Repository logo
 

Efficient Reactive Forensic Investigation Model for Large APT Computer Network Events

dc.contributor.authorCusack, Brian
dc.contributor.authorNicho, Mathew
dc.date.accessioned2025-02-14T03:07:46Z
dc.date.available2025-02-14T03:07:46Z
dc.date.issued2024-09-07
dc.description.abstractForensic investigation is an evidential process that occurs after a computer network security event to ascertain causes, vulnerabilities, and remediation actions. The security problem is establishing evidential providence when Advanced persistent threats (APT) are deceptive, learn new behaviors, and erase evidence of activity. Proactive defense mechanisms such as honey pots, fake files and so on filter many APT attacks but network security also relies on reactive forensic investigation after security events to learn tactics and to harden the system. Root cause analysis of APT activity is frustrated by gaps in the data, similarity of normal and malicious network processes, confusion with other network attacks, and the evasive behavior of an APT. In this research the problem of APT evidential providence in reactive APT investigation is addressed by innovating an APT network forensic investigation model (APT-FIM) solution to differentiate reactive APT evidence from other evidence in a computer network investigation. The APT-FIM is structured from the APT definition using Object Oriented (OO) methods and designed for practical use by a security practitioner on secondary data sources. The contribution of the research is to formulate efficient methods and effective big data guidance for reactive APT investigation. Two use cases are used to assess the model and to identify missing requirements. A practitioner flow chart for use results.
dc.identifier.doi10.2139/ssrn.4949860
dc.identifier.urihttp://hdl.handle.net/10292/18660
dc.relation.urihttps://papers.ssrn.com/sol3/papers.cfm?abstract_id=4949860
dc.rightsCopyright © 2024 Elsevier Inc., its licensors, and contributors. All rights are reserved, including those for text and data mining, AI training, and similar technologies. For all open access content, the relevant licensing terms apply. This is a preprint article, it offers immediate access but has not been peer reviewed.
dc.rights.accessrightsOpenAccess
dc.subject08 Information and Computing Sciences
dc.subjectStrategic, Defence & Security Studies
dc.subject4604 Cybersecurity and privacy
dc.subjectBig data evidential efficiency
dc.subjectEvidential providence
dc.subjectNetwork security
dc.subjectForensic investigation
dc.subjectAdvanced persistent threat
dc.titleEfficient Reactive Forensic Investigation Model for Large APT Computer Network Events
dc.typeJournal article (preprint)
pubs.elements-id572611

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Cusack_2024_preprint_Effective reactive forensic investigation model.pdf
Size:
253.31 KB
Format:
Adobe Portable Document Format
Description:
Journal article (preprint)