Lawful Remote Forensics Mechanism With Admissibility of Evidence in Stochastic and Unpredictable Transnational Crime
Chit-Jie Chew,Wei-Bin Lee,Tzu-Li Sung,Ying-Chin Chen,Shiuh-Jeng Wang,Jung-San Lee
DOI: https://doi.org/10.1109/tifs.2024.3368888
IF: 7.231
2024-06-07
IEEE Transactions on Information Forensics and Security
Abstract:Traditional industries rapidly transcend the time and place restrictions of the country according to the technology growth by leaps and bounds over the year. Regrettably, international cybercrime incidents simultaneously explode by 2,400 million from 2020 to 2021. Undoubtedly, the real-time incident response has become the primary subject of incident handling. In this article, we aim to propose lawful remote forensics mechanism for ensuring the optimal protection of potential evidence in stochastic and unpredictable transnational crime. Meanwhile, the entire process can be performed remotely and compliant with legal requirements, such as ISO/IEC and NIST regulations. Specifically, all the procedures can be retroactive based on the design of the chain of custody, which leads to the proof of evidence admissibility. Aside from the security essential confirmation by the formal tools Proverif, AVISPA, and Scyther, simulation results have demonstrated that remote forensics can fulfill the legal requirements and perform excellently in various incident scales.
computer science, theory & methods,engineering, electrical & electronic