I. Alfadli, F. Ghabban, O. Ameerbakhsh, A. AbuAli, Arafat Al-dhaqm, M. Al-Khasawneh
{"title":"CIPM: Common Identification Process Model for Database Forensics Field","authors":"I. Alfadli, F. Ghabban, O. Ameerbakhsh, A. AbuAli, Arafat Al-dhaqm, M. Al-Khasawneh","doi":"10.1109/ICSCEE50312.2021.9498014","DOIUrl":null,"url":null,"abstract":"Database Forensics (DBF) domain is a branch of digital forensics, concerned with the identification, collection, reconstruction, analysis, and documentation of database crimes. Different researchers have introduced several identification models to handle database crimes. Majority of proposed models are not specific and are redundant, which makes these models a problem because of the multidimensional nature and high diversity of database systems. Accordingly, using the metamodeling approach, the current study is aimed at proposing a unified identification model applicable to the database forensic field. The model integrates and harmonizes all exiting identification processes into a single abstract model, called Common Identification Process Model (CIPM). The model comprises six phases: 1) notifying an incident, 2) responding to the incident, 3) identification of the incident source, 4) verification of the incident, 5) isolation of the database server and 6) provision of an investigation environment. CIMP was found capable of helping the practitioners and newcomers to the forensics domain to control database crimes.","PeriodicalId":252529,"journal":{"name":"2021 2nd International Conference on Smart Computing and Electronic Enterprise (ICSCEE)","volume":"31 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-06-15","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"4","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2021 2nd International Conference on Smart Computing and Electronic Enterprise (ICSCEE)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICSCEE50312.2021.9498014","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 4
Abstract
Database Forensics (DBF) domain is a branch of digital forensics, concerned with the identification, collection, reconstruction, analysis, and documentation of database crimes. Different researchers have introduced several identification models to handle database crimes. Majority of proposed models are not specific and are redundant, which makes these models a problem because of the multidimensional nature and high diversity of database systems. Accordingly, using the metamodeling approach, the current study is aimed at proposing a unified identification model applicable to the database forensic field. The model integrates and harmonizes all exiting identification processes into a single abstract model, called Common Identification Process Model (CIPM). The model comprises six phases: 1) notifying an incident, 2) responding to the incident, 3) identification of the incident source, 4) verification of the incident, 5) isolation of the database server and 6) provision of an investigation environment. CIMP was found capable of helping the practitioners and newcomers to the forensics domain to control database crimes.
数据库取证(DBF)领域是数字取证的一个分支,涉及数据库犯罪的识别、收集、重建、分析和记录。不同的研究人员提出了几种识别模型来处理数据库犯罪。由于数据库系统的多维性和高度多样性,大多数被提出的模型都是不具体的和冗余的,这使得这些模型成为一个问题。因此,本研究旨在利用元建模方法,提出一种适用于数据库取证领域的统一识别模型。该模型将所有现有的识别过程集成并协调为一个抽象模型,称为公共识别过程模型(Common identification Process model, CIPM)。该模型包括六个阶段:1)通知事件,2)响应事件,3)识别事件来源,4)验证事件,5)隔离数据库服务器,6)提供调查环境。发现CIMP能够帮助取证领域的从业人员和新手控制数据库犯罪。