Open Access. Powered by Scholars. Published by Universities.®
Forensic Science and Technology Commons™
Open Access. Powered by Scholars. Published by Universities.®
- Institution
-
- Embry-Riddle Aeronautical University (465)
- University of New Haven (58)
- University of Nebraska - Lincoln (20)
- Old Dominion University (5)
- Marshall University (3)
-
- San Jose State University (3)
- University of Central Florida (3)
- Air Force Institute of Technology (1)
- California State University, San Bernardino (1)
- City University of New York (CUNY) (1)
- Eastern Kentucky University (1)
- Harrisburg University of Science and Technology (1)
- Kennesaw State University (1)
- Penn State Dickinson Law (1)
- Washington University in St. Louis (1)
- Keyword
-
- Digital forensics (50)
- Computer forensics (21)
- Forensics (20)
- Digital Forensics (18)
- Digital evidence (15)
-
- Approximate matching (9)
- Computer Forensics (9)
- Mobile device forensics (9)
- Privacy (9)
- Security (9)
- Cyber forensics (8)
- Mrsh-v2 (8)
- Survey (8)
- Android (6)
- Data recovery (6)
- Information security (6)
- Sdhash (6)
- Android forensics (5)
- Cyber crime (5)
- Cyber security (5)
- Data disposal (5)
- Disk analysis (5)
- Mobile forensics (5)
- Network forensics (5)
- Visualization (5)
- Artifacts (4)
- Bloom filter (4)
- Computer crime (4)
- Computer security (4)
- Cryptocurrency (4)
- Publication Year
- Publication
-
- Journal of Digital Forensics, Security and Law (290)
- Annual ADFSL Conference on Digital Forensics, Security and Law (174)
- Electrical & Computer Engineering and Computer Science Faculty Publications (56)
- Nebraska Academy of Sciences: Programs and Proceedings (20)
- Computer Sciences and Electrical Engineering Faculty Research (3)
-
- Electronic Theses and Dissertations (3)
- Library Philosophy and Practice (e-journal) (2)
- Master's Theses (2)
- Computational Modeling & Simulation Engineering Faculty Publications (1)
- Dental Hygiene Theses & Dissertations (1)
- Dickinson Law Review (2017-Present) (1)
- Electronic Theses, Projects, and Dissertations (1)
- Engineering Management & Systems Engineering Faculty Publications (1)
- Harrisburg University Other Works (1)
- International Journal of Aviation, Aeronautics, and Aerospace (1)
- Journal of Cybersecurity Education, Research and Practice (1)
- McKelvey School of Engineering Graduate Student Theses & Dissertations (1)
- Online Theses and Dissertations (1)
- School of Cybersecurity Master's Level Projects and Papers (1)
- Student Theses (1)
- Themis: Research Journal of Justice Studies and Forensic Science (1)
- Theses and Dissertations (1)
- VMASC Publications (1)
- Publication Type
Articles 1 - 30 of 565
Full-Text Articles in Forensic Science and Technology
Stop Blaming My Users: Illumination Of The Technocentric Mythos Bias, Ervin H. Frenzel, Richard Lightcap
Stop Blaming My Users: Illumination Of The Technocentric Mythos Bias, Ervin H. Frenzel, Richard Lightcap
Journal of Cybersecurity Education, Research and Practice
Abstract -This conceptual essay addresses the need for systemic and systematic transdisciplinary analytical techniques within cybersecurity and technical security. This conceptual essay is contingent upon recognition that cybersecurity is not simply technical in nature, it does not need an adversary, and more importantly it is based upon systems engineering and systems thinking. The essay contributes a socio-technical attribution chain and field-specific ontology/taxonomy which distinguish user-triggered events from root causes, latent conditions, technical debt, validation failures, governance failures, and attribution bias before assigning responsibility to end users. It systematically defines an ontology inclusive of developer technical debt, organizational debt arising from …
Program And Proceedings, The Nebraska Academy Of Sciences 1880–2026: 146th Anniversary Year, One Hundred-Thirty-Sixth Annual Meeting
Nebraska Academy of Sciences: Programs and Proceedings
Program and abstracts of the proceedings for the Nebraska Academy of Sciences 136th annual meeting, 2025
Sessions
Aeronautics and Space Science
Anthropology
Biological and Medical Sciences
Earth Sciences
Ecology, Sustainability, and Environmental Science
Physics and Engineering
General Poster Session
2026 Maiben Lecture: Shifting Extremes: Understanding Nebraska’s Changing Climate and Preparing for What Lies Ahead, Deborah Bathke
2026 Friends of Science Awards: Julie Shaffer and Irina Filina
2026 C. Bertrand and Marian Othmer Schultz Colleaguate Schoalrship Award: Piper Ryschon and Bryce Reeson
In Memoriam: Paul Royster
Applications Of Suas Thermal Imaging And Lidar At Letort Spring Garden Preserve: An Independent Study, Kelsey Wardell
Applications Of Suas Thermal Imaging And Lidar At Letort Spring Garden Preserve: An Independent Study, Kelsey Wardell
Harrisburg University Other Works
No abstract provided.
The Psychology Behind Ai-Generated Phishing And Social Engineering Attacks, A’Shya Reynolds
The Psychology Behind Ai-Generated Phishing And Social Engineering Attacks, A’Shya Reynolds
School of Cybersecurity Master's Level Projects and Papers
Cybercrime has evolved significantly with the integration of artificial intelligence (AI), transforming traditional phishing and social engineering attacks into highly sophisticated and personalized threats. While early phishing attempts relied on generic messaging and low success rates, modern AI-driven attacks leverage advanced data analytics, natural language processing, and behavioral prediction to manipulate victims more effectively.
This research examines how cybercriminals utilize AI to enhance psychological manipulation techniques in phishing and social engineering attacks, increasing victim susceptibility. Drawing from interdisciplinary literature in cybersecurity and psychology, this study explores key psychological mechanisms, including cognitive biases, emotional triggers, and decision-making processes that influence victim …
Program And Proceedings: Nebraska Academy Of Sciences 1880–2025, 145th Anniversary Year, One Hundred-Thirty-Fifth Annual Meeting
Nebraska Academy of Sciences: Programs and Proceedings
Program
Aeronautics and Space Science
Biological and Medical Sciences
Biology
Chemistry
Earth Sciences
Science Education
Anthropology
Applied Science and Technology
Physics and Engineering
Forensic Sciences
Ecology, Sustainability, and Environmental Science
Maiben Lecture: Mary Ann Vinton, "State of the Academy"
Friends of Science Awards: David Crouse and Daniel Sitzman
Program And Proceedings: Nebraska Academy Of Sciences 1880–2024, 144th Anniversary Year, One Hundred-Thirty-Fourth Annual Meeting
Nebraska Academy of Sciences: Programs and Proceedings
Program
Aeronautics and Space Science
Aeronautics and Space Science Poster Session
Anthropology: Humans Past and Present
Maiben Lecture: "Platte Basin Timelapse: A Watershed in Motion," Grant Reiner
Applied Science and Technology
Biological Sciences
Biomedical Sciences
Chemistry
Earh Sciences
Environmental Sciences
Physics
Science Education
Cheiloscopy Examination And Classification Of Lip Prints With And Without Parafunctional Oral Habits: A Cross-Sectional Observation Study, Emily Smith Regan
Cheiloscopy Examination And Classification Of Lip Prints With And Without Parafunctional Oral Habits: A Cross-Sectional Observation Study, Emily Smith Regan
Dental Hygiene Theses & Dissertations
Problem: Lip prints are unique and have potential for use as a human identifier. The purpose of this study was to observe possible cheiloscopy differences of individuals with and without parafunctional oral habits. Additionally, inter-rater reliability (IRR) of lip print examiners was observed. Methods: This IRB approved blinded cross-sectional observational study collected lip prints from sixty-six individuals using lipstick and adhesive tape to transfer lip prints to white bond paper for viewing purposes. Each set of included lip prints was divided into quadrants and dichotomized as those with or without an oral parafunctional habit. Each quadrant sample was manually analyzed …
Trace Dna Detection Using Diamond Dye: A Recovery Technique To Yield More Dna, Leah Davis
Trace Dna Detection Using Diamond Dye: A Recovery Technique To Yield More Dna, Leah Davis
Master's Theses
This study aspires to find a new screening approach to trace DNA recovery techniques to yield a higher quantity of trace DNA from larger items of evidence. It takes the path of visualizing trace DNA on items of evidence with potential DNA so analysts can swab a more localized area rather than attempting to recover trace DNA through the general swabbing technique currently used for trace DNA recovery. The first and second parts consisted of observing trace DNA interaction with Diamond Dye on porous and non-porous surfaces.
The third part involved applying the Diamond Dye solution by spraying it onto …
Program And Proceedings: Nebraska Academy Of Sciences 1880–2023, 143rd Anniversary Year, One Hundred-Thirty-Third Annual Meeting, April 21, 2023
Nebraska Academy of Sciences: Programs and Proceedings
Program
Aeronautics and Space Science
Humans Past and Present
Applied Science and Technology Section
Biology
Biomedical Sciences
Chemistry
Earth Sciences
Environmental Science
Physics
Science Education
2023 Maiben Lecture: Jason Bartz
2023 Friend of Science Award: Ray Ward and Jim Lewis
Chatgpt As Metamorphosis Designer For The Future Of Artificial Intelligence (Ai): A Conceptual Investigation, Amarjit Kumar Singh (Library Assistant), Dr. Pankaj Mathur (Deputy Librarian)
Chatgpt As Metamorphosis Designer For The Future Of Artificial Intelligence (Ai): A Conceptual Investigation, Amarjit Kumar Singh (Library Assistant), Dr. Pankaj Mathur (Deputy Librarian)
Library Philosophy and Practice (e-journal)
Abstract
Purpose: The purpose of this research paper is to explore ChatGPT’s potential as an innovative designer tool for the future development of artificial intelligence. Specifically, this conceptual investigation aims to analyze ChatGPT’s capabilities as a tool for designing and developing near about human intelligent systems for futuristic used and developed in the field of Artificial Intelligence (AI). Also with the helps of this paper, researchers are analyzed the strengths and weaknesses of ChatGPT as a tool, and identify possible areas for improvement in its development and implementation. This investigation focused on the various features and functions of ChatGPT that …
The Rise Of Terrorism In Africa And What It Means For U.S. Policymakers, Bridget Mary Hughes
The Rise Of Terrorism In Africa And What It Means For U.S. Policymakers, Bridget Mary Hughes
Master's Theses
This thesis utilizes three case studies to measure the rise of terrorism in Africa. This qualitative data leads the reader to one ultimate question: what does the rise in terrorism in Africa mean for the United States (U.S.) and U.S. policymakers, National Security academia, students in National Security, if anything at all? The answer is: if civilian and military compounds are being targeted by these violent extremists, as these three case studies demonstrate, it is my recommendation that U.S. policymakers cease sending troops to the African theater and, instead, allocate funding to the citizens and nonprofits of the countries whom …
Program And Proceedings: Nebraska Academy Of Sciences 1880–2022, 142nd Anniversary Year, One Hundred-Thirty-Second Annual Meeting, April 22, 2022
Nebraska Academy of Sciences: Programs and Proceedings
Program
Aeronautics and Space Science
Anthropology
Applied Science and Technology
Biological Sciences
Biomedical Sciences
Chemistry
Earth Sciences
Environmental Sciences
Physics
2022 Maiben Lecture: Dan Sitzman
2022 Friend of Science Award: Julie Sigmon and Chris Schaben
Timestamp Estimation From Outdoor Scenes, Tawfiq Salem, Jisoo Hwang, Rafael Padilha
Timestamp Estimation From Outdoor Scenes, Tawfiq Salem, Jisoo Hwang, Rafael Padilha
Annual ADFSL Conference on Digital Forensics, Security and Law
The increasing availability of smartphones allowed people to easily capture and share images on the internet. These images are often associated with metadata, including the image capture time (timestamp) and the location where the image was captured (geolocation). The metadata associated with images provides valuable information to better understand scenes and events presented in these images. The timestamp can be manipulated intentionally to provide false information to convey a twisted version of reality. Images with manipulated timestamps are often used as a cover-up for wrongdoing or broadcasting false claims and competing views on the internet. Estimating the time of capture …
Anatomy Of An Internet Hijack And Interception Attack: A Global And Educational Perspective, Ben A. Scott, Michael N. Johnstone, Patryk Szewczyk
Anatomy Of An Internet Hijack And Interception Attack: A Global And Educational Perspective, Ben A. Scott, Michael N. Johnstone, Patryk Szewczyk
Annual ADFSL Conference on Digital Forensics, Security and Law
The Internet’s underlying vulnerable protocol infrastructure is a rich target for cyber crime, cyber espionage and cyber warfare operations. The stability and security of the Internet infrastructure are important to the function of global matters of state, critical infrastructure, global e-commerce and election systems. There are global approaches to tackle Internet security challenges that include governance, law, educational and technical perspectives. This paper reviews a number of approaches to these challenges, the increasingly surgical attacks that target the underlying vulnerable protocol infrastructure of the Internet, and the extant cyber security education curricula; we find the majority of predominant cyber security …
Deepfakes, Shallowfakes, And The Need For A Private Right Of Action, Eric Kocsis
Deepfakes, Shallowfakes, And The Need For A Private Right Of Action, Eric Kocsis
Dickinson Law Review (2017-Present)
For nearly as long as there have been photographs and videos, people have been editing and manipulating them to make them appear to be something they are not. Usually edited or manipulated photographs are relatively easy to detect, but those days are numbered. Technology has no morality; as it advances, so do the ways it can be misused. The lack of morality is no clearer than with deepfake technology.
People create deepfakes by inputting data sets, most often pictures or videos into a computer. A series of neural networks attempt to mimic the original data set until they are nearly …
A Lightweight Reliably Quantified Deepfake Detection Approach, Tianyi Wang, Kam Pui Chow
A Lightweight Reliably Quantified Deepfake Detection Approach, Tianyi Wang, Kam Pui Chow
Annual ADFSL Conference on Digital Forensics, Security and Law
Deepfake has brought huge threats to society such that everyone can become a potential victim. Current Deepfake detection approaches have unsatisfactory performance in either accuracy or efficiency. Meanwhile, most models are only evaluated on different benchmark test datasets with different accuracies, which could not imitate the real-life Deepfake unknown population. As Deepfake cases have already been raised and brought challenges at the court, it is disappointed that no existing work has studied the model reliability and attempted to make the detection model act as the evidence at the court. We propose a lightweight Deepfake detection deep learning approach using the …
Leveraging Maching Learning In Financial Fraud Forensics In The Age Of Cybersecurity, Md. Ariful Haque, Sachin Shetty
Leveraging Maching Learning In Financial Fraud Forensics In The Age Of Cybersecurity, Md. Ariful Haque, Sachin Shetty
VMASC Publications
Financial sectors are lucrative cyber-attack targets because of their immediate financial gain. As a result, financial institutions face challenges in developing systems that can automatically identify security breaches and separate fraudulent transactions from legitimate transactions. Today, organizations widely use machine learning techniques to identify any fraudulent behavior in customers' transactions. However, machine learning techniques are often challenging because of financial institutions' confidentiality policy, leading to not sharing the customer transaction data. This chapter discusses some crucial challenges of handling cybersecurity and fraud in the financial industry and building machine learning-based models to address those challenges. The authors utilize an open-source …
Core Point Pixel-Level Localization By Fingerprint Features In Spatial Domain, Xueyi Ye, Yuzhong Shen, Maosheng Zeng, Yirui Liu, Huahua Chen, Zhijing Zhao
Core Point Pixel-Level Localization By Fingerprint Features In Spatial Domain, Xueyi Ye, Yuzhong Shen, Maosheng Zeng, Yirui Liu, Huahua Chen, Zhijing Zhao
Computational Modeling & Simulation Engineering Faculty Publications
Singular point detection is a primary step in fingerprint recognition, especially for fingerprint alignment and classification. But in present there are still some problems and challenges such as more false-positive singular points or inaccurate reference point localization. This paper proposes an accurate core point localization method based on spatial domain features of fingerprint images from a completely different viewpoint to improve the fingerprint core point displacement problem of singular point detection. The method first defines new fingerprint features, called furcation and confluence, to represent specific ridge/valley distribution in a core point area, and uses them to extract the innermost Curve …
A Low-Cost Machine Learning Based Network Intrusion Detection System With Data Privacy Preservation, Jyoti Fakirah, Lauhim Mahfuz Zishan, Roshni Mooruth, Michael L. Johnstone, Wencheng Yang
A Low-Cost Machine Learning Based Network Intrusion Detection System With Data Privacy Preservation, Jyoti Fakirah, Lauhim Mahfuz Zishan, Roshni Mooruth, Michael L. Johnstone, Wencheng Yang
Annual ADFSL Conference on Digital Forensics, Security and Law
Network intrusion is a well-studied area of cyber security. Current machine learning-based network intrusion detection systems (NIDSs) monitor network data and the patterns within those data but at the cost of presenting significant issues in terms of privacy violations which may threaten end-user privacy. Therefore, to mitigate risk and preserve a balance between security and privacy, it is imperative to protect user privacy with respect to intrusion data. Moreover, cost is a driver of a machine learning-based NIDS because such systems are increasingly being deployed on resource-limited edge devices. To solve these issues, in this paper we propose a NIDS …
Human-Controlled Fuzzing With Afl, Maxim Grishin, Igor Korkin, Phd
Human-Controlled Fuzzing With Afl, Maxim Grishin, Igor Korkin, Phd
Annual ADFSL Conference on Digital Forensics, Security and Law
Fuzzing techniques are applied to reveal different types of bugs and vulnerabilities. American Fuzzy Lop (AFL) is a free most popular software fuzzer used by many other fuzzing frameworks. AFL supports autonomous mode of operation that uses the previous step output into the next step, as a result fuzzer spends a lot of time analyzing minor code sections. By making fuzzing process more focused and human controlled security expert can save time and find more bugs in less time. We designed a new module that can fuzz only the specified functions. As a result, the chosen ones will be inspected …
The Amorphous Nature Of Hackers: An Exploratory Study, Kento Yasuhara, Daniel Walnycky, Ibrahim Baggili, Ahmed Alhishwan
The Amorphous Nature Of Hackers: An Exploratory Study, Kento Yasuhara, Daniel Walnycky, Ibrahim Baggili, Ahmed Alhishwan
Annual ADFSL Conference on Digital Forensics, Security and Law
In this work, we aim to better understand outsider perspectives of the hacker community through a series of situation based survey questions. By doing this, we hope to gain insight into the overall reputation of hackers from participants in a wide range of technical and non-technical backgrounds. This is important to digital forensics since convicted hackers will be tried by people, each with their own perception of who hackers are. Do cyber crimes and national security issues negatively affect people’s perceptions of hackers? Does hacktivism and information warfare positively affect people’s perception of hackers? Do individual personality factors affect one’s …
Digital Forensics For Mobility As A Service Platform: Analysis Of Uber Application On Iphone And Cloud, Nina Matulis, Umit Karabiyik
Digital Forensics For Mobility As A Service Platform: Analysis Of Uber Application On Iphone And Cloud, Nina Matulis, Umit Karabiyik
Annual ADFSL Conference on Digital Forensics, Security and Law
Uber is a ride-hailing smartphone application (app) that allows users to order a ride in a highly efficient manner. The Uber app provides Mobility as a Service and allows users to easily order a ride in a private car with just a few clicks. Uber stores large amounts of data on both the mobile device the app is being used on, and in the cloud. Examples of this data include geolocation data, date/time, origin/destination addresses, departure/arrival times, and distance. Uber geolocation data has been previously researched to investigate the privacy of the Uber app; however, there is minimal research relating …
Smart Home Forensics: Identifying Ddos Attack Patterns On Iot Devices, Samuel Ho, Hope Greeson, Umit Karabiyik
Smart Home Forensics: Identifying Ddos Attack Patterns On Iot Devices, Samuel Ho, Hope Greeson, Umit Karabiyik
Annual ADFSL Conference on Digital Forensics, Security and Law
Smart homes are becoming more common as more people integrate IoT devices into their home environment. As such, these devices have access to personal data on their homeowners’ networks. One of the advantages of IoT devices is that they are compact. However, this limits the incorporation of security measures in their hardware. Misconfigured IoT devices are commonly the target of malicious attacks. Additionally, distributed denial-of-service attacks are becoming more common due to applications and software that provides users with easy-to-use user interfaces. Since one vulnerable device is all an attacker needs to launch an attack on a network, in regards …
Microsoft Defender Will Be Defended: Memoryranger Prevents Blinding Windows Av, Denis Pogonin, Igor Korkin, Phd
Microsoft Defender Will Be Defended: Memoryranger Prevents Blinding Windows Av, Denis Pogonin, Igor Korkin, Phd
Annual ADFSL Conference on Digital Forensics, Security and Law
Windows OS is facing a huge rise in kernel attacks. An overview of popular techniques that result in loading kernel drivers will be presented. One of the key targets of modern threats is disabling and blinding Microsoft Defender, a default Windows AV. The analysis of recent driver-based attacks will be given, the challenge is to block them. The survey of user- and kernel-level attacks on Microsoft Defender will be given. One of the recently published attackers’ techniques abuses Mandatory Integrity Control (MIC) and Security Reference Monitor (SRM) by modifying Integrity Level and Debug Privileges for the Microsoft Defender via syscalls. …
Detection Of Overlapping Passive Manipulation Techniques In Image Forensics, Gianna S. Lint, Umit Karabiyik
Detection Of Overlapping Passive Manipulation Techniques In Image Forensics, Gianna S. Lint, Umit Karabiyik
Annual ADFSL Conference on Digital Forensics, Security and Law
With a growing number of images uploaded daily to social media sites, it is essential to understand if an image can be used to trace its origin. Forensic investigations are focusing on analyzing images that are uploaded to social media sites resulting in an emphasis on building and validating tools. There has been a strong focus on understanding active manipulation or tampering techniques and building tools for analysis. However, research on manipulation is often studied in a vacuum, involving only one technique at a time. Additionally, less focus has been placed on passive manipulation, which can occur by simply uploading …
Integration Of Blockchain Technology Into Automobiles To Prevent And Study The Causes Of Accidents, John Kim
Integration Of Blockchain Technology Into Automobiles To Prevent And Study The Causes Of Accidents, John Kim
Electronic Theses, Projects, and Dissertations
Automobile collisions occur daily. We now live in an information-driven world, one where technology is quickly evolving. Blockchain technology can change the automotive industry, the safety of the motoring public and its surrounding environment by incorporating this vast array of information. It can place safety and efficiency at the forefront to pedestrians, public establishments, and provide public agencies with pertinent information securely and efficiently. Other industries where Blockchain technology has been effective in are as follows: supply chain management, logistics, and banking. This paper reviews some statistical information regarding automobile collisions, Blockchain technology, Smart Contracts, Smart Cities; assesses the feasibility …
Forensic Artifact Finder (Forensicaf): An Approach & Tool For Leveraging Crowd-Sourced Curated Forensic Artifacts, Tyler Balon, Krikor Herlopian, Ibrahim Baggili, Cinthya Grajeda-Mendez
Forensic Artifact Finder (Forensicaf): An Approach & Tool For Leveraging Crowd-Sourced Curated Forensic Artifacts, Tyler Balon, Krikor Herlopian, Ibrahim Baggili, Cinthya Grajeda-Mendez
Electrical & Computer Engineering and Computer Science Faculty Publications
Current methods for artifact analysis and understanding depend on investigator expertise. Experienced and technically savvy examiners spend a lot of time reverse engineering applications while attempting to find crumbs they leave behind on systems. This takes away valuable time from the investigative process, and slows down forensic examination. Furthermore, when specific artifact knowledge is gained, it stays within the respective forensic units. To combat these challenges, we present ForensicAF, an approach for leveraging curated, crowd-sourced artifacts from the Artifact Genome Project (AGP). The approach has the overarching goal of uncovering forensically relevant artifacts from storage media. We explain our approach …
Forensicast: A Non-Intrusive Approach & Tool For Logical Forensic Acquisition & Analysis Of The Google Chromecast Tv, Alex Sitterer, Nicholas Dubois, Ibrahim Baggili
Forensicast: A Non-Intrusive Approach & Tool For Logical Forensic Acquisition & Analysis Of The Google Chromecast Tv, Alex Sitterer, Nicholas Dubois, Ibrahim Baggili
Electrical & Computer Engineering and Computer Science Faculty Publications
The era of traditional cable Television (TV) is swiftly coming to an end. People today subscribe to a multitude of streaming services. Smart TVs have enabled a new generation of entertainment, not only limited to constant on-demand streaming as they now offer other features such as web browsing, communication, gaming etc. These functions have recently been embedded into a small IoT device that can connect to any TV with High Definition Multimedia Interface (HDMI) input known as Google Chromecast TV. Its wide adoption makes it a treasure trove for potential digital evidence. Our work is the primary source on forensically …
Duck Hunt: Memory Forensics Of Usb Attack Platforms, Tyler Thomas, Mathew Piscitelli, Bhavik Ashok Nahar, Ibrahim Baggili
Duck Hunt: Memory Forensics Of Usb Attack Platforms, Tyler Thomas, Mathew Piscitelli, Bhavik Ashok Nahar, Ibrahim Baggili
Electrical & Computer Engineering and Computer Science Faculty Publications
To explore the memory forensic artifacts generated by USB-based attack platforms, we analyzed two of the most popular commercially available devices, Hak5's USB Rubber Ducky and Bash Bunny. We present two open source Volatility plugins, usbhunt and dhcphunt, which extract artifacts generated by these USB attacks from Windows 10 system memory images. Such artifacts include driver-related diagnostic events, unique device identifiers, and DHCP client logs. Our tools are capable of extracting metadata-rich Windows diagnostic events generated by any USB device. The device identifiers presented in this work may also be used to definitively detect device usage. Likewise, the DHCP logs …
Another Brick In The Wall: An Exploratory Analysis Of Digital Forensics Programs In The United States, Syria Mccullough, Stella Abudu, Ebere Onwubuariri, Ibrahim Baggili
Another Brick In The Wall: An Exploratory Analysis Of Digital Forensics Programs In The United States, Syria Mccullough, Stella Abudu, Ebere Onwubuariri, Ibrahim Baggili
Electrical & Computer Engineering and Computer Science Faculty Publications
We present a comprehensive review of digital forensics programs offered by universities across the United States (U.S.). While numerous studies on digital forensics standards and curriculum exist, few, if any, have examined digital forensics courses offered across the nation. Since digital forensics courses vary from university to university, online course catalogs for academic institutions were evaluated to curate a dataset. Universities were selected based on online searches, similar to those that would be made by prospective students. Ninety-seven (n = 97) degree programs in the U.S. were evaluated. Overall, results showed that advanced technical courses are missing from curricula. We …