IEEE Access (Jan 2020)

Towards the Development of an Integrated Incident Response Model for Database Forensic Investigation Field

  • Arafat Al-Dhaqm,
  • Shukor Abd Razak,
  • Kamran Siddique,
  • Richard Adeyemi Ikuesan,
  • Victor R. Kebande

DOI
https://doi.org/10.1109/ACCESS.2020.3008696
Journal volume & issue
Vol. 8
pp. 145018 – 145032

Abstract

Read online

For every contact that is made in a database, a digital trace will potentially be left and most of the database breaches are mostly aimed at defeating the major security goals (Confidentiality, Integrity, and Authenticity) of data that reside in the database. In order to prove/refute a fact during litigation, it is important to identify suitable investigation techniques that can be used to link a potential incident/suspect to the digital crime. As a result, this paper has proposed suitable steps of constructing and Integrated Incident Response Model (IIRM) that can be relied upon in the database forensic investigation field. While developing the IIRM, design science methodology has been adapted and the outcome of this study has shown significant and promising approaches that could be leveraged by digital forensic experts, legal practitioners and law enforcement agencies. This is owing to the fact, that IIRM construction has followed incident investigation principles that are stipulated in ISO guidelines.

Keywords