A unified forensic model applicable to the database forensics field
The Database Forensics Investigation (DBFI) field is focused on capturing and investigating database incidents. DBFI is a subdomain of the digital forensics domain, which deals with database files and dictionaries to identify, acquire, preserve, examine, analyze, reconstruct, present, and document d...
Saved in:
Main Authors: | , , , , , |
---|---|
Format: | Article |
Language: | English |
Published: |
MDPI
2022
|
Subjects: | |
Online Access: | http://eprints.utm.my/103554/1/ArafatMohammedRashad2022_AUnifiedForensicModelApplicabletotheDatabase.pdf http://eprints.utm.my/103554/ http://dx.doi.org/10.3390/electronics11091347 |
Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Institution: | Universiti Teknologi Malaysia |
Language: | English |
id |
my.utm.103554 |
---|---|
record_format |
eprints |
spelling |
my.utm.1035542023-11-19T07:41:26Z http://eprints.utm.my/103554/ A unified forensic model applicable to the database forensics field Alhussan, Amel Ali Al-Dhaqm, Arafat Yafooz, Wael M. S. M. Emara, Abdel-Hamid Abd. Razak, Shukor Khafaga, Doaa Sami QA75 Electronic computers. Computer science The Database Forensics Investigation (DBFI) field is focused on capturing and investigating database incidents. DBFI is a subdomain of the digital forensics domain, which deals with database files and dictionaries to identify, acquire, preserve, examine, analyze, reconstruct, present, and document database incidents. Several frameworks and models have been offered for the DBFI field in the literature. However, these specific models and frameworks have redundant investigation processes and activities. Therefore, this study has two aims: (i) conducting a compressive survey to discover the challenges and issues of the DBFI field and (ii) developing a Unified forensic model for the database forensics field. To this end, the design science research (DSR) method was used in this study. The results showed that the DBFI field suffers from many issues such as the lack of standardization, multidimensional nature, heterogeneity, and ambiguity, making it complex for those working in this domain. In addition, a model was proposed in this paper, called the Unified Forensic Model (UFM), which consists of five main stages: initialization stage, acquiring stage, investigation stage, restoring and recovering stage, and evaluation stage. Each stage has several processes and activities. The applicability of UFM was evaluated from two perspectives: completeness and implementation perspectives. UFM is a novel model covering all existing DBFI models and comprises two new stages: the recovering and restoring stage and the evaluation stage. The proposed UFM is so flexible that any forensic investigator could employ it easily when investigating database incidents. MDPI 2022 Article PeerReviewed application/pdf en http://eprints.utm.my/103554/1/ArafatMohammedRashad2022_AUnifiedForensicModelApplicabletotheDatabase.pdf Alhussan, Amel Ali and Al-Dhaqm, Arafat and Yafooz, Wael M. S. and M. Emara, Abdel-Hamid and Abd. Razak, Shukor and Khafaga, Doaa Sami (2022) A unified forensic model applicable to the database forensics field. Electronics (Switzerland), 11 (9). pp. 1-21. ISSN 2079-9292 http://dx.doi.org/10.3390/electronics11091347 DOI : 10.3390/electronics11091347 |
institution |
Universiti Teknologi Malaysia |
building |
UTM Library |
collection |
Institutional Repository |
continent |
Asia |
country |
Malaysia |
content_provider |
Universiti Teknologi Malaysia |
content_source |
UTM Institutional Repository |
url_provider |
http://eprints.utm.my/ |
language |
English |
topic |
QA75 Electronic computers. Computer science |
spellingShingle |
QA75 Electronic computers. Computer science Alhussan, Amel Ali Al-Dhaqm, Arafat Yafooz, Wael M. S. M. Emara, Abdel-Hamid Abd. Razak, Shukor Khafaga, Doaa Sami A unified forensic model applicable to the database forensics field |
description |
The Database Forensics Investigation (DBFI) field is focused on capturing and investigating database incidents. DBFI is a subdomain of the digital forensics domain, which deals with database files and dictionaries to identify, acquire, preserve, examine, analyze, reconstruct, present, and document database incidents. Several frameworks and models have been offered for the DBFI field in the literature. However, these specific models and frameworks have redundant investigation processes and activities. Therefore, this study has two aims: (i) conducting a compressive survey to discover the challenges and issues of the DBFI field and (ii) developing a Unified forensic model for the database forensics field. To this end, the design science research (DSR) method was used in this study. The results showed that the DBFI field suffers from many issues such as the lack of standardization, multidimensional nature, heterogeneity, and ambiguity, making it complex for those working in this domain. In addition, a model was proposed in this paper, called the Unified Forensic Model (UFM), which consists of five main stages: initialization stage, acquiring stage, investigation stage, restoring and recovering stage, and evaluation stage. Each stage has several processes and activities. The applicability of UFM was evaluated from two perspectives: completeness and implementation perspectives. UFM is a novel model covering all existing DBFI models and comprises two new stages: the recovering and restoring stage and the evaluation stage. The proposed UFM is so flexible that any forensic investigator could employ it easily when investigating database incidents. |
format |
Article |
author |
Alhussan, Amel Ali Al-Dhaqm, Arafat Yafooz, Wael M. S. M. Emara, Abdel-Hamid Abd. Razak, Shukor Khafaga, Doaa Sami |
author_facet |
Alhussan, Amel Ali Al-Dhaqm, Arafat Yafooz, Wael M. S. M. Emara, Abdel-Hamid Abd. Razak, Shukor Khafaga, Doaa Sami |
author_sort |
Alhussan, Amel Ali |
title |
A unified forensic model applicable to the database forensics field |
title_short |
A unified forensic model applicable to the database forensics field |
title_full |
A unified forensic model applicable to the database forensics field |
title_fullStr |
A unified forensic model applicable to the database forensics field |
title_full_unstemmed |
A unified forensic model applicable to the database forensics field |
title_sort |
unified forensic model applicable to the database forensics field |
publisher |
MDPI |
publishDate |
2022 |
url |
http://eprints.utm.my/103554/1/ArafatMohammedRashad2022_AUnifiedForensicModelApplicabletotheDatabase.pdf http://eprints.utm.my/103554/ http://dx.doi.org/10.3390/electronics11091347 |
_version_ |
1783876381347676160 |