The continual integration of digital capabilities into a globally networked world highlights the necessity of cyber operations, defenses, and digital forensics capabilities and research.This ongoing digital amalgamation demands discussions that explore real-world technological advancements, administrative issues, and tactical analysis solutions.Hence, this mini-track presents research that focuses on relevant issues.The papers in the mini-track investigate 'Safe Reinforcement Learning via Observation Shielding', 'Towards Hardware-Based Application Fingerprinting with Microarchitectural Signals for Zero Trust Environments', as well as 'Image Attribute Estimation for Forensic Image Reconstruction from Fragments', and 'Data Exfiltration via Flow Hijacking at the Socket Layer'.The contributions offered in these papers highlight the escalating need for cyber operations, defense, and forensics research.
These days, there are many ways to watch streaming videos on television. When compared to a standalone smart television, streaming devices such as Roku and Amazon Fire Stick have a plethora of app selections. While these devices are platform agnostic and compatible with smartphones, they can still leave behind crumbs of sensitive data that can cause privacy, security, and forensic issues. In this paper, the authors conduct an experiment with streaming devices to ascertain digital footprints from network traffic and mobile forensics that they leave behind.
Globally, the impact of cyber threats on industry, government, and even academia has catapulted cybersecurity to the forefront of attention. The need for improved cyber operations, defenses, and digital forensics capabilities and research grows yearly. The field requires constant refreshment of ideas, techniques, and study with the view of transitioning ideas into practical use. This mini-track presents a multi-faceted view of these topics which highlight threat analysis (CAVA- Cognitive Aid for Vulnerability Analysis), network security (Identifying Subdomain Doppelganger Attacks against Companies), and incident response (Environmental Factors that Hinder an Organization's Ability to Learn from Cyber Incidents: A Case Study on SolarWinds). The contributions offered in these papers provide further impetus for cyber operations, defense, and forensics research.
The recent pandemic fosters an increasing dependency on various forms of digital communications that support social distancing. To mitigate widespread exposure to COVID, the Louisiana Department of Health’s COVID Defense contact tracing application helps users learn about potential exposures to infected individuals. This research investigates the viability of using the Louisiana Department of Health’s COVID Defense application symptoms share feature as an attack vector. The primary contribution of this research is an initial assessment of the effective modification and distribution of packaged JSON files to contain malicious behavior. Secondly, it highlights the effectiveness of this attack through email, WIFI direct, and nearby share.
Smartphone devices are increasingly being integrated into a variety of medical settings. An emerging trend is the development of smartphone applications that interact with medical devices connected to the Internet. While this fusion of technology can provide various benefits for both patients and medical professionals, there are concerns that these devices could become targets for cybercriminals. Therefore, a digital forensic investigation of these medical devices could be needed. However, researchers have suggested that the investigation of medical devices is unlikely to be straightforward, and that conventional forensic evidence acquisition might not be possible. Hence, this paper proposes that smartphone applications, which interact with medical devices, could provide an alternative source of digital evidence when investigating the device itself. The research contribution is twofold. First, the paper presents an empirical investigation to using residual data recovered from medical smartphone applications, as a means for forensically examining medical devices. Second, the paper documents the forensic artifacts that are generated by specific medical device smartphone applications on Android and iOS smartphones.
Realistic case studies are essential to training successful digital forensics examiners. However, the generation of realistic datasets is time-consuming and resource taxing. This paper presents a technical solution that populates Android emulators with realistic mobile forensic data. The emulator's data can be extracted into a raw disk image that is usable in mobile forensic training scenarios. In addition, the tool allows a user to populate the Android emulators with custom text messages, phone contacts, phone calls, and files. This population task is achieved by utilizing the Android Debug Bridge, Android Content Providers, SQLite databases, and the NodeJS runtime environment. This paper presents the software design and development, the requirements and limitations, and the testing process implemented in this research. The contribution of this paper is twofold. First, it identifies potential data and mechanisms to generate Android mobile forensic datasets using customized data population. Second, it creates a foundation for future research on the topic of mobile forensic emulators for training purposes. This article is categorized under: Digital and Multimedia Science > Mobile Forensics Crime Scene Investigation > Education and Formation
Footwear prints are one of the most commonly recovered in criminal investigations.They can be used to discover a criminal's identity and to connect various crimes.Nowadays, footwear recognition techniques take time to be processed due to the use of current methods to extract the shoe print layout such as platter castings, gel lifting, and 3D-imaging techniques.Traditional techniques are prone to human error and waste valuable investigative time, which can be a problem for timely investigations.In terms of 3D-imaging techniques, one of the issues is that footwear prints can be blurred or missing, which renders their recognition and comparison inaccurate by completely automated approaches.Hence, this research investigates a footwear recognition model based on camera RGB images of the shoe print taken directly from the investigation site to reduce the time and cost required for the investigative process.First, the model extracts the layout information of the evidence shoe print using known image processing techniques.The layout information is then sent to a hierarchical network of neural networks.Each layer of this network is examined in an attempt to process and recognize footwear features to eliminate and narrow down the possible matches until returning the final result to the investigator.
The introduction of Internet of Things (IoT) ecosystems into personal homes and businesses prompts the idea that such ecosystems contain residual data, which can be used as digital evidence in court proceedings. However, the forensic examination of IoT ecosystems introduces a number of investigative problems for the digital forensics community. One of these problems is the limited availability of practical processes and techniques to guide the preservation and analysis of residual data from these ecosystems. Focusing on a detailed case study of the iHealth Smart Scale ecosystem, we present an empirical demonstration of practical techniques to recover residual data from different evidence sources within a smart scale ecosystem. We also document the artifacts that can be recovered from a smart scale ecosystem, which could inform a digital (forensic) investigation. The findings in this research provides a foundation for future studies regarding the development of processes and techniques suitable for extracting and examining residual data from IoT ecosystems.
Hard drives are a predominant source of residual data in today's digital environments. However, the increasing size of hard disks compounds the challenge of digital forensics, particularly in time-poor and resource-constrained forensic laboratories (e.g., due to the time required to recover residual data), using conventional digital investigation techniques. There are various types of information in the disk images such as e-mail data (a key source of information in disk images). However, it is time-consuming to identify and extract e-mail files from the disk images, when the hard disk size is big and contains large number of (other) files. We posit the importance of improving existing processes, for example by incorporating efficient and scalable processing mechanisms, to handle increasing volume of data. This study investigates the development of an Autopsy module for Distributed Identification of E-mail Files (DIEF). Initial experiments on the benchmark dataset show that DIEF achieves an average of 52% performance improvement in the process method, as compared to a traditional approach that does not employ distributed processing.
Android devices continue to dominate the mobile device market. However, ever-increasing reverse engineering capabilities and the ability to repackage apps to include malicious code with relative ease introduce significant challenges for marketplace providers. This research investigates the idea that system stats generated from running apps can be utilized to identify apps. The stats are collected from the host system while apps are running in an Android Virtual Device environment. The dataset comprises 998 repackaged apps, 1,533 malicious apps, and 2,130 normal apps. The results were analyzed using a J48 decision tree and achieved 99% accuracy.
Modern-day aircraft are flying computer networks, vulnerable to ground station flooding, ghost aircraft injection or flooding, aircraft disappearance, virtual trajectory modifications or false alarm attacks, and aircraft spoofing. This work lays out a data mining process, in the context of big data, to determine flight patterns, including patterns for possible attacks, in the U.S. National Air Space (NAS). Flights outside the flight patterns are possible attacks. For this study, OpenSky was used as the data source of Automatic Dependent Surveillance-Broadcast (ADS-B) messages, NiFi was used for data management, Elasticsearch was used as the log analyzer, Kibana was used to visualize the data for feature selection, and Support Vector Machine (SVM) was used for classification. This research provides a solution for attack mitigation by packaging a machine learning algorithm, SVM, into an intrusion detection system and calculating the feasibility of processing US ADS-B messages in near real time. Results of this work show that ADS-B network attacks can be detected using network attack signatures, and volume and velocity calculations show that ADS-B messages are processable at the scale of the U.S. Next Generation (NextGen) Air Traffic Systems using commodity hardware, facilitating real time attack detection. Precision and recall close to 80% were obtained using SVM.
The Android operating system is currently the most prevalent mobile device operating system holding roughly 54 percent of the total global market share.Due to Android's substantial presence, it has gained the attention of those with malicious intent, namely, malware authors.As such, there exists a need for validating and improving current malware detection techniques.Automated detection methods such as anti-virus programs are critical in protecting the wide variety of Android-powered mobile devices on the market.This research investigates effectiveness of four different machine learning algorithms in conjunction with features selected from Android manifest file permissions to classify applications as malicious or benign.Case study results, on a test set consisting of 5,243 samples, produce accuracy, recall, and precision rates above 80%.Of the considered algorithms (Random Forest, Support Vector Machine, Gaussian Naïve Bayes, and K-Means), Random Forest performed the best with 82.5% precision and 81.5% accuracy.
Today’s digital society creates an environment potentially conducive to the exchange of deceptive information. The dissemination of misleading information can have severe consequences on society. This research investigates the possibility of using shared characteristics among reviews, news articles, and emails to detect deception in text-based communication using machine learning techniques. The experiment discussed in this paper examines the use of Bag of Words and Part of Speech tag features to detect deception on the aforementioned types of communication using Neural Networks, Support Vector Machine, Naïve Bayesian, Random Forest, Logistic Regression, and Decision Tree. The contribution of this paper is two-fold. First, it provides initial insight into the identification of text communication cues useful in detecting deception across different types of text-based communication. Second, it provides a foundation for future research involving the application of machine learning algorithms to detect deception on different types of text communication.
The continuous amalgamation of technology into everyday life is creating an environment that is conducive to encouraging cybercrimes.As a result, it is becoming increasingly important that organizations and law enforcement agencies have the capability to conduct in-depth and detailed investigations.Hence, corporate and legal responses that address the resulting concerns presented in this mini-track include 'DNA Feature Selection for Discriminating WirelessHART IIoT Devices' and 'Container and VM Visualization for Rapid Forensic Analysis'.These contributions highlight the growing need to investigate and address cybersecurity vulnerabilities in the broad context of today's information-driven society.
The last decade has shown a steady rate of Android device dominance in market share and the emergence of hundreds of thousands of apps available to the public. Because of the ease of reverse engineering Android applications, repackaged malicious apps that clone existing code have become a severe problem in the marketplace. This research proposes a novel repackaged detection system based on perceptual hashes of vetted Android apps and their associated dynamic user interface (UI) behavior. Results show that an average hash approach produces 88% accuracy (indicating low false negative and false positive rates) in a sample set of 4878 Android apps, including 2151 repackaged apps. The approach is the first dynamic method proposed in the research community using imagebased hashing techniques with reasonable performance to other known dynamic approaches and the possibility for practical implementation at scale for new applications entering the Android market.
An emerging trend is the development of smartphone applications, which act as an interface to medical devices connected to the Internet. Many of these devices, along with their smartphone applications, have been approved by the United States Food and Drug Administration (FDA) for use in medical settings. Furthermore, device manufacturers are expected to comply with the Health Insurance Portability and Accountability Act (HIPAA) of 1996. As a result, manufacturers are required to implement safeguards to protect a patient’s personal and medical information. Previous research has shown that smartphone applications produce residual data, which can have security and privacy implications. Hence, there is the potential that the residual data generated by smartphone applications that interact with medical devices is potentially putting patient information at risk. This study investigates residual data recovered from a smartphone application, which interacts with a medical device, from the perspective of Security and Privacy violations within HIPAA. This study includes a controlled experiment to investigate the residual data generated by Android and iOS smartphone applications that accompany seven FDA-approved medical devices. The devices and their smartphone applications were used for five days in a test environment. The smartphone applications were then processed using industry-accepted mobile forensic toolkits to retrieve resident residual artifacts. Once the processing was complete, the data extractions were analyzed for patient information as well as medical device interactions. The analysis of the Android and iOS smartphone applications revealed that data related to the test patient, and their use of the medical device could be retrieved from three out of the four applications. These three applications store patient and device data in plaintext, including passwords. However, analysis of the fourth application evaluated in this experiment has shown that while the iOS version stores information in plaintext, the Android version appears to encrypt artifacts containing patient and therapy details. While all the medical devices included in the controlled experiment are cleared by the FDA, and all the manufacturers claim to be HIPPA compliant; the devices and applications used in this study demonstrate that it is possible to recover plaintext patient-specific and device information from the smartphone applications that interface with these devices.
The escalating integration of network-enabled medical devices raises concerns for both practitioners and academics in terms of introducing new vulnerabilities and attack vectors. This prompts the idea that combining medical device data, security vulnerability enumerations, and attack-modeling data into a single database could enable security analysts to proactively identify potential security weaknesses in medical devices and formulate appropriate mitigation and remediation plans. This study introduces a novel extension to a relational database risk assessment framework by using the open-source tool OVAL to capture device states and compare them to security advisories that warn of threats and vulnerabilities, and where threats and vulnerabilities exist provide mitigation recommendations. The contribution of this research is a proof of concept evaluation that demonstrates the integration of OVAL and CAPEC attack patterns for analysis using a database-driven risk assessment framework.
Conducting digital forensic investigations in a big data distributed file system environment presents significant challenges to an investigator given the high volume of physical data storage space. Presented is an approach from which the Hadoop Distributed File System logical file space is mapped to the physical data location. This approach uses metadata collection and analysis to reconstruct events in a finite time series.
Ray Welland合作论文数Department of Computing Science;University of Glasgow11