A generic database forensic investigation process model

Database Forensic investigation is a domain which deals with database contents and their metadata to reveal malicious activities on database systems. Even though it is still new, but due to the overwhelming challenges and issues in the domain, this makes database forensic become a fast growing and m...

Full description

Bibliographic Details
Main Authors: Al-Dhaqm, Arafat (Author), Abd. Razak, Shukor (Author), Othman, Siti Hajar (Author), Nagdi, Asri (Author), Ali, Abdulalem (Author)
Format: Article
Language:English
Published: Penerbit UTM Press, 2016.
Subjects:
Online Access:Get fulltext
LEADER 01727 am a22001813u 4500
001 71404
042 |a dc 
100 1 0 |a Al-Dhaqm, Arafat  |e author 
700 1 0 |a Abd. Razak, Shukor  |e author 
700 1 0 |a Othman, Siti Hajar  |e author 
700 1 0 |a Nagdi, Asri  |e author 
700 1 0 |a Ali, Abdulalem  |e author 
245 0 0 |a A generic database forensic investigation process model 
260 |b Penerbit UTM Press,   |c 2016. 
856 |z Get fulltext  |u http://eprints.utm.my/id/eprint/71404/1/ShukorAbdRazak2016_Agenericdatabaseforensicinvestigation.pdf 
520 |a Database Forensic investigation is a domain which deals with database contents and their metadata to reveal malicious activities on database systems. Even though it is still new, but due to the overwhelming challenges and issues in the domain, this makes database forensic become a fast growing and much sought after research area. Based on observations made, we found that database forensic suffers from having a common standard which could unify knowledge of the domain. Therefore, through this paper, we present the use of Design Science Research (DSR) as a research methodology to develop a Generic Database Forensic Investigation Process Model (DBFIPM). From the creation of DBFIPM, five common forensic investigation processes have been proposed namely, the i) identification, ii) collection, iii) preservation, iv) analysis and v) presentation process. From the DBFIPM, it allows the reconciliation of concepts and terminologies of all common databases forensic investigation processes. Thus, this will potentially facilitate the sharing of knowledge on database forensic investigation among domain stakeholders. 
546 |a en 
650 0 4 |a QA75 Electronic computers. Computer science