Digital Forensic Evidence-The missing link in Threat Modeling
2020 (Engelska)Ingår i: 2020 International Conference on Data Analytics for Business and Industry: Way Towards a Sustainable Economy, ICDABI 2020, Institute of Electrical and Electronics Engineers Inc. , 2020Konferensbidrag, Publicerat paper (Refereegranskat)
Abstract [en]
Threat modeling is a set of methodologies to analyze the potential threats in a digital system, in order to mitigate them. Digital forensics, on the other hand, is used in order to find the true origin of an event with the help of forensic evidence. Digital forensics is based on Locard's Principle and dictates that even digital crime leaves behind some form of remnants. Both the domains, threat modeling and digital forensics, have separately existed, but have to our knowledge not been used together. In this research we establish the importance of forensic evidence and how it can aid threat modeling by providing more comprehensive threat intelligence. We provide practical examples of how the two fields can be combined, based on attack graphs and Bayesian networks.
Ort, förlag, år, upplaga, sidor
Institute of Electrical and Electronics Engineers Inc. , 2020.
Nyckelord [en]
Attack Graph, Bayesian Network, DFET Modeling, Digital Forensics, Forensic Evidence, Threat, Threat Model, Bayesian networks, Computer crime, Electronic crime countermeasures, Industrial economics, Digital crime, Digital system, Potential threats, Threat modeling
Nationell ämneskategori
Datorsystem
Identifikatorer
URN: urn:nbn:se:kth:diva-301059DOI: 10.1109/ICDABI51230.2020.9325650Scopus ID: 2-s2.0-85100489294OAI: oai:DiVA.org:kth-301059DiVA, id: diva2:1598020
Konferens
2020 International Conference on Data Analytics for Business and Industry: Way Towards a Sustainable Economy, ICDABI 2020, 26 October 2020 through 27 October 2020
Anmärkning
QC 20210928
2021-09-282021-09-282023-04-05Bibliografiskt granskad