CuFA: A more formal definition for digital forensic artifacts

Details

Serval ID
serval:BIB_4B70E27D7C14
Type
Article: article from journal or magazin.
Collection
Publications
Title
CuFA: A more formal definition for digital forensic artifacts
Journal
Digital Investigation
Author(s)
Harichandran Vikram S., Walnycky Daniel, Baggili Ibrahim, Breitinger Frank
ISSN
1742-2876
Publication state
Published
Issued date
08/2016
Volume
18
Pages
S125-S137
Language
english
Abstract
The term “artifact” currently does not have a formal definition within the domain of cyber/digital forensics, resulting in a lack of standardized reporting, linguistic understanding between professionals, and efficiency. In this paper we propose a new definition based on a survey we conducted, literature usage, prior definitions of the word itself, and similarities with archival science. This definition includes required fields that all artifacts must have and encompasses the notion of curation. Thus, we propose using a new term – curated forensic artifact (CuFA) – to address items which have been cleared for entry into a CuFA database (one implementation, the Artifact Genome Project, abbreviated as AGP, is under development and briefly outlined). An ontological model encapsulates these required fields while utilizing a lower-level taxonomic schema. We use the Cyber Observable eXpression (CybOX) project due to its rising popularity and rigorous classifications of forensic objects. Additionally, we suggest some improvements on its integration into our model and identify higher-level location categories to illustrate tracing an object from creation through investigative leads. Finally, a step-wise procedure for researching and logging CuFAs is devised to accompany the model.
Keywords
Forensic artifact, Digital forensics, CybOX, Curated forensic artifact, CuFA, Artifact definition, Survey, Cyber forensics, Taxonomy, Ontology
Web of science
Open Access
Yes
Create date
06/05/2021 12:01
Last modification date
06/05/2021 12:38
Usage data