dc.contributor.author | Nisioti, Antonia | |
dc.contributor.author | Loukas, George | |
dc.contributor.author | Mylonas, Alexios | |
dc.contributor.author | Panaousis, Emmanouil | |
dc.date.accessioned | 2023-01-13T12:00:02Z | |
dc.date.available | 2023-01-13T12:00:02Z | |
dc.date.issued | 2023-03-01 | |
dc.identifier.citation | Nisioti , A , Loukas , G , Mylonas , A & Panaousis , E 2023 , ' Forensics for multi-stage cyber incidents : Survey and future directions ' , Forensic Science International: Digital Investigation , vol. 44 , 301480 . https://doi.org/10.1016/j.fsidi.2022.301480 | |
dc.identifier.issn | 2666-2825 | |
dc.identifier.uri | http://hdl.handle.net/2299/26000 | |
dc.description | © 2022 The Authors. Published by Elsevier Ltd. This is an open access article under the CC BY-NC-ND license (http://creativecommons.org/licenses/by-nc-nd/4.0/). | |
dc.description.abstract | The increase in the complexity and sophistication of multi-stage cyber attacks, such as advanced persistent threats, paired with the large volume of data produced by modern systems and networks, have made forensic investigations more demanding in knowledge and resources. Thus, it is essential that cyber forensic investigators are supported to operate more efficiently, in terms of resources and evidence recovery, and cope with a wide range of cyber incidents. This paper presents a comprehensive survey of 49 works that aim to support cyber forensic investigations of modern multi-stage cyber incidents and highlights the need for decision support systems on the field. The works reviewed are compared using 11 criteria, such as their evaluation method, how they optimise the forensic process, or what stage of investigation they study. We also classify the surveyed papers using 8 categories that represent the overall aim of the proposed cyber investigation method or tool. We identify and discuss open issues, arising from this extensive survey, such as the need for realistic evaluation, as well as realistic and representative modelling to increase applicability and performance. Finally, we provide directions for future research on improving the state-of-the-art of cyber forensics. | en |
dc.format.extent | 16 | |
dc.format.extent | 1930937 | |
dc.language.iso | eng | |
dc.relation.ispartof | Forensic Science International: Digital Investigation | |
dc.subject | Advanced persistent threats | |
dc.subject | Anti-forensics | |
dc.subject | Cyber forensics | |
dc.subject | Digital forensics | |
dc.subject | Multi-stage attacks | |
dc.subject | Review | |
dc.subject | Survey | |
dc.subject | Pathology and Forensic Medicine | |
dc.subject | Information Systems | |
dc.subject | Computer Science Applications | |
dc.subject | Medical Laboratory Technology | |
dc.subject | Law | |
dc.title | Forensics for multi-stage cyber incidents : Survey and future directions | en |
dc.contributor.institution | School of Physics, Engineering & Computer Science | |
dc.contributor.institution | Department of Computer Science | |
dc.contributor.institution | Cybersecurity and Computing Systems | |
dc.contributor.institution | Networks and Security Research Centre | |
dc.description.status | Peer reviewed | |
dc.identifier.url | http://www.scopus.com/inward/record.url?scp=85145262956&partnerID=8YFLogxK | |
rioxxterms.versionofrecord | 10.1016/j.fsidi.2022.301480 | |
rioxxterms.type | Other | |
herts.preservation.rarelyaccessed | true | |