Skip to main content
Top

2024 | OriginalPaper | Chapter

Forensic-Ready Analysis Suite: A Tool Support for Forensic-Ready Software Systems Design

Authors : Lukas Daubner, Sofija Maksović, Raimundas Matulevičius, Barbora Buhnova, Tomás̆ Sedlác̆ek

Published in: Research Challenges in Information Science

Publisher: Springer Nature Switzerland

Activate our intelligent search to find suitable subject content or patents.

search-config
loading …

Abstract

Forensic-ready software systems integrate preparedness for digital forensic investigation into their design. It includes ensuring the production of potential evidence with sufficient coverage and quality to improve the odds of successful investigation or admissibility. However, the design of such software systems is challenging without in-depth forensic readiness expertise. Thus, this paper presents a tool suite to help the designer. It includes a graphical editor for creating system models in BPMN4FRSS notation, an extended BPMN with forensic readiness constructs, and an analyser utilising Z3 solver for satisfiability checking of formulas derived from the models. It verifies the models’ validity, provides targeted hints to enhance forensic readiness capabilities, and allows for what-if analysis of potential evidence quality.

Dont have a licence yet? Then find out more about our products and how to get one now:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Footnotes
1
Note the difference: potential digital evidence – potentially useable for future investigation, and digital evidence – used to satisfy or refute the investigation hypothesis.
 
2
The documentation is available at: https://​freas-tools.​github.​io/​wiki/​.
 
3
Code, models, and a video demo are available at: https://​doi.​org/​10.​58126/​bcxs-cr23.
 
Literature
1.
go back to reference Bjørner, N., de Moura, L., Nachmanson, L., Wintersteiger, C.M.: Programming Z3, pp. 148–201. Springer, Cham (2019) Bjørner, N., de Moura, L., Nachmanson, L., Wintersteiger, C.M.: Programming Z3, pp. 148–201. Springer, Cham (2019)
3.
go back to reference CESG: Good Practice Guide No. 18: Forensic Readiness. Guideline, National Technical Authority for Information Assurance, United Kingdom (2015) CESG: Good Practice Guide No. 18: Forensic Readiness. Guideline, National Technical Authority for Information Assurance, United Kingdom (2015)
4.
go back to reference Daubner, L., Macak, M., Matulevic̆ius, R., Buhnova, B., Maksović, S., Pitner, T.: Addressing insider attacks via forensic-ready risk management. J. Inf. Secur. Appl. 73, 103433 (2023) Daubner, L., Macak, M., Matulevic̆ius, R., Buhnova, B., Maksović, S., Pitner, T.: Addressing insider attacks via forensic-ready risk management. J. Inf. Secur. Appl. 73, 103433 (2023)
7.
go back to reference Daubner, L., Matulevičius, R.: Risk-oriented design approach for forensic-ready software systems. In: The 16th International Conference on Availability, Reliability and Security. ACM (2021) Daubner, L., Matulevičius, R.: Risk-oriented design approach for forensic-ready software systems. In: The 16th International Conference on Availability, Reliability and Security. ACM (2021)
8.
go back to reference Dzurenda, P., et al.: Privacy-preserving solution for vehicle parking services complying with EU legislation. PeerJ Comput. Sci. 8, e1165 (2022)CrossRef Dzurenda, P., et al.: Privacy-preserving solution for vehicle parking services complying with EU legislation. PeerJ Comput. Sci. 8, e1165 (2022)CrossRef
9.
go back to reference Erol-Kantarci, M., Mouftah, H.T.: Smart grid forensic science: applications, challenges, and open issues. IEEE Commun. Mag. 51(1), 68–74 (2013)CrossRef Erol-Kantarci, M., Mouftah, H.T.: Smart grid forensic science: applications, challenges, and open issues. IEEE Commun. Mag. 51(1), 68–74 (2013)CrossRef
10.
go back to reference Grispos, G., Glisson, W.B., Choo, K.K.R.: Medical cyber-physical systems development: a forensics-driven approach. In: IEEE/ACM International Conference on Connected Health: Applications, Systems and Engineering Technologies, pp. 108–113 (2017) Grispos, G., Glisson, W.B., Choo, K.K.R.: Medical cyber-physical systems development: a forensics-driven approach. In: IEEE/ACM International Conference on Connected Health: Applications, Systems and Engineering Technologies, pp. 108–113 (2017)
15.
go back to reference Moura, L.D., Bjørner, N.: Z3: an efficient SMT solver. In: Proceedings of the Theory and Practice of Software, 14th International Conference on Tools and Algorithms for the Construction and Analysis of Systems, pp. 337–340 (2008) Moura, L.D., Bjørner, N.: Z3: an efficient SMT solver. In: Proceedings of the Theory and Practice of Software, 14th International Conference on Tools and Algorithms for the Construction and Analysis of Systems, pp. 337–340 (2008)
16.
go back to reference Pasquale, L., Alrajeh, D., Peersman, C., Tun, T., Nuseibeh, B., Rashid, A.: Towards forensic-ready software systems. In: Proceedings of the 40th International Conference on Software Engineering: NIER, pp. 9–12. ACM (2018) Pasquale, L., Alrajeh, D., Peersman, C., Tun, T., Nuseibeh, B., Rashid, A.: Towards forensic-ready software systems. In: Proceedings of the 40th International Conference on Software Engineering: NIER, pp. 9–12. ACM (2018)
17.
go back to reference Pasquale, L., Spoletini, P., Salehie, M., Cavallaro, L., Nuseibeh, B.: Automating trade-off analysis of security requirements. Requirements Eng. 21(4), 481–504 (2016)CrossRef Pasquale, L., Spoletini, P., Salehie, M., Cavallaro, L., Nuseibeh, B.: Automating trade-off analysis of security requirements. Requirements Eng. 21(4), 481–504 (2016)CrossRef
19.
go back to reference Rivera-Ortiz, F., Pasquale, L.: Automated modelling of security incidents to represent logging requirements in software systems. In: Proceedings of the 15th International Conference on Availability, Reliability and Security. ACM (2020) Rivera-Ortiz, F., Pasquale, L.: Automated modelling of security incidents to represent logging requirements in software systems. In: Proceedings of the 15th International Conference on Availability, Reliability and Security. ACM (2020)
20.
go back to reference Rowlingson, R.: A ten step process for forensic readiness. Int. J. Digit. Evid. 2, 1–28 (2004) Rowlingson, R.: A ten step process for forensic readiness. Int. J. Digit. Evid. 2, 1–28 (2004)
22.
go back to reference Simou, S., Kalloniatis, C., Gritzalis, S., Katos, V.: A framework for designing cloud forensic-enabled services (CFES). Requirements Eng. 24(3), 403–430 (2019)CrossRef Simou, S., Kalloniatis, C., Gritzalis, S., Katos, V.: A framework for designing cloud forensic-enabled services (CFES). Requirements Eng. 24(3), 403–430 (2019)CrossRef
23.
go back to reference Tan, J.: Forensic readiness. Technical report, @stake, Inc. (2001) Tan, J.: Forensic readiness. Technical report, @stake, Inc. (2001)
Metadata
Title
Forensic-Ready Analysis Suite: A Tool Support for Forensic-Ready Software Systems Design
Authors
Lukas Daubner
Sofija Maksović
Raimundas Matulevičius
Barbora Buhnova
Tomás̆ Sedlác̆ek
Copyright Year
2024
DOI
https://doi.org/10.1007/978-3-031-59468-7_6

Premium Partner