Towards the development of an integrated incident response model for database forensic investigation field

For every contact that is made in a database, a digital trace will potentially be left and most of the database breaches are mostly aimed at defeating the major security goals (Confidentiality, Integrity, and Authenticity) of data that reside in the database. In order to prove/refute a fact during l...

Full description

Saved in:
Bibliographic Details
Main Authors: Al-Dhaqm, Arafat, Abd. Razak, Shukor, Siddique, Kamran, Ikuesan, Richard Adeyemi, Kebande, Victor R.
Format: Article
Language:English
Published: Institute of Electrical and Electronics Engineers Inc. 2020
Subjects:
Online Access:http://eprints.utm.my/id/eprint/91030/1/ArafatAlDhaqm2020_TowardstheDevelopmentofanIntegratedIncident.pdf
http://eprints.utm.my/id/eprint/91030/
http://dx.doi.org/10.1109/ACCESS.2020.3008696
Tags: Add Tag
No Tags, Be the first to tag this record!
Description
Summary:For every contact that is made in a database, a digital trace will potentially be left and most of the database breaches are mostly aimed at defeating the major security goals (Confidentiality, Integrity, and Authenticity) of data that reside in the database. In order to prove/refute a fact during litigation, it is important to identify suitable investigation techniques that can be used to link a potential incident/suspect to the digital crime. As a result, this paper has proposed suitable steps of constructing and Integrated Incident Response Model (IIRM) that can be relied upon in the database forensic investigation field. While developing the IIRM, design science methodology has been adapted and the outcome of this study has shown significant and promising approaches that could be leveraged by digital forensic experts, legal practitioners and law enforcement agencies. This is owing to the fact, that IIRM construction has followed incident investigation principles that are stipulated in ISO guidelines.