449 PY - 2013 DA - 2013/08/01/ SN - 0267-3649 DO - https://doi.org/10.1016/j.clsr.2013.05.012 UR - https://www.sciencedirect.com/science/article/pii/S0267364913001039 KW - Computer based testing KW - KW - Bar exam AB - The most significant change to law licensing in the United States is the recent11Virginia, for example, has been providing the computer-based test on a wide scale since 2005. New Jersey was the very first, in 2001. Since then, almost all of the states are now administering a computer-based test. reliance on computer-based testing for the bar exam in all of the fifty states. The following comment piece is meant to inform the computer and technology law community how the use of testing software must necessarily be accompanied by additional procedural protections and corrective processes that may not have existed previously. Chief among these is the availability of discovery of the item in question, namely in this case the essays in a computer-based bar exam, which constitutes evidence that is essential to vindicating one's rights when a software failure occurs. ER - TY - CHAP T1 - Index A2 - Vacca, John R. BT - Computer and Information Security Handbook (Third Edition) PB - Morgan Kaufmann CY - Boston SP - 1197 EP - 1237 PY - 2017 DA - 2017/01/01/ SN - 978-0-12-803843-7 DO - https://doi.org/10.1016/B978-0-12-803843-7.18001-9 UR - https://www.sciencedirect.com/science/article/pii/B9780128038437180019 ER - TY - JOUR T1 - Subject Index JO - Decision Support Systems VL - 51 IS - 4 SP - VI EP - IX PY - 2011 DA - 2011/11/01/ T2 - Recent Advances in Data, Text, and Media Mining & Information Issues in Supply Chain and in Service System Design SN - 0167-9236 DO - https://doi.org/10.1016/S0167-9236(11)00149-7 UR - https://www.sciencedirect.com/science/article/pii/S0167923611001497 ER - TY - JOUR T1 - AIDIS: Detecting and classifying anomalous behavior in ubiquitous kernel processes AU - Luh, Robert AU - Janicke, Helge AU - Schrittwieser, Sebastian JO - Computers & Security VL - 84 SP - 120 EP - 147 PY - 2019 DA - 2019/07/01/ SN - 0167-4048 DO - https://doi.org/10.1016/j.cose.2019.03.015 UR - https://www.sciencedirect.com/science/article/pii/S0167404818314457 KW - Intrusion detection KW - Malware KW - Anomaly detection KW - Graph matching KW - Star structure KW - Security model KW - Semantic gap KW - Machine learning KW - Classification KW - SVM AB - Targeted attacks on IT systems are a rising threat against the confidentiality, integrity, and availability of critical information and infrastructures. With the rising prominence of advanced persistent threats (APTs), identifying and understanding such attacks has become increasingly important. Current signature-based systems are heavily reliant on fixed patterns that struggle with unknown or evasive applications, while behavior-based solutions usually leave most of the interpretative work to a human analyst. In this article we propose AIDIS, an Advanced Intrusion Detection and Interpretation System capable to explain anomalous behavior within a network-enabled user session by considering kernel event anomalies identified through their deviation from a set of baseline process graphs. For this purpose we adapt star structures, a bipartite representation used to approximate the edit distance between two graphs. Baseline templates are generated automatically and adapt to the nature of the respective operating system process. We prototypically implemented smart anomaly classification through a set of competency questions applied to graph template deviations and evaluated the approach using both Random Forest and linear kernel support vector machines. The determined attack classes are ultimately mapped to a dedicated APT attacker/defender meta model that considers actions, actors, as well as assets and mitigating controls, thereby enabling decision support and contextual interpretation of ongoing attacks. ER - TY - JOUR T1 - IT Technology Implications Analysis on the Occupational Risk: Cloud Computing Architecture AU - Cioca, Lucian-Ionel AU - Ivascu, Larisa JO - Procedia Technology VL - 16 SP - 1548 EP - 1559 PY - 2014 DA - 2014/01/01/ T2 - CENTERIS 2014 - Conference on ENTERprise Information Systems / ProjMAN 2014 - International Conference on Project MANagement / HCIST 2014 - International Conference on Health and Social Care Information Systems and Technologies SN - 2212-0173 DO - https://doi.org/10.1016/j.protcy.2014.10.177 UR - https://www.sciencedirect.com/science/article/pii/S2212017314004046 KW - Occupational risk KW - occupational health and safety KW - cloud computing KW - risk KW - hazard KW - health KW - risk management KW - e-health ; AB - The present paper is divided into three major areas: the analysis of occupational risk implications at national and international level, the European priorities in terms of occupational risk and the existing cloud computing services. Since human resource is present within each organization, it is required a comprehensive and actual assessment of the processes in which they participate. Like in any daily activity, processes and people contribute to the emergence of risks. If each organization creates healthy and safe workplaces that means that it contributes to the sustainable development of the area in which it operates. It can be said that occupational risk assessment and occupational health and safety is the foundation for optimal functioning of the enterprise, thus aiding in reaching the enterprise objectives. The combination of these key concepts, occupational risk and occupational health and safety with technological developments contribute to an innovative approach to risk. This paper presents the literature review, European strategic directions and their implementation in occupational risk assessment in Romanian organizations, analysis of work accidents in Romania compared to EU and authors addressing occupational risk assessment using cloud computing by developing the associated architecture. ER - TY - JOUR T1 - Humans forget, machines remember: Artificial intelligence and the Right to Be Forgotten AU - Villaronga, Eduard Fosch AU - Kieseberg, Peter AU - Li, Tiffany JO - Computer Law & Security Review VL - 34 IS - 2 SP - 304 EP - 313 PY - 2018 DA - 2018/04/01/ SN - 0267-3649 DO - https://doi.org/10.1016/j.clsr.2017.08.007 UR - https://www.sciencedirect.com/science/article/pii/S0267364917302091 KW - Right to Be Forgotten KW - Artificial intelligence (AI) KW - Privacy KW - Data deletion KW - Memory AB - This article examines the problem of AI memory and the Right to Be Forgotten. First, this article analyzes the legal background behind the Right to Be Forgotten, in order to understand its potential applicability to AI, including a discussion on the antagonism between the values of privacy and transparency under current E.U. privacy law. Next, the authors explore whether the Right to Be Forgotten is practicable or beneficial in an AI/machine learning context, in order to understand whether and how the law should address the Right to Be Forgotten in a post-AI world. The authors discuss the technical problems faced when adhering to strict interpretation of data deletion requirements under the Right to Be Forgotten, ultimately concluding that it may be impossible to fulfill the legal aims of the Right to Be Forgotten in artificial intelligence environments. Finally, this article addresses the core issue at the heart of the AI and Right to Be Forgotten problem: the unfortunate dearth of interdisciplinary scholarship supporting privacy law and regulation. ER - TY - JOUR T1 - An efficient privacy preserving protocol for dynamic continuous data collection AU - Sajjad, Haider AU - Kanwal, Tehsin AU - Anjum, Adeel AU - Malik, Saif ur Rehman AU - Khan, Ahmed AU - Khan, Abid AU - Manzoor, Umar JO - Computers & Security VL - 86 SP - 358 EP - 371 PY - 2019 DA - 2019/09/01/ SN - 0167-4048 DO - https://doi.org/10.1016/j.cose.2019.06.017 UR - https://www.sciencedirect.com/science/article/pii/S0167404819301312 KW - Data privacy KW - Privacy preserving data collection KW - Anonymization KW - -anonymity AB - Past and ongoing decades have witnessed significant uplift in data generation due to ever growing sources of data. Collection and aggradation of such huge data have triggered serious concerns on privacy of data-owners’ sensitive information. Catering this, several existing anonymization models proffer privacy-preserving data collection. However, the models put-forth either strict or unrealistic assumptions regarding leaders’ selection (the concept of first and last leaders in data collection process). In this paper, we have identified and formally defined a privacy attack, Leader Collusion Attack (LCA); where first and second leaders may collude to breech individuals’ privacy during data collection process. In this regard, we have proposed a novel k-anonymity based dynamic data collection protocol (presented single leader election) to mitigate LCA. Moreover, we have formally modelled and analysed the proposed protocol through HLPNs and demonstrated the mitigation of LCA. Experimentations on real-world datasets advocate the outperformance of our protocol over existing model in terms of better utility and privacy levels. ER - TY - CHAP T1 - 3 - Digital history, archives, and curating digital cultural heritage AU - Sabharwal, Arjun A2 - Sabharwal, Arjun BT - Digital Curation in the Digital Humanities PB - Chandos Publishing SP - 49 EP - 67 PY - 2015 DA - 2015/01/01/ SN - 978-0-08-100143-1 DO - https://doi.org/10.1016/B978-0-08-100143-1.00003-9 UR - https://www.sciencedirect.com/science/article/pii/B9780081001431000039 KW - Archives KW - Digital curation KW - Digital historical representation KW - Digital historiography KW - Digital history KW - Digital history data curation AB - Digital history presents a new chapter for collaboration among historians, archivists, librarians, and technologists. While historians had integrated computing into various research projects well prior to the arrival of the World Wide Web, digital technology has opened up the field to newer methods in historiography, analysis, and interpretation. For archivists and digital curators, this stage also presents new possibilities, questions, and concerns about preserving, promoting, and providing long-term access to born-digital, digitized, and hypertextual content. This chapter focuses on the relationship between digital history and archives, and the implications of digital history and historiography for digital curation and vice versa. ER - TY - JOUR T1 - Discovering missing me edges across social networks AU - Buccafurri, Francesco AU - Lax, Gianluca AU - Nocera, Antonino AU - Ursino, Domenico JO - Information Sciences VL - 319 SP - 18 EP - 37 PY - 2015 DA - 2015/10/20/ T2 - Energy Efficient Data, Services and Memory Management in Big Data Information Systems SN - 0020-0255 DO - https://doi.org/10.1016/j.ins.2015.05.014 UR - https://www.sciencedirect.com/science/article/pii/S0020025515003722 KW - Social networks KW - Identity management KW - Membership overlap AB - Distinct social networks are interconnected via membership overlap, which plays a key role when crossing information is investigated in the context of multiple-social-network analysis. Unfortunately, users do not always make their membership to two distinct social networks explicit, by specifying the so-called me edge (practically, corresponding to a link between the two accounts), thus missing a potentially very useful information. As a consequence, discovering missing me edges is an important problem to address in this context with potential powerful applications. In this paper, we propose a common-neighbor approach to detecting missing me edges, which returns good results in real-life settings. Indeed, an experimental campaign shows both that the state-of-the-art common-neighbor approaches cannot be effectively applied to our problem and, conversely, that our approach returns precise and complete results. ER - TY - JOUR T1 - A Structured Control Selection Methodology for Insider Threat Mitigation AU - Roy, Puloma AU - Sengupta, Anirban AU - Mazumdar, Chandan JO - Procedia Computer Science VL - 181 SP - 1187 EP - 1195 PY - 2021 DA - 2021/01/01/ T2 - CENTERIS 2020 - International Conference on ENTERprise Information Systems / ProjMAN 2020 - International Conference on Project MANagement / HCist 2020 - International Conference on Health and Social Care Information Systems and Technologies 2020, CENTERIS/ProjMAN/HCist 2020 SN - 1877-0509 DO - https://doi.org/10.1016/j.procs.2021.01.316 UR - https://www.sciencedirect.com/science/article/pii/S1877050921003677 KW - Insider threat KW - Security control KW - Threat-control mapping KW - Threat mitigation KW - Threat model AB - An insider is a person or software that possesses positive authorization to access the asset(s) of an enterprise. In recent years, security incidents perpetrated by enterprise insiders have increased considerably. Enterprises attempt to mitigate such threats by implementing controls intuitively, on an ad-hoc basis. However, such intuitive control implementation is both time-consuming, as well as prone to errors, leading to insecure enterprise systems. The paper attempts to address this issue by proposing a structured methodology for the selection of relevant security controls. The technique is to model insider threats and security controls, and match their constituent components against each other. The proposed methodology has been illustrated with suitable examples. ER - TY - JOUR T1 - A model-driven approach for quality of context in pervasive systems AU - Hoyos, José R. AU - García-Molina, Jesús AU - Botía, Juan A. AU - Preuveneers, Davy JO - Computers & Electrical Engineering VL - 55 SP - 39 EP - 58 PY - 2016 DA - 2016/10/01/ SN - 0045-7906 DO - https://doi.org/10.1016/j.compeleceng.2016.07.002 UR - https://www.sciencedirect.com/science/article/pii/S0045790616301744 KW - Quality of context KW - Model driven engineering KW - Domain specific language KW - Context modeling KW - Context-aware AB - Handling context is a crucial activity in context-aware systems. In building such systems, the creation of models helps developers to understand and reason on the context information. The quality of context information is required to achieve these systems behavior according to the requirements. Therefore, context models should not only represent the context information but also the quality of context (QoC). MLContext is a textual domain-specific language (DSL) designed to model context, which has been used to automatically generate software artifacts related to the context management for some context-aware frameworks. In this article we present an MLContext extension for modeling QoC. The QoC added features include constructs to express context situations (i.e. constraints on context information), quality requirements and quality levels. The new constructs have been mapped to code for two frameworks supporting QoC (COSMOS and SAMURAI). These mappings have been validated by means of a case study. ER - TY - JOUR T1 - FAMOUS: Forensic Analysis of MObile devices Using Scoring of application permissions AU - Kumar, Ajit AU - Kuppusamy, K.S. AU - Aghila, G. JO - Future Generation Computer Systems VL - 83 SP - 158 EP - 172 PY - 2018 DA - 2018/06/01/ SN - 0167-739X DO - https://doi.org/10.1016/j.future.2018.02.001 UR - https://www.sciencedirect.com/science/article/pii/S0167739X17323257 KW - Apk permissions KW - Static analysis KW - Weighted feature KW - Machine learning KW - Android malware triage KW - Forensic triage tool AB - With the emergence of Android as a leading operating system in mobile devices, it becomes mandatory to develop specialized, predictive and robust security measures to provide a dependable environment for users. Extant reactive and proactive security techniques would not be enough to tackle the fast-growing security challenges in the Android environment. This paper has proposed a predictive forensic approach to detect suspicious Android applications. An in-depth study of statistical properties of permissions used by the malicious and benign Android applications has been performed. Based on the results of this study, a weighted score based feature set has been created which is used to build a predictive and lightweight malware detector for Android devices. Various experiments conducted on the aforementioned feature set, an improved accuracy level of 99% has been achieved with Random Forest classifier. This trained model has been used to build a forensic tool entitled FAMOUS (F orensic A nalysis of MO bile devices U sing S coring of application permissions) which is able to scan all the installed applications of an attached device and provide a descriptive report. ER - TY - JOUR T1 - INSiGHT: A system to detect violent extremist radicalization trajectories in dynamic graphs AU - Hung, Benjamin W.K. AU - Jayasumana, Anura P. AU - Bandara, Vidarshana W. JO - Data & Knowledge Engineering VL - 118 SP - 52 EP - 70 PY - 2018 DA - 2018/11/01/ SN - 0169-023X DO - https://doi.org/10.1016/j.datak.2018.09.003 UR - https://www.sciencedirect.com/science/article/pii/S0169023X17303920 KW - Graph pattern matching KW - Pattern matching trajectories KW - Investigative graph search KW - Radicalization KW - Violent extremists AB - The number and lethality of violent extremist plots motivated by the Salafi-jihadist ideology have been growing for nearly the last decade in many parts of the world including both the U.S and Western Europe. While detecting the radicalization of violent extremists is a key component in preventing future terrorist attacks, it remains a significant challenge to law enforcement due to the issues of both scale and dynamics. We propose the development of a radicalization trend detection system as a risk assessment assistance technology that relies on data mined from public data and government databases for individuals who exhibit risk indicators for extremist violence, and enables law enforcement to monitor those individuals at the scope and scale that is lawful, and accounts for the dynamic indicative behaviors of the individuals and their associates rigorously and automatically. We frame our approach to monitoring the radicalization pattern of behaviors as a unique dynamic graph pattern matching problem, and develop a technology called INSiGHT (Investigative Search for Graph-Trajectories) to help identify individuals or small groups with conforming subgraphs to a radicalization query pattern, and follow the match trajectories over time. This paper presents the overall INSiGHT architecture and is aimed at assisting law enforcement and intelligence agencies in monitoring and screening for those individuals whose behaviors indicate a significant risk for violence, and allow for the better prioritization of limited investigative resources. We demonstrated the performance of INSiGHT on a variety of datasets, to include small synthetic radicalization-specific datasets and a real behavioral dataset of time-stamped radicalization indicators of recent U.S. violent extremists. ER - TY - JOUR T1 - Community Detection On Citation Network Of DBLP Data Sample Set Using LinkRank Algorithm AU - Yudhoatmojo, Satrio Baskoro AU - Samuar, Muhammad Arvin JO - Procedia Computer Science VL - 124 SP - 29 EP - 37 PY - 2017 DA - 2017/01/01/ T2 - 4th Information Systems International Conference 2017, ISICO 2017, 6-8 November 2017, Bali, Indonesia SN - 1877-0509 DO - https://doi.org/10.1016/j.procs.2017.12.126 UR - https://www.sciencedirect.com/science/article/pii/S1877050917328946 KW - Citation Network KW - Community Detection KW - Complex Network KW - Directed Network KW - LinkRank Algorithm KW - Social Network Analysis AB - This paper describes the application of a community detection algorithm, namely LinkRank algorithm, on a citation network. Community detection is a task in network analysis which aims to find sets of tightly connected nodes that are loosely connected with other nodes outside of those sets. In our study, we focused on a citation network which depicts relationships between cited papers and the papers which cite those papers. The objectives of our study are to identify communities of papers based on the citation relationships and analyze the similarities of topics within each community. The approach of our study to reach the objectives is by applying LinkRank algorithm to a citation network. LinkRank algorithm is chosen because it can be applied to a directed network where other algorithms that we have surveyed can only be used on undirected network. The citation network that we used in our study is from Aminer website. In applying the algorithm, we had to port the original source code which is written in C programming language into Python programming language for our convenience in doing the experiment. The result shows that the algorithm able to detect 10,442 communities from 188,514 nodes. Once the communities have been detected, we sampled top three communities (the ones with the largest number of members) and took the top 10 nodes with the highest PageRank score in each of those communities. The samples show that most of the nodes have similar topic, but there are still some nodes with different topics mixed inside the same community. We found the ratio between nodes with similar and different topics to be 7 to 3, that is 70% of the nodes have similar topic while the other 30% have different topics. Thus, the homophily of each community does not reach 100%. Nevertheless, our study confirms that LinkRank algorithm can be used for community detection on directed network. ER - TY - JOUR T1 - Contents JO - Procedia Engineering VL - 15 SP - iii EP - xliv PY - 2011 DA - 2011/01/01/ T2 - CEIS 2011 SN - 1877-7058 DO - https://doi.org/10.1016/S1877-7058(11)04811-9 UR - https://www.sciencedirect.com/science/article/pii/S1877705811048119 ER - TY - JOUR T1 - Contents JO - Procedia Computer Science VL - 35 SP - 1 EP - 10 PY - 2014 DA - 2014/01/01/ T2 - Knowledge-Based and Intelligent Information & Engineering Systems 18th Annual Conference, KES-2014 Gdynia, Poland, September 2014 Proceedings SN - 1877-0509 DO - https://doi.org/10.1016/j.procs.2014.08.079 UR - https://www.sciencedirect.com/science/article/pii/S1877050914010448 ER - TY - JOUR T1 - Introducing validity in fuzzy probability for judicial decision-making AU - Sabahi, Farnaz AU - Akbarzadeh-T, Mohammad-R. JO - International Journal of Approximate Reasoning VL - 55 IS - 6 SP - 1383 EP - 1403 PY - 2014 DA - 2014/09/01/ SN - 0888-613X DO - https://doi.org/10.1016/j.ijar.2013.12.003 UR - https://www.sciencedirect.com/science/article/pii/S0888613X13002922 KW - Decision-making KW - -Constraints KW - Judicial cases KW - Possibility KW - Probability KW - Validity AB - Since the Age of Enlightenment, most philosophers have associated reasoning with the rules of probability and logic. This association has been enhanced over the years and now incorporates the theory of fuzzy logic as a complement to the probability theory, leading to the concept of fuzzy probability. Our insight, here, is integrating the concept of validity into the notion of fuzzy probability within an extended fuzzy logic (FLe) framework keeping with the notion of collective intelligence. In this regard, we propose a novel framework of possibility–probability–validity distribution (PPVD). The proposed distribution is applied to a real world setting of actual judicial cases to examine the role of validity measures in automated judicial decision-making within a fuzzy probabilistic framework. We compute valid fuzzy probability of conviction and acquittal based on different factors. This determines a possible overall hypothesis for the decision of a case, which is valid only to a degree. Validity is computed by aggregating validities of all the involved factors that are obtained from a factor vocabulary based on the empirical data. We then map the combined validity based on the Jaccard similarity measure into linguistic forms, so that a human can understand the results. Then PPVDs that are obtained based on the relevant factors in the given case yield the final valid fuzzy probabilities for conviction and acquittal. Finally, the judge has to make a decision; we therefore provide a numerical measure. Our approach supports the proposed hypothesis within the three-dimensional contexts of probability, possibility, and validity to improve the ability to solve problems with incomplete, unreliable, or ambiguous information to deliver a more reliable decision. ER - TY - JOUR T1 - Perception layer security in Internet of Things AU - Khattak, Hasan Ali AU - Shah, Munam Ali AU - Khan, Sangeen AU - Ali, Ihsan AU - Imran, Muhammad JO - Future Generation Computer Systems VL - 100 SP - 144 EP - 164 PY - 2019 DA - 2019/11/01/ SN - 0167-739X DO - https://doi.org/10.1016/j.future.2019.04.038 UR - https://www.sciencedirect.com/science/article/pii/S0167739X19304194 KW - Perception layer KW - Internet of Things KW - Security KW - Radio frequency identification KW - Wireless sensor networks AB - Internet of Things (IoT) is one of the rising innovations of the current era that has largely attracted both the industry and the academia. Life without the IoT is entirely indispensable. To dispel the doubts, if any, about the widespread adoption, the IoT certainly necessitates both technically and logically correct solutions to ensure the underlying security and privacy. This paper explicitly investigates the security issues in the perception layer of IoT, the countermeasures and the research challenges faced for large scale deployment of IoT. Perception layer being one of the important layers in IoT is responsible for data collection from things and its successful transmission for further processing. The contribution of this paper is twofold. Firstly, we describe the crucial components of the IoT (i.e., architectures, standards, and protocols) in the context of security at perception layer followed by IoT security requirements. Secondly, after describing the generic IoT-layered security, we focus on two key enabling technologies (i.e., RFID and sensor network) at the perception layer. We categorize and classify various attacks at different layers of both of these technologies through taxonomic classification and discuss possible solutions. Finally, open research issues and challenges relevant to the perception layer are identified and analyzed. ER - TY - JOUR T1 - An automated Psychometric Analyzer based on Sentiment Analysis and Emotion Recognition for healthcare AU - Vij, Anneketh AU - Pruthi, Jyotika JO - Procedia Computer Science VL - 132 SP - 1184 EP - 1191 PY - 2018 DA - 2018/01/01/ T2 - International Conference on Computational Intelligence and Data Science SN - 1877-0509 DO - https://doi.org/10.1016/j.procs.2018.05.033 UR - https://www.sciencedirect.com/science/article/pii/S1877050918307658 KW - Schizophrenia KW - Sentiment KW - Emotion AB - In the present era of technology, technological advancements are going on at an exponential rate leading to rise in peer competition, stress and various psychological problems like severe depression, bipolar disorders, schizophrenia. So, there is a need for proper psychometric analysis of people so as to curb these problems. Sentiment analysis and emotional recognition have gained a lot of popularity on social networking sites but they have not been applied to the very complex field of healthcare. These two domains through psychologist, patient written text and their conversations hold a great potential for advancement in both medicine and technology. This paper proposes an application of data science in health care based on the survey of various sentiments and emotional analysis methodologies. The scope of sentiment and emotional analysis in visualization of medical records and patient’s medical history is presented in this paper. So, an amalgamated view of data mining, data analytics and data visualization in health care has been presented. ER - TY - JOUR T1 - Table of Contents JO - Procedia Computer Science VL - 19 SP - 1 EP - 12 PY - 2013 DA - 2013/01/01/ T2 - The 4th International Conference on Ambient Systems, Networks and Technologies (ANT 2013), the 3rd International Conference on Sustainable Energy Information Technology (SEIT-2013) SN - 1877-0509 DO - https://doi.org/10.1016/j.procs.2013.06.003 UR - https://www.sciencedirect.com/science/article/pii/S187705091300611X ER - TY - JOUR T1 - The rise of ransomware and emerging security challenges in the Internet of Things AU - Yaqoob, Ibrar AU - Ahmed, Ejaz AU - Rehman, Muhammad Habib ur AU - Ahmed, Abdelmuttlib Ibrahim Abdalla AU - Al-garadi, Mohammed Ali AU - Imran, Muhammad AU - Guizani, Mohsen JO - Computer Networks VL - 129 SP - 444 EP - 458 PY - 2017 DA - 2017/12/24/ T2 - Special Issue on 5G Wireless Networks for IoT and Body Sensors SN - 1389-1286 DO - https://doi.org/10.1016/j.comnet.2017.09.003 UR - https://www.sciencedirect.com/science/article/pii/S1389128617303468 KW - Internet of Things KW - Security KW - Authentication KW - Ransomware KW - Trust AB - With the increasing miniaturization of smartphones, computers, and sensors in the Internet of Things (IoT) paradigm, strengthening the security and preventing ransomware attacks have become key concerns. Traditional security mechanisms are no longer applicable because of the involvement of resource-constrained devices, which require more computation power and resources. This paper presents the ransomware attacks and security concerns in IoT. We initially discuss the rise of ransomware attacks and outline the associated challenges. Then, we investigate, report, and highlight the state-of-the-art research efforts directed at IoT from a security perspective. A taxonomy is devised by classifying and categorizing the literature based on important parameters (e.g., threats, requirements, IEEE standards, deployment level, and technologies). Furthermore, a few credible case studies are outlined to alert people regarding how seriously IoT devices are vulnerable to threats. We enumerate the requirements that need to be met for securing IoT. Several indispensable open research challenges (e.g., data integrity, lightweight security mechanisms, lack of security software’s upgradability and patchability features, physical protection of trillions of devices, privacy, and trust) are identified and discussed. Several prominent future research directions are provided. ER - TY - JOUR T1 - Contents JO - Procedia Computer Science VL - 19 SP - iii EP - viii PY - 2013 DA - 2013/01/01/ T2 - The 4th International Conference on Ambient Systems, Networks and Technologies (ANT 2013), the 3rd International Conference on Sustainable Energy Information Technology (SEIT-2013) SN - 1877-0509 DO - https://doi.org/10.1016/S1877-0509(13)00790-4 UR - https://www.sciencedirect.com/science/article/pii/S1877050913007904 ER - TY - JOUR T1 - Author Index JO - Decision Support Systems VL - 51 IS - 4 SP - I EP - V PY - 2011 DA - 2011/11/01/ T2 - Recent Advances in Data, Text, and Media Mining & Information Issues in Supply Chain and in Service System Design SN - 0167-9236 DO - https://doi.org/10.1016/S0167-9236(11)00148-5 UR - https://www.sciencedirect.com/science/article/pii/S0167923611001485 ER - TY - JOUR T1 - Privacy-enhancing identity management AU - Hansen, Marit AU - Berlich, Peter AU - Camenisch, Jan AU - Clauß, Sebastian AU - Pfitzmann, Andreas AU - Waidner, Michael JO - Information Security Technical Report VL - 9 IS - 1 SP - 35 EP - 44 PY - 2004 DA - 2004/01/01/ SN - 1363-4127 DO - https://doi.org/10.1016/S1363-4127(04)00014-7 UR - https://www.sciencedirect.com/science/article/pii/S1363412704000147 AB - Privacy-Enhancing Technologies (PET) are the technical answer to social and legal privacy requirements. PET become constituents for tools to manage users' personal data. Users can thereby control their individual digital identity, i.e. their individual partial identities in an online world. Existing commercially available identity management systems (IMS) do not yet provide privacy-enhancing functionality. We discuss general concepts and mechanisms for privacy-enhancing IMS (PE-IMS) in detail and highlight where existing IMS need to be improved in order to deliver them. Derived from general concepts and incorporating existing mechanisms, we define a component-based architecture for PE-IMS. This architecture describes the basic building blocks a PE-IMS must include, and so it is meant to be used as a fundamental concept for PE-IMS in practice. Finally, we give an outlook on the future development concerning IMS. Identity, Privacy, Identity Management System, Privacy-Enhancing Technologies, PET, Privacy-Enhancing Identity Management System, Multilateral Security ER - TY - JOUR T1 - Towards augmented proactive cyberthreat intelligence AU - Khan, Tanveer AU - Alam, Masoom AU - Akhunzada, Adnan AU - Hur, Ali AU - Asif, Muhammad AU - Khan, Muhammad Khurram JO - Journal of Parallel and Distributed Computing VL - 124 SP - 47 EP - 59 PY - 2019 DA - 2019/02/01/ SN - 0743-7315 DO - https://doi.org/10.1016/j.jpdc.2018.10.006 UR - https://www.sciencedirect.com/science/article/pii/S0743731518307408 KW - T-Eye platform KW - T-Eye feeds KW - Rules KW - IBM Q-Radar KW - Confidence KW - Severity KW - Risk score AB - In cyber crimes, attackers are becoming more inventive with their exploits and use more sophisticated techniques to bypass the deployed security system. These attacks are targeted and are commonly referred as Advanced Persistent Threats (APTs). The currently available techniques to tackle these attacks are mostly reactive and signature based. Security Information and Event Management (SIEM), a proactive approach is the best solution. However, the major problem with SIEM is tackling huge amount of data in real time that makes it a time consuming and tedious task for security analyst. The use of threat intelligence caters to such issue by prioritizing the level of threat. In this paper, we assign risk score and confidence value to each feed generated at our product “T-Eye platform”. On the basis of these values, we assign a severity score to each feed type. Severity score assigns a level to the threat means prioritize the threat. The results, we achieved for prioritizing the threat is more apparent and accurate. In addition, we optimize the rules of IBM-Q-Radar by using threat feeds generated at T-Eye platform. Furthermore, a huge amount of false positive alarms generated at IBM Q-Radar is reduced to a certain extent. ER - TY - JOUR T1 - Insider Threat Risk Prediction based on Bayesian Network AU - Elmrabit, Nebrase AU - Yang, Shuang-Hua AU - Yang, Lili AU - Zhou, Huiyu JO - Computers & Security VL - 96 SP - 101908 PY - 2020 DA - 2020/09/01/ SN - 0167-4048 DO - https://doi.org/10.1016/j.cose.2020.101908 UR - https://www.sciencedirect.com/science/article/pii/S016740482030184X KW - Bayesian network model KW - Insider threats KW - Predictions KW - User abuse AB - Insider threat protection has received increasing attention in the last ten years due to the serious consequences of malicious insider threats. Moreover, data leaks and the sale of mass data have become much simpler to achieve, e.g., the dark web can allow malicious insiders to divulge confidential data whilst hiding their identities. In this paper, we propose a novel approach to predict the risk of malicious insider threats prior to a breach taking place. Firstly, we propose a new framework for insider threat risk prediction, drawing on technical, organisational and human factor perspectives. Secondly, we employ a Bayesian network to model and implement the proposed framework. Furthermore, this Bayesian network-based prediction model is evaluated in a range of challenging environments. The risk level predictions for each authorised users within the organisation are examined so that any insider threat risk can be identified. The proposed insider threat prediction model achieved better results when compared to the empirical judgments of security experts ER - TY - JOUR T1 - A Blockchain-Based Notarization Service for Biomedical Knowledge Retrieval AU - Kleinaki, Athina-Styliani AU - Mytis-Gkometh, Petros AU - Drosatos, George AU - Efraimidis, Pavlos S. AU - Kaldoudi, Eleni JO - Computational and Structural Biotechnology Journal VL - 16 SP - 288 EP - 297 PY - 2018 DA - 2018/01/01/ SN - 2001-0370 DO - https://doi.org/10.1016/j.csbj.2018.08.002 UR - https://www.sciencedirect.com/science/article/pii/S2001037018300400 KW - Biomedical repositories KW - Cryptographic techniques KW - Blockchain KW - Integrity KW - Non-repudiation KW - Versioning AB - Biomedical research and clinical decision depend increasingly on scientific evidence realized by a number of authoritative databases, mostly public and continually enriched via peer scientific contributions. Given the dynamic nature of biomedical evidence data and their usage in the sensitive domain of biomedical science, it is important to ensure retrieved data integrity and non-repudiation. In this work, we present a blockchain-based notarization service that uses smart digital contracts to seal a biomedical database query and the respective results. The goal is to ensure that retrieved data cannot be modified after retrieval and that the database cannot validly deny that the particular data has been provided as a result of a specific query. Biomedical evidence data versioning is also supported. The feasibility of the proposed notarization approach is demonstrated using a real blockchain infrastructure and is tested on two different biomedical evidence databases: a publicly available medical risk factor reference repository and on the PubMed database of biomedical literature references and abstracts. ER - TY - JOUR T1 - Security of smart manufacturing systems AU - Tuptuk, Nilufer AU - Hailes, Stephen JO - Journal of Manufacturing Systems VL - 47 SP - 93 EP - 106 PY - 2018 DA - 2018/04/01/ SN - 0278-6125 DO - https://doi.org/10.1016/j.jmsy.2018.04.007 UR - https://www.sciencedirect.com/science/article/pii/S0278612518300463 KW - Smart manufacturing KW - Sustainable manufacturing KW - Design for manufacturing KW - Internet of Things KW - Information security KW - Cyber-physical systems AB - A revolution in manufacturing systems is underway: substantial recent investment has been directed towards the development of smart manufacturing systems that are able to respond in real time to changes in customer demands, as well as the conditions in the supply chain and in the factory itself. Smart manufacturing is a key component of the broader thrust towards Industry 4.0, and relies on the creation of a bridge between digital and physical environments through Internet of Things (IoT) technologies, coupled with enhancements to those digital environments through greater use of cloud systems, data analytics and machine learning. Whilst these individual technologies have been in development for some time, their integration with industrial systems leads to new challenges as well as potential benefits. In this paper, we explore the challenges faced by those wishing to secure smart manufacturing systems. Lessons from history suggest that where an attempt has been made to retrofit security on systems for which the primary driver was the development of functionality, there are inevitable and costly breaches. Indeed, today's manufacturing systems have started to experience this over the past few years; however, the integration of complex smart manufacturing technologies massively increases the scope for attack from adversaries aiming at industrial espionage and sabotage. The potential outcome of these attacks ranges from economic damage and lost production, through injury and loss of life, to catastrophic nation-wide effects. In this paper, we discuss the security of existing industrial and manufacturing systems, existing vulnerabilities, potential future cyber-attacks, the weaknesses of existing measures, the levels of awareness and preparedness for future security challenges, and why security must play a key role underpinning the development of future smart manufacturing systems. ER - TY - CHAP T1 - 2 - An Overview on Social Networking: Design, Issues, Emerging Trends, and Security AU - Rath, Mamata AU - Pati, Bibudhendu AU - Pattanayak, Binod Kumar A2 - Dey, Nilanjan A2 - Borah, Samarjeet A2 - Babo, Rosalina A2 - Ashour, Amira S. BT - Social Network Analytics PB - Academic Press SP - 21 EP - 47 PY - 2019 DA - 2019/01/01/ SN - 978-0-12-815458-8 DO - https://doi.org/10.1016/B978-0-12-815458-8.00002-5 UR - https://www.sciencedirect.com/science/article/pii/B9780128154588000025 KW - Social network KW - Communication KW - Social groups KW - Crowd sourcing AB - A social network is a description of the social structure between actors, mostly individuals or organizations. It indicates the ways in which they are connected through various social familiarities ranging from casual acquaintance to close familiar bonds. With rapid increase of Internet users, more people have access to global information and communication technology, as a result of which the issues of using Internet as a global platform and enabling the smart objects and machines to coordinate, communicate, compute, and calculate gradually emerge. This chapter presents an overview of the social network design, various issues, and emerging trends that are evolved simultaneously with modern age. This chapter also exhibits an exhaustive review of various security and protection issues in social networks that directly or indirectly affect the individual member of the network. Furthermore, different threats in social networks have been focused that appear because of the sharing of interactive media content inside a social networking site. In addition, the chapter also reports on the current cutting edge guard arrangements that can shield social network clients from these dangers. ER - TY - JOUR T1 - Discovery of functional module alignment AU - Xie, Jiang AU - Xiang, Chaojuan AU - Xu, Junfu AU - Zhang, Wu AU - Wang, Jiao JO - Neurocomputing VL - 206 SP - 19 EP - 27 PY - 2016 DA - 2016/09/19/ T2 - SI:DMSB SN - 0925-2312 DO - https://doi.org/10.1016/j.neucom.2016.04.055 UR - https://www.sciencedirect.com/science/article/pii/S0925231216304362 KW - Functional module alignment KW - Visualization KW - Protein interaction networks alignment AB - The alignment of protein interaction networks (PINs) could help reveal similar subnetworks that may play important roles in biology. However, it is challenging to visualize the network alignment, especially for those large-scale PINs. In this work, we present a tool, namely FMA-finder, which can visualize large-scale network alignments between different species. Moreover, instead of focusing on the protein pairs to detect functional homologies, functional module alignment (FMA) is proposed in this study. FMAs are biologically meaningful because they are pairs of subnetworks sharing similar functions. The FMA-finder tool provides both analysis and visualization of FMAs. Experiments on the alignment between Homo sapiens and Saccharomyces cerevisiae protein interaction networks demonstrate that our FMA-finder can visualize and analyze large-scale network alignments. ER - TY - JOUR T1 - A cyber kill chain based taxonomy of banking Trojans for evolutionary computational intelligence AU - Kiwia, Dennis AU - Dehghantanha, Ali AU - Choo, Kim-Kwang Raymond AU - Slaughter, Jim JO - Journal of Computational Science VL - 27 SP - 394 EP - 409 PY - 2018 DA - 2018/07/01/ SN - 1877-7503 DO - https://doi.org/10.1016/j.jocs.2017.10.020 UR - https://www.sciencedirect.com/science/article/pii/S1877750317304957 KW - Cyber kill chain KW - Banking Trojans KW - Banking Trojans taxonomy KW - Evolutionary computational intelligence-based Trojan detection AB - Malware such as banking Trojans are popular with financially-motivated cybercriminals. Detection of banking Trojans remains a challenging task, due to the constant evolution of techniques used to obfuscate and circumvent existing detection and security solutions. Having a malware taxonomy can facilitate the design of mitigation strategies such as those based on evolutionary computational intelligence. Specifically, in this paper, we propose a cyber kill chain based taxonomy of banking Trojans features. This threat intelligence based taxonomy provides a stage-by-stage operational understanding of a cyber-attack, and can be highly beneficial to security practitioners and inform the design of evolutionary computational intelligence on Trojans detection and mitigation strategy. The proposed taxonomy is built upon our analysis of a real-world dataset of 127 banking Trojans collected from December 2014 to January 2016 by a major UK-based financial organization. ER - TY - JOUR T1 - On cloud security attacks: A taxonomy and intrusion detection and prevention as a service AU - Iqbal, Salman AU - Mat Kiah, Miss Laiha AU - Dhaghighi, Babak AU - Hussain, Muzammil AU - Khan, Suleman AU - Khan, Muhammad Khurram AU - Raymond Choo, Kim-Kwang JO - Journal of Network and Computer Applications VL - 74 SP - 98 EP - 120 PY - 2016 DA - 2016/10/01/ SN - 1084-8045 DO - https://doi.org/10.1016/j.jnca.2016.08.016 UR - https://www.sciencedirect.com/science/article/pii/S1084804516301771 KW - Cloud computing KW - Taxonomy KW - Security attacks KW - Intrusion detection AB - Major provisioning of cloud computing is mainly delivered via Software as a Service, Platform as a Service and Infrastructure as a Service. However, these service delivery models are vulnerable to a range of security attacks, exploiting both cloud specific and existing web service vulnerabilities. Taxonomies are a useful tool for system designers as they provide a systematic way of understanding, identifying and addressing security risks. In this research work, Cloud based attacks and vulnerabilities are collected and classify with respect to their cloud models. We also present taxonomy of cloud security attacks and potential mitigation strategies with the aim of providing an in-depth understanding of security requirements in the cloud environment. We also highlight the importance of intrusion detection and prevention as a service. ER - TY - JOUR T1 - A survey on cybersecurity, data privacy, and policy issues in cyber-physical system deployments in smart cities AU - Habibzadeh, Hadi AU - Nussbaum, Brian H. AU - Anjomshoa, Fazel AU - Kantarci, Burak AU - Soyata, Tolga JO - Sustainable Cities and Society VL - 50 SP - 101660 PY - 2019 DA - 2019/10/01/ SN - 2210-6707 DO - https://doi.org/10.1016/j.scs.2019.101660 UR - https://www.sciencedirect.com/science/article/pii/S2210670718316883 KW - Smart cities KW - Cyber security KW - Government policy making KW - Cryptography KW - Security and privacy KW - Authentication AB - Deployments of Cyber Physical Systems (CPSs) in smart cities are poised to significantly improve healthcare, transportation services, utilities, safety, and environmental health. However, these efficiencies and service improvements will come at a price: increased vulnerability and risk. Smart city deployments have already begun to proliferate, as have the upsides, efficiencies, and cost-savings they can facilitate. There are, however, proliferating challenges and costs as well. These challenges include important technical questions, but equally important policy and organizational questions. It is important to understand that these policy and technical implementation hurdles are perhaps equally likely to slow or disable smart city implementation efforts. In this paper, a survey of the theoretical and practical challenges and opportunities are enumerated not only in terms of their technical aspects, but also in terms of policy and governance issues of concern. ER - TY - JOUR T1 - Biometrics and forensics integration using deep multi-modal semantic alignment and joint embedding AU - Toor, Andeep S. AU - Wechsler, Harry JO - Pattern Recognition Letters VL - 113 SP - 29 EP - 37 PY - 2018 DA - 2018/10/01/ T2 - Integrating Biometrics and Forensics SN - 0167-8655 DO - https://doi.org/10.1016/j.patrec.2017.02.012 UR - https://www.sciencedirect.com/science/article/pii/S0167865517300430 KW - Biometrics KW - Deep learning (DL) KW - Forensics KW - Joint embedding KW - meta-reasoning KW - Semantic alignment KW - Visual question answering (VQA) KW - Visual Turing Test (VTT) KW - Convolutional Neural Network (CNN) AB - This paper proposes collaborative and context-aware visual question answering (C2VQA) for multi-modal information channels integration, and details its particular mapping and realization for biometrics forensic integration (BFI) using Show and Tell like architectures. C2VQA, which expands on Visual Query Answering (VQA) and the Visual Turing Test (VTT), engages deep semantic alignment and joint embedding using deep learning (DL) for image analysis, vector space as skip-grams and long-term dependencies as gated recurrent networks for context prediction, and multi-strategy learning including conformal prediction for control and meta-reasoning. C2VQA would engage in purposeful dialog to address and correct for misinformation and uncertainty and considers behavior to model realistic VQA problems characteristic of open rather than closed set VQA. ER - TY - JOUR T1 - Internet court's challenges and future in China AU - Guo, Meirong JO - Computer Law & Security Review VL - 40 SP - 105522 PY - 2021 DA - 2021/04/01/ SN - 0267-3649 DO - https://doi.org/10.1016/j.clsr.2020.105522 UR - https://www.sciencedirect.com/science/article/pii/S0267364920301278 KW - Internet court KW - Adjudication model KW - Civil jurisdiction KW - Internet technology AB - China established the world's first Internet court in Hangzhou in August 2017. Subsequently in 2018 Internet courts in Beijing and Guangzhou were established respectively. With the official establishment of these three Internet courts, China's electronic litigation advanced to a new stage.. Internet courts offer many advantages, and this innovative adjudication model has earned widespread approval for both its speedy acceptance of cases and speedy hearing of cases. This article analyzes the questions and challenges faced by Internet courts, proposes solutions such as compliance with three basic legal ethical principles, re-establishing the sense of presence and ritual of litigation, establishment of risk mitigation mechanisms between the legal system and technological systems to develop the ability for the construction of Internet courts in China. ER - TY - JOUR T1 - Contents JO - Procedia Computer Science VL - 22 SP - iii EP - viii PY - 2013 DA - 2013/01/01/ T2 - 17th International Conference in Knowledge Based and Intelligent Information and Engineering Systems - KES2013 SN - 1877-0509 DO - https://doi.org/10.1016/S1877-0509(13)01124-1 UR - https://www.sciencedirect.com/science/article/pii/S1877050913011241 ER - TY - JOUR T1 - Social network security: Issues, challenges, threats, and solutions AU - Rathore, Shailendra AU - Sharma, Pradip Kumar AU - Loia, Vincenzo AU - Jeong, Young-Sik AU - Park, Jong Hyuk JO - Information Sciences VL - 421 SP - 43 EP - 69 PY - 2017 DA - 2017/12/01/ SN - 0020-0255 DO - https://doi.org/10.1016/j.ins.2017.08.063 UR - https://www.sciencedirect.com/science/article/pii/S0020025517309106 KW - Social network service KW - Security and privacy KW - Multimedia data KW - Security threats AB - Social networks are very popular in today's world. Millions of people use various forms of social networks as they allow individuals to connect with friends and family, and share private information. However, issues related to maintaining the privacy and security of a user's information can occur, especially when the user's uploaded content is multimedia, such as photos, videos, and audios. Uploaded multimedia content carries information that can be transmitted virally and almost instantaneously within a social networking site and beyond. In this paper, we present a comprehensive survey of different security and privacy threats that target every user of social networking sites. In addition, we separately focus on various threats that arise due to the sharing of multimedia content within a social networking site. We also discuss current state-of- the-art defense solutions that can protect social network users from these threats. We then present future direction and discuss some easy-to-apply response techniques to achieve the goal of a trustworthy and secure social network ecosystem. ER - TY - JOUR T1 - Multimedia big data computing and Internet of Things applications: A taxonomy and process model AU - Kumari, Aparna AU - Tanwar, Sudeep AU - Tyagi, Sudhanshu AU - Kumar, Neeraj AU - Maasberg, Michele AU - Choo, Kim-Kwang Raymond JO - Journal of Network and Computer Applications VL - 124 SP - 169 EP - 195 PY - 2018 DA - 2018/12/15/ SN - 1084-8045 DO - https://doi.org/10.1016/j.jnca.2018.09.014 UR - https://www.sciencedirect.com/science/article/pii/S1084804518303011 KW - Multimedia big data KW - Data acquisition KW - Data representation KW - Data reduction KW - Data analysis KW - Data security and privacy KW - System intelligence KW - Distributed system KW - Social media AB - With an exponential increase in the provisioning of multimedia devices over the Internet of Things (IoT), a significant amount of multimedia data (also referred to as multimedia big data – MMBD) is being generated. Current research and development activities focus on scalar sensor data based IoT or general MMBD and overlook the complexity of facilitating MMBD over IoT. This paper examines the unique nature and complexity of MMBD computing for IoT applications and develops a comprehensive taxonomy for MMBD abstracted into a novel process model reflecting MMBD over IoT. This process model addresses a number of research challenges associated with MMBD, such as scalability, accessibility, reliability, heterogeneity, and Quality of Service (QoS) requirements. A case study is presented to demonstrate the process model. ER - TY - JOUR T1 - Extended U+F Social Network Protocol: Interoperability, reusability, data protection and indirect relationships in Web Based Social Networks AU - González-Manzano, Lorena AU - González-Tablas, Ana I. AU - de Fuentes, José M. AU - Ribagorda, Arturo JO - Journal of Systems and Software VL - 94 SP - 50 EP - 71 PY - 2014 DA - 2014/08/01/ SN - 0164-1212 DO - https://doi.org/10.1016/j.jss.2014.04.044 UR - https://www.sciencedirect.com/science/article/pii/S0164121214001083 KW - Data disclosures KW - Interoperability KW - Web Based Social Networks AB - An interconnected world is what current technologies look for, being Web Based Social Networks (WBSNs) a promising development in this regard. Four desirable WBSN features are identified, namely, interoperability, reusability, protection against WBSNs providers and indirect relationships. A protocol, called U+F, addressed interoperability and reusability of identity data, resources and access control policies between different WBSNs. In order to address the remaining couple of features, that is, achieving the protection of data against WBSNs providers and indirect relationships management across different WBSNs, this paper presents eU+F, an extension of U+F. A prototype is developed to verify the feasibility of implementing the proposed protocol in a real environment, as well as to compare its workload regarding three well-known WBSNs, Facebook, MySpace and LinkedIn. ER - TY - JOUR T1 - A domain-specific language for context modeling in context-aware systems AU - Hoyos, José R. AU - García-Molina, Jesús AU - Botía, Juan A. JO - Journal of Systems and Software VL - 86 IS - 11 SP - 2890 EP - 2905 PY - 2013 DA - 2013/11/01/ SN - 0164-1212 DO - https://doi.org/10.1016/j.jss.2013.07.008 UR - https://www.sciencedirect.com/science/article/pii/S0164121213001696 KW - Model Driven Development KW - Context modeling KW - Context aware AB - Context-awareness refers to systems that can both sense and react based on their environment. One of the main difficulties that developers of context-aware systems must tackle is how to manage the needed context information. In this paper we present MLContext, a textual Domain-Specific Language (DSL) which is specially tailored for modeling context information. It has been implemented by applying Model-Driven Development (MDD) techniques to automatically generate software artifacts from context models. The MLContext abstract syntax has been defined as a metamodel, and model-to text transformations have been written to generate the desired software artifacts. The concrete syntax has been defined with the EMFText tool, which generates an editor and model injector. MLContext has been designed to provide a high-level abstraction, to be easy to learn, and to promote reuse of context models. A domain analysis has been applied to elicit the requirements and design choices to be taken into account in creating the DSL. As a proof of concept of the proposal, the generative approach has been applied to two different middleware platforms for context management. ER - TY - CHAP T1 - Chapter 3 - CATRA: Conceptual cloud attack taxonomy and risk assessment framework AU - Juliadotter, Nina Viktoria AU - Choo, Kim-Kwang Raymond A2 - Ko, Ryan A2 - Choo, Kim-Kwang Raymond BT - The Cloud Security Ecosystem PB - Syngress CY - Boston SP - 37 EP - 81 PY - 2015 DA - 2015/01/01/ SN - 978-0-12-801595-7 DO - https://doi.org/10.1016/B978-0-12-801595-7.00003-3 UR - https://www.sciencedirect.com/science/article/pii/B9780128015957000033 KW - Cloud attack taxonomy and risk assessment framework KW - Cloud risk mitigation strategies KW - Cloud security and attack taxonomies KW - Cloud taxonomy characteristics KW - Cloud threat actors and vectors AB - As our dependence on cloud services increase, so does the risks associated with attacks on these services. To improve our defense against such attacks, we need to better understand their characteristics. A taxonomy is useful in this regard because it classifies and categorizes the different aspects of cloud attacks and appropriate countermeasures. Using on this classification, we can then assess and manage the risks. Based on a literature review of existing attack taxonomies published between January 2003 and April 2014 and attacks against cloud services, this chapter proposes a conceptual taxonomy of cloud attacks and risk mitigation strategies. To demonstrate how this taxonomy can be used in risk assessment, an example attack scenario is presented. ER -