A generic database forensic investigation process model

Database Forensic investigation is a domain which deals with database contents and their metadata to reveal malicious activities on database systems. Even though it is still new, but due to the overwhelming challenges and issues in the domain, this makes database forensic become a fast growing and m...

Full description

Saved in:
Bibliographic Details
Main Authors: Al-Dhaqm, Arafat, Abd. Razak, Shukor, Othman, Siti Hajar, Nagdi, Asri, Ali, Abdulalem
Format: Article
Language:English
Published: Penerbit UTM Press 2016
Subjects:
Online Access:http://eprints.utm.my/id/eprint/71404/1/ShukorAbdRazak2016_Agenericdatabaseforensicinvestigation.pdf
http://eprints.utm.my/id/eprint/71404/
https://www.scopus.com/inward/record.uri?eid=2-s2.0-84976415506&doi=10.11113%2fjt.v78.9190&partnerID=40&md5=48c313d2ba31e3077264e9c5c05baf58
Tags: Add Tag
No Tags, Be the first to tag this record!
Institution: Universiti Teknologi Malaysia
Language: English
id my.utm.71404
record_format eprints
spelling my.utm.714042017-11-21T03:28:04Z http://eprints.utm.my/id/eprint/71404/ A generic database forensic investigation process model Al-Dhaqm, Arafat Abd. Razak, Shukor Othman, Siti Hajar Nagdi, Asri Ali, Abdulalem QA75 Electronic computers. Computer science Database Forensic investigation is a domain which deals with database contents and their metadata to reveal malicious activities on database systems. Even though it is still new, but due to the overwhelming challenges and issues in the domain, this makes database forensic become a fast growing and much sought after research area. Based on observations made, we found that database forensic suffers from having a common standard which could unify knowledge of the domain. Therefore, through this paper, we present the use of Design Science Research (DSR) as a research methodology to develop a Generic Database Forensic Investigation Process Model (DBFIPM). From the creation of DBFIPM, five common forensic investigation processes have been proposed namely, the i) identification, ii) collection, iii) preservation, iv) analysis and v) presentation process. From the DBFIPM, it allows the reconciliation of concepts and terminologies of all common databases forensic investigation processes. Thus, this will potentially facilitate the sharing of knowledge on database forensic investigation among domain stakeholders. Penerbit UTM Press 2016 Article PeerReviewed application/pdf en http://eprints.utm.my/id/eprint/71404/1/ShukorAbdRazak2016_Agenericdatabaseforensicinvestigation.pdf Al-Dhaqm, Arafat and Abd. Razak, Shukor and Othman, Siti Hajar and Nagdi, Asri and Ali, Abdulalem (2016) A generic database forensic investigation process model. Jurnal Teknologi, 78 (6-11). pp. 45-57. ISSN 0127=9696 https://www.scopus.com/inward/record.uri?eid=2-s2.0-84976415506&doi=10.11113%2fjt.v78.9190&partnerID=40&md5=48c313d2ba31e3077264e9c5c05baf58
institution Universiti Teknologi Malaysia
building UTM Library
collection Institutional Repository
continent Asia
country Malaysia
content_provider Universiti Teknologi Malaysia
content_source UTM Institutional Repository
url_provider http://eprints.utm.my/
language English
topic QA75 Electronic computers. Computer science
spellingShingle QA75 Electronic computers. Computer science
Al-Dhaqm, Arafat
Abd. Razak, Shukor
Othman, Siti Hajar
Nagdi, Asri
Ali, Abdulalem
A generic database forensic investigation process model
description Database Forensic investigation is a domain which deals with database contents and their metadata to reveal malicious activities on database systems. Even though it is still new, but due to the overwhelming challenges and issues in the domain, this makes database forensic become a fast growing and much sought after research area. Based on observations made, we found that database forensic suffers from having a common standard which could unify knowledge of the domain. Therefore, through this paper, we present the use of Design Science Research (DSR) as a research methodology to develop a Generic Database Forensic Investigation Process Model (DBFIPM). From the creation of DBFIPM, five common forensic investigation processes have been proposed namely, the i) identification, ii) collection, iii) preservation, iv) analysis and v) presentation process. From the DBFIPM, it allows the reconciliation of concepts and terminologies of all common databases forensic investigation processes. Thus, this will potentially facilitate the sharing of knowledge on database forensic investigation among domain stakeholders.
format Article
author Al-Dhaqm, Arafat
Abd. Razak, Shukor
Othman, Siti Hajar
Nagdi, Asri
Ali, Abdulalem
author_facet Al-Dhaqm, Arafat
Abd. Razak, Shukor
Othman, Siti Hajar
Nagdi, Asri
Ali, Abdulalem
author_sort Al-Dhaqm, Arafat
title A generic database forensic investigation process model
title_short A generic database forensic investigation process model
title_full A generic database forensic investigation process model
title_fullStr A generic database forensic investigation process model
title_full_unstemmed A generic database forensic investigation process model
title_sort generic database forensic investigation process model
publisher Penerbit UTM Press
publishDate 2016
url http://eprints.utm.my/id/eprint/71404/1/ShukorAbdRazak2016_Agenericdatabaseforensicinvestigation.pdf
http://eprints.utm.my/id/eprint/71404/
https://www.scopus.com/inward/record.uri?eid=2-s2.0-84976415506&doi=10.11113%2fjt.v78.9190&partnerID=40&md5=48c313d2ba31e3077264e9c5c05baf58
_version_ 1643656186308853760