Simplified database forensic investigation using metamodeling approach
Database Forensic Investigation (DBFI) domain is a significant field used to identify, collect, preserve, reconstruct, analyze and document database incidents. However, it is a heterogeneous, complex, and ambiguous domain due to the variety and multidimensional nature of database systems. Numerous s...
Saved in:
Main Author: | |
---|---|
Format: | Thesis |
Language: | English |
Published: |
2019
|
Subjects: | |
Online Access: | http://eprints.utm.my/id/eprint/98147/1/ArafatMohammedRashadPSC2019.pdf http://eprints.utm.my/id/eprint/98147/ http://dms.library.utm.my:8080/vital/access/manager/Repository/vital:144038 |
Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Institution: | Universiti Teknologi Malaysia |
Language: | English |
id |
my.utm.98147 |
---|---|
record_format |
eprints |
spelling |
my.utm.981472022-11-14T10:22:57Z http://eprints.utm.my/id/eprint/98147/ Simplified database forensic investigation using metamodeling approach Al-Dhaqm, Arafat Mohammed Rashad QA75 Electronic computers. Computer science Database Forensic Investigation (DBFI) domain is a significant field used to identify, collect, preserve, reconstruct, analyze and document database incidents. However, it is a heterogeneous, complex, and ambiguous domain due to the variety and multidimensional nature of database systems. Numerous specific DBFI models and frameworks have been proposed to solve specific database scenarios but there is a lack of structured and unified frameworks to facilitate managing, sharing and reusing of DBFI tasks and activities. Thus, this research developed a DBFI Metamodel (DBFIM) to structure and organize DBFI domain. A Design Science Research Methodology (DSRM) to provide a logical, testable and communicable metamodel was applied in this study. In this methodology, the steps included problem identification, define objectives, design and development, demonstration and evaluation, and communication. The outcome of this study is a DBFIM developed for structuring and organizing DBFI domain knowledge that facilitates the managing, sharing and reusing of DBFI domain knowledge among domain practitioners. DBFIM identifies, recognizes, extracts and matches different DBFI processes, concepts, activities, and tasks from different DBFI models into a developed metamodel, thus, allowing domain practitioners to derive/instantiate solution models easily. The DBFIM was validated using qualitative techniques: comparison against other models; face validity (domain experts); and case study. Comparisons against other models and face validity were applied to ensure completeness, logicalness, and usefulness of DBFIM against other DBFI domain models. Following this, two case studies were selected and implemented to demonstrate the applicability and effectiveness of the DBFIM in the DBFI domain using a DBFIM Prototype (DBFIMP). The results showed that DBFIMP allowed domain practitioners to create their solution models easily based on their requirements. 2019 Thesis NonPeerReviewed application/pdf en http://eprints.utm.my/id/eprint/98147/1/ArafatMohammedRashadPSC2019.pdf Al-Dhaqm, Arafat Mohammed Rashad (2019) Simplified database forensic investigation using metamodeling approach. PhD thesis, Universiti Teknologi Malaysia, Faculty of Engineering - School of Computing. http://dms.library.utm.my:8080/vital/access/manager/Repository/vital:144038 |
institution |
Universiti Teknologi Malaysia |
building |
UTM Library |
collection |
Institutional Repository |
continent |
Asia |
country |
Malaysia |
content_provider |
Universiti Teknologi Malaysia |
content_source |
UTM Institutional Repository |
url_provider |
http://eprints.utm.my/ |
language |
English |
topic |
QA75 Electronic computers. Computer science |
spellingShingle |
QA75 Electronic computers. Computer science Al-Dhaqm, Arafat Mohammed Rashad Simplified database forensic investigation using metamodeling approach |
description |
Database Forensic Investigation (DBFI) domain is a significant field used to identify, collect, preserve, reconstruct, analyze and document database incidents. However, it is a heterogeneous, complex, and ambiguous domain due to the variety and multidimensional nature of database systems. Numerous specific DBFI models and frameworks have been proposed to solve specific database scenarios but there is a lack of structured and unified frameworks to facilitate managing, sharing and reusing of DBFI tasks and activities. Thus, this research developed a DBFI Metamodel (DBFIM) to structure and organize DBFI domain. A Design Science Research Methodology (DSRM) to provide a logical, testable and communicable metamodel was applied in this study. In this methodology, the steps included problem identification, define objectives, design and development, demonstration and evaluation, and communication. The outcome of this study is a DBFIM developed for structuring and organizing DBFI domain knowledge that facilitates the managing, sharing and reusing of DBFI domain knowledge among domain practitioners. DBFIM identifies, recognizes, extracts and matches different DBFI processes, concepts, activities, and tasks from different DBFI models into a developed metamodel, thus, allowing domain practitioners to derive/instantiate solution models easily. The DBFIM was validated using qualitative techniques: comparison against other models; face validity (domain experts); and case study. Comparisons against other models and face validity were applied to ensure completeness, logicalness, and usefulness of DBFIM against other DBFI domain models. Following this, two case studies were selected and implemented to demonstrate the applicability and effectiveness of the DBFIM in the DBFI domain using a DBFIM Prototype (DBFIMP). The results showed that DBFIMP allowed domain practitioners to create their solution models easily based on their requirements. |
format |
Thesis |
author |
Al-Dhaqm, Arafat Mohammed Rashad |
author_facet |
Al-Dhaqm, Arafat Mohammed Rashad |
author_sort |
Al-Dhaqm, Arafat Mohammed Rashad |
title |
Simplified database forensic investigation using metamodeling approach |
title_short |
Simplified database forensic investigation using metamodeling approach |
title_full |
Simplified database forensic investigation using metamodeling approach |
title_fullStr |
Simplified database forensic investigation using metamodeling approach |
title_full_unstemmed |
Simplified database forensic investigation using metamodeling approach |
title_sort |
simplified database forensic investigation using metamodeling approach |
publishDate |
2019 |
url |
http://eprints.utm.my/id/eprint/98147/1/ArafatMohammedRashadPSC2019.pdf http://eprints.utm.my/id/eprint/98147/ http://dms.library.utm.my:8080/vital/access/manager/Repository/vital:144038 |
_version_ |
1751536154227769344 |