Leveraging CybOX™ to standardize representation and exchange of digital forensic information

被引:48
作者
Casey, Eoghan [1 ]
Back, Greg [1 ]
Barnum, Sean [1 ]
机构
[1] Mitre Corp, Mclean, VA 22102 USA
关键词
Digital forensics; Standard representation; Digital forensic ontology; Digital forensic XML; CybOX; DFXML; DFAX; PROVENANCE;
D O I
10.1016/j.diin.2015.01.014
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
With the growing number of digital forensic tools and the increasing use of digital forensics in various contexts, including incident response and cyber threat intelligence, there is a pressing need for a widely accepted standard for representing and exchanging digital forensic information. Such a standard representation can support correlation between different data sources, enabling more effective and efficient querying and analysis of digital evidence. This work summarizes the strengths and weaknesses of existing schemas, and proposes the open-source CybOX schema as a foundation for storing and sharing digital forensic information. The suitability of CybOX for representing objects and relationships that are common in forensic investigations is demonstrated with examples involving digital evidence. The capability to represent provenance by leveraging CybOX is also demonstrated, including specifics of the tool used to process digital evidence and the resulting output. An example is provided of an ongoing project that uses CybOX to record the state of a system before and after an event in order to capture cause and effect information that can be useful for digital forensics. An additional open-source schema and associated ontology called Digital Forensic Analysis eXpression (DFAX) is proposed that provides a layer of domain specific information overlaid on CybOX. DFAX extends the capability of CybOX to represent more abstract forensic-relevant actions, including actions performed by subjects and by forensic examiners, which can be useful for sharing knowledge and supporting more advanced forensic analysis. DFAX can be used in combination with other existing schemas for representing identity information (CIQ), and location information (KML). This work also introduces and leverages initial steps of a Unified Cyber Ontology (UCO) effort to abstract and express concepts/constructs that are common across the cyber domain. (C) 2015 The Authors. Published by Elsevier Ltd.
引用
收藏
页码:S102 / S110
页数:9
相关论文
共 21 条
[1]   XIRAF - XML-based indexing and querying for digital forensics [J].
Alink, W. ;
Bhoedjang, R. A. F. ;
Boncz, P. A. ;
de Vries, A. P. .
DIGITAL INVESTIGATION, 2006, :S50-S58
[2]  
Barnum S., 2012, STRUCTURED THREAT IN
[3]  
Bhoedjang RAF, 2012, DIGITAL INVESTIGATIO, V9
[4]  
Casey E, 2013, DIGIT INVESTIG, V10
[5]  
Casey E., 2013, THESIS U COLL DUBLIN
[6]  
Cohen M, 2013, DIGIT INVESTIG, V10
[7]   Extending the advanced forensic format to accommodate multiple data sources, logical evidence, arbitrary information and forensic workflow [J].
Cohen, Michael ;
Garfinkel, Simson ;
Schatz, Bradley .
DIGITAL INVESTIGATION, 2009, 6 :S57-S68
[8]  
Eaglin R., 2005, 1 ANN GJXDM US C ATL
[9]   Storage and exchange formats for digital evidence [J].
Flaglien, Anders O. ;
Mallasvik, Aleksander ;
Mustorp, Magnus ;
Arnes, Andre .
DIGITAL INVESTIGATION, 2011, 8 (02) :122-128
[10]   Digital forensics XML and the DFXML toolset [J].
Garfinkel, Simson .
DIGITAL INVESTIGATION, 2012, 8 (3-4) :161-174