Digital Forensic Evidence-The missing link in Threat Modeling
2020 (English)In: 2020 International Conference on Data Analytics for Business and Industry: Way Towards a Sustainable Economy, ICDABI 2020, Institute of Electrical and Electronics Engineers Inc. , 2020Conference paper, Published paper (Refereed)
Abstract [en]
Threat modeling is a set of methodologies to analyze the potential threats in a digital system, in order to mitigate them. Digital forensics, on the other hand, is used in order to find the true origin of an event with the help of forensic evidence. Digital forensics is based on Locard's Principle and dictates that even digital crime leaves behind some form of remnants. Both the domains, threat modeling and digital forensics, have separately existed, but have to our knowledge not been used together. In this research we establish the importance of forensic evidence and how it can aid threat modeling by providing more comprehensive threat intelligence. We provide practical examples of how the two fields can be combined, based on attack graphs and Bayesian networks.
Place, publisher, year, edition, pages
Institute of Electrical and Electronics Engineers Inc. , 2020.
Keywords [en]
Attack Graph, Bayesian Network, DFET Modeling, Digital Forensics, Forensic Evidence, Threat, Threat Model, Bayesian networks, Computer crime, Electronic crime countermeasures, Industrial economics, Digital crime, Digital system, Potential threats, Threat modeling
National Category
Computer Systems
Identifiers
URN: urn:nbn:se:kth:diva-301059DOI: 10.1109/ICDABI51230.2020.9325650Scopus ID: 2-s2.0-85100489294OAI: oai:DiVA.org:kth-301059DiVA, id: diva2:1598020
Conference
2020 International Conference on Data Analytics for Business and Industry: Way Towards a Sustainable Economy, ICDABI 2020, 26 October 2020 through 27 October 2020
Note
QC 20210928
2021-09-282021-09-282023-04-05Bibliographically approved