ORCID
- Clarke, Nathan: 0000-0002-3595-3800
- Ghita, Bogdan: 0000-0002-1788-547X
Abstract
Digital forensics is now essential in addressing cybercrime and cyber-enabled crime but potentially it can have a role in almost every other type of crime. Given technology's continuous development and prevalence, the widespread adoption of technologies among society and the subsequent digital footprints that exist, the analysis of these technologies can help support investigations. The abundance of interconnected technologies and telecommunication platforms has significantly changed the nature of digital evidence. Subsequently, the nature and characteristics of digital forensic cases involve an enormous volume of data heterogeneity, scattered across multiple evidence sources, technologies, applications, and services. It is indisputable that the outspread and connections between existing technologies have raised the need to integrate, harmonise, unify and correlate evidence across data sources in an automated fashion. Unfortunately, the current state of the art in digital forensics leads to siloed approaches focussed upon specific technologies or support of a particular part of digital investigation. Due to this shortcoming, the digital investigator examines each data source independently, trawls through interconnected data across various sources, and often has to conduct data correlation manually, thus restricting the digital investigator’s ability to answer high-level questions in a timely manner with a low cognitive load. Therefore, this research paper investigates the limitations of the current state of the art in the digital forensics discipline and categorises common investigation crimes with the necessary corresponding digital analyses to define the characteristics of the next-generation approach. Based on these observations, it discusses the future capabilities of the next-generation unified forensics analysis tool (U-FAT), with a workflow example that illustrates data unification, correlation and visualisation processes within the proposed method.
DOI
10.34190/iccws.18.1.972
Publication Date
2023-02-28
Publication Title
International Conference on Cyber Warfare and Security
Volume
18
Issue
1
ISSN
2048-9870
Embargo Period
2023-03-21
Organisational Unit
School of Engineering, Computing and Mathematics
First Page
466
Last Page
475
Recommended Citation
Alshumrani, A., Clarke, N., & Ghita, B. (2023) 'A Unified Forensics Analysis Approach to Digital Investigation', International Conference on Cyber Warfare and Security, 18(1), pp. 466-475. Available at: https://doi.org/10.34190/iccws.18.1.972