Forensics for multi-stage cyber incidents: Survey and future directions

Antonia Nisioti, George Loukas, Alexios Mylonas, Emmanouil Panaousis

Research output: Contribution to journalReview articlepeer-review

45 Downloads (Pure)

Abstract

The increase in the complexity and sophistication of multi-stage cyber attacks, such as advanced persistent threats, paired with the large volume of data produced by modern systems and networks, have made forensic investigations more demanding in knowledge and resources. Thus, it is essential that cyber forensic investigators are supported to operate more efficiently, in terms of resources and evidence recovery, and cope with a wide range of cyber incidents. This paper presents a comprehensive survey of 49 works that aim to support cyber forensic investigations of modern multi-stage cyber incidents and highlights the need for decision support systems on the field. The works reviewed are compared using 11 criteria, such as their evaluation method, how they optimise the forensic process, or what stage of investigation they study. We also classify the surveyed papers using 8 categories that represent the overall aim of the proposed cyber investigation method or tool. We identify and discuss open issues, arising from this extensive survey, such as the need for realistic evaluation, as well as realistic and representative modelling to increase applicability and performance. Finally, we provide directions for future research on improving the state-of-the-art of cyber forensics.
Original languageEnglish
Article number301480
Number of pages16
JournalForensic Science International: Digital Investigation
Volume44
Early online date30 Dec 2022
DOIs
Publication statusPublished - 1 Mar 2023

Keywords

  • Advanced persistent threats
  • Anti-forensics
  • Cyber forensics
  • Digital forensics
  • Multi-stage attacks
  • Review
  • Survey

Fingerprint

Dive into the research topics of 'Forensics for multi-stage cyber incidents: Survey and future directions'. Together they form a unique fingerprint.

Cite this