kth.sePublications KTH
Change search
Link to record
Permanent link

Direct link
Iqbal, Asif
Publications (10 of 22) Show all publications
Iqbal, A., Olegard, J. & Ghimire, R. (2020). Digital Forensic Evidence-The missing link in Threat Modeling. In: 2020 International Conference on Data Analytics for Business and Industry: Way Towards a Sustainable Economy, ICDABI 2020. Paper presented at 2020 International Conference on Data Analytics for Business and Industry: Way Towards a Sustainable Economy, ICDABI 2020, 26 October 2020 through 27 October 2020. Institute of Electrical and Electronics Engineers Inc.
Open this publication in new window or tab >>Digital Forensic Evidence-The missing link in Threat Modeling
2020 (English)In: 2020 International Conference on Data Analytics for Business and Industry: Way Towards a Sustainable Economy, ICDABI 2020, Institute of Electrical and Electronics Engineers Inc. , 2020Conference paper, Published paper (Refereed)
Abstract [en]

Threat modeling is a set of methodologies to analyze the potential threats in a digital system, in order to mitigate them. Digital forensics, on the other hand, is used in order to find the true origin of an event with the help of forensic evidence. Digital forensics is based on Locard's Principle and dictates that even digital crime leaves behind some form of remnants. Both the domains, threat modeling and digital forensics, have separately existed, but have to our knowledge not been used together. In this research we establish the importance of forensic evidence and how it can aid threat modeling by providing more comprehensive threat intelligence. We provide practical examples of how the two fields can be combined, based on attack graphs and Bayesian networks.

Place, publisher, year, edition, pages
Institute of Electrical and Electronics Engineers Inc., 2020
Keywords
Attack Graph, Bayesian Network, DFET Modeling, Digital Forensics, Forensic Evidence, Threat, Threat Model, Bayesian networks, Computer crime, Electronic crime countermeasures, Industrial economics, Digital crime, Digital system, Potential threats, Threat modeling
National Category
Computer Systems
Identifiers
urn:nbn:se:kth:diva-301059 (URN)10.1109/ICDABI51230.2020.9325650 (DOI)2-s2.0-85100489294 (Scopus ID)
Conference
2020 International Conference on Data Analytics for Business and Industry: Way Towards a Sustainable Economy, ICDABI 2020, 26 October 2020 through 27 October 2020
Note

QC 20210928

Available from: 2021-09-28 Created: 2021-09-28 Last updated: 2023-04-05Bibliographically approved
Shalaginov, A., Iqbal, A. & Olegård, J. (2020). IoT Digital Forensics Readiness in the Edge: A Roadmap for Acquiring Digital Evidences from Intelligent Smart Applications. In: Lect. Notes Comput. Sci.: . Paper presented at EDGE 2020: Edge Computing – EDGE 2020 , 18 September 2020 through 20 September 2020 (pp. 1-17). Springer Science and Business Media Deutschland GmbH, 12407
Open this publication in new window or tab >>IoT Digital Forensics Readiness in the Edge: A Roadmap for Acquiring Digital Evidences from Intelligent Smart Applications
2020 (English)In: Lect. Notes Comput. Sci., Springer Science and Business Media Deutschland GmbH , 2020, Vol. 12407, p. 1-17Conference paper, Published paper (Refereed)
Abstract [en]

Entering the era of the Internet of Things, the traditional Computer Forensics is no longer as trivial as decades ago with a rather limited pool of possible computer components. It has been demonstrated recently how the complexity and advancement of IoT are being used by malicious actors attack digital and physical infrastructures and systems. The investigative methodology, therefore, faces multiple challenges related to the fact that billions of interconnected devices generate tiny pieces of data that easily comprehend the Big Data paradigm. As a result, Computer Forensics is no longer a simple methodology of the straightforward process. In this paper, we study the complexity and readiness of community-accepted devices in a smart application towards assistance in criminal investigations. In particular, we present a clear methodology and involved tools related to Smart Applications. Relevant artefacts are discussed and analysed using the prism of the Digital Forensics Process. This research contributes towards increased awareness of the IoT Forensics in the Edge, corresponding challenges and opportunities.

Place, publisher, year, edition, pages
Springer Science and Business Media Deutschland GmbH, 2020
Keywords
Computer forensics, Edge computing, Electronic crime countermeasures, Computer components, Criminal investigation, Digital evidence, Roadmap, Smart applications, Traditional computers, Internet of things
National Category
Communication Systems
Identifiers
urn:nbn:se:kth:diva-285321 (URN)10.1007/978-3-030-59824-2_1 (DOI)2-s2.0-85092075608 (Scopus ID)
Conference
EDGE 2020: Edge Computing – EDGE 2020 , 18 September 2020 through 20 September 2020
Note

QC 20201202

Available from: 2020-12-02 Created: 2020-12-02 Last updated: 2024-01-10Bibliographically approved
Iqbal, A., Olegård, J., Ghimire, R., Jamshir, S. & Shalaginov, A. (2020). Smart Home Forensics: An Exploratory Study on Smart Plug Forensic Analysis. In: Wu, XT Jermaine, C Xiong, L Hu, XH Kotevska, O Lu, SY Xu, WJ Aluru, S Zhai, CX Al-Masri, E Chen, ZY Saltz, J (Ed.), 2020 IEEE International conference on big data (big data): . Paper presented at 8th IEEE International Conference on Big Data (Big Data), DEC 10-13, 2020, ELECTR NETWORK (pp. 2283-2290). Institute of Electrical and Electronics Engineers (IEEE)
Open this publication in new window or tab >>Smart Home Forensics: An Exploratory Study on Smart Plug Forensic Analysis
Show others...
2020 (English)In: 2020 IEEE International conference on big data (big data) / [ed] Wu, XT Jermaine, C Xiong, L Hu, XH Kotevska, O Lu, SY Xu, WJ Aluru, S Zhai, CX Al-Masri, E Chen, ZY Saltz, J, Institute of Electrical and Electronics Engineers (IEEE) , 2020, p. 2283-2290Conference paper, Published paper (Refereed)
Abstract [en]

Connectivity as a whole and the Internet of Things (IoT) has influenced a great many things in the past decade. Among those, the most prominent is our daily life routines, which have increasingly started to depend on technology. A Smart Home, being a central part, has gained more importance from a forensic perspective since it affects many lives and can be an easy target for cybercrimes. In this work in progress paper, we explore the feasibility of conducting forensic analysis on different Smart Plugs and what sort of challenges are encountered in such a forensic investigation. We also review current related work for forensic analysis of Smart Plugs.

Place, publisher, year, edition, pages
Institute of Electrical and Electronics Engineers (IEEE), 2020
Series
IEEE International Conference on Big Data, ISSN 2639-1589
Keywords
Smart Plug, Smart Outlet, Smart Home, Cyber Forensics, Digital Forensics, Forensic analysis, Threat analysis, IoT, Smart Things
National Category
Computer Sciences
Identifiers
urn:nbn:se:kth:diva-299079 (URN)10.1109/BigData50022.2020.9378183 (DOI)000662554702052 ()2-s2.0-85103855439 (Scopus ID)
Conference
8th IEEE International Conference on Big Data (Big Data), DEC 10-13, 2020, ELECTR NETWORK
Note

QC 20210802

Available from: 2021-08-02 Created: 2021-08-02 Last updated: 2023-02-27Bibliographically approved
Shalaginov, A., Kotsiuba, I. & Iqbal, A. (2019). Cybercrime Investigations in the Era of Smart Applications: Way Forward Through Big Data. In: Proceedings - 2019 IEEE International Conference on Big Data, Big Data 2019: . Paper presented at 2019 IEEE International Conference on Big Data, Big Data 2019, 9 December 2019 through 12 December 2019 (pp. 4309-4314). Institute of Electrical and Electronics Engineers Inc.
Open this publication in new window or tab >>Cybercrime Investigations in the Era of Smart Applications: Way Forward Through Big Data
2019 (English)In: Proceedings - 2019 IEEE International Conference on Big Data, Big Data 2019, Institute of Electrical and Electronics Engineers Inc. , 2019, p. 4309-4314Conference paper, Published paper (Refereed)
Abstract [en]

The omnipresence of smart devices in many aspects of modern everyday life has helped to achieve an enormous level of automation, has ensured sustainable development, and improved quality of life. Over the last decade, such small and portable devices became cheap and easy to deploy in any kind of application. With the full range of versatile connectivity, such technological development also brings multiple challenges related to the security of infrastructure and data. Many individuals, companies, and states worldwide experience the previously unseen scale and scope of the attacks using novel approaches. All these smart applications have also increased the overall attack surface leading to multiple attack vectors available through vulnerabilities. Lack of standards, insufficient security awareness, and new technological landscape does not help either. Considering this, one needs to enhance forensics investigation methodologies, employ novel tools, combine threat intelligence, and integrate forensic readiness. Such measures will help to reduce the total cyber risk through a high level of preparedness for anticipated data-driven crimes in smart applications. We believe that this paper will help in bringing novel focus to existing digital forensics methodologies with a focus on smart applications. 

Place, publisher, year, edition, pages
Institute of Electrical and Electronics Engineers Inc., 2019
Keywords
big data, cyber investigtions, cybersecurity, smart applications, smart cities, Risk assessment, Smart city, Cyber security, Forensics investigations, Forensics methodologies, Level of automations, Security awareness, Technological development, Digital forensics
National Category
Computer and Information Sciences
Identifiers
urn:nbn:se:kth:diva-274113 (URN)10.1109/BigData47090.2019.9006596 (DOI)000554828704061 ()2-s2.0-85081368685 (Scopus ID)
Conference
2019 IEEE International Conference on Big Data, Big Data 2019, 9 December 2019 through 12 December 2019
Note

QC 20200702

Available from: 2020-07-02 Created: 2020-07-02 Last updated: 2022-06-26Bibliographically approved
Iqbal, A., Mahmood, F. & Ekstedt, M. (2019). Digital Forensic Analysis of Industrial Control Systems Using Sandboxing: A Case of WAMPAC Applications in the Power Systems. Energies, 12(13), Article ID 2598.
Open this publication in new window or tab >>Digital Forensic Analysis of Industrial Control Systems Using Sandboxing: A Case of WAMPAC Applications in the Power Systems
2019 (English)In: Energies, E-ISSN 1996-1073, Vol. 12, no 13, article id 2598Article in journal (Refereed) Published
Abstract [en]

In today's connected world, there is a tendency of connectivity even in the sectors which conventionally have been not so connected in the past, such as power systems substations. Substations have seen considerable digitalization of the grid hence, providing much more available insights than before. This has all been possible due to connectivity, digitalization and automation of the power grids. Interestingly, this also means that anybody can access such critical infrastructures from a remote location and gone are the days of physical barriers. The power of connectivity and control makes it a much more challenging task to protect critical industrial control systems. This capability comes at a price, in this case, increasing the risk of potential cyber threats to substations. With all such potential risks, it is important that they can be traced back and attributed to any potential threats to their roots. It is extremely important for a forensic investigation to get credible evidence of any cyber-attack as required by the Daubert standard. Hence, to be able to identify and capture digital artifacts as a result of different attacks, in this paper, the authors have implemented and improvised a forensic testbed by implementing a sandboxing technique in the context of real time-hardware-in-the-loop setup. Newer experiments have been added by emulating the cyber-attacks on WAMPAC applications, and collecting and analyzing captured artifacts. Further, using sandboxing for the first time in such a setup has proven helpful.

Place, publisher, year, edition, pages
MDPI, 2019
Keywords
forensic investigations; forensic evidence substation; wide area monitoring protection and control; phasor measurement units (PMUs); industrial control systems; sandboxing
National Category
Electrical Engineering, Electronic Engineering, Information Engineering
Research subject
Electrical Engineering; Industrial Information and Control Systems
Identifiers
urn:nbn:se:kth:diva-254917 (URN)10.3390/en12132598 (DOI)000477034700136 ()2-s2.0-85068759897 (Scopus ID)
Funder
Swedish Civil Contingencies Agency
Note

QC 20190710

Available from: 2019-07-09 Created: 2019-07-09 Last updated: 2023-08-28Bibliographically approved
Iqbal, A., Mahmood, F. & Ekstedt, M. (2018). An Experimental Forensic Test bed: Attack-based Digital Forensic Analysis of WAMPAC Applications. In: : . Paper presented at The 11th Mediterranean Conference on Power Generation, Transmission, Distribution and Energy Conversion (MedPower 2018). Croatia: IEEE
Open this publication in new window or tab >>An Experimental Forensic Test bed: Attack-based Digital Forensic Analysis of WAMPAC Applications
2018 (English)Conference paper, Published paper (Refereed)
Abstract [en]

The global trend is to go digital, in other words go 'smart'. Like the rest of the world getting smarter, so is the power sector hence the term smart power grids and substations. Such capability comes at a price, in this case increasing risk of potential cyber threats to substations. With all such potential risks, it is important that we are able to trace back and attribute any potential threats to its root. In this paper, we're exploring substations to find potential evidences in case a forensic investigation becomes a necessity. Moreover, a forensic experimental test bed is proposed for digital forensic analysis. Finally, a mapping of attack-based forensic evidences is presented.

Place, publisher, year, edition, pages
Croatia: IEEE, 2018
Keywords
Forensic Investigations; Forensic Evidence Substation; Wide Area Monitoring Protection and Control; PMUs
National Category
Electrical Engineering, Electronic Engineering, Information Engineering
Research subject
Electrical Engineering
Identifiers
urn:nbn:se:kth:diva-240575 (URN)
Conference
The 11th Mediterranean Conference on Power Generation, Transmission, Distribution and Energy Conversion (MedPower 2018)
Funder
Swedish Civil Contingencies Agency
Note

QC 20190108

Available from: 2018-12-19 Created: 2018-12-19 Last updated: 2024-03-15Bibliographically approved
Iqbal, A., Mahmood, F. & Ekstedt, M. (2018). An experimental forensic testbed: Attack-based digital forensic analysis of WAMPAC applications. In: IET Conference Publications: . Paper presented at Mediterranean Conference on Power Generation, Transmission, Distribution and Energy Conversion, MEDPOWER 2018, 12-15 November 2018. Institution of Engineering and Technology (IET) (CP759)
Open this publication in new window or tab >>An experimental forensic testbed: Attack-based digital forensic analysis of WAMPAC applications
2018 (English)In: IET Conference Publications, Institution of Engineering and Technology (IET) , 2018, no CP759Conference paper, Published paper (Refereed)
Abstract [en]

Forensic Investigations; Forensic Evidence Substation; Wide Area Monitoring Protection and Control; PMUs etc. Abstract The global trend is to go digital, in other words, go 'smart'. Like the rest of the world, power sector is also getting smarter hence the term smart power grids and substations. Such capability comes at the price of heightened risk of potential cyber threats to substations. With all such potential risks, we must be able to trace back and attribute any potential threats to its root. In this paper, we're exploring substations to find potential evidence in case a forensic investigation becomes a necessity. Moreover, a forensic experimental testbed is proposed for digital forensic analysis. Finally, a mapping of attack-based forensic evidence is presented.

Place, publisher, year, edition, pages
Institution of Engineering and Technology (IET), 2018
Keywords
Computer crime, Electric power transmission networks, Electronic crime countermeasures, Energy conversion, Testbeds, Digital forensic analysis, Experimental testbed, Forensic evidence, Forensic investigation, Potential risks, Potential threats, Protection and controls, Wide area monitoring, Digital forensics
National Category
Computer Sciences
Identifiers
urn:nbn:se:kth:diva-302088 (URN)10.1049/cp.2018.1917 (DOI)2-s2.0-85062613815 (Scopus ID)
Conference
Mediterranean Conference on Power Generation, Transmission, Distribution and Energy Conversion, MEDPOWER 2018, 12-15 November 2018
Note

QC 20210927

Available from: 2021-09-27 Created: 2021-09-27 Last updated: 2022-06-25Bibliographically approved
Iqbal, A., Ekstedt, M. & Alobaidli, H. (2018). Digital Forensic Readiness in Critical Infrastructures: A case of substation automation in the power sector. In: Petr Matoušek, Martin Schmiedecker (Ed.), Digital Forensics and Cyber Crime: 9th International Conference, ICDF2C 2017, Prague, Czech Republic, October 9-11, 2017, Proceedings. Paper presented at 9th International Conference on Digital Forensics and Cyber Crime, ICDF2C 2017, Prague, Czech Republic, 9 October 2017 through 11 October 2017 (pp. 117-129). Springer Publishing Company, 216
Open this publication in new window or tab >>Digital Forensic Readiness in Critical Infrastructures: A case of substation automation in the power sector
2018 (English)In: Digital Forensics and Cyber Crime: 9th International Conference, ICDF2C 2017, Prague, Czech Republic, October 9-11, 2017, Proceedings, Springer Publishing Company, 2018, Vol. 216, p. 117-129Conference paper, Published paper (Refereed)
Abstract [en]

The proliferation of intelligent devices has provisioned more functionality in Critical Infrastructures. But the same automation also brings challenges when it comes to malicious activity, either internally or externally. One such challenge is the attribution of an attack and to ascertain who did what, when and how? Answers to these questions can only be found if the overall underlying infrastructure supports answering such queries. This study sheds light on the power sector specifically on smart grids to learn whether current setups support digital forensic investigations or no. We also address several challenges that arise in the process and a detailed look at the literature on the subject. To facilitate such a study our scope of work revolves around substation automation and devices called intelligent electronic devices (IEDs) in smart grids. 

Place, publisher, year, edition, pages
Springer Publishing Company, 2018
Series
Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering, ISSN 1867-8211 ; 216
Keywords
Digital Forensics, Forensic Readiness, Substation Automation, Smart Grid, Forensic Investigation, Critical Infrastructures, FIGRID, FIICS
National Category
Electrical Engineering, Electronic Engineering, Information Engineering
Research subject
Electrical Engineering; Industrial Information and Control Systems
Identifiers
urn:nbn:se:kth:diva-218067 (URN)10.1007/978-3-319-73697-6_9 (DOI)000923525500009 ()2-s2.0-85041098702 (Scopus ID)978-3-319-73697-6 (ISBN)978-3-319-73696-9 (ISBN)
Conference
9th International Conference on Digital Forensics and Cyber Crime, ICDF2C 2017, Prague, Czech Republic, 9 October 2017 through 11 October 2017
Funder
Swedish Civil Contingencies Agency
Note

QC 20171206

Available from: 2017-11-22 Created: 2017-11-22 Last updated: 2024-03-15Bibliographically approved
Iqbal, A., Mahmood, F., Shalaginov, A. & Ekstedt, M. (2018). Identification of Attack-based Digital Forensic Evidences for WAMPAC Systems. In: Proceedings - 2018 IEEE International Conference on Big Data, Big Data 2018: . Paper presented at 2018 IEEE International Conference on Big Data, Big Data 2018; Seattle; United States; 10 December 2018 through 13 December 2018 (pp. 3078-3086). Seattle, Washington, USA: IEEE conference proceedings, Article ID 8622550.
Open this publication in new window or tab >>Identification of Attack-based Digital Forensic Evidences for WAMPAC Systems
2018 (English)In: Proceedings - 2018 IEEE International Conference on Big Data, Big Data 2018, Seattle, Washington, USA: IEEE conference proceedings, 2018, p. 3078-3086, article id 8622550Conference paper, Published paper (Refereed)
Abstract [en]

Power systems domain has generally been very conservative in terms of conducting digital forensic investigations, especially so since the advent of smart grids. This lack of research due to a multitude of challenges has resulted in absence of knowledge base and resources to facilitate such an investigation. Digitalization in the form of smart grids is upon us but in case of cyber-attacks, attribution to such attacks is challenging and difficult if not impossible. In this research, we have identified digital forensic artifacts resulting from a cyber-attack on Wide Area Monitoring, Protection and Control (WAMPAC) systems, which will help an investigator attribute an attack using the identified evidences. The research also shows the usage of sandboxing for digital forensics along with hardware-in-the-loop (HIL) setup. This is first of its kind effort to identify and acquire all the digital forensic evidences for WAMPAC systems which will ultimately help in building a body of knowledge and taxonomy for power system forensics.

Place, publisher, year, edition, pages
Seattle, Washington, USA: IEEE conference proceedings, 2018
Keywords
Forensic Investigations; Substation; Wide Area Monitoring Protection and Control; Forensic Artifacts; Evidence; PMUs.
National Category
Electrical Engineering, Electronic Engineering, Information Engineering
Research subject
Electrical Engineering
Identifiers
urn:nbn:se:kth:diva-240576 (URN)10.1109/BigData.2018.8622550 (DOI)000468499303020 ()2-s2.0-85062598217 (Scopus ID)978-1-5386-5035-6 (ISBN)
Conference
2018 IEEE International Conference on Big Data, Big Data 2018; Seattle; United States; 10 December 2018 through 13 December 2018
Funder
Swedish Civil Contingencies Agency
Note

QC 20190108

Available from: 2018-12-19 Created: 2018-12-19 Last updated: 2024-03-15Bibliographically approved
Iqbal, A., Shalaginov, A. & Mahmood, F. (2018). Intelligent analysis of digital evidences in large-scale logs in power systems attributed to the attacks. In: Proceedings - 2018 IEEE International Conference on Big Data, Big Data 2018: . Paper presented at 2018 IEEE International Conference on Big Data, Big Data 2018; Seattle; United States; 10 December 2018 through 13 December 2018 (pp. 3087-3092).
Open this publication in new window or tab >>Intelligent analysis of digital evidences in large-scale logs in power systems attributed to the attacks
2018 (English)In: Proceedings - 2018 IEEE International Conference on Big Data, Big Data 2018, 2018, p. 3087-3092Conference paper, Published paper (Refereed)
Abstract [en]

Smart grid improves and revolutionizes the way how energy is generated, distributed and consumed. Despite utilization of such technologies for better life of end-users and communities, there might be outlier events happening that will introduce disturbance to the smart grids. To mitigate impact from such events in power grid, particularly in Wide Area Monitoring Protection and Control (WAMPAC) has been introduced for mitigation and prevention of large disruption and extreme events. Large network of interconnected devices is being monitored through WAMPAC sub-system to avoid major events with negative impact through analysis of system-wide contextual information. The assessment of the state is being made based on the data from Phasor Measurement Unit (PMUs) collected and processed in the Phasor Data Concentrator (PDC). There is an enormous amount of Machine-to-Machine (M2M) communication that the system has to analyze. However, blackout prediction and mitigation is done using measurements data and does not necessarily focus on more high level adversarial events. This paper proposes an ongoing research into timely detection of adversarial attack on the power grid.  During the experimental phase, authentication attack scenario was successfully executed on power substation setup. Further, framework for intelligent identification of digital evidences related to attack was suggested unveiling possibility for crime investigations preparedness.

Keywords
Big Data Applications; Forensic Investigations; Forensic Artifacts; Evidence; PMUs; Machine Learning; Wide Area Monitoring Protection and Control
National Category
Electrical Engineering, Electronic Engineering, Information Engineering
Research subject
Electrical Engineering
Identifiers
urn:nbn:se:kth:diva-240577 (URN)10.1109/BigData.2018.8622220 (DOI)000468499303021 ()2-s2.0-85062643351 (Scopus ID)978-1-5386-5035-6 (ISBN)
Conference
2018 IEEE International Conference on Big Data, Big Data 2018; Seattle; United States; 10 December 2018 through 13 December 2018
Funder
Swedish Civil Contingencies Agency
Note

QC 20190108

Available from: 2018-12-19 Created: 2018-12-19 Last updated: 2024-03-15Bibliographically approved
Organisations

Search in DiVA

Show all publications