[Paper Review] Evaluation of Digital Forensic Process Models with Respect to Digital Forensics as a Service
This paper evaluates existing digital forensic process models to assess their applicability to a cloud-based Digital Forensics as a Service (DFaaS) paradigm and cloud evidence processing.
Digital forensic science is very much still in its infancy, but is becoming increasingly invaluable to investigators. A popular area for research is seeking a standard methodology to make the digital forensic process accurate, robust, and efficient. The first digital forensic process model proposed contains four steps: Acquisition, Identification, Evaluation and Admission. Since then, numerous process models have been proposed to explain the steps of identifying, acquiring, analysing, storage, and reporting on the evidence obtained from various digital devices. In recent years, an increasing number of more sophisticated process models have been proposed. These models attempt to speed up the entire investigative process or solve various of problems commonly encountered in the forensic investigation. In the last decade, cloud computing has emerged as a disruptive technological concept, and most leading enterprises such as IBM, Amazon, Google, and Microsoft have set up their own cloud-based services. In the field of digital forensic investigation, moving to a cloud-based evidence processing model would be extremely beneficial and preliminary attempts have been made in its implementation. Moving towards a Digital Forensics as a Service model would not only expedite the investigative process, but can also result in significant cost savings - freeing up digital forensic experts and law enforcement personnel to progress their caseload. This paper aims to evaluate the applicability of existing digital forensic process models and analyse how each of these might apply to a cloud-based evidence processing paradigm.
Motivation & Objective
- Assess the state of digital forensic process models and their ability to support a cloud-based DFaaS paradigm.
- Analyze how traditional processes map to cloud-enabled evidence processing and service-oriented workflows.
- Identify potential benefits and challenges of adopting DFaaS in investigative workflows.
Proposed method
- Review and critique of established digital forensic process models with respect to DFaaS requirements.
- Analysis of the impact of cloud computing on evidence handling, processing, and service delivery.
- Conceptual assessment of how process steps (acquisition, identification, analysis, storage, reporting) align with cloud-based processing.
Experimental results
Research questions
- RQ1How well do existing digital forensic process models align with a Digital Forensics as a Service (DFaaS) approach?
- RQ2What are the potential benefits and limitations of moving digital forensic workflows to a cloud-based service model?
- RQ3Which process model steps are most affected by cloud-enabled evidence processing?
- RQ4What considerations are necessary to implement cloud-based DFaaS in practice?
Key findings
- Existing process models provide foundational structures but require adaptation for cloud-based processing.
- DFaaS can expedite investigations and offer cost savings through cloud-enabled evidence processing.
- Adoption of cloud-based DFaaS entails considerations around efficiency, security, and governance in the forensic workflow.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.