{"id":297,"date":"2015-10-12T21:38:58","date_gmt":"2015-10-13T02:38:58","guid":{"rendered":"https:\/\/fbreitinger.de\/?page_id=297"},"modified":"2021-08-17T07:27:30","modified_gmt":"2021-08-17T12:27:30","slug":"all-publications-by-year","status":"publish","type":"page","link":"https:\/\/fbreitinger.de\/?page_id=297","title":{"rendered":"All publications by year"},"content":{"rendered":"<div class=\"teachpress_pub_list\"><form name=\"tppublistform\" method=\"get\"><a name=\"tppubs\" id=\"tppubs\"><\/a><div class=\"tp_search_input\"><input type=\"hidden\" name=\"p\" id=\"page_id\" value=\"297\"\/><input name=\"tsr\" id=\"tp_search_input_field\" type=\"search\" placeholder=\"Enter search word\" value=\"\" tabindex=\"1\"\/><div class=\"teachpress_search_button\"><input name=\"tps_button\" class=\"tp_search_button\" type=\"submit\" tabindex=\"10\" value=\"Search\"\/><\/div><\/div><\/form><div class=\"tablenav\"><div class=\"tablenav-pages\"><span class=\"displaying-num\">120 entries<\/span> <a class=\"page-numbers button disabled\">&laquo;<\/a> <a class=\"page-numbers button disabled\">&lsaquo;<\/a> 1 of 3 <a href=\"https:\/\/fbreitinger.de\/?page_id=297&amp;limit=2&amp;tgid=&amp;yr=&amp;type=&amp;usr=&amp;auth=&amp;tsr=\" title=\"next page\" class=\"page-numbers button\">&rsaquo;<\/a> <a href=\"https:\/\/fbreitinger.de\/?page_id=297&amp;limit=3&amp;tgid=&amp;yr=&amp;type=&amp;usr=&amp;auth=&amp;tsr=\" title=\"last page\" class=\"page-numbers button\">&raquo;<\/a> <\/div><\/div><table class=\"teachpress_publication_list\"><tr class=\"tp_publication tp_publication_inproceedings\"><td class=\"tp_pub_number\">1.<\/td><td class=\"tp_pub_info\"><p class=\"tp_pub_author\"> K\u00fclper, Michael;  Hilgert, Jan-Niclas;  Breitinger, Frank;  Lambertz, Martin<\/p><p class=\"tp_pub_title\"><a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('950','tp_links')\" style=\"cursor:pointer;\">What's Next, Cloud? A Forensic Framework for Analyzing Self-hosted Cloud Storage Solutions<\/a> (<span class=\"tp_pub_type tp_  inproceedings\">Proceedings Article<\/span>)<\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_in\">In: <\/span> Choo, Kim-Kwang Raymond;  Perez-Pons, Alexander;  Upadhyay, Himanshu;  Lu, Rongxing;  Chow, Kam Pui (Ed.): <span class=\"tp_pub_additional_booktitle\">Digital Forensics and Cyber Crime, <\/span><span class=\"tp_pub_additional_pages\">pp. 241\u2013263, <\/span><span class=\"tp_pub_additional_publisher\">Springer Nature Switzerland, <\/span><span class=\"tp_pub_additional_address\">Cham, <\/span><span class=\"tp_pub_additional_year\">2026<\/span>, <span class=\"tp_pub_additional_isbn\">ISBN: 978-3-032-22542-9<\/span>.<\/p><p class=\"tp_pub_menu\">(<span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_950\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('950','tp_abstract')\" title=\"Show abstract\" style=\"cursor:pointer;\">Abstract<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_950\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('950','tp_links')\" title=\"Show links and resources\" style=\"cursor:pointer;\">Links<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_950\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('950','tp_bibtex')\" title=\"Show BibTeX entry\" style=\"cursor:pointer;\">BibTeX<\/a><\/span>)<\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_950\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@inproceedings{10.1007\/978-3-032-22542-9_15,<br \/>\r\ntitle = {What's Next, Cloud? A Forensic Framework for Analyzing Self-hosted Cloud Storage Solutions},<br \/>\r\nauthor = {Michael K\u00fclper and Jan-Niclas Hilgert and Frank Breitinger and Martin Lambertz},<br \/>\r\neditor = {Kim-Kwang Raymond Choo and Alexander Perez-Pons and Himanshu Upadhyay and Rongxing Lu and Kam Pui Chow},<br \/>\r\ndoi = {10.1007\/978-3-032-22542-9_15},<br \/>\r\nisbn = {978-3-032-22542-9},<br \/>\r\nyear  = {2026},<br \/>\r\ndate = {2026-07-17},<br \/>\r\nbooktitle = {Digital Forensics and Cyber Crime},<br \/>\r\npages = {241\u2013263},<br \/>\r\npublisher = {Springer Nature Switzerland},<br \/>\r\naddress = {Cham},<br \/>\r\nabstract = {Self-hosted cloud storage platforms like Nextcloud are gaining popularity among individuals and organizations seeking greater control over their data. However, this shift introduces new challenges for digital forensic investigations, particularly in systematically analyzing both client and server components. Despite Nextcloud's widespread use, it has received limited attention in forensic research. In this work, we critically examine existing cloud storage forensic frameworks and highlight their limitations. To address the gaps, we propose an extended forensic framework that incorporates device monitoring and leverages cloud APIs for structured, repeatable evidence acquisition. Using Nextcloud as a case study, we demonstrate how its native APIs can be used to reliably access forensic artifacts, and we introduce an open-source acquisition tool that implements this approach. Our framework equips investigators with a more flexible method for analyzing self-hosted cloud storage systems, and offers a foundation for further development in this evolving area of digital forensics.},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {inproceedings}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('950','tp_bibtex')\">Close<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_950\" style=\"display:none;\"><div class=\"tp_abstract_entry\">Self-hosted cloud storage platforms like Nextcloud are gaining popularity among individuals and organizations seeking greater control over their data. However, this shift introduces new challenges for digital forensic investigations, particularly in systematically analyzing both client and server components. Despite Nextcloud's widespread use, it has received limited attention in forensic research. In this work, we critically examine existing cloud storage forensic frameworks and highlight their limitations. To address the gaps, we propose an extended forensic framework that incorporates device monitoring and leverages cloud APIs for structured, repeatable evidence acquisition. Using Nextcloud as a case study, we demonstrate how its native APIs can be used to reliably access forensic artifacts, and we introduce an open-source acquisition tool that implements this approach. Our framework equips investigators with a more flexible method for analyzing self-hosted cloud storage systems, and offers a foundation for further development in this evolving area of digital forensics.<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('950','tp_abstract')\">Close<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_950\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"ai ai-doi\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/dx.doi.org\/10.1007\/978-3-032-22542-9_15\" title=\"Follow DOI:10.1007\/978-3-032-22542-9_15\" target=\"_blank\">doi:10.1007\/978-3-032-22542-9_15<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('950','tp_links')\">Close<\/a><\/p><\/div><\/td><\/tr><tr class=\"tp_publication tp_publication_article\"><td class=\"tp_pub_number\">2.<\/td><td class=\"tp_pub_info\"><p class=\"tp_pub_author\"> Herrmann, Jessica;  Breitinger, Frank<\/p><p class=\"tp_pub_title\"><a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('946','tp_links')\" style=\"cursor:pointer;\">KI in der Rechtspr\u00fcfung: Warum XAI allein nicht ausreicht<\/a> (<span class=\"tp_pub_type tp_  article\">Journal Article<\/span>)<\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_in\">In: <\/span><span class=\"tp_pub_additional_journal\">SIAK-Journal \u2212Zeitschrift f\u00fcr Polizeiwissenschaft und polizeiliche Praxis, <\/span><span class=\"tp_pub_additional_volume\">vol. 23, <\/span><span class=\"tp_pub_additional_number\">no. 1, <\/span><span class=\"tp_pub_additional_pages\">pp. 85-101, <\/span><span class=\"tp_pub_additional_year\">2026<\/span>, <span class=\"tp_pub_additional_isbn\">ISBN: 1813-3495<\/span>.<\/p><p class=\"tp_pub_menu\">(<span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_946\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('946','tp_abstract')\" title=\"Show abstract\" style=\"cursor:pointer;\">Abstract<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_946\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('946','tp_links')\" title=\"Show links and resources\" style=\"cursor:pointer;\">Links<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_946\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('946','tp_bibtex')\" title=\"Show BibTeX entry\" style=\"cursor:pointer;\">BibTeX<\/a><\/span>)<\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_946\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@article{herrmann2026siak,<br \/>\r\ntitle = {KI in der Rechtspr\u00fcfung: Warum XAI allein nicht ausreicht},<br \/>\r\nauthor = {Jessica Herrmann AND Frank Breitinger},<br \/>\r\nurl = {https:\/\/www.bmi.gv.at\/104\/Wissenschaft_und_Forschung\/SIAK-Journal\/SIAK-Journal-Ausgaben\/Jahrgang_2026\/files\/Herrmann_1_2026.pdf},<br \/>\r\ndoi = {10.7396\/2026_1_G},<br \/>\r\nisbn = {1813-3495},<br \/>\r\nyear  = {2026},<br \/>\r\ndate = {2026-04-01},<br \/>\r\njournal = {SIAK-Journal \u2212Zeitschrift f\u00fcr Polizeiwissenschaft und polizeiliche Praxis},<br \/>\r\nvolume = {23},<br \/>\r\nnumber = {1},<br \/>\r\npages = {85-101},<br \/>\r\nedition = {3\/2026},<br \/>\r\nabstract = {Die juristische Subsumtion gilt seit jeher als Pr\u00fcfstein f\u00fcr die Leistungsf\u00e4higkeit moderner KI-Systeme. Trotz jahrzehntelanger Forschung gelingt es bislang kaum, juristische Pr\u00fcfschritte in ihrer dogmatischen Tiefe maschinell abzubilden. Fr\u00fche Expertensysteme scheiterten an starren Formalisierungen, aktuelle Sprachmodelle er\u00f6ffnen zwar neue M\u00f6glichkeiten, doch ihre Argumentationslogik bleibt probabilistisch und rechtlich nur eingeschr\u00e4nkt nachvollziehbar. Hier zeigt sich die Spannung zwischen technischer Leistungsf\u00e4higkeit und normativer Strukturtreue. KI-Modelle k\u00f6nnen plausibel klingende Texte erzeugen, ohne eine systematische Pr\u00fcfstruktur einzuhalten. Vor diesem Hintergrund stellt sich die Frage: Was fehlt noch zum KI-Richter und womit m\u00fcssen wir uns befassen, um eine rechtsstaatliche Einf\u00fchrung zu erm\u00f6glichen? Die meisten Verfahren der \u201eExplainable AI``(\u201eerkl\u00e4rbare KI``, XAI) liefern bislang lediglich technische Transparenz, nicht aber eine rechtsstaatlich tragf\u00e4hige Begr\u00fcndung im Sinne einer \u201eExplainability by Design``. Ein juristisch normiertes Lastenheft kann hier Ma\u00dfst\u00e4be setzen, indem es Anforderungen an Pr\u00fcfschritte, Alternativdarstellungen, Protokollierung und Zielgruppenad\u00e4quanz definiert. Dieser Artikel stellt den aktuellen Forschungsstand entlang von f\u00fcnf methodischen Hauptlinien dar: regelbasierte Systeme, sprachmodellbasierte Ans\u00e4tze, fall- und vektorbasierte Verfahren, wissensrepr\u00e4sentationsbasierte Modelle sowie hybride Architekturen und diskutiert ihre jeweiligen St\u00e4rken und Grenzen im Hinblick auf Transparenz, Flexibilit\u00e4t und dogmatische Steuerbarkeit. Im Zentrum steht die These, dass nur Systeme, die von vornherein so konstruiert sind, dass jeder Subsumtionsschritt explizit nachvollziehbar bleibt, perspektivisch als eigenst\u00e4ndige Entscheidungsinstanz diskutiert werden k\u00f6nnen.},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {article}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('946','tp_bibtex')\">Close<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_946\" style=\"display:none;\"><div class=\"tp_abstract_entry\">Die juristische Subsumtion gilt seit jeher als Pr\u00fcfstein f\u00fcr die Leistungsf\u00e4higkeit moderner KI-Systeme. Trotz jahrzehntelanger Forschung gelingt es bislang kaum, juristische Pr\u00fcfschritte in ihrer dogmatischen Tiefe maschinell abzubilden. Fr\u00fche Expertensysteme scheiterten an starren Formalisierungen, aktuelle Sprachmodelle er\u00f6ffnen zwar neue M\u00f6glichkeiten, doch ihre Argumentationslogik bleibt probabilistisch und rechtlich nur eingeschr\u00e4nkt nachvollziehbar. Hier zeigt sich die Spannung zwischen technischer Leistungsf\u00e4higkeit und normativer Strukturtreue. KI-Modelle k\u00f6nnen plausibel klingende Texte erzeugen, ohne eine systematische Pr\u00fcfstruktur einzuhalten. Vor diesem Hintergrund stellt sich die Frage: Was fehlt noch zum KI-Richter und womit m\u00fcssen wir uns befassen, um eine rechtsstaatliche Einf\u00fchrung zu erm\u00f6glichen? Die meisten Verfahren der \u201eExplainable AI``(\u201eerkl\u00e4rbare KI``, XAI) liefern bislang lediglich technische Transparenz, nicht aber eine rechtsstaatlich tragf\u00e4hige Begr\u00fcndung im Sinne einer \u201eExplainability by Design``. Ein juristisch normiertes Lastenheft kann hier Ma\u00dfst\u00e4be setzen, indem es Anforderungen an Pr\u00fcfschritte, Alternativdarstellungen, Protokollierung und Zielgruppenad\u00e4quanz definiert. Dieser Artikel stellt den aktuellen Forschungsstand entlang von f\u00fcnf methodischen Hauptlinien dar: regelbasierte Systeme, sprachmodellbasierte Ans\u00e4tze, fall- und vektorbasierte Verfahren, wissensrepr\u00e4sentationsbasierte Modelle sowie hybride Architekturen und diskutiert ihre jeweiligen St\u00e4rken und Grenzen im Hinblick auf Transparenz, Flexibilit\u00e4t und dogmatische Steuerbarkeit. Im Zentrum steht die These, dass nur Systeme, die von vornherein so konstruiert sind, dass jeder Subsumtionsschritt explizit nachvollziehbar bleibt, perspektivisch als eigenst\u00e4ndige Entscheidungsinstanz diskutiert werden k\u00f6nnen.<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('946','tp_abstract')\">Close<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_946\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"fas fa-file-pdf\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/www.bmi.gv.at\/104\/Wissenschaft_und_Forschung\/SIAK-Journal\/SIAK-Journal-Ausgaben\/Jahrgang_2026\/files\/Herrmann_1_2026.pdf\" title=\"https:\/\/www.bmi.gv.at\/104\/Wissenschaft_und_Forschung\/SIAK-Journal\/SIAK-Journal-A[...]\" target=\"_blank\">https:\/\/www.bmi.gv.at\/104\/Wissenschaft_und_Forschung\/SIAK-Journal\/SIAK-Journal-A[...]<\/a><\/li><li><i class=\"ai ai-doi\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/dx.doi.org\/10.7396\/2026_1_G\" title=\"Follow DOI:10.7396\/2026_1_G\" target=\"_blank\">doi:10.7396\/2026_1_G<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('946','tp_links')\">Close<\/a><\/p><\/div><\/td><\/tr><tr class=\"tp_publication tp_publication_article\"><td class=\"tp_pub_number\">3.<\/td><td class=\"tp_pub_info\"><p class=\"tp_pub_author\"> Michelet, Ga\u00ebtan;  Schneider, Janine;  Withanage, Aruna;  Breitinger, Frank<\/p><p class=\"tp_pub_title\"><a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('947','tp_links')\" style=\"cursor:pointer;\">Hey GPT-OSS, looks like you got it \u2013 Now walk me through it! An assessment of the reasoning language models chain of thought process for digital forensics<\/a> (<span class=\"tp_pub_type tp_  article\">Journal Article<\/span>)<\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_in\">In: <\/span><span class=\"tp_pub_additional_journal\">Forensic Science International: Digital Investigation, <\/span><span class=\"tp_pub_additional_volume\">vol. 56, <\/span><span class=\"tp_pub_additional_pages\">pp. 302052, <\/span><span class=\"tp_pub_additional_year\">2026<\/span>, <span class=\"tp_pub_additional_issn\">ISSN: 2666-2817<\/span>.<\/p><p class=\"tp_pub_menu\">(<span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_947\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('947','tp_abstract')\" title=\"Show abstract\" style=\"cursor:pointer;\">Abstract<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_947\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('947','tp_links')\" title=\"Show links and resources\" style=\"cursor:pointer;\">Links<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_947\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('947','tp_bibtex')\" title=\"Show BibTeX entry\" style=\"cursor:pointer;\">BibTeX<\/a><\/span>)<\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_947\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@article{MICHELET2026302052,<br \/>\r\ntitle = {Hey GPT-OSS, looks like you got it \u2013 Now walk me through it! An assessment of the reasoning language models chain of thought process for digital forensics},<br \/>\r\nauthor = {Ga{\u00eb}tan Michelet and Janine Schneider and Aruna Withanage and Frank Breitinger},<br \/>\r\nurl = {https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281726000090},<br \/>\r\ndoi = {10.1016\/j.fsidi.2026.302052},<br \/>\r\nissn = {2666-2817},<br \/>\r\nyear  = {2026},<br \/>\r\ndate = {2026-03-24},<br \/>\r\njournal = {Forensic Science International: Digital Investigation},<br \/>\r\nvolume = {56},<br \/>\r\npages = {302052},<br \/>\r\nabstract = {Large language models (LLMs), including systems such as ChatGPT, are increasingly examined for their role in digital forensics. Current research not only surveys their potential applications but also investigates how fine-tuning and model adaptation can enhance performance on specialized forensic tasks. However, the understandability and interpretability of the results (outputs) reduce their operational and legal usability. Recently, a new class of reasoning language models has emerged, designed to handle logic-based tasks through an `internal reasoning' mechanism. Yet, users typically only see the final answer, not the underlying reasoning. One of these reasoning models is gpt-oss, which can be deployed locally, providing full access to its underlying reasoning process. This article presents the first investigation into the potential of reasoning language models for digital forensics. Four test use cases are examined to assess the usability of the reasoning component in supporting results understandability. The evaluation combines a new quantitative metric with qualitative analysis. Findings show that the reasoning component aids in understanding, interpreting, and validating LLM outputs in digital forensics at medium reasoning levels, but the support is often limited, and higher reasoning levels do not enhance response quality.},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {article}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('947','tp_bibtex')\">Close<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_947\" style=\"display:none;\"><div class=\"tp_abstract_entry\">Large language models (LLMs), including systems such as ChatGPT, are increasingly examined for their role in digital forensics. Current research not only surveys their potential applications but also investigates how fine-tuning and model adaptation can enhance performance on specialized forensic tasks. However, the understandability and interpretability of the results (outputs) reduce their operational and legal usability. Recently, a new class of reasoning language models has emerged, designed to handle logic-based tasks through an `internal reasoning' mechanism. Yet, users typically only see the final answer, not the underlying reasoning. One of these reasoning models is gpt-oss, which can be deployed locally, providing full access to its underlying reasoning process. This article presents the first investigation into the potential of reasoning language models for digital forensics. Four test use cases are examined to assess the usability of the reasoning component in supporting results understandability. The evaluation combines a new quantitative metric with qualitative analysis. Findings show that the reasoning component aids in understanding, interpreting, and validating LLM outputs in digital forensics at medium reasoning levels, but the support is often limited, and higher reasoning levels do not enhance response quality.<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('947','tp_abstract')\">Close<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_947\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"fas fa-globe\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281726000090\" title=\"https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281726000090\" target=\"_blank\">https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281726000090<\/a><\/li><li><i class=\"ai ai-doi\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/dx.doi.org\/10.1016\/j.fsidi.2026.302052\" title=\"Follow DOI:10.1016\/j.fsidi.2026.302052\" target=\"_blank\">doi:10.1016\/j.fsidi.2026.302052<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('947','tp_links')\">Close<\/a><\/p><\/div><\/td><\/tr><tr class=\"tp_publication tp_publication_article\"><td class=\"tp_pub_number\">4.<\/td><td class=\"tp_pub_info\"><p class=\"tp_pub_author\"> Silalahi, Swardiantara;  Ahmad, Tohari;  Studiawan, Hudan;  Breitinger, Frank<\/p><p class=\"tp_pub_title\"><a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('948','tp_links')\" style=\"cursor:pointer;\">DroPTC: Sentence-level drone flight log forensics using contrastive learning and explainable AI<\/a> (<span class=\"tp_pub_type tp_  article\">Journal Article<\/span>)<\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_in\">In: <\/span><span class=\"tp_pub_additional_journal\">Forensic Science International: Digital Investigation, <\/span><span class=\"tp_pub_additional_volume\">vol. 56, <\/span><span class=\"tp_pub_additional_pages\">pp. 302051, <\/span><span class=\"tp_pub_additional_year\">2026<\/span>, <span class=\"tp_pub_additional_issn\">ISSN: 2666-2817<\/span>.<\/p><p class=\"tp_pub_menu\">(<span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_948\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('948','tp_abstract')\" title=\"Show abstract\" style=\"cursor:pointer;\">Abstract<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_948\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('948','tp_links')\" title=\"Show links and resources\" style=\"cursor:pointer;\">Links<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_948\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('948','tp_bibtex')\" title=\"Show BibTeX entry\" style=\"cursor:pointer;\">BibTeX<\/a><\/span>)<\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_948\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@article{SILALAHI2026302051,<br \/>\r\ntitle = {DroPTC: Sentence-level drone flight log forensics using contrastive learning and explainable AI},<br \/>\r\nauthor = {Swardiantara Silalahi and Tohari Ahmad and Hudan Studiawan and Frank Breitinger},<br \/>\r\nurl = {https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281726000089},<br \/>\r\ndoi = {10.1016\/j.fsidi.2026.302051},<br \/>\r\nissn = {2666-2817},<br \/>\r\nyear  = {2026},<br \/>\r\ndate = {2026-03-24},<br \/>\r\njournal = {Forensic Science International: Digital Investigation},<br \/>\r\nvolume = {56},<br \/>\r\npages = {302051},<br \/>\r\nabstract = {Unmanned Aerial Vehicles (UAVs), commonly known as drones, are increasingly deployed across diverse application domains, raising critical challenges for digital forensic investigation following safety incidents and system failures. In drone investigations, systematic analysis of flight logs is essential for reconstructing events, identifying root causes, and supporting reliable incident attribution and risk mitigation. Because a message may contain multiple sentences, message-level analysis cannot precisely pinpoint which log segment indicates a problem. Therefore, this paper proposes DroPTC (Drone Problem Type Classifier), an end-to-end framework to identify and classify problems at the sentence level. A rule-based segmenter is designed to segment log messages into sentences based on historical log characteristics. Using the resulting log sentences, a pre-trained embedding is fine-tuned using contrastive learning for semantic alignment. The integrated gradient is employed to enhance the model's interpretability, enabling admissible and trustworthy analysis. Sentence deduplication is utilized to identify unique log events, thereby reducing the analyst workload. Quantitative and qualitative analysis of the experimental results show that DroPTC outperforms the baselines in three aspects: performance, trustworthiness, and efficiency. This paper also presents a working open-source tool as the tested implementation of the proposed framework. The tool accepts the decrypted flight log file and produces a forensic report in HTML and PDF format.},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {article}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('948','tp_bibtex')\">Close<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_948\" style=\"display:none;\"><div class=\"tp_abstract_entry\">Unmanned Aerial Vehicles (UAVs), commonly known as drones, are increasingly deployed across diverse application domains, raising critical challenges for digital forensic investigation following safety incidents and system failures. In drone investigations, systematic analysis of flight logs is essential for reconstructing events, identifying root causes, and supporting reliable incident attribution and risk mitigation. Because a message may contain multiple sentences, message-level analysis cannot precisely pinpoint which log segment indicates a problem. Therefore, this paper proposes DroPTC (Drone Problem Type Classifier), an end-to-end framework to identify and classify problems at the sentence level. A rule-based segmenter is designed to segment log messages into sentences based on historical log characteristics. Using the resulting log sentences, a pre-trained embedding is fine-tuned using contrastive learning for semantic alignment. The integrated gradient is employed to enhance the model's interpretability, enabling admissible and trustworthy analysis. Sentence deduplication is utilized to identify unique log events, thereby reducing the analyst workload. Quantitative and qualitative analysis of the experimental results show that DroPTC outperforms the baselines in three aspects: performance, trustworthiness, and efficiency. This paper also presents a working open-source tool as the tested implementation of the proposed framework. The tool accepts the decrypted flight log file and produces a forensic report in HTML and PDF format.<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('948','tp_abstract')\">Close<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_948\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"fas fa-globe\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281726000089\" title=\"https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281726000089\" target=\"_blank\">https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281726000089<\/a><\/li><li><i class=\"ai ai-doi\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/dx.doi.org\/10.1016\/j.fsidi.2026.302051\" title=\"Follow DOI:10.1016\/j.fsidi.2026.302051\" target=\"_blank\">doi:10.1016\/j.fsidi.2026.302051<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('948','tp_links')\">Close<\/a><\/p><\/div><\/td><\/tr><tr class=\"tp_publication tp_publication_article\"><td class=\"tp_pub_number\">5.<\/td><td class=\"tp_pub_info\"><p class=\"tp_pub_author\"> Wickramasekara, Akila;  Mihiranga, Tharusha;  Withanage, Aruna;  Weerasinghe, Buddhima;  Breitinger, Frank;  Sheppard, John;  Scanlon, Mark<\/p><p class=\"tp_pub_title\"><a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('949','tp_links')\" style=\"cursor:pointer;\">AutoDFBench 1.0: A benchmarking framework for digital forensic tool testing and generated code evaluation<\/a> (<span class=\"tp_pub_type tp_  article\">Journal Article<\/span>)<\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_in\">In: <\/span><span class=\"tp_pub_additional_journal\">Forensic Science International: Digital Investigation, <\/span><span class=\"tp_pub_additional_volume\">vol. 56, <\/span><span class=\"tp_pub_additional_pages\">pp. 302055, <\/span><span class=\"tp_pub_additional_year\">2026<\/span>, <span class=\"tp_pub_additional_issn\">ISSN: 2666-2817<\/span>.<\/p><p class=\"tp_pub_menu\">(<span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_949\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('949','tp_abstract')\" title=\"Show abstract\" style=\"cursor:pointer;\">Abstract<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_949\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('949','tp_links')\" title=\"Show links and resources\" style=\"cursor:pointer;\">Links<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_949\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('949','tp_bibtex')\" title=\"Show BibTeX entry\" style=\"cursor:pointer;\">BibTeX<\/a><\/span>)<\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_949\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@article{WICKRAMASEKARA2026302055,<br \/>\r\ntitle = {AutoDFBench 1.0: A benchmarking framework for digital forensic tool testing and generated code evaluation},<br \/>\r\nauthor = {Akila Wickramasekara and Tharusha Mihiranga and Aruna Withanage and Buddhima Weerasinghe and Frank Breitinger and John Sheppard and Mark Scanlon},<br \/>\r\nurl = {https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281726000120},<br \/>\r\ndoi = {10.1016\/j.fsidi.2026.302055},<br \/>\r\nissn = {2666-2817},<br \/>\r\nyear  = {2026},<br \/>\r\ndate = {2026-03-24},<br \/>\r\njournal = {Forensic Science International: Digital Investigation},<br \/>\r\nvolume = {56},<br \/>\r\npages = {302055},<br \/>\r\nabstract = {The National Institute of Standards and Technology (NIST) Computer Forensic Tool Testing (CFTT) programme has become the de facto standard for providing digital forensic tool testing and validation. However to date, no comprehensive framework exists to automate benchmarking across the diverse forensic tasks included in the programme. This gap results in inconsistent validation, challenges in comparing tools, and limited validation reproducibility. This paper introduces AutoDFBench 1.0, a modular benchmarking framework that supports the evaluation of both conventional DF tools and scripts, as well as AI-generated code and agentic approaches. The framework integrates five areas defined by the CFTT programme: string search, deleted file recovery, file carving, Windows registry recovery, and SQLite data recovery. AutoDFBench 1.0 includes ground truth data comprising of 63 test cases and 10,968 unique test scenarios, and execute evaluations through a RESTful API that produces structured JSON outputs with standardised metrics, including precision, recall, and F1 score for each test case, and the average of these F1 scores becomes the AutoDFBench Score. The benchmarking framework is validated against CFTT's datasets. The framework enables fair and reproducible comparison across tools and forensic scripts, establishing the first unified, automated, and extensible benchmarking framework for digital forensic tool testing and validation. AutoDFBench 1.0 supports tool vendors, researchers, practitioners, and standardisation bodies by facilitating transparent, reproducible, and comparable assessments of DF technologies.},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {article}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('949','tp_bibtex')\">Close<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_949\" style=\"display:none;\"><div class=\"tp_abstract_entry\">The National Institute of Standards and Technology (NIST) Computer Forensic Tool Testing (CFTT) programme has become the de facto standard for providing digital forensic tool testing and validation. However to date, no comprehensive framework exists to automate benchmarking across the diverse forensic tasks included in the programme. This gap results in inconsistent validation, challenges in comparing tools, and limited validation reproducibility. This paper introduces AutoDFBench 1.0, a modular benchmarking framework that supports the evaluation of both conventional DF tools and scripts, as well as AI-generated code and agentic approaches. The framework integrates five areas defined by the CFTT programme: string search, deleted file recovery, file carving, Windows registry recovery, and SQLite data recovery. AutoDFBench 1.0 includes ground truth data comprising of 63 test cases and 10,968 unique test scenarios, and execute evaluations through a RESTful API that produces structured JSON outputs with standardised metrics, including precision, recall, and F1 score for each test case, and the average of these F1 scores becomes the AutoDFBench Score. The benchmarking framework is validated against CFTT's datasets. The framework enables fair and reproducible comparison across tools and forensic scripts, establishing the first unified, automated, and extensible benchmarking framework for digital forensic tool testing and validation. AutoDFBench 1.0 supports tool vendors, researchers, practitioners, and standardisation bodies by facilitating transparent, reproducible, and comparable assessments of DF technologies.<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('949','tp_abstract')\">Close<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_949\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"fas fa-globe\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281726000120\" title=\"https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281726000120\" target=\"_blank\">https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281726000120<\/a><\/li><li><i class=\"ai ai-doi\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/dx.doi.org\/10.1016\/j.fsidi.2026.302055\" title=\"Follow DOI:10.1016\/j.fsidi.2026.302055\" target=\"_blank\">doi:10.1016\/j.fsidi.2026.302055<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('949','tp_links')\">Close<\/a><\/p><\/div><\/td><\/tr><tr class=\"tp_publication tp_publication_article\"><td class=\"tp_pub_number\">6.<\/td><td class=\"tp_pub_info\"><p class=\"tp_pub_author\"> Adila, Rida;  Studiawan, Hudan;  Breitinger, Frank<\/p><p class=\"tp_pub_title\"><a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('945','tp_links')\" style=\"cursor:pointer;\">Forensic Event Reconstruction With Process Mining<\/a> (<span class=\"tp_pub_type tp_  article\">Journal Article<\/span>)<\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_in\">In: <\/span><span class=\"tp_pub_additional_journal\">IEEE Access, <\/span><span class=\"tp_pub_additional_volume\">vol. 14, <\/span><span class=\"tp_pub_additional_pages\">pp. 18964-18985, <\/span><span class=\"tp_pub_additional_year\">2026<\/span>, <span class=\"tp_pub_additional_issn\">ISSN: 2169-3536<\/span>.<\/p><p class=\"tp_pub_menu\">(<span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_945\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('945','tp_abstract')\" title=\"Show abstract\" style=\"cursor:pointer;\">Abstract<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_945\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('945','tp_links')\" title=\"Show links and resources\" style=\"cursor:pointer;\">Links<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_945\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('945','tp_bibtex')\" title=\"Show BibTeX entry\" style=\"cursor:pointer;\">BibTeX<\/a><\/span>)<\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_945\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@article{11369961,<br \/>\r\ntitle = {Forensic Event Reconstruction With Process Mining},<br \/>\r\nauthor = {Rida Adila and Hudan Studiawan and Frank Breitinger},<br \/>\r\ndoi = {10.1109\/ACCESS.2026.3660165},<br \/>\r\nissn = {2169-3536},<br \/>\r\nyear  = {2026},<br \/>\r\ndate = {2026-02-02},<br \/>\r\njournal = {IEEE Access},<br \/>\r\nvolume = {14},<br \/>\r\npages = {18964-18985},<br \/>\r\nabstract = {Event reconstruction is a fundamental aspect of the investigative process in digital forensics. During this process, one systematically analyzes and organizes evidence to formulate a hypothesis regarding past events. The starting point is often the raw data from forensic timelines (e.g., a table including all parsed events), which may include millions of timeline entries. Various tools and techniques have been proposed to create and analyze timelines. However, the feasibility of applying process mining solutions remains unexplored. Process mining, with its ability to uncover patterns, deviations, and process flows from event data, can offer valuable insights into forensic event reconstruction. In this study, we explore the utilization of episode mining to generate case identifiers and provide event sequences, visualizations, and evaluation metrics from process models generated by process mining algorithms. As a result, we developed an open-source, web-based prototype application. Experiments and case studies conclude that the proposed method can reconstruct events and provide intuitive results to forensic investigators.},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {article}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('945','tp_bibtex')\">Close<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_945\" style=\"display:none;\"><div class=\"tp_abstract_entry\">Event reconstruction is a fundamental aspect of the investigative process in digital forensics. During this process, one systematically analyzes and organizes evidence to formulate a hypothesis regarding past events. The starting point is often the raw data from forensic timelines (e.g., a table including all parsed events), which may include millions of timeline entries. Various tools and techniques have been proposed to create and analyze timelines. However, the feasibility of applying process mining solutions remains unexplored. Process mining, with its ability to uncover patterns, deviations, and process flows from event data, can offer valuable insights into forensic event reconstruction. In this study, we explore the utilization of episode mining to generate case identifiers and provide event sequences, visualizations, and evaluation metrics from process models generated by process mining algorithms. As a result, we developed an open-source, web-based prototype application. Experiments and case studies conclude that the proposed method can reconstruct events and provide intuitive results to forensic investigators.<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('945','tp_abstract')\">Close<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_945\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"ai ai-doi\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/dx.doi.org\/10.1109\/ACCESS.2026.3660165\" title=\"Follow DOI:10.1109\/ACCESS.2026.3660165\" target=\"_blank\">doi:10.1109\/ACCESS.2026.3660165<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('945','tp_links')\">Close<\/a><\/p><\/div><\/td><\/tr><tr class=\"tp_publication tp_publication_misc\"><td class=\"tp_pub_number\">7.<\/td><td class=\"tp_pub_info\"><p class=\"tp_pub_author\"> Breitinger, Frank<\/p><p class=\"tp_pub_title\">AI and Forensics: Where We Are and the Shape of What\u2019s Next (<span class=\"tp_pub_type tp_  misc\">Miscellaneous<\/span>)<\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_howpublished\">bf Keynote at Fifth ISEA International Conference on Security and Privacy 2026 (ISEA\u2013ISAP 2026), <\/span><span class=\"tp_pub_additional_year\">2026<\/span><span class=\"tp_pub_additional_note\">, (IIT Madras, Chennai, India)<\/span>.<\/p><p class=\"tp_pub_menu\">(<span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_932\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('932','tp_bibtex')\" title=\"Show BibTeX entry\" style=\"cursor:pointer;\">BibTeX<\/a><\/span>)<\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_932\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@misc{keynote-chennai,<br \/>\r\ntitle = {AI and Forensics: Where We Are and the Shape of What\u2019s Next},<br \/>\r\nauthor = {Frank Breitinger},<br \/>\r\nyear  = {2026},<br \/>\r\ndate = {2026-01-17},<br \/>\r\nhowpublished = {bf Keynote at Fifth ISEA International Conference on Security and Privacy 2026 (ISEA\u2013ISAP 2026)},<br \/>\r\nnote = {IIT Madras, Chennai, India},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {misc}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('932','tp_bibtex')\">Close<\/a><\/p><\/div><\/td><\/tr><tr class=\"tp_publication tp_publication_article\"><td class=\"tp_pub_number\">8.<\/td><td class=\"tp_pub_info\"><p class=\"tp_pub_author\"> Vanini, C\u00e9line;  Hargreaves, Chris;  Breitinger, Frank<\/p><p class=\"tp_pub_title\"><a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('929','tp_links')\" style=\"cursor:pointer;\">Evaluating tamper resistance of digital forensic artifacts during event reconstruction<\/a> (<span class=\"tp_pub_type tp_  article\">Journal Article<\/span>)<\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_in\">In: <\/span><span class=\"tp_pub_additional_journal\">Digital Threats, <\/span><span class=\"tp_pub_additional_year\">2025<\/span><span class=\"tp_pub_additional_note\">, (Just Accepted)<\/span>.<\/p><p class=\"tp_pub_menu\">(<span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_929\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('929','tp_abstract')\" title=\"Show abstract\" style=\"cursor:pointer;\">Abstract<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_929\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('929','tp_links')\" title=\"Show links and resources\" style=\"cursor:pointer;\">Links<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_929\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('929','tp_bibtex')\" title=\"Show BibTeX entry\" style=\"cursor:pointer;\">BibTeX<\/a><\/span>)<\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_929\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@article{10.1145\/3765627,<br \/>\r\ntitle = {Evaluating tamper resistance of digital forensic artifacts during event reconstruction},<br \/>\r\nauthor = { C\u00e9line Vanini and Chris Hargreaves and Frank Breitinger},<br \/>\r\nurl = {https:\/\/doi.org\/10.1145\/3765627},<br \/>\r\ndoi = {10.1145\/3765627},<br \/>\r\nyear  = {2025},<br \/>\r\ndate = {2025-09-02},<br \/>\r\njournal = {Digital Threats},<br \/>\r\npublisher = {Association for Computing Machinery},<br \/>\r\naddress = {New York, NY, USA},<br \/>\r\nabstract = {Event reconstruction is a fundamental part of the digital forensic process, helping to answer key questions like who, what, when, and how. A common way of accomplishing that is to use tools to create timelines, which are then analyzed. However, various challenges exist, such as large volumes of data or contamination. While prior research has focused on simplifying timelines, less attention has been given to tampering, i.e., the deliberate manipulation of evidence, which can lead to errors in interpretation. This article addresses the issue by proposing a framework to assess the relative tamper resistance of different data sources used in event reconstruction. We discuss factors affecting data resilience, introduce a scoring system for evaluation, and illustrate its application with case studies. This work aims to improve the reliability of forensic event reconstruction by considering tamper resistance.},<br \/>\r\nnote = {Just Accepted},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {article}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('929','tp_bibtex')\">Close<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_929\" style=\"display:none;\"><div class=\"tp_abstract_entry\">Event reconstruction is a fundamental part of the digital forensic process, helping to answer key questions like who, what, when, and how. A common way of accomplishing that is to use tools to create timelines, which are then analyzed. However, various challenges exist, such as large volumes of data or contamination. While prior research has focused on simplifying timelines, less attention has been given to tampering, i.e., the deliberate manipulation of evidence, which can lead to errors in interpretation. This article addresses the issue by proposing a framework to assess the relative tamper resistance of different data sources used in event reconstruction. We discuss factors affecting data resilience, introduce a scoring system for evaluation, and illustrate its application with case studies. This work aims to improve the reliability of forensic event reconstruction by considering tamper resistance.<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('929','tp_abstract')\">Close<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_929\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"fas fa-globe\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/doi.org\/10.1145\/3765627\" title=\"https:\/\/doi.org\/10.1145\/3765627\" target=\"_blank\">https:\/\/doi.org\/10.1145\/3765627<\/a><\/li><li><i class=\"ai ai-doi\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/dx.doi.org\/10.1145\/3765627\" title=\"Follow DOI:10.1145\/3765627\" target=\"_blank\">doi:10.1145\/3765627<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('929','tp_links')\">Close<\/a><\/p><\/div><\/td><\/tr><tr class=\"tp_publication tp_publication_inproceedings\"><td class=\"tp_pub_number\">9.<\/td><td class=\"tp_pub_info\"><p class=\"tp_pub_author\"> Dorai, Gokila;  Rad, Pouria;  Breitinger, Frank;  Bardhan, Rajon;  Ramasamy, Vijayalakshmi<\/p><p class=\"tp_pub_title\"><a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('930','tp_links')\" style=\"cursor:pointer;\">Mapping the Research Landscape - An Exploratory Analysis of AI Applications in Digital Forensics<\/a> (<span class=\"tp_pub_type tp_  inproceedings\">Proceedings Article<\/span>)<\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_in\">In: <\/span> Coppens, Bart;  Volckaert, Bruno;  Naessens, Vincent;  De Sutter, Bjorn (Ed.): <span class=\"tp_pub_additional_booktitle\">Availability, Reliability and Security, <\/span><span class=\"tp_pub_additional_pages\">pp. 113\u2013130, <\/span><span class=\"tp_pub_additional_publisher\">Springer Nature Switzerland, <\/span><span class=\"tp_pub_additional_address\">Cham, <\/span><span class=\"tp_pub_additional_year\">2025<\/span>, <span class=\"tp_pub_additional_isbn\">ISBN: 978-3-032-00635-6<\/span>.<\/p><p class=\"tp_pub_menu\">(<span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_930\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('930','tp_abstract')\" title=\"Show abstract\" style=\"cursor:pointer;\">Abstract<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_930\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('930','tp_links')\" title=\"Show links and resources\" style=\"cursor:pointer;\">Links<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_930\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('930','tp_bibtex')\" title=\"Show BibTeX entry\" style=\"cursor:pointer;\">BibTeX<\/a><\/span>)<\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_930\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@inproceedings{10.1007\/978-3-032-00635-6_7,<br \/>\r\ntitle = {Mapping the Research Landscape - An Exploratory Analysis of AI Applications in Digital Forensics},<br \/>\r\nauthor = {Gokila Dorai and Pouria Rad and Frank Breitinger and Rajon Bardhan and Vijayalakshmi Ramasamy},<br \/>\r\neditor = {Coppens, Bart and Volckaert, Bruno and Naessens, Vincent and De Sutter, Bjorn},<br \/>\r\nurl = {https:\/\/doi.org\/10.1007\/978-3-032-00635-6_7},<br \/>\r\ndoi = {10.1007\/978-3-032-00635-6_7},<br \/>\r\nisbn = {978-3-032-00635-6},<br \/>\r\nyear  = {2025},<br \/>\r\ndate = {2025-08-09},<br \/>\r\nurldate = {2025-08-09},<br \/>\r\nbooktitle = {Availability, Reliability and Security},<br \/>\r\npages = {113\u2013130},<br \/>\r\npublisher = {Springer Nature Switzerland},<br \/>\r\naddress = {Cham},<br \/>\r\nabstract = {Artificial intelligence (AI) and machine learning (ML) have great potential to enhance digital forensic investigation, but progress is impeded by challenges in building datasets that meet technical accuracy and legal requirements. We herein compile findings from the latest scholarly literature to identify potential key aspects that are required for building forensic datasets that can effectively support AI-based investigative tools. We examine current practices in dataset building, ranging from representativeness of data, quality of annotation, chain-of-custody documentation, and metadata standardization, and consider their effects carefully on training robust AI models. Results point to key shortcomings that impede advanced AI implementations in digital forensics, which form a strong baseline for developing a standard workflow for building forensic datasets. This work, therefore, forms a stepping stone for future projects to enhance investigation capabilities through a better-structured and legally sound process of dataset building.},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {inproceedings}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('930','tp_bibtex')\">Close<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_930\" style=\"display:none;\"><div class=\"tp_abstract_entry\">Artificial intelligence (AI) and machine learning (ML) have great potential to enhance digital forensic investigation, but progress is impeded by challenges in building datasets that meet technical accuracy and legal requirements. We herein compile findings from the latest scholarly literature to identify potential key aspects that are required for building forensic datasets that can effectively support AI-based investigative tools. We examine current practices in dataset building, ranging from representativeness of data, quality of annotation, chain-of-custody documentation, and metadata standardization, and consider their effects carefully on training robust AI models. Results point to key shortcomings that impede advanced AI implementations in digital forensics, which form a strong baseline for developing a standard workflow for building forensic datasets. This work, therefore, forms a stepping stone for future projects to enhance investigation capabilities through a better-structured and legally sound process of dataset building.<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('930','tp_abstract')\">Close<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_930\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"fas fa-globe\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/doi.org\/10.1007\/978-3-032-00635-6_7\" title=\"https:\/\/doi.org\/10.1007\/978-3-032-00635-6_7\" target=\"_blank\">https:\/\/doi.org\/10.1007\/978-3-032-00635-6_7<\/a><\/li><li><i class=\"ai ai-doi\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/dx.doi.org\/10.1007\/978-3-032-00635-6_7\" title=\"Follow DOI:10.1007\/978-3-032-00635-6_7\" target=\"_blank\">doi:10.1007\/978-3-032-00635-6_7<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('930','tp_links')\">Close<\/a><\/p><\/div><\/td><\/tr><tr class=\"tp_publication tp_publication_article\"><td class=\"tp_pub_number\">10.<\/td><td class=\"tp_pub_info\"><p class=\"tp_pub_author\"> Breitinger, Frank;  Studiawan, Hudan;  Hargreaves, Chris<\/p><p class=\"tp_pub_title\"><a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('931','tp_links')\" style=\"cursor:pointer;\">SoK: Timeline based event reconstruction for digital forensics: Terminology, methodology, and current challenges<\/a> (<span class=\"tp_pub_type tp_  article\">Journal Article<\/span>)<\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_in\">In: <\/span><span class=\"tp_pub_additional_journal\">Forensic Science International: Digital Investigation, <\/span><span class=\"tp_pub_additional_volume\">vol. 53, <\/span><span class=\"tp_pub_additional_pages\">pp. 301932, <\/span><span class=\"tp_pub_additional_year\">2025<\/span>, <span class=\"tp_pub_additional_issn\">ISSN: 2666-2817<\/span><span class=\"tp_pub_additional_note\">, (DFRWS USA 2025 - Selected Papers from the 25th Annual Digital Forensics Research Conference USA)<\/span>.<\/p><p class=\"tp_pub_menu\">(<span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_931\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('931','tp_abstract')\" title=\"Show abstract\" style=\"cursor:pointer;\">Abstract<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_931\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('931','tp_links')\" title=\"Show links and resources\" style=\"cursor:pointer;\">Links<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_931\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('931','tp_bibtex')\" title=\"Show BibTeX entry\" style=\"cursor:pointer;\">BibTeX<\/a><\/span>)<\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_931\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@article{BREITINGER2025301932,<br \/>\r\ntitle = {SoK: Timeline based event reconstruction for digital forensics: Terminology, methodology, and current challenges},<br \/>\r\nauthor = {Frank Breitinger and Hudan Studiawan and Chris Hargreaves},<br \/>\r\nurl = {https:\/\/www.sciencedirect.com\/science\/article\/pii\/S266628172500071X},<br \/>\r\ndoi = {https:\/\/doi.org\/10.1016\/j.fsidi.2025.301932},<br \/>\r\nissn = {2666-2817},<br \/>\r\nyear  = {2025},<br \/>\r\ndate = {2025-08-01},<br \/>\r\njournal = {Forensic Science International: Digital Investigation},<br \/>\r\nvolume = {53},<br \/>\r\npages = {301932},<br \/>\r\nabstract = {Event reconstruction is a technique that examiners can use to attempt to infer past activities by analyzing digital artifacts. Despite its significance, the field suffers from fragmented research, with studies often focusing narrowly on aspects like timeline creation or tampering detection. This paper addresses the lack of a unified perspective by proposing a comprehensive framework for timeline-based event reconstruction, adapted from traditional forensic science models. We begin by harmonizing existing terminology and presenting a cohesive diagram that clarifies the relationships between key elements of the reconstruction process. Through a comprehensive literature survey, we classify and organize the main challenges, extending the discussion beyond common issues like data volume. Lastly, we highlight recent advancements and propose directions for future research, including specific research gaps. By providing a structured approach, key findings, and a clearer understanding of the underlying challenges, this work aims to strengthen the foundation of digital forensics.},<br \/>\r\nnote = {DFRWS USA 2025 - Selected Papers from the 25th Annual Digital Forensics Research Conference USA},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {article}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('931','tp_bibtex')\">Close<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_931\" style=\"display:none;\"><div class=\"tp_abstract_entry\">Event reconstruction is a technique that examiners can use to attempt to infer past activities by analyzing digital artifacts. Despite its significance, the field suffers from fragmented research, with studies often focusing narrowly on aspects like timeline creation or tampering detection. This paper addresses the lack of a unified perspective by proposing a comprehensive framework for timeline-based event reconstruction, adapted from traditional forensic science models. We begin by harmonizing existing terminology and presenting a cohesive diagram that clarifies the relationships between key elements of the reconstruction process. Through a comprehensive literature survey, we classify and organize the main challenges, extending the discussion beyond common issues like data volume. Lastly, we highlight recent advancements and propose directions for future research, including specific research gaps. By providing a structured approach, key findings, and a clearer understanding of the underlying challenges, this work aims to strengthen the foundation of digital forensics.<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('931','tp_abstract')\">Close<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_931\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"fas fa-globe\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/www.sciencedirect.com\/science\/article\/pii\/S266628172500071X\" title=\"https:\/\/www.sciencedirect.com\/science\/article\/pii\/S266628172500071X\" target=\"_blank\">https:\/\/www.sciencedirect.com\/science\/article\/pii\/S266628172500071X<\/a><\/li><li><i class=\"ai ai-doi\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/dx.doi.org\/https:\/\/doi.org\/10.1016\/j.fsidi.2025.301932\" title=\"Follow DOI:https:\/\/doi.org\/10.1016\/j.fsidi.2025.301932\" target=\"_blank\">doi:https:\/\/doi.org\/10.1016\/j.fsidi.2025.301932<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('931','tp_links')\">Close<\/a><\/p><\/div><\/td><\/tr><tr class=\"tp_publication tp_publication_article\"><td class=\"tp_pub_number\">11.<\/td><td class=\"tp_pub_info\"><p class=\"tp_pub_author\"> Michelet, Ga\u00ebtan;  Henseler, Hans;  Beek, Harm;  Scanlon, Mark;  Breitinger, Frank<\/p><p class=\"tp_pub_title\"><a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('928','tp_links')\" style=\"cursor:pointer;\">Fine-Tuning Large Language Models for Digital Forensics: Case Study and General Recommendations<\/a> (<span class=\"tp_pub_type tp_  article\">Journal Article<\/span>)<\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_in\">In: <\/span><span class=\"tp_pub_additional_journal\">Digital Threats: Research and Practice, <\/span><span class=\"tp_pub_additional_year\">2025<\/span>.<\/p><p class=\"tp_pub_menu\">(<span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_928\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('928','tp_abstract')\" title=\"Show abstract\" style=\"cursor:pointer;\">Abstract<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_928\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('928','tp_links')\" title=\"Show links and resources\" style=\"cursor:pointer;\">Links<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_928\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('928','tp_bibtex')\" title=\"Show BibTeX entry\" style=\"cursor:pointer;\">BibTeX<\/a><\/span>)<\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_928\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@article{10.1145\/3748264,<br \/>\r\ntitle = {Fine-Tuning Large Language Models for Digital Forensics: Case Study and General Recommendations},<br \/>\r\nauthor = {Ga\u00ebtan Michelet and Hans Henseler and Harm Beek and Mark Scanlon and Frank Breitinger},<br \/>\r\nurl = {https:\/\/doi.org\/10.1145\/3748264},<br \/>\r\ndoi = {10.1145\/3748264},<br \/>\r\nyear  = {2025},<br \/>\r\ndate = {2025-07-24},<br \/>\r\njournal = {Digital Threats: Research and Practice},<br \/>\r\npublisher = {Association for Computing Machinery},<br \/>\r\naddress = {New York, NY, USA},<br \/>\r\nabstract = {Large language models (LLMs) have rapidly gained popularity in various fields, including digital forensics (DF), where they offer the potential to accelerate investigative processes. Although several studies have explored LLMs for tasks such as evidence identification, artifact analysis, and report writing, fine-tuning models for specific forensic applications remains underexplored. This paper addresses this gap by proposing recommendations for fine-tuning LLMs tailored to digital forensics tasks. A case study on chat summarization is presented to showcase the applicability of the recommendations, where we evaluate multiple fine-tuned models to assess their performance. The study concludes with sharing the lessons learned from the case study.},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {article}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('928','tp_bibtex')\">Close<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_928\" style=\"display:none;\"><div class=\"tp_abstract_entry\">Large language models (LLMs) have rapidly gained popularity in various fields, including digital forensics (DF), where they offer the potential to accelerate investigative processes. Although several studies have explored LLMs for tasks such as evidence identification, artifact analysis, and report writing, fine-tuning models for specific forensic applications remains underexplored. This paper addresses this gap by proposing recommendations for fine-tuning LLMs tailored to digital forensics tasks. A case study on chat summarization is presented to showcase the applicability of the recommendations, where we evaluate multiple fine-tuned models to assess their performance. The study concludes with sharing the lessons learned from the case study.<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('928','tp_abstract')\">Close<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_928\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"fas fa-globe\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/doi.org\/10.1145\/3748264\" title=\"https:\/\/doi.org\/10.1145\/3748264\" target=\"_blank\">https:\/\/doi.org\/10.1145\/3748264<\/a><\/li><li><i class=\"ai ai-doi\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/dx.doi.org\/10.1145\/3748264\" title=\"Follow DOI:10.1145\/3748264\" target=\"_blank\">doi:10.1145\/3748264<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('928','tp_links')\">Close<\/a><\/p><\/div><\/td><\/tr><tr class=\"tp_publication tp_publication_misc\"><td class=\"tp_pub_number\">12.<\/td><td class=\"tp_pub_info\"><p class=\"tp_pub_author\"> Breitinger, Frank<\/p><p class=\"tp_pub_title\">AI in Forensics: Where We Are and the Shape of What\u2019s Next (<span class=\"tp_pub_type tp_  misc\">Miscellaneous<\/span>)<\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_howpublished\">bf Keynote at AFSN Digital Forensic Workshop Symposium, <\/span><span class=\"tp_pub_additional_year\">2025<\/span><span class=\"tp_pub_additional_note\">, (Beijing, China)<\/span>.<\/p><p class=\"tp_pub_menu\">(<span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_933\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('933','tp_bibtex')\" title=\"Show BibTeX entry\" style=\"cursor:pointer;\">BibTeX<\/a><\/span>)<\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_933\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@misc{keynote-beijing,<br \/>\r\ntitle = {AI in Forensics: Where We Are and the Shape of What\u2019s Next},<br \/>\r\nauthor = {Frank Breitinger},<br \/>\r\nyear  = {2025},<br \/>\r\ndate = {2025-06-17},<br \/>\r\nhowpublished = {bf Keynote at AFSN Digital Forensic Workshop Symposium},<br \/>\r\nnote = {Beijing, China},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {misc}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('933','tp_bibtex')\">Close<\/a><\/p><\/div><\/td><\/tr><tr class=\"tp_publication tp_publication_inproceedings\"><td class=\"tp_pub_number\">13.<\/td><td class=\"tp_pub_info\"><p class=\"tp_pub_author\"> Wickramasekara, Akila;  Densmore, Alanna;  Breitinger, Frank;  Studiawan, Hudan;  Scanlon, Mark<\/p><p class=\"tp_pub_title\"><a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('924','tp_links')\" style=\"cursor:pointer;\">AutoDFBench: A Framework for AI Generated Digital Forensic Code and Tool Testing and Evaluation<\/a> (<span class=\"tp_pub_type tp_  inproceedings\">Proceedings Article<\/span>)<\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_in\">In: <\/span><span class=\"tp_pub_additional_booktitle\">Proceedings of the Digital Forensics Doctoral Symposium, <\/span><span class=\"tp_pub_additional_publisher\">Association for Computing Machinery, <\/span><span class=\"tp_pub_additional_address\">Brno, CZ, <\/span><span class=\"tp_pub_additional_year\">2025<\/span>, <span class=\"tp_pub_additional_isbn\">ISBN: 9798400710766<\/span>.<\/p><p class=\"tp_pub_menu\">(<span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_924\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('924','tp_abstract')\" title=\"Show abstract\" style=\"cursor:pointer;\">Abstract<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_924\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('924','tp_links')\" title=\"Show links and resources\" style=\"cursor:pointer;\">Links<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_924\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('924','tp_bibtex')\" title=\"Show BibTeX entry\" style=\"cursor:pointer;\">BibTeX<\/a><\/span>)<\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_924\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@inproceedings{10.1145\/3712716.3712718,<br \/>\r\ntitle = {AutoDFBench: A Framework for AI Generated Digital Forensic Code and Tool Testing and Evaluation},<br \/>\r\nauthor = {Akila Wickramasekara and Alanna Densmore and Frank Breitinger and Hudan Studiawan and Mark Scanlon},<br \/>\r\nurl = {https:\/\/doi.org\/10.1145\/3712716.3712718},<br \/>\r\ndoi = {10.1145\/3712716.3712718},<br \/>\r\nisbn = {9798400710766},<br \/>\r\nyear  = {2025},<br \/>\r\ndate = {2025-04-01},<br \/>\r\nurldate = {2025-01-01},<br \/>\r\nbooktitle = {Proceedings of the Digital Forensics Doctoral Symposium},<br \/>\r\npublisher = {Association for Computing Machinery},<br \/>\r\naddress = {Brno, CZ},<br \/>\r\nseries = {DFDS '25},<br \/>\r\nabstract = {Generative AI (GenAI) and Large Language Models (LLMs) show great potential in various domains, including digital forensics. A notable use case of these technologies is automatic code generation, which can reasonably be expected to include digital forensic applications in the not-too-distant future. As with any digital forensic tool, these systems must undergo extensive testing and validation. However, manually evaluating outputs, including generated DF code, remains a challenge. AutoDFBench is an automated framework designed to address this by validating AI-generated code and tools against NIST\u2019s Computer Forensics Tool Testing Program (CFTT) procedures and subsequently calculating an AutoDFBench benchmarking score. The framework operates in four phases: data preparation, API handling, code execution, and result recording with score calculation. It benchmarks generative AI systems, such as LLMs and automated code generation agents, for DF applications. This benchmark can support iterative development or serve as a comparison metric between GenAI DF systems. As a proof of concept, NIST\u2019s forensic string search tests were used, involving more than 24,200 tests with five top-performing code generation LLMs. These tests validated the output of 121 cases, considering two levels of user expertise, two programming languages, and ten iterations per case with varying prompts. The results also highlight the significant limitations of the DF-specific solutions generated by generic LLMs.},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {inproceedings}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('924','tp_bibtex')\">Close<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_924\" style=\"display:none;\"><div class=\"tp_abstract_entry\">Generative AI (GenAI) and Large Language Models (LLMs) show great potential in various domains, including digital forensics. A notable use case of these technologies is automatic code generation, which can reasonably be expected to include digital forensic applications in the not-too-distant future. As with any digital forensic tool, these systems must undergo extensive testing and validation. However, manually evaluating outputs, including generated DF code, remains a challenge. AutoDFBench is an automated framework designed to address this by validating AI-generated code and tools against NIST\u2019s Computer Forensics Tool Testing Program (CFTT) procedures and subsequently calculating an AutoDFBench benchmarking score. The framework operates in four phases: data preparation, API handling, code execution, and result recording with score calculation. It benchmarks generative AI systems, such as LLMs and automated code generation agents, for DF applications. This benchmark can support iterative development or serve as a comparison metric between GenAI DF systems. As a proof of concept, NIST\u2019s forensic string search tests were used, involving more than 24,200 tests with five top-performing code generation LLMs. These tests validated the output of 121 cases, considering two levels of user expertise, two programming languages, and ten iterations per case with varying prompts. The results also highlight the significant limitations of the DF-specific solutions generated by generic LLMs.<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('924','tp_abstract')\">Close<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_924\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"fas fa-globe\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/doi.org\/10.1145\/3712716.3712718\" title=\"https:\/\/doi.org\/10.1145\/3712716.3712718\" target=\"_blank\">https:\/\/doi.org\/10.1145\/3712716.3712718<\/a><\/li><li><i class=\"ai ai-doi\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/dx.doi.org\/10.1145\/3712716.3712718\" title=\"Follow DOI:10.1145\/3712716.3712718\" target=\"_blank\">doi:10.1145\/3712716.3712718<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('924','tp_links')\">Close<\/a><\/p><\/div><\/td><\/tr><tr class=\"tp_publication tp_publication_inproceedings\"><td class=\"tp_pub_number\">14.<\/td><td class=\"tp_pub_info\"><p class=\"tp_pub_author\"> Vanini, C\u00e9line;  Gruber, Jan;  Hargreaves, Christopher;  Benenson, Zinaida;  Freiling, Felix;  Breitinger, Frank<\/p><p class=\"tp_pub_title\"><a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('925','tp_links')\" style=\"cursor:pointer;\">Understanding Strategies and Challenges of Timestamp Tampering for Improved Digital Forensic Event Reconstruction<\/a> (<span class=\"tp_pub_type tp_  inproceedings\">Proceedings Article<\/span>)<\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_in\">In: <\/span><span class=\"tp_pub_additional_booktitle\">Proceedings of the Digital Forensics Doctoral Symposium, <\/span><span class=\"tp_pub_additional_publisher\">Association for Computing Machinery, <\/span><span class=\"tp_pub_additional_address\">Brno, CZ, <\/span><span class=\"tp_pub_additional_year\">2025<\/span>, <span class=\"tp_pub_additional_isbn\">ISBN: 9798400710766<\/span>.<\/p><p class=\"tp_pub_menu\">(<span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_925\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('925','tp_abstract')\" title=\"Show abstract\" style=\"cursor:pointer;\">Abstract<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_925\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('925','tp_links')\" title=\"Show links and resources\" style=\"cursor:pointer;\">Links<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_925\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('925','tp_bibtex')\" title=\"Show BibTeX entry\" style=\"cursor:pointer;\">BibTeX<\/a><\/span>)<\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_925\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@inproceedings{10.1145\/3712716.3712727,<br \/>\r\ntitle = {Understanding Strategies and Challenges of Timestamp Tampering for Improved Digital Forensic Event Reconstruction},<br \/>\r\nauthor = {C\u00e9line Vanini and Jan Gruber and Christopher Hargreaves and Zinaida Benenson and Felix Freiling and Frank Breitinger},<br \/>\r\nurl = {https:\/\/doi.org\/10.1145\/3712716.3712727},<br \/>\r\ndoi = {10.1145\/3712716.3712727},<br \/>\r\nisbn = {9798400710766},<br \/>\r\nyear  = {2025},<br \/>\r\ndate = {2025-04-01},<br \/>\r\nurldate = {2025-01-01},<br \/>\r\nbooktitle = {Proceedings of the Digital Forensics Doctoral Symposium},<br \/>\r\npublisher = {Association for Computing Machinery},<br \/>\r\naddress = {Brno, CZ},<br \/>\r\nseries = {DFDS '25},<br \/>\r\nabstract = {Timestamps play a pivotal role in digital forensic event reconstruction, but due to their non-essential nature, tampering or manipulation of timestamps is possible by users in multiple ways, even on running systems. This has a significant effect on the reliability of the results from applying a timeline analysis as part of an investigation. We investigate the problem of users tampering with timestamps on a running (\u201clive\u201d) system. While prior work has shown that digital evidence tampering is hard, we focus on the question of why this is so. By performing a qualitative user study with advanced university students, we derive factors that influence the reliability of successful tampering, such as the individual knowledge about temporal traces, and technical restrictions to change them. These insights help to assess the reliability of timestamps from individual artifacts that are used for event reconstruction and subsequently reduce the risk of misinterpretations.},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {inproceedings}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('925','tp_bibtex')\">Close<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_925\" style=\"display:none;\"><div class=\"tp_abstract_entry\">Timestamps play a pivotal role in digital forensic event reconstruction, but due to their non-essential nature, tampering or manipulation of timestamps is possible by users in multiple ways, even on running systems. This has a significant effect on the reliability of the results from applying a timeline analysis as part of an investigation. We investigate the problem of users tampering with timestamps on a running (\u201clive\u201d) system. While prior work has shown that digital evidence tampering is hard, we focus on the question of why this is so. By performing a qualitative user study with advanced university students, we derive factors that influence the reliability of successful tampering, such as the individual knowledge about temporal traces, and technical restrictions to change them. These insights help to assess the reliability of timestamps from individual artifacts that are used for event reconstruction and subsequently reduce the risk of misinterpretations.<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('925','tp_abstract')\">Close<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_925\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"fas fa-globe\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/doi.org\/10.1145\/3712716.3712727\" title=\"https:\/\/doi.org\/10.1145\/3712716.3712727\" target=\"_blank\">https:\/\/doi.org\/10.1145\/3712716.3712727<\/a><\/li><li><i class=\"ai ai-doi\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/dx.doi.org\/10.1145\/3712716.3712727\" title=\"Follow DOI:10.1145\/3712716.3712727\" target=\"_blank\">doi:10.1145\/3712716.3712727<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('925','tp_links')\">Close<\/a><\/p><\/div><\/td><\/tr><tr class=\"tp_publication tp_publication_inproceedings\"><td class=\"tp_pub_number\">15.<\/td><td class=\"tp_pub_info\"><p class=\"tp_pub_author\"> Michelet, Ga\u00ebtan;  Breitinger, Frank<\/p><p class=\"tp_pub_title\"><a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('926','tp_links')\" style=\"cursor:pointer;\">Automation for digital forensics: Towards a classification model for the community<\/a> (<span class=\"tp_pub_type tp_  inproceedings\">Proceedings Article<\/span>)<\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_in\">In: <\/span><span class=\"tp_pub_additional_booktitle\">Proceedings of the Digital Forensics Doctoral Symposium, <\/span><span class=\"tp_pub_additional_publisher\">Association for Computing Machinery, <\/span><span class=\"tp_pub_additional_address\">Brno, CZ, <\/span><span class=\"tp_pub_additional_year\">2025<\/span>, <span class=\"tp_pub_additional_isbn\">ISBN: 9798400710766<\/span>.<\/p><p class=\"tp_pub_menu\">(<span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_926\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('926','tp_abstract')\" title=\"Show abstract\" style=\"cursor:pointer;\">Abstract<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_926\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('926','tp_links')\" title=\"Show links and resources\" style=\"cursor:pointer;\">Links<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_926\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('926','tp_bibtex')\" title=\"Show BibTeX entry\" style=\"cursor:pointer;\">BibTeX<\/a><\/span>)<\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_926\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@inproceedings{10.1145\/3712716.3712725,<br \/>\r\ntitle = {Automation for digital forensics: Towards a classification model for the community},<br \/>\r\nauthor = {Ga\u00ebtan Michelet and Frank Breitinger},<br \/>\r\nurl = {https:\/\/doi.org\/10.1145\/3712716.3712725},<br \/>\r\ndoi = {10.1145\/3712716.3712725},<br \/>\r\nisbn = {9798400710766},<br \/>\r\nyear  = {2025},<br \/>\r\ndate = {2025-04-01},<br \/>\r\nbooktitle = {Proceedings of the Digital Forensics Doctoral Symposium},<br \/>\r\npublisher = {Association for Computing Machinery},<br \/>\r\naddress = {Brno, CZ},<br \/>\r\nseries = {DFDS '25},<br \/>\r\nabstract = {The current state of automation in digital forensics remains insufficiently defined. While the complexity of automated tools and methods has evolved significantly (e.g., from basic parsers to the integration of advanced techniques), it remains challenging to pinpoint the field\u2019s overall progress or compare methods. A first step towards a solution was the work \u2018Automation for digital forensics: Towards a definition for the community\u2019 which defines automation but cannot categorize various methods. This work aims to address this gap and presents a first classification model for automation for digital forensics. Therefore, we analyzed automation classification schemes from different disciplines (e.g., cars) and assessed various model possibilities as well as characteristics. We conclude that a 2-dimensional model with the axis \u2018decision\u2019 and \u2018level of automation\u2019 is most appropriate and provide an overview table with examples.},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {inproceedings}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('926','tp_bibtex')\">Close<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_926\" style=\"display:none;\"><div class=\"tp_abstract_entry\">The current state of automation in digital forensics remains insufficiently defined. While the complexity of automated tools and methods has evolved significantly (e.g., from basic parsers to the integration of advanced techniques), it remains challenging to pinpoint the field\u2019s overall progress or compare methods. A first step towards a solution was the work \u2018Automation for digital forensics: Towards a definition for the community\u2019 which defines automation but cannot categorize various methods. This work aims to address this gap and presents a first classification model for automation for digital forensics. Therefore, we analyzed automation classification schemes from different disciplines (e.g., cars) and assessed various model possibilities as well as characteristics. We conclude that a 2-dimensional model with the axis \u2018decision\u2019 and \u2018level of automation\u2019 is most appropriate and provide an overview table with examples.<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('926','tp_abstract')\">Close<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_926\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"fas fa-globe\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/doi.org\/10.1145\/3712716.3712725\" title=\"https:\/\/doi.org\/10.1145\/3712716.3712725\" target=\"_blank\">https:\/\/doi.org\/10.1145\/3712716.3712725<\/a><\/li><li><i class=\"ai ai-doi\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/dx.doi.org\/10.1145\/3712716.3712725\" title=\"Follow DOI:10.1145\/3712716.3712725\" target=\"_blank\">doi:10.1145\/3712716.3712725<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('926','tp_links')\">Close<\/a><\/p><\/div><\/td><\/tr><tr class=\"tp_publication tp_publication_article\"><td class=\"tp_pub_number\">16.<\/td><td class=\"tp_pub_info\"><p class=\"tp_pub_author\"> Wickramasekara, Akila;  Breitinger, Frank;  Scanlon, Mark<\/p><p class=\"tp_pub_title\"><a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('923','tp_links')\" style=\"cursor:pointer;\">Exploring the potential of large language models for improving digital forensic investigation efficiency<\/a> (<span class=\"tp_pub_type tp_  article\">Journal Article<\/span>)<\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_in\">In: <\/span><span class=\"tp_pub_additional_journal\">Forensic Science International: Digital Investigation, <\/span><span class=\"tp_pub_additional_volume\">vol. 52, <\/span><span class=\"tp_pub_additional_pages\">pp. 301859, <\/span><span class=\"tp_pub_additional_year\">2025<\/span>, <span class=\"tp_pub_additional_issn\">ISSN: 2666-2817<\/span>.<\/p><p class=\"tp_pub_menu\">(<span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_923\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('923','tp_abstract')\" title=\"Show abstract\" style=\"cursor:pointer;\">Abstract<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_923\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('923','tp_links')\" title=\"Show links and resources\" style=\"cursor:pointer;\">Links<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_923\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('923','tp_bibtex')\" title=\"Show BibTeX entry\" style=\"cursor:pointer;\">BibTeX<\/a><\/span>)<\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_923\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@article{WICKRAMASEKARA2025301859,<br \/>\r\ntitle = {Exploring the potential of large language models for improving digital forensic investigation efficiency},<br \/>\r\nauthor = {Akila Wickramasekara and Frank Breitinger and Mark Scanlon},<br \/>\r\nurl = {https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281724001860},<br \/>\r\ndoi = {https:\/\/doi.org\/10.1016\/j.fsidi.2024.301859},<br \/>\r\nissn = {2666-2817},<br \/>\r\nyear  = {2025},<br \/>\r\ndate = {2025-02-03},<br \/>\r\njournal = {Forensic Science International: Digital Investigation},<br \/>\r\nvolume = {52},<br \/>\r\npages = {301859},<br \/>\r\nabstract = {The ever-increasing workload of digital forensic labs raises concerns about law enforcement's ability to conduct both cyber-related and non-cyber-related investigations promptly. Consequently, this article explores the potential and usefulness of integrating Large Language Models (LLMs) into digital forensic investigations to address challenges such as bias, explainability, censorship, resource-intensive infrastructure, and ethical and legal considerations. A comprehensive literature review is carried out, encompassing existing digital forensic models, tools, LLMs, deep learning techniques, and the use of LLMs in investigations. The review identifies current challenges within existing digital forensic processes and explores both the obstacles and the possibilities of incorporating LLMs. In conclusion, the study states that the adoption of LLMs in digital forensics, with appropriate constraints, has the potential to improve investigation efficiency, improve traceability, and alleviate the technical and judicial barriers faced by law enforcement entities.},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {article}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('923','tp_bibtex')\">Close<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_923\" style=\"display:none;\"><div class=\"tp_abstract_entry\">The ever-increasing workload of digital forensic labs raises concerns about law enforcement's ability to conduct both cyber-related and non-cyber-related investigations promptly. Consequently, this article explores the potential and usefulness of integrating Large Language Models (LLMs) into digital forensic investigations to address challenges such as bias, explainability, censorship, resource-intensive infrastructure, and ethical and legal considerations. A comprehensive literature review is carried out, encompassing existing digital forensic models, tools, LLMs, deep learning techniques, and the use of LLMs in investigations. The review identifies current challenges within existing digital forensic processes and explores both the obstacles and the possibilities of incorporating LLMs. In conclusion, the study states that the adoption of LLMs in digital forensics, with appropriate constraints, has the potential to improve investigation efficiency, improve traceability, and alleviate the technical and judicial barriers faced by law enforcement entities.<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('923','tp_abstract')\">Close<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_923\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"fas fa-globe\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281724001860\" title=\"https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281724001860\" target=\"_blank\">https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281724001860<\/a><\/li><li><i class=\"ai ai-doi\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/dx.doi.org\/https:\/\/doi.org\/10.1016\/j.fsidi.2024.301859\" title=\"Follow DOI:https:\/\/doi.org\/10.1016\/j.fsidi.2024.301859\" target=\"_blank\">doi:https:\/\/doi.org\/10.1016\/j.fsidi.2024.301859<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('923','tp_links')\">Close<\/a><\/p><\/div><\/td><\/tr><tr class=\"tp_publication tp_publication_article\"><td class=\"tp_pub_number\">17.<\/td><td class=\"tp_pub_info\"><p class=\"tp_pub_author\"> G\u00f6bel, Thomas;  Breitinger, Frank;  Baier, Harald<\/p><p class=\"tp_pub_title\"><a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('922','tp_links')\" style=\"cursor:pointer;\">Optimising data set creation in the cybersecurity landscape with a special focus on digital forensics: Principles, characteristics, and use cases<\/a> (<span class=\"tp_pub_type tp_  article\">Journal Article<\/span>)<\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_in\">In: <\/span><span class=\"tp_pub_additional_journal\">Forensic Science International: Digital Investigation, <\/span><span class=\"tp_pub_additional_volume\">vol. 52, <\/span><span class=\"tp_pub_additional_pages\">pp. 301882, <\/span><span class=\"tp_pub_additional_year\">2025<\/span>, <span class=\"tp_pub_additional_issn\">ISSN: 2666-2817<\/span>.<\/p><p class=\"tp_pub_menu\">(<span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_922\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('922','tp_abstract')\" title=\"Show abstract\" style=\"cursor:pointer;\">Abstract<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_922\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('922','tp_links')\" title=\"Show links and resources\" style=\"cursor:pointer;\">Links<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_922\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('922','tp_bibtex')\" title=\"Show BibTeX entry\" style=\"cursor:pointer;\">BibTeX<\/a><\/span>)<\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_922\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@article{GOBEL2025301882,<br \/>\r\ntitle = {Optimising data set creation in the cybersecurity landscape with a special focus on digital forensics: Principles, characteristics, and use cases},<br \/>\r\nauthor = {Thomas G\u00f6bel and Frank Breitinger and Harald Baier},<br \/>\r\nurl = {https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281725000216},<br \/>\r\ndoi = {https:\/\/doi.org\/10.1016\/j.fsidi.2025.301882},<br \/>\r\nissn = {2666-2817},<br \/>\r\nyear  = {2025},<br \/>\r\ndate = {2025-01-29},<br \/>\r\nurldate = {2025-01-01},<br \/>\r\njournal = {Forensic Science International: Digital Investigation},<br \/>\r\nvolume = {52},<br \/>\r\npages = {301882},<br \/>\r\nabstract = {Data sets (samples) are important for research, training, and tool development. While the FAIR principles, data repositories and archives like Zenodo and NIST's Computer Forensic Reference Data Sets (CFReDS) enhance the accessibility and reusability of data sets, standardised practices for crafting and describing these data sets require further attention. This paper analyses the existing literature to identify the key data set (generation) characteristics, issues, desirable attributes, and use cases. Although our findings are generally applicable, i.e., to the cybersecurity domain, our special focus is on the digital forensics domain. We define principles and properties for cybersecurity-relevant data sets and their implications for the data creation process to maximise their quality, utility and applicability, taking into account specific data set use cases and data origin. We aim to guide data set creators in enhancing their data sets' value for the cybersecurity and digital forensics field.},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {article}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('922','tp_bibtex')\">Close<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_922\" style=\"display:none;\"><div class=\"tp_abstract_entry\">Data sets (samples) are important for research, training, and tool development. While the FAIR principles, data repositories and archives like Zenodo and NIST's Computer Forensic Reference Data Sets (CFReDS) enhance the accessibility and reusability of data sets, standardised practices for crafting and describing these data sets require further attention. This paper analyses the existing literature to identify the key data set (generation) characteristics, issues, desirable attributes, and use cases. Although our findings are generally applicable, i.e., to the cybersecurity domain, our special focus is on the digital forensics domain. We define principles and properties for cybersecurity-relevant data sets and their implications for the data creation process to maximise their quality, utility and applicability, taking into account specific data set use cases and data origin. We aim to guide data set creators in enhancing their data sets' value for the cybersecurity and digital forensics field.<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('922','tp_abstract')\">Close<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_922\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"fas fa-globe\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281725000216\" title=\"https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281725000216\" target=\"_blank\">https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281725000216<\/a><\/li><li><i class=\"ai ai-doi\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/dx.doi.org\/https:\/\/doi.org\/10.1016\/j.fsidi.2025.301882\" title=\"Follow DOI:https:\/\/doi.org\/10.1016\/j.fsidi.2025.301882\" target=\"_blank\">doi:https:\/\/doi.org\/10.1016\/j.fsidi.2025.301882<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('922','tp_links')\">Close<\/a><\/p><\/div><\/td><\/tr><tr class=\"tp_publication tp_publication_article\"><td class=\"tp_pub_number\">18.<\/td><td class=\"tp_pub_info\"><p class=\"tp_pub_author\"> Hargreaves, Christopher;  Breitinger, Frank;  Dowthwaite, Liz;  Webb, Helena;  Scanlon, Mark<\/p><p class=\"tp_pub_title\"><a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('921','tp_links')\" style=\"cursor:pointer;\">DFPulse: The 2024 digital forensic practitioner survey<\/a> (<span class=\"tp_pub_type tp_  article\">Journal Article<\/span>)<\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_in\">In: <\/span><span class=\"tp_pub_additional_journal\">Forensic Science International: Digital Investigation, <\/span><span class=\"tp_pub_additional_volume\">vol. 51, <\/span><span class=\"tp_pub_additional_pages\">pp. 301844, <\/span><span class=\"tp_pub_additional_year\">2024<\/span>, <span class=\"tp_pub_additional_issn\">ISSN: 2666-2817<\/span>.<\/p><p class=\"tp_pub_menu\">(<span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_921\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('921','tp_abstract')\" title=\"Show abstract\" style=\"cursor:pointer;\">Abstract<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_921\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('921','tp_links')\" title=\"Show links and resources\" style=\"cursor:pointer;\">Links<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_921\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('921','tp_bibtex')\" title=\"Show BibTeX entry\" style=\"cursor:pointer;\">BibTeX<\/a><\/span>)<\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_921\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@article{HARGREAVES2024301844,<br \/>\r\ntitle = {DFPulse: The 2024 digital forensic practitioner survey},<br \/>\r\nauthor = {Christopher Hargreaves and Frank Breitinger and Liz Dowthwaite and Helena Webb and Mark Scanlon},<br \/>\r\nurl = {https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281724001719},<br \/>\r\ndoi = {10.1016\/j.fsidi.2024.301844},<br \/>\r\nissn = {2666-2817},<br \/>\r\nyear  = {2024},<br \/>\r\ndate = {2024-11-29},<br \/>\r\njournal = {Forensic Science International: Digital Investigation},<br \/>\r\nvolume = {51},<br \/>\r\npages = {301844},<br \/>\r\nabstract = {This paper reports on the largest survey of digital forensic practitioners to date (DFPulse) conducted from March to May 2024 resulting in 122 responses. The survey collected information about practitioners' operating environments, the technologies they encounter, investigative techniques they use, the challenges they face, the degree to which academic research is accessed and useful to the practitioner community, and their suggested future research directions. The paper includes quantitative and qualitative results from the survey and a discussion of the implications for academia, the improvements that can be made, and future research directions.},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {article}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('921','tp_bibtex')\">Close<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_921\" style=\"display:none;\"><div class=\"tp_abstract_entry\">This paper reports on the largest survey of digital forensic practitioners to date (DFPulse) conducted from March to May 2024 resulting in 122 responses. The survey collected information about practitioners' operating environments, the technologies they encounter, investigative techniques they use, the challenges they face, the degree to which academic research is accessed and useful to the practitioner community, and their suggested future research directions. The paper includes quantitative and qualitative results from the survey and a discussion of the implications for academia, the improvements that can be made, and future research directions.<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('921','tp_abstract')\">Close<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_921\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"fas fa-globe\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281724001719\" title=\"https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281724001719\" target=\"_blank\">https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281724001719<\/a><\/li><li><i class=\"ai ai-doi\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/dx.doi.org\/10.1016\/j.fsidi.2024.301844\" title=\"Follow DOI:10.1016\/j.fsidi.2024.301844\" target=\"_blank\">doi:10.1016\/j.fsidi.2024.301844<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('921','tp_links')\">Close<\/a><\/p><\/div><\/td><\/tr><tr class=\"tp_publication tp_publication_article\"><td class=\"tp_pub_number\">19.<\/td><td class=\"tp_pub_info\"><p class=\"tp_pub_author\"> Dreier, Lisa Marie;  Vanini, C\u00e9line;  Hargreaves, Christopher J.;  Breitinger, Frank;  Freiling, Felix<\/p><p class=\"tp_pub_title\"><a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('919','tp_links')\" style=\"cursor:pointer;\">Beyond timestamps: Integrating implicit timing information into digital forensic timelines<\/a> (<span class=\"tp_pub_type tp_  article\">Journal Article<\/span>)<\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_in\">In: <\/span><span class=\"tp_pub_additional_journal\">Forensic Science International: Digital Investigation, <\/span><span class=\"tp_pub_additional_volume\">vol. 49, <\/span><span class=\"tp_pub_additional_pages\">pp. 301755, <\/span><span class=\"tp_pub_additional_year\">2024<\/span>, <span class=\"tp_pub_additional_issn\">ISSN: 2666-2817<\/span><span class=\"tp_pub_additional_note\">, (bf Best Paper Award)<\/span>.<\/p><p class=\"tp_pub_menu\">(<span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_919\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('919','tp_abstract')\" title=\"Show abstract\" style=\"cursor:pointer;\">Abstract<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_919\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('919','tp_links')\" title=\"Show links and resources\" style=\"cursor:pointer;\">Links<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_919\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('919','tp_bibtex')\" title=\"Show BibTeX entry\" style=\"cursor:pointer;\">BibTeX<\/a><\/span>)<\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_919\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@article{DREIER2024301755,<br \/>\r\ntitle = {Beyond timestamps: Integrating implicit timing information into digital forensic timelines},<br \/>\r\nauthor = {Lisa Marie Dreier and C\u00e9line Vanini and Christopher J. Hargreaves and Frank Breitinger and Felix Freiling},<br \/>\r\nurl = {https:\/\/www.sciencedirect.com\/science\/article\/pii\/S266628172400074X},<br \/>\r\ndoi = {10.1016\/j.fsidi.2024.301755},<br \/>\r\nissn = {2666-2817},<br \/>\r\nyear  = {2024},<br \/>\r\ndate = {2024-07-08},<br \/>\r\njournal = {Forensic Science International: Digital Investigation},<br \/>\r\nvolume = {49},<br \/>\r\npages = {301755},<br \/>\r\nabstract = {Generating timelines, i.e., sorting events by their respective timestamps, is an essential technique commonly used in digital forensic investigations. But timestamps are not the only source of timing information. For example, sequence numbers embedded in databases or positional information, such as the line numbers in log files, often contain implicit information about the order of events without directly referencing a timestamp. We present a method that can integrate such timing information into digital forensic timelines by separating sources of timing information into distinct time domains, each with its own timeline, and then connecting these timelines based on relations observed within digital evidence. The classical ``flat'' timeline is thereby extended into a ``rich'' partial order, which we call hyper timeline. Our technique allows ordering of events without timestamps and opens a rich set of possibilities to identify and characterize timestamp inconsistencies, e.g., those that arise from timestamp tampering.},<br \/>\r\nnote = {bf Best Paper Award},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {article}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('919','tp_bibtex')\">Close<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_919\" style=\"display:none;\"><div class=\"tp_abstract_entry\">Generating timelines, i.e., sorting events by their respective timestamps, is an essential technique commonly used in digital forensic investigations. But timestamps are not the only source of timing information. For example, sequence numbers embedded in databases or positional information, such as the line numbers in log files, often contain implicit information about the order of events without directly referencing a timestamp. We present a method that can integrate such timing information into digital forensic timelines by separating sources of timing information into distinct time domains, each with its own timeline, and then connecting these timelines based on relations observed within digital evidence. The classical ``flat'' timeline is thereby extended into a ``rich'' partial order, which we call hyper timeline. Our technique allows ordering of events without timestamps and opens a rich set of possibilities to identify and characterize timestamp inconsistencies, e.g., those that arise from timestamp tampering.<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('919','tp_abstract')\">Close<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_919\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"fas fa-globe\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/www.sciencedirect.com\/science\/article\/pii\/S266628172400074X\" title=\"https:\/\/www.sciencedirect.com\/science\/article\/pii\/S266628172400074X\" target=\"_blank\">https:\/\/www.sciencedirect.com\/science\/article\/pii\/S266628172400074X<\/a><\/li><li><i class=\"ai ai-doi\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/dx.doi.org\/10.1016\/j.fsidi.2024.301755\" title=\"Follow DOI:10.1016\/j.fsidi.2024.301755\" target=\"_blank\">doi:10.1016\/j.fsidi.2024.301755<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('919','tp_links')\">Close<\/a><\/p><\/div><\/td><\/tr><tr class=\"tp_publication tp_publication_article\"><td class=\"tp_pub_number\">20.<\/td><td class=\"tp_pub_info\"><p class=\"tp_pub_author\"> Vanini, C\u00e9line;  Hargreaves, Christopher J.;  Beek, Harm;  Breitinger, Frank<\/p><p class=\"tp_pub_title\"><a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('920','tp_links')\" style=\"cursor:pointer;\">Was the clock correct? Exploring timestamp interpretation through time anchors for digital forensic event reconstruction<\/a> (<span class=\"tp_pub_type tp_  article\">Journal Article<\/span>)<\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_in\">In: <\/span><span class=\"tp_pub_additional_journal\">Forensic Science International: Digital Investigation, <\/span><span class=\"tp_pub_additional_volume\">vol. 49, <\/span><span class=\"tp_pub_additional_pages\">pp. 301759, <\/span><span class=\"tp_pub_additional_year\">2024<\/span>, <span class=\"tp_pub_additional_issn\">ISSN: 2666-2817<\/span><span class=\"tp_pub_additional_note\">, (DFRWS USA 2024 - Selected Papers from the 24th Annual Digital Forensics Research Conference USA)<\/span>.<\/p><p class=\"tp_pub_menu\">(<span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_920\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('920','tp_abstract')\" title=\"Show abstract\" style=\"cursor:pointer;\">Abstract<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_920\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('920','tp_links')\" title=\"Show links and resources\" style=\"cursor:pointer;\">Links<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_920\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('920','tp_bibtex')\" title=\"Show BibTeX entry\" style=\"cursor:pointer;\">BibTeX<\/a><\/span>)<\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_920\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@article{VANINI2024301759,<br \/>\r\ntitle = {Was the clock correct? Exploring timestamp interpretation through time anchors for digital forensic event reconstruction},<br \/>\r\nauthor = {C\u00e9line Vanini and Christopher J. Hargreaves and Harm Beek and Frank Breitinger},<br \/>\r\nurl = {https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281724000787},<br \/>\r\ndoi = {10.1016\/j.fsidi.2024.301759},<br \/>\r\nissn = {2666-2817},<br \/>\r\nyear  = {2024},<br \/>\r\ndate = {2024-07-08},<br \/>\r\njournal = {Forensic Science International: Digital Investigation},<br \/>\r\nvolume = {49},<br \/>\r\npages = {301759},<br \/>\r\nabstract = {Timestamps and their correct interpretation play a crucial role in digital forensic investigations, particularly when the objective is to establish a timeline of events a.k.a. event reconstruction. However, the way these timestamps are generated heavily depends on an internal clock, or `system time', from which many are derived. Consequently, when this system time is skewed due to tampering, natural clock drift, or system malfunctions, recorded timestamps will not reflect the actual times the (real-world) events occurred. This raises the question of how to validate the correctness of the system clock when recording timestamps and, if found incorrect, how to determine system clock skew. To address this problem, this paper defines several important concepts such as time anchors, anchoring events, non-anchoring events and time anomalies which can be used to determine if the system time was correct. Using two examples - a Google search and a file creation - and comparing correct and skewed versions of the same set of performed actions, we illustrate the use and potential benefits of time anchors to demonstrate the correctness of the system clock for event reconstruction.},<br \/>\r\nnote = {DFRWS USA 2024 - Selected Papers from the 24th Annual Digital Forensics Research Conference USA},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {article}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('920','tp_bibtex')\">Close<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_920\" style=\"display:none;\"><div class=\"tp_abstract_entry\">Timestamps and their correct interpretation play a crucial role in digital forensic investigations, particularly when the objective is to establish a timeline of events a.k.a. event reconstruction. However, the way these timestamps are generated heavily depends on an internal clock, or `system time', from which many are derived. Consequently, when this system time is skewed due to tampering, natural clock drift, or system malfunctions, recorded timestamps will not reflect the actual times the (real-world) events occurred. This raises the question of how to validate the correctness of the system clock when recording timestamps and, if found incorrect, how to determine system clock skew. To address this problem, this paper defines several important concepts such as time anchors, anchoring events, non-anchoring events and time anomalies which can be used to determine if the system time was correct. Using two examples - a Google search and a file creation - and comparing correct and skewed versions of the same set of performed actions, we illustrate the use and potential benefits of time anchors to demonstrate the correctness of the system clock for event reconstruction.<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('920','tp_abstract')\">Close<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_920\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"fas fa-globe\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281724000787\" title=\"https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281724000787\" target=\"_blank\">https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281724000787<\/a><\/li><li><i class=\"ai ai-doi\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/dx.doi.org\/10.1016\/j.fsidi.2024.301759\" title=\"Follow DOI:10.1016\/j.fsidi.2024.301759\" target=\"_blank\">doi:10.1016\/j.fsidi.2024.301759<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('920','tp_links')\">Close<\/a><\/p><\/div><\/td><\/tr><tr class=\"tp_publication tp_publication_article\"><td class=\"tp_pub_number\">21.<\/td><td class=\"tp_pub_info\"><p class=\"tp_pub_author\"> Breitinger, Frank;  Hilgert, Jan-Niclas;  Hargreaves, Christopher;  Sheppard, John;  Overdorf, Rebekah;  Scanlon, Mark<\/p><p class=\"tp_pub_title\"><a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('916','tp_links')\" style=\"cursor:pointer;\">DFRWS EU 10-year review and future directions in Digital Forensic Research<\/a> (<span class=\"tp_pub_type tp_  article\">Journal Article<\/span>)<\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_in\">In: <\/span><span class=\"tp_pub_additional_journal\">Forensic Science International: Digital Investigation, <\/span><span class=\"tp_pub_additional_volume\">vol. 48, <\/span><span class=\"tp_pub_additional_pages\">pp. 301685, <\/span><span class=\"tp_pub_additional_year\">2024<\/span>, <span class=\"tp_pub_additional_issn\">ISSN: 2666-2817<\/span><span class=\"tp_pub_additional_note\">, (DFRWS EU 2024 - Selected Papers from the 11th Annual Digital Forensics Research Conference Europe)<\/span>.<\/p><p class=\"tp_pub_menu\">(<span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_916\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('916','tp_abstract')\" title=\"Show abstract\" style=\"cursor:pointer;\">Abstract<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_916\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('916','tp_links')\" title=\"Show links and resources\" style=\"cursor:pointer;\">Links<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_916\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('916','tp_bibtex')\" title=\"Show BibTeX entry\" style=\"cursor:pointer;\">BibTeX<\/a><\/span>)<\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_916\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@article{BREITINGER2024301685,<br \/>\r\ntitle = {DFRWS EU 10-year review and future directions in Digital Forensic Research},<br \/>\r\nauthor = {Frank Breitinger and Jan-Niclas Hilgert and Christopher Hargreaves and John Sheppard and Rebekah Overdorf and Mark Scanlon},<br \/>\r\nurl = {https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281723002044},<br \/>\r\ndoi = {10.1016\/j.fsidi.2023.301685},<br \/>\r\nissn = {2666-2817},<br \/>\r\nyear  = {2024},<br \/>\r\ndate = {2024-03-15},<br \/>\r\njournal = {Forensic Science International: Digital Investigation},<br \/>\r\nvolume = {48},<br \/>\r\npages = {301685},<br \/>\r\nabstract = {Conducting a systematic literature review and comprehensive analysis, this paper surveys all 135 peer-reviewed articles published at the Digital Forensics Research Conference Europe (DFRWS EU) spanning the decade since its inaugural running (2014\u20132023). This comprehensive study of DFRWS EU articles encompasses sub-disciplines such as digital forensic science, device forensics, techniques and fundamentals, artefact forensics, multimedia forensics, memory forensics, and network forensics. Quantitative analysis of the articles' co-authorships, geographical spread and citation metrics are outlined. The analysis presented offers insights into the evolution of digital forensic research efforts over these ten years and informs some identified future research directions.},<br \/>\r\nnote = {DFRWS EU 2024 - Selected Papers from the 11th Annual Digital Forensics Research Conference Europe},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {article}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('916','tp_bibtex')\">Close<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_916\" style=\"display:none;\"><div class=\"tp_abstract_entry\">Conducting a systematic literature review and comprehensive analysis, this paper surveys all 135 peer-reviewed articles published at the Digital Forensics Research Conference Europe (DFRWS EU) spanning the decade since its inaugural running (2014\u20132023). This comprehensive study of DFRWS EU articles encompasses sub-disciplines such as digital forensic science, device forensics, techniques and fundamentals, artefact forensics, multimedia forensics, memory forensics, and network forensics. Quantitative analysis of the articles' co-authorships, geographical spread and citation metrics are outlined. The analysis presented offers insights into the evolution of digital forensic research efforts over these ten years and informs some identified future research directions.<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('916','tp_abstract')\">Close<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_916\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"fas fa-globe\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281723002044\" title=\"https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281723002044\" target=\"_blank\">https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281723002044<\/a><\/li><li><i class=\"ai ai-doi\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/dx.doi.org\/10.1016\/j.fsidi.2023.301685\" title=\"Follow DOI:10.1016\/j.fsidi.2023.301685\" target=\"_blank\">doi:10.1016\/j.fsidi.2023.301685<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('916','tp_links')\">Close<\/a><\/p><\/div><\/td><\/tr><tr class=\"tp_publication tp_publication_article\"><td class=\"tp_pub_number\">22.<\/td><td class=\"tp_pub_info\"><p class=\"tp_pub_author\"> Mombelli, Samuele;  Lyle, James R.;  Breitinger, Frank<\/p><p class=\"tp_pub_title\"><a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('917','tp_links')\" style=\"cursor:pointer;\">FAIRness in digital forensics datasets' metadata \u2013 and how to improve it<\/a> (<span class=\"tp_pub_type tp_  article\">Journal Article<\/span>)<\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_in\">In: <\/span><span class=\"tp_pub_additional_journal\">Forensic Science International: Digital Investigation, <\/span><span class=\"tp_pub_additional_volume\">vol. 48, <\/span><span class=\"tp_pub_additional_pages\">pp. 301681, <\/span><span class=\"tp_pub_additional_year\">2024<\/span>, <span class=\"tp_pub_additional_issn\">ISSN: 2666-2817<\/span><span class=\"tp_pub_additional_note\">, (DFRWS EU 2024 - Selected Papers from the 11th Annual Digital Forensics Research Conference Europe)<\/span>.<\/p><p class=\"tp_pub_menu\">(<span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_917\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('917','tp_abstract')\" title=\"Show abstract\" style=\"cursor:pointer;\">Abstract<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_917\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('917','tp_links')\" title=\"Show links and resources\" style=\"cursor:pointer;\">Links<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_917\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('917','tp_bibtex')\" title=\"Show BibTeX entry\" style=\"cursor:pointer;\">BibTeX<\/a><\/span>)<\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_917\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@article{MOMBELLI2024301681,<br \/>\r\ntitle = {FAIRness in digital forensics datasets' metadata \u2013 and how to improve it},<br \/>\r\nauthor = {Samuele Mombelli and James R. Lyle and Frank Breitinger},<br \/>\r\nurl = {https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281723002007},<br \/>\r\ndoi = {10.1016\/j.fsidi.2023.301681},<br \/>\r\nissn = {2666-2817},<br \/>\r\nyear  = {2024},<br \/>\r\ndate = {2024-03-15},<br \/>\r\njournal = {Forensic Science International: Digital Investigation},<br \/>\r\nvolume = {48},<br \/>\r\npages = {301681},<br \/>\r\nabstract = {The availability of research data (datasets) and compliance with FAIR principles\u2014Findability, Accessibility, Interoperability, and Reusability\u2014is critical to progressing digital forensics. This study evaluates metadata completeness and assesses the alignment with the FAIR principles using all 212 datasets from NIST's Computer Forensic Reference DataSet Portal (CFReDS). The findings underscore deficiencies in metadata quality and FAIR compliance, emphasizing the need for improved data management standards. Based on our critical review, we then propose and discuss various approaches to improve the status quo.},<br \/>\r\nnote = {DFRWS EU 2024 - Selected Papers from the 11th Annual Digital Forensics Research Conference Europe},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {article}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('917','tp_bibtex')\">Close<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_917\" style=\"display:none;\"><div class=\"tp_abstract_entry\">The availability of research data (datasets) and compliance with FAIR principles\u2014Findability, Accessibility, Interoperability, and Reusability\u2014is critical to progressing digital forensics. This study evaluates metadata completeness and assesses the alignment with the FAIR principles using all 212 datasets from NIST's Computer Forensic Reference DataSet Portal (CFReDS). The findings underscore deficiencies in metadata quality and FAIR compliance, emphasizing the need for improved data management standards. Based on our critical review, we then propose and discuss various approaches to improve the status quo.<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('917','tp_abstract')\">Close<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_917\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"fas fa-globe\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281723002007\" title=\"https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281723002007\" target=\"_blank\">https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281723002007<\/a><\/li><li><i class=\"ai ai-doi\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/dx.doi.org\/10.1016\/j.fsidi.2023.301681\" title=\"Follow DOI:10.1016\/j.fsidi.2023.301681\" target=\"_blank\">doi:10.1016\/j.fsidi.2023.301681<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('917','tp_links')\">Close<\/a><\/p><\/div><\/td><\/tr><tr class=\"tp_publication tp_publication_article\"><td class=\"tp_pub_number\">23.<\/td><td class=\"tp_pub_info\"><p class=\"tp_pub_author\"> Michelet, Ga\u00ebtan;  Breitinger, Frank<\/p><p class=\"tp_pub_title\"><a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('918','tp_links')\" style=\"cursor:pointer;\">ChatGPT, Llama, can you write my report? An experiment on assisted digital forensics reports written using (local) large language models<\/a> (<span class=\"tp_pub_type tp_  article\">Journal Article<\/span>)<\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_in\">In: <\/span><span class=\"tp_pub_additional_journal\">Forensic Science International: Digital Investigation, <\/span><span class=\"tp_pub_additional_volume\">vol. 48, <\/span><span class=\"tp_pub_additional_pages\">pp. 301683, <\/span><span class=\"tp_pub_additional_year\">2024<\/span>, <span class=\"tp_pub_additional_issn\">ISSN: 2666-2817<\/span><span class=\"tp_pub_additional_note\">, (DFRWS EU 2024 - Selected Papers from the 11th Annual Digital Forensics Research Conference Europe)<\/span>.<\/p><p class=\"tp_pub_menu\">(<span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_918\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('918','tp_abstract')\" title=\"Show abstract\" style=\"cursor:pointer;\">Abstract<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_918\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('918','tp_links')\" title=\"Show links and resources\" style=\"cursor:pointer;\">Links<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_918\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('918','tp_bibtex')\" title=\"Show BibTeX entry\" style=\"cursor:pointer;\">BibTeX<\/a><\/span>)<\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_918\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@article{MICHELET2024301683,<br \/>\r\ntitle = {ChatGPT, Llama, can you write my report? An experiment on assisted digital forensics reports written using (local) large language models},<br \/>\r\nauthor = {Ga\u00ebtan Michelet and Frank Breitinger},<br \/>\r\nurl = {https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281723002020},<br \/>\r\ndoi = {10.1016\/j.fsidi.2023.301683},<br \/>\r\nissn = {2666-2817},<br \/>\r\nyear  = {2024},<br \/>\r\ndate = {2024-03-15},<br \/>\r\njournal = {Forensic Science International: Digital Investigation},<br \/>\r\nvolume = {48},<br \/>\r\npages = {301683},<br \/>\r\nabstract = {Generative AIs, especially Large Language Models (LLMs) such as ChatGPT or Llama, have advanced significantly, positioning them as valuable tools for digital forensics. While initial studies have explored the potential of ChatGPT in the context of investigations, the question of to what extent LLMs can assist the forensic report writing process remains unresolved. To answer the question, this article first examines forensic reports with the goal of generalization (e.g., finding the `average structure' of a report). We then evaluate the strengths and limitations of LLMs for generating the different parts of the forensic report using a case study. This work thus provides valuable insights into the automation of report writing, a critical facet of digital forensics investigations. We conclude that combined with thorough proofreading and corrections, LLMs may assist practitioners during the report writing process but at this point cannot replace them.},<br \/>\r\nnote = {DFRWS EU 2024 - Selected Papers from the 11th Annual Digital Forensics Research Conference Europe},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {article}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('918','tp_bibtex')\">Close<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_918\" style=\"display:none;\"><div class=\"tp_abstract_entry\">Generative AIs, especially Large Language Models (LLMs) such as ChatGPT or Llama, have advanced significantly, positioning them as valuable tools for digital forensics. While initial studies have explored the potential of ChatGPT in the context of investigations, the question of to what extent LLMs can assist the forensic report writing process remains unresolved. To answer the question, this article first examines forensic reports with the goal of generalization (e.g., finding the `average structure' of a report). We then evaluate the strengths and limitations of LLMs for generating the different parts of the forensic report using a case study. This work thus provides valuable insights into the automation of report writing, a critical facet of digital forensics investigations. We conclude that combined with thorough proofreading and corrections, LLMs may assist practitioners during the report writing process but at this point cannot replace them.<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('918','tp_abstract')\">Close<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_918\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"fas fa-globe\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281723002020\" title=\"https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281723002020\" target=\"_blank\">https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281723002020<\/a><\/li><li><i class=\"ai ai-doi\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/dx.doi.org\/10.1016\/j.fsidi.2023.301683\" title=\"Follow DOI:10.1016\/j.fsidi.2023.301683\" target=\"_blank\">doi:10.1016\/j.fsidi.2023.301683<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('918','tp_links')\">Close<\/a><\/p><\/div><\/td><\/tr><tr class=\"tp_publication tp_publication_misc\"><td class=\"tp_pub_number\">24.<\/td><td class=\"tp_pub_info\"><p class=\"tp_pub_author\"> Breitinger, Frank<\/p><p class=\"tp_pub_title\">Network Threats and their Detection (<span class=\"tp_pub_type tp_  misc\">Miscellaneous<\/span>)<\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_howpublished\">Invited Tutorial Presenter at the International Conference on Innovations in Information Technology (IIT\u201923), <\/span><span class=\"tp_pub_additional_year\">2023<\/span><span class=\"tp_pub_additional_note\">, (Al Ain, United Arab Emirates)<\/span>.<\/p><p class=\"tp_pub_menu\">(<span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_934\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('934','tp_bibtex')\" title=\"Show BibTeX entry\" style=\"cursor:pointer;\">BibTeX<\/a><\/span>)<\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_934\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@misc{tutorial-UAE,<br \/>\r\ntitle = {Network Threats and their Detection},<br \/>\r\nauthor = {Frank Breitinger},<br \/>\r\nyear  = {2023},<br \/>\r\ndate = {2023-11-16},<br \/>\r\nhowpublished = {Invited Tutorial Presenter at the International Conference on Innovations in Information Technology (IIT\u201923)},<br \/>\r\nnote = {Al Ain, United Arab Emirates},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {misc}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('934','tp_bibtex')\">Close<\/a><\/p><\/div><\/td><\/tr><tr class=\"tp_publication tp_publication_article\"><td class=\"tp_pub_number\">25.<\/td><td class=\"tp_pub_info\"><p class=\"tp_pub_author\"> Ottmann, Jenny;  Breitinger, Frank;  Freiling, Felix<\/p><p class=\"tp_pub_title\"><a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('927','tp_links')\" style=\"cursor:pointer;\">An Experimental Assessment of Inconsistencies in Memory Forensics<\/a> (<span class=\"tp_pub_type tp_  article\">Journal Article<\/span>)<\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_in\">In: <\/span><span class=\"tp_pub_additional_journal\">ACM Trans. Priv. Secur., <\/span><span class=\"tp_pub_additional_volume\">vol. 27, <\/span><span class=\"tp_pub_additional_number\">no. 1, <\/span><span class=\"tp_pub_additional_year\">2023<\/span>, <span class=\"tp_pub_additional_issn\">ISSN: 2471-2566<\/span>.<\/p><p class=\"tp_pub_menu\">(<span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_927\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('927','tp_abstract')\" title=\"Show abstract\" style=\"cursor:pointer;\">Abstract<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_927\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('927','tp_links')\" title=\"Show links and resources\" style=\"cursor:pointer;\">Links<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_927\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('927','tp_bibtex')\" title=\"Show BibTeX entry\" style=\"cursor:pointer;\">BibTeX<\/a><\/span>)<\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_927\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@article{10.1145\/3628600,<br \/>\r\ntitle = {An Experimental Assessment of Inconsistencies in Memory Forensics},<br \/>\r\nauthor = {Jenny Ottmann and Frank Breitinger and Felix Freiling},<br \/>\r\nurl = {https:\/\/doi.org10.1145\/3628600},<br \/>\r\ndoi = {10.1145\/3628600},<br \/>\r\nissn = {2471-2566},<br \/>\r\nyear  = {2023},<br \/>\r\ndate = {2023-10-20},<br \/>\r\njournal = {ACM Trans. Priv. Secur.},<br \/>\r\nvolume = {27},<br \/>\r\nnumber = {1},<br \/>\r\npublisher = {Association for Computing Machinery},<br \/>\r\naddress = {New York, NY, USA},<br \/>\r\nabstract = {Memory forensics is concerned with the acquisition and analysis of copies of volatile memory (memory dumps). Based on an empirical assessment of observable inconsistencies in 360 memory dumps of a running Linux system, we confirm a state of overwhelming inconsistency in memory forensics: almost a third of these dumps had an empty process list and was therefore obviously incomplete. Out of those dumps that were analyzable, almost every second dump showed some form of inconsistency that potentially impacts the interpretation of the dump in a forensic investigation. These results are based on a new way to estimate the level of causal consistency of a memory dump. The factors influencing these inconsistencies are less clear but in general correlate with the level of concurrency (system load and number of threads).},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {article}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('927','tp_bibtex')\">Close<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_927\" style=\"display:none;\"><div class=\"tp_abstract_entry\">Memory forensics is concerned with the acquisition and analysis of copies of volatile memory (memory dumps). Based on an empirical assessment of observable inconsistencies in 360 memory dumps of a running Linux system, we confirm a state of overwhelming inconsistency in memory forensics: almost a third of these dumps had an empty process list and was therefore obviously incomplete. Out of those dumps that were analyzable, almost every second dump showed some form of inconsistency that potentially impacts the interpretation of the dump in a forensic investigation. These results are based on a new way to estimate the level of causal consistency of a memory dump. The factors influencing these inconsistencies are less clear but in general correlate with the level of concurrency (system load and number of threads).<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('927','tp_abstract')\">Close<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_927\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"fas fa-globe\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/doi.org10.1145\/3628600\" title=\"https:\/\/doi.org10.1145\/3628600\" target=\"_blank\">https:\/\/doi.org10.1145\/3628600<\/a><\/li><li><i class=\"ai ai-doi\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/dx.doi.org\/10.1145\/3628600\" title=\"Follow DOI:10.1145\/3628600\" target=\"_blank\">doi:10.1145\/3628600<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('927','tp_links')\">Close<\/a><\/p><\/div><\/td><\/tr><tr class=\"tp_publication tp_publication_article\"><td class=\"tp_pub_number\">26.<\/td><td class=\"tp_pub_info\"><p class=\"tp_pub_author\"> Scanlon, Mark;  Breitinger, Frank;  Hargreaves, Christopher;  Hilgert, Jan-Niclas;  Sheppard, John<\/p><p class=\"tp_pub_title\"><a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('915','tp_links')\" style=\"cursor:pointer;\">ChatGPT for digital forensic investigation: The good, the bad, and the unknown<\/a> (<span class=\"tp_pub_type tp_  article\">Journal Article<\/span>)<\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_in\">In: <\/span><span class=\"tp_pub_additional_journal\">Forensic Science International: Digital Investigation, <\/span><span class=\"tp_pub_additional_volume\">vol. 46, <\/span><span class=\"tp_pub_additional_pages\">pp. 301609, <\/span><span class=\"tp_pub_additional_year\">2023<\/span>, <span class=\"tp_pub_additional_issn\">ISSN: 2666-2817<\/span><span class=\"tp_pub_additional_note\">, (bf Best Paper Award)<\/span>.<\/p><p class=\"tp_pub_menu\">(<span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_915\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('915','tp_abstract')\" title=\"Show abstract\" style=\"cursor:pointer;\">Abstract<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_915\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('915','tp_links')\" title=\"Show links and resources\" style=\"cursor:pointer;\">Links<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_915\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('915','tp_bibtex')\" title=\"Show BibTeX entry\" style=\"cursor:pointer;\">BibTeX<\/a><\/span>)<\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_915\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@article{SCANLON2023301609,<br \/>\r\ntitle = {ChatGPT for digital forensic investigation: The good, the bad, and the unknown},<br \/>\r\nauthor = {Mark Scanlon and Frank Breitinger and Christopher Hargreaves and Jan-Niclas Hilgert and John Sheppard},<br \/>\r\nurl = {https:\/\/www.sciencedirect.com\/science\/article\/pii\/S266628172300121X},<br \/>\r\ndoi = {10.1016\/j.fsidi.2023.301609},<br \/>\r\nissn = {2666-2817},<br \/>\r\nyear  = {2023},<br \/>\r\ndate = {2023-10-13},<br \/>\r\nurldate = {2023-10-13},<br \/>\r\njournal = {Forensic Science International: Digital Investigation},<br \/>\r\nvolume = {46},<br \/>\r\npages = {301609},<br \/>\r\nabstract = {The disruptive application of ChatGPT (GPT-3.5, GPT-4) to a variety of domains has become a topic of much discussion in the scientific community and society at large. Large Language Models (LLMs), e.g., BERT, Bard, Generative Pre-trained Transformers (GPTs), LLaMA, etc., have the ability to take instructions, or prompts, from users and generate answers and solutions based on very large volumes of text-based training data. This paper assesses the impact and potential impact of ChatGPT on the field of digital forensics, specifically looking at its latest pre-trained LLM, GPT-4. A series of experiments are conducted to assess its capability across several digital forensic use cases including artefact understanding, evidence searching, code generation, anomaly detection, incident response, and education. Across these topics, its strengths and risks are outlined and a number of general conclusions are drawn. Overall this paper concludes that while there are some potential low-risk applications of ChatGPT within digital forensics, many are either unsuitable at present, since the evidence would need to be uploaded to the service, or they require sufficient knowledge of the topic being asked of the tool to identify incorrect assumptions, inaccuracies, and mistakes. However, to an appropriately knowledgeable user, it could act as a useful supporting tool in some circumstances.},<br \/>\r\nnote = {bf Best Paper Award},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {article}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('915','tp_bibtex')\">Close<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_915\" style=\"display:none;\"><div class=\"tp_abstract_entry\">The disruptive application of ChatGPT (GPT-3.5, GPT-4) to a variety of domains has become a topic of much discussion in the scientific community and society at large. Large Language Models (LLMs), e.g., BERT, Bard, Generative Pre-trained Transformers (GPTs), LLaMA, etc., have the ability to take instructions, or prompts, from users and generate answers and solutions based on very large volumes of text-based training data. This paper assesses the impact and potential impact of ChatGPT on the field of digital forensics, specifically looking at its latest pre-trained LLM, GPT-4. A series of experiments are conducted to assess its capability across several digital forensic use cases including artefact understanding, evidence searching, code generation, anomaly detection, incident response, and education. Across these topics, its strengths and risks are outlined and a number of general conclusions are drawn. Overall this paper concludes that while there are some potential low-risk applications of ChatGPT within digital forensics, many are either unsuitable at present, since the evidence would need to be uploaded to the service, or they require sufficient knowledge of the topic being asked of the tool to identify incorrect assumptions, inaccuracies, and mistakes. However, to an appropriately knowledgeable user, it could act as a useful supporting tool in some circumstances.<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('915','tp_abstract')\">Close<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_915\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"fas fa-globe\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/www.sciencedirect.com\/science\/article\/pii\/S266628172300121X\" title=\"https:\/\/www.sciencedirect.com\/science\/article\/pii\/S266628172300121X\" target=\"_blank\">https:\/\/www.sciencedirect.com\/science\/article\/pii\/S266628172300121X<\/a><\/li><li><i class=\"ai ai-doi\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/dx.doi.org\/10.1016\/j.fsidi.2023.301609\" title=\"Follow DOI:10.1016\/j.fsidi.2023.301609\" target=\"_blank\">doi:10.1016\/j.fsidi.2023.301609<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('915','tp_links')\">Close<\/a><\/p><\/div><\/td><\/tr><tr class=\"tp_publication tp_publication_article\"><td class=\"tp_pub_number\">27.<\/td><td class=\"tp_pub_info\"><p class=\"tp_pub_author\"> G\u00f6bel, Thomas;  Baier, Harald;  Breitinger, Frank<\/p><p class=\"tp_pub_title\"><a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('831','tp_links')\" style=\"cursor:pointer;\">Data for Digital Forensics: Why a Discussion on `How Realistic is Synthetic Data' is Dispensable<\/a> (<span class=\"tp_pub_type tp_  article\">Journal Article<\/span>)<\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_in\">In: <\/span><span class=\"tp_pub_additional_journal\">Digital Threats: Research and Practice, <\/span><span class=\"tp_pub_additional_year\">2023<\/span>, <span class=\"tp_pub_additional_issn\">ISSN: 2692-1626<\/span><span class=\"tp_pub_additional_note\">, (Presented at the 12th International Conference on IT Security Incident Management IT Forensics (IMF))<\/span>.<\/p><p class=\"tp_pub_menu\">(<span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_831\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('831','tp_abstract')\" title=\"Show abstract\" style=\"cursor:pointer;\">Abstract<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_831\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('831','tp_links')\" title=\"Show links and resources\" style=\"cursor:pointer;\">Links<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_831\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('831','tp_bibtex')\" title=\"Show BibTeX entry\" style=\"cursor:pointer;\">BibTeX<\/a><\/span>)<\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_831\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@article{10.1145\/3609863,<br \/>\r\ntitle = {Data for Digital Forensics: Why a Discussion on `How Realistic is Synthetic Data' is Dispensable},<br \/>\r\nauthor = {Thomas G\u00f6bel and Harald Baier and Frank Breitinger},<br \/>\r\nurl = {https:\/\/doi.org\/10.1145\/3609863},<br \/>\r\ndoi = {10.1145\/3609863},<br \/>\r\nissn = {2692-1626},<br \/>\r\nyear  = {2023},<br \/>\r\ndate = {2023-07-20},<br \/>\r\nurldate = {2023-07-20},<br \/>\r\njournal = {Digital Threats: Research and Practice},<br \/>\r\npublisher = {Association for Computing Machinery (ACM)},<br \/>\r\naddress = {New York, NY, USA},<br \/>\r\nabstract = {Digital forensics depends on data sets for various purposes like concept evaluation, educational training, and tool validation. Researchers have gathered such data sets into repositories and created data simulation frameworks for producing large amounts of data. Synthetic data often face skepticism due to its perceived deviation from real-world data, raising doubts about its realism. This paper addresses this concern, arguing that there is no definitive answer. We focus on four common digital forensic use cases that rely on data. Through these, we elucidate the specifications and prerequisites of data sets within their respective contexts. Our discourse uncovers that both real-world and synthetic data are indispensable for advancing digital forensic science, software, tools, and the competence of practitioners. Additionally, we provide an overview of available data set repositories and data generation frameworks, contributing to the ongoing dialogue on digital forensic data sets\u2019 utility.},<br \/>\r\nnote = {Presented at the 12th International Conference on IT Security Incident Management IT Forensics (IMF)},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {article}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('831','tp_bibtex')\">Close<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_831\" style=\"display:none;\"><div class=\"tp_abstract_entry\">Digital forensics depends on data sets for various purposes like concept evaluation, educational training, and tool validation. Researchers have gathered such data sets into repositories and created data simulation frameworks for producing large amounts of data. Synthetic data often face skepticism due to its perceived deviation from real-world data, raising doubts about its realism. This paper addresses this concern, arguing that there is no definitive answer. We focus on four common digital forensic use cases that rely on data. Through these, we elucidate the specifications and prerequisites of data sets within their respective contexts. Our discourse uncovers that both real-world and synthetic data are indispensable for advancing digital forensic science, software, tools, and the competence of practitioners. Additionally, we provide an overview of available data set repositories and data generation frameworks, contributing to the ongoing dialogue on digital forensic data sets\u2019 utility.<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('831','tp_abstract')\">Close<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_831\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"fas fa-globe\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/doi.org\/10.1145\/3609863\" title=\"https:\/\/doi.org\/10.1145\/3609863\" target=\"_blank\">https:\/\/doi.org\/10.1145\/3609863<\/a><\/li><li><i class=\"ai ai-doi\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/dx.doi.org\/10.1145\/3609863\" title=\"Follow DOI:10.1145\/3609863\" target=\"_blank\">doi:10.1145\/3609863<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('831','tp_links')\">Close<\/a><\/p><\/div><\/td><\/tr><tr class=\"tp_publication tp_publication_inproceedings\"><td class=\"tp_pub_number\">28.<\/td><td class=\"tp_pub_info\"><p class=\"tp_pub_author\"> Ottmann, Jenny;  Cengiz, \u00dcsame;  Breitinger, Frank;  Freiling, Felix<\/p><p class=\"tp_pub_title\"><a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('832','tp_links')\" style=\"cursor:pointer;\">As if Time Had Stopped \u2013 Checking Memory Dumps for Quasi-Instantaneous Consistency<\/a> (<span class=\"tp_pub_type tp_  inproceedings\">Proceedings Article<\/span>)<\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_in\">In: <\/span><span class=\"tp_pub_additional_booktitle\">Proceedings of the Digital Forensics Research Conference USA (DFRWS USA), <\/span><span class=\"tp_pub_additional_year\">2023<\/span>.<\/p><p class=\"tp_pub_menu\">(<span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_832\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('832','tp_abstract')\" title=\"Show abstract\" style=\"cursor:pointer;\">Abstract<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_832\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('832','tp_links')\" title=\"Show links and resources\" style=\"cursor:pointer;\">Links<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_832\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('832','tp_bibtex')\" title=\"Show BibTeX entry\" style=\"cursor:pointer;\">BibTeX<\/a><\/span>)<\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_832\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@inproceedings{OUBF2023,<br \/>\r\ntitle = {As if Time Had Stopped \u2013 Checking Memory Dumps for Quasi-Instantaneous Consistency},<br \/>\r\nauthor = {Jenny Ottmann and \u00dcsame Cengiz and Frank Breitinger and Felix Freiling},<br \/>\r\nurl = {https:\/\/dfrws.org\/presentation\/as-if-time-had-stopped-checking-memory-dumps-for-quasi-instantaneous-consistency\/},<br \/>\r\ndoi = {10.48550\/arXiv.2307.12060},<br \/>\r\nyear  = {2023},<br \/>\r\ndate = {2023-07-10},<br \/>\r\nbooktitle = {Proceedings of the Digital Forensics Research Conference USA (DFRWS USA)},<br \/>\r\nabstract = {Memory dumps that are acquired while the system is running often contain inconsistencies like page smearing which hamper the analysis. One possibility to avoid inconsistencies is to pause the system during the acquisition and take an instantaneous memory dump. While this is possible for virtual machines, most systems cannot be frozen and thus the ideal dump can only be quasi-instantaneous, i.e., consistent despite the system running. In this article, we introduce a method allowing us to measure quasi-instantaneous consistency and show both, theoretically, and practically, that our method is valid but that in reality, dumps can be but usually are not quasi-instantaneously consistent. For the assessment, we run a pivot program enabling the evaluation of quasi-instantaneous consistency for its heap and allowing us to pinpoint where exactly inconsistencies occurred.},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {inproceedings}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('832','tp_bibtex')\">Close<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_832\" style=\"display:none;\"><div class=\"tp_abstract_entry\">Memory dumps that are acquired while the system is running often contain inconsistencies like page smearing which hamper the analysis. One possibility to avoid inconsistencies is to pause the system during the acquisition and take an instantaneous memory dump. While this is possible for virtual machines, most systems cannot be frozen and thus the ideal dump can only be quasi-instantaneous, i.e., consistent despite the system running. In this article, we introduce a method allowing us to measure quasi-instantaneous consistency and show both, theoretically, and practically, that our method is valid but that in reality, dumps can be but usually are not quasi-instantaneously consistent. For the assessment, we run a pivot program enabling the evaluation of quasi-instantaneous consistency for its heap and allowing us to pinpoint where exactly inconsistencies occurred.<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('832','tp_abstract')\">Close<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_832\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"fas fa-globe\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/dfrws.org\/presentation\/as-if-time-had-stopped-checking-memory-dumps-for-quasi-instantaneous-consistency\/\" title=\"https:\/\/dfrws.org\/presentation\/as-if-time-had-stopped-checking-memory-dumps-for-[...]\" target=\"_blank\">https:\/\/dfrws.org\/presentation\/as-if-time-had-stopped-checking-memory-dumps-for-[...]<\/a><\/li><li><i class=\"ai ai-doi\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/dx.doi.org\/10.48550\/arXiv.2307.12060\" title=\"Follow DOI:10.48550\/arXiv.2307.12060\" target=\"_blank\">doi:10.48550\/arXiv.2307.12060<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('832','tp_links')\">Close<\/a><\/p><\/div><\/td><\/tr><tr class=\"tp_publication tp_publication_article\"><td class=\"tp_pub_number\">29.<\/td><td class=\"tp_pub_info\"><p class=\"tp_pub_author\"> Breitinger, Frank;  Jotterand, Alexandre<\/p><p class=\"tp_pub_title\"><a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('833','tp_links')\" style=\"cursor:pointer;\">Sharing datasets for digital forensic: A novel taxonomy and legal concerns<\/a> (<span class=\"tp_pub_type tp_  article\">Journal Article<\/span>)<\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_in\">In: <\/span><span class=\"tp_pub_additional_journal\">Forensic Science International: Digital Investigation, <\/span><span class=\"tp_pub_additional_volume\">vol. 45, <\/span><span class=\"tp_pub_additional_pages\">pp. 301562, <\/span><span class=\"tp_pub_additional_year\">2023<\/span>, <span class=\"tp_pub_additional_issn\">ISSN: 2666-2817<\/span>.<\/p><p class=\"tp_pub_menu\">(<span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_833\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('833','tp_abstract')\" title=\"Show abstract\" style=\"cursor:pointer;\">Abstract<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_833\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('833','tp_links')\" title=\"Show links and resources\" style=\"cursor:pointer;\">Links<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_833\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('833','tp_bibtex')\" title=\"Show BibTeX entry\" style=\"cursor:pointer;\">BibTeX<\/a><\/span>)<\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_833\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@article{BREITINGER2023301562,<br \/>\r\ntitle = {Sharing datasets for digital forensic: A novel taxonomy and legal concerns},<br \/>\r\nauthor = {Frank Breitinger and Alexandre Jotterand},<br \/>\r\nurl = {https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281723000719},<br \/>\r\ndoi = {10.1016\/j.fsidi.2023.301562},<br \/>\r\nissn = {2666-2817},<br \/>\r\nyear  = {2023},<br \/>\r\ndate = {2023-07-07},<br \/>\r\njournal = {Forensic Science International: Digital Investigation},<br \/>\r\nvolume = {45},<br \/>\r\npages = {301562},<br \/>\r\nabstract = {During the last few years, there have been numerous changes concerning datasets for digital forensics like the development of data generation frameworks or the newly released CFReDS website by NIST. In addition, it becomes mandatory (e.g., by funding agencies) to share datasets and publish them in a manner that they can be found and processed. The core of this article is a novel taxonomy that should be used to structure the data commonly used in the domain, complementing the existing methods. Based on the taxonomy, we discuss that it is not always necessary to release the dataset, e.g., in the case of random data. In addition, we address the legal aspects of sharing data. Lastly, as a minor contribution, we provide a separation of the terms structured, semi-structured, and unstructured data where there is currently no consent in the community.},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {article}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('833','tp_bibtex')\">Close<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_833\" style=\"display:none;\"><div class=\"tp_abstract_entry\">During the last few years, there have been numerous changes concerning datasets for digital forensics like the development of data generation frameworks or the newly released CFReDS website by NIST. In addition, it becomes mandatory (e.g., by funding agencies) to share datasets and publish them in a manner that they can be found and processed. The core of this article is a novel taxonomy that should be used to structure the data commonly used in the domain, complementing the existing methods. Based on the taxonomy, we discuss that it is not always necessary to release the dataset, e.g., in the case of random data. In addition, we address the legal aspects of sharing data. Lastly, as a minor contribution, we provide a separation of the terms structured, semi-structured, and unstructured data where there is currently no consent in the community.<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('833','tp_abstract')\">Close<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_833\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"fas fa-globe\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281723000719\" title=\"https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281723000719\" target=\"_blank\">https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281723000719<\/a><\/li><li><i class=\"ai ai-doi\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/dx.doi.org\/10.1016\/j.fsidi.2023.301562\" title=\"Follow DOI:10.1016\/j.fsidi.2023.301562\" target=\"_blank\">doi:10.1016\/j.fsidi.2023.301562<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('833','tp_links')\">Close<\/a><\/p><\/div><\/td><\/tr><tr class=\"tp_publication tp_publication_article\"><td class=\"tp_pub_number\">30.<\/td><td class=\"tp_pub_info\"><p class=\"tp_pub_author\"> Michelet, Ga\u00ebtan;  Breitinger, Frank;  Horsman, Graeme<\/p><p class=\"tp_pub_title\"><a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('834','tp_links')\" style=\"cursor:pointer;\">Automation for digital forensics: Towards a definition for the community<\/a> (<span class=\"tp_pub_type tp_  article\">Journal Article<\/span>)<\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_in\">In: <\/span><span class=\"tp_pub_additional_journal\">Forensic Science International, <\/span><span class=\"tp_pub_additional_volume\">vol. 349, <\/span><span class=\"tp_pub_additional_pages\">pp. 111769, <\/span><span class=\"tp_pub_additional_year\">2023<\/span>, <span class=\"tp_pub_additional_issn\">ISSN: 0379-0738<\/span>.<\/p><p class=\"tp_pub_menu\">(<span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_834\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('834','tp_abstract')\" title=\"Show abstract\" style=\"cursor:pointer;\">Abstract<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_834\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('834','tp_links')\" title=\"Show links and resources\" style=\"cursor:pointer;\">Links<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_834\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('834','tp_bibtex')\" title=\"Show BibTeX entry\" style=\"cursor:pointer;\">BibTeX<\/a><\/span>)<\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_834\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@article{MICHELET2023111769,<br \/>\r\ntitle = {Automation for digital forensics: Towards a definition for the community},<br \/>\r\nauthor = {Ga\u00ebtan Michelet and Frank Breitinger and Graeme Horsman},<br \/>\r\nurl = {https:\/\/www.sciencedirect.com\/science\/article\/pii\/S0379073823002190},<br \/>\r\ndoi = {10.1016\/j.forsciint.2023.111769},<br \/>\r\nissn = {0379-0738},<br \/>\r\nyear  = {2023},<br \/>\r\ndate = {2023-07-04},<br \/>\r\njournal = {Forensic Science International},<br \/>\r\nvolume = {349},<br \/>\r\npages = {111769},<br \/>\r\nabstract = {Automation is crucial for managing the increasing volume of digital evidence. However, the absence of a clear foundation comprising a definition, classification, and common terminology has led to a fragmented landscape where diverse interpretations of automation exist. This resembles the wild west: some consider keyword searches or file carving as automation while others do not. We, therefore, reviewed automation literature (in the domain of digital forensics and other domains), performed three practitioner interviews, and discussed the topic with domain experts from academia. On this basis, we propose a definition and then showcase several considerations concerning automation for digital forensics, e.g., what we classify as no\/basic automation or full automation (autonomous). We conclude that it requires these foundational discussions to promote and progress the discipline through a common understanding.},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {article}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('834','tp_bibtex')\">Close<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_834\" style=\"display:none;\"><div class=\"tp_abstract_entry\">Automation is crucial for managing the increasing volume of digital evidence. However, the absence of a clear foundation comprising a definition, classification, and common terminology has led to a fragmented landscape where diverse interpretations of automation exist. This resembles the wild west: some consider keyword searches or file carving as automation while others do not. We, therefore, reviewed automation literature (in the domain of digital forensics and other domains), performed three practitioner interviews, and discussed the topic with domain experts from academia. On this basis, we propose a definition and then showcase several considerations concerning automation for digital forensics, e.g., what we classify as no\/basic automation or full automation (autonomous). We conclude that it requires these foundational discussions to promote and progress the discipline through a common understanding.<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('834','tp_abstract')\">Close<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_834\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"fas fa-globe\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/www.sciencedirect.com\/science\/article\/pii\/S0379073823002190\" title=\"https:\/\/www.sciencedirect.com\/science\/article\/pii\/S0379073823002190\" target=\"_blank\">https:\/\/www.sciencedirect.com\/science\/article\/pii\/S0379073823002190<\/a><\/li><li><i class=\"ai ai-doi\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/dx.doi.org\/10.1016\/j.forsciint.2023.111769\" title=\"Follow DOI:10.1016\/j.forsciint.2023.111769\" target=\"_blank\">doi:10.1016\/j.forsciint.2023.111769<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('834','tp_links')\">Close<\/a><\/p><\/div><\/td><\/tr><tr class=\"tp_publication tp_publication_article\"><td class=\"tp_pub_number\">31.<\/td><td class=\"tp_pub_info\"><p class=\"tp_pub_author\"> Schneider, Johannes;  Breitinger, Frank<\/p><p class=\"tp_pub_title\"><a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('835','tp_links')\" style=\"cursor:pointer;\">Towards AI forensics: Did the artificial intelligence system do it?<\/a> (<span class=\"tp_pub_type tp_  article\">Journal Article<\/span>)<\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_in\">In: <\/span><span class=\"tp_pub_additional_journal\">Journal of Information Security and Applications, <\/span><span class=\"tp_pub_additional_volume\">vol. 76, <\/span><span class=\"tp_pub_additional_pages\">pp. 103517, <\/span><span class=\"tp_pub_additional_year\">2023<\/span>, <span class=\"tp_pub_additional_issn\">ISSN: 2214-2126<\/span>.<\/p><p class=\"tp_pub_menu\">(<span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_835\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('835','tp_abstract')\" title=\"Show abstract\" style=\"cursor:pointer;\">Abstract<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_835\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('835','tp_links')\" title=\"Show links and resources\" style=\"cursor:pointer;\">Links<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_835\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('835','tp_bibtex')\" title=\"Show BibTeX entry\" style=\"cursor:pointer;\">BibTeX<\/a><\/span>)<\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_835\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@article{schneider2023towards,<br \/>\r\ntitle = {Towards AI forensics: Did the artificial intelligence system do it?},<br \/>\r\nauthor = {Johannes Schneider and Frank Breitinger},<br \/>\r\nurl = {https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2214212623001011},<br \/>\r\ndoi = {10.1016\/j.jisa.2023.103517},<br \/>\r\nissn = {2214-2126},<br \/>\r\nyear  = {2023},<br \/>\r\ndate = {2023-06-07},<br \/>\r\njournal = {Journal of Information Security and Applications},<br \/>\r\nvolume = {76},<br \/>\r\npages = {103517},<br \/>\r\nabstract = {Artificial intelligence (AI) makes decisions impacting our daily lives in an increasingly autonomous manner. Their actions might cause accidents, harm, or, more generally, violate regulations. Determining whether an AI caused a specific event and, if so, what triggered the AI's action, are key forensic questions. We provide a conceptualization of the problems and strategies for forensic investigation. We focus on AI that is potentially ``malicious by design'' and gray box analysis. Our evaluation using convolutional neural networks illustrates challenges and ideas for identifying malicious AI.},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {article}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('835','tp_bibtex')\">Close<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_835\" style=\"display:none;\"><div class=\"tp_abstract_entry\">Artificial intelligence (AI) makes decisions impacting our daily lives in an increasingly autonomous manner. Their actions might cause accidents, harm, or, more generally, violate regulations. Determining whether an AI caused a specific event and, if so, what triggered the AI's action, are key forensic questions. We provide a conceptualization of the problems and strategies for forensic investigation. We focus on AI that is potentially ``malicious by design'' and gray box analysis. Our evaluation using convolutional neural networks illustrates challenges and ideas for identifying malicious AI.<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('835','tp_abstract')\">Close<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_835\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"fas fa-globe\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2214212623001011\" title=\"https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2214212623001011\" target=\"_blank\">https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2214212623001011<\/a><\/li><li><i class=\"ai ai-doi\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/dx.doi.org\/10.1016\/j.jisa.2023.103517\" title=\"Follow DOI:10.1016\/j.jisa.2023.103517\" target=\"_blank\">doi:10.1016\/j.jisa.2023.103517<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('835','tp_links')\">Close<\/a><\/p><\/div><\/td><\/tr><tr class=\"tp_publication tp_publication_article\"><td class=\"tp_pub_number\">32.<\/td><td class=\"tp_pub_info\"><p class=\"tp_pub_author\"> Breitinger, Frank;  Zhang, Xiaolu;  Quick, Darren<\/p><p class=\"tp_pub_title\"><a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('836','tp_links')\" style=\"cursor:pointer;\">A forensic analysis of rclone and rclone's prospects for digital forensic investigations of cloud storage<\/a> (<span class=\"tp_pub_type tp_  article\">Journal Article<\/span>)<\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_in\">In: <\/span><span class=\"tp_pub_additional_journal\">Forensic Science International: Digital Investigation, <\/span><span class=\"tp_pub_additional_volume\">vol. 43, <\/span><span class=\"tp_pub_additional_pages\">pp. 301443, <\/span><span class=\"tp_pub_additional_year\">2022<\/span>, <span class=\"tp_pub_additional_issn\">ISSN: 2666-2817<\/span><span class=\"tp_pub_additional_note\">, (bf Best Paper Award)<\/span>.<\/p><p class=\"tp_pub_menu\">(<span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_836\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('836','tp_abstract')\" title=\"Show abstract\" style=\"cursor:pointer;\">Abstract<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_836\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('836','tp_links')\" title=\"Show links and resources\" style=\"cursor:pointer;\">Links<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_836\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('836','tp_bibtex')\" title=\"Show BibTeX entry\" style=\"cursor:pointer;\">BibTeX<\/a><\/span>)<\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_836\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@article{breitinger2023rclone,<br \/>\r\ntitle = {A forensic analysis of rclone and rclone's prospects for digital forensic investigations of cloud storage},<br \/>\r\nauthor = {Frank Breitinger and Xiaolu Zhang and Darren Quick},<br \/>\r\nurl = {https:\/\/www.sciencedirect.com\/science\/article\/pii\/S266628172200124X},<br \/>\r\ndoi = {10.1016\/j.fsidi.2022.301443},<br \/>\r\nissn = {2666-2817},<br \/>\r\nyear  = {2022},<br \/>\r\ndate = {2022-09-27},<br \/>\r\njournal = {Forensic Science International: Digital Investigation},<br \/>\r\nvolume = {43},<br \/>\r\npages = {301443},<br \/>\r\nabstract = {Organizations and end users are moving their data into the cloud and trust Cloud Storage Providers (CSP) such as pCloud, Dropbox, or Backblaze. Given their popularity, it is likely that forensic examiners encounter one or more online storage types that they will have to acquire and analyze during an investigation. To access cloud storage, CSPs provide web-interfaces, proprietary software solutions (e.g., Dropbox client for Windows) as well as APIs allowing third-party access. One of these third-party applications is rclone which is an open-source tool to access many common CSPs through a command line interface. In this article, we look at rclone from two perspectives: First, we perform a forensic analysis on rclone and discuss aspects such as password recovery of the configuration file, encryption, and JA3 fingerprints. Second, we discuss rclone as a prospect to be a forensic tool which includes its read-only mount feature and sample cases. Under the circumstances tested, rclone is suitable for forensic practitioners as it is open-source, documented, and includes some essential functionality frequently needed but practitioners need to be aware of the caveats.},<br \/>\r\nnote = {bf Best Paper Award},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {article}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('836','tp_bibtex')\">Close<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_836\" style=\"display:none;\"><div class=\"tp_abstract_entry\">Organizations and end users are moving their data into the cloud and trust Cloud Storage Providers (CSP) such as pCloud, Dropbox, or Backblaze. Given their popularity, it is likely that forensic examiners encounter one or more online storage types that they will have to acquire and analyze during an investigation. To access cloud storage, CSPs provide web-interfaces, proprietary software solutions (e.g., Dropbox client for Windows) as well as APIs allowing third-party access. One of these third-party applications is rclone which is an open-source tool to access many common CSPs through a command line interface. In this article, we look at rclone from two perspectives: First, we perform a forensic analysis on rclone and discuss aspects such as password recovery of the configuration file, encryption, and JA3 fingerprints. Second, we discuss rclone as a prospect to be a forensic tool which includes its read-only mount feature and sample cases. Under the circumstances tested, rclone is suitable for forensic practitioners as it is open-source, documented, and includes some essential functionality frequently needed but practitioners need to be aware of the caveats.<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('836','tp_abstract')\">Close<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_836\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"fas fa-globe\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/www.sciencedirect.com\/science\/article\/pii\/S266628172200124X\" title=\"https:\/\/www.sciencedirect.com\/science\/article\/pii\/S266628172200124X\" target=\"_blank\">https:\/\/www.sciencedirect.com\/science\/article\/pii\/S266628172200124X<\/a><\/li><li><i class=\"ai ai-doi\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/dx.doi.org\/10.1016\/j.fsidi.2022.301443\" title=\"Follow DOI:10.1016\/j.fsidi.2022.301443\" target=\"_blank\">doi:10.1016\/j.fsidi.2022.301443<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('836','tp_links')\">Close<\/a><\/p><\/div><\/td><\/tr><tr class=\"tp_publication tp_publication_article\"><td class=\"tp_pub_number\">33.<\/td><td class=\"tp_pub_info\"><p class=\"tp_pub_author\"> G\u00f6bel, Thomas;  Uhlig, Frieder;  Baier, Harald;  Breitinger, Frank<\/p><p class=\"tp_pub_title\"><a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('837','tp_links')\" style=\"cursor:pointer;\">FRASHER \u2013 A framework for automated evaluation of similarity hashing<\/a> (<span class=\"tp_pub_type tp_  article\">Journal Article<\/span>)<\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_in\">In: <\/span><span class=\"tp_pub_additional_journal\">Forensic Science International: Digital Investigation, <\/span><span class=\"tp_pub_additional_volume\">vol. 42, <\/span><span class=\"tp_pub_additional_number\">no. 2022-, <\/span><span class=\"tp_pub_additional_pages\">pp. 301407, <\/span><span class=\"tp_pub_additional_year\">2022<\/span>, <span class=\"tp_pub_additional_issn\">ISSN: 2666-2817<\/span><span class=\"tp_pub_additional_note\">, (Proceedings of the Twenty-Second Annual DFRWS USA)<\/span>.<\/p><p class=\"tp_pub_menu\">(<span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_837\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('837','tp_abstract')\" title=\"Show abstract\" style=\"cursor:pointer;\">Abstract<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_837\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('837','tp_links')\" title=\"Show links and resources\" style=\"cursor:pointer;\">Links<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_837\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('837','tp_bibtex')\" title=\"Show BibTeX entry\" style=\"cursor:pointer;\">BibTeX<\/a><\/span>)<\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_837\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@article{Goebel2022Frasher,<br \/>\r\ntitle = {FRASHER \u2013 A framework for automated evaluation of similarity hashing},<br \/>\r\nauthor = {Thomas G\u00f6bel and Frieder Uhlig and Harald Baier and Frank Breitinger},<br \/>\r\nurl = {https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281722000889},<br \/>\r\ndoi = {10.1016\/j.fsidi.2022.301407},<br \/>\r\nissn = {2666-2817},<br \/>\r\nyear  = {2022},<br \/>\r\ndate = {2022-07-09},<br \/>\r\njournal = {Forensic Science International: Digital Investigation},<br \/>\r\nvolume = {42},<br \/>\r\nnumber = {2022-},<br \/>\r\npages = {301407},<br \/>\r\nabstract = {A challenge for digital forensic investigations is dealing with large amounts of data that need to be processed. Approximate matching (AM), a.k.a. similarity hashing or fuzzy hashing, plays a pivotal role in solving this challenge. Many algorithms have been proposed over the years such as ssdeep, sdhash, MRSH-v2, or TLSH, which can be used for similarity assessment, clustering of different artifacts, or finding fragments and embedded objects. To assess the differences between these implementations (e.g., in terms of runtime efficiency, fragment detection, or resistance against obfuscation attacks), a testing framework is indispensable and the core of this article. The proposed framework is called FRASHER (referring to a predecessor FRASH from 2013) and provides an up-to-date view on the problem of evaluating AM algorithms with respect to both the conceptual and the practical aspects. Consequently, we present and discuss relevant test case scenarios as well as release and demonstrate our framework allowing a comprehensive evaluation of AM algorithms. Compared to its predecessor, we adapt it to a modern environment providing better modularity and usability as well as more thorough testing cases.},<br \/>\r\nnote = {Proceedings of the Twenty-Second Annual DFRWS USA},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {article}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('837','tp_bibtex')\">Close<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_837\" style=\"display:none;\"><div class=\"tp_abstract_entry\">A challenge for digital forensic investigations is dealing with large amounts of data that need to be processed. Approximate matching (AM), a.k.a. similarity hashing or fuzzy hashing, plays a pivotal role in solving this challenge. Many algorithms have been proposed over the years such as ssdeep, sdhash, MRSH-v2, or TLSH, which can be used for similarity assessment, clustering of different artifacts, or finding fragments and embedded objects. To assess the differences between these implementations (e.g., in terms of runtime efficiency, fragment detection, or resistance against obfuscation attacks), a testing framework is indispensable and the core of this article. The proposed framework is called FRASHER (referring to a predecessor FRASH from 2013) and provides an up-to-date view on the problem of evaluating AM algorithms with respect to both the conceptual and the practical aspects. Consequently, we present and discuss relevant test case scenarios as well as release and demonstrate our framework allowing a comprehensive evaluation of AM algorithms. Compared to its predecessor, we adapt it to a modern environment providing better modularity and usability as well as more thorough testing cases.<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('837','tp_abstract')\">Close<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_837\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"fas fa-globe\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281722000889\" title=\"https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281722000889\" target=\"_blank\">https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281722000889<\/a><\/li><li><i class=\"ai ai-doi\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/dx.doi.org\/10.1016\/j.fsidi.2022.301407\" title=\"Follow DOI:10.1016\/j.fsidi.2022.301407\" target=\"_blank\">doi:10.1016\/j.fsidi.2022.301407<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('837','tp_links')\">Close<\/a><\/p><\/div><\/td><\/tr><tr class=\"tp_publication tp_publication_article\"><td class=\"tp_pub_number\">34.<\/td><td class=\"tp_pub_info\"><p class=\"tp_pub_author\"> AlDaajeh, Saleh;  Saleous, Heba;  Alrabaee, Saed;  Barka, Ezedin;  Breitinger, Frank;  Choo, Kim-Kwang Raymond<\/p><p class=\"tp_pub_title\"><a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('838','tp_links')\" style=\"cursor:pointer;\">The Role of National Cybersecurity Strategies on the Improvement of Cybersecurity Education<\/a> (<span class=\"tp_pub_type tp_  article\">Journal Article<\/span>)<\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_in\">In: <\/span><span class=\"tp_pub_additional_journal\">Computers &amp; Security, <\/span><span class=\"tp_pub_additional_pages\">pp. 102754, <\/span><span class=\"tp_pub_additional_year\">2022<\/span>, <span class=\"tp_pub_additional_issn\">ISSN: 0167-4048<\/span>.<\/p><p class=\"tp_pub_menu\">(<span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_838\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('838','tp_abstract')\" title=\"Show abstract\" style=\"cursor:pointer;\">Abstract<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_838\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('838','tp_links')\" title=\"Show links and resources\" style=\"cursor:pointer;\">Links<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_838\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('838','tp_bibtex')\" title=\"Show BibTeX entry\" style=\"cursor:pointer;\">BibTeX<\/a><\/span>)<\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_838\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@article{ALDAAJEH2022102754,<br \/>\r\ntitle = {The Role of National Cybersecurity Strategies on the Improvement of Cybersecurity Education},<br \/>\r\nauthor = {Saleh AlDaajeh and Heba Saleous and Saed Alrabaee and Ezedin Barka and Frank Breitinger and Kim-Kwang Raymond Choo},<br \/>\r\nurl = {https:\/\/www.sciencedirect.com\/science\/article\/pii\/S0167404822001493},<br \/>\r\ndoi = {10.1016\/j.cose.2022.102754},<br \/>\r\nissn = {0167-4048},<br \/>\r\nyear  = {2022},<br \/>\r\ndate = {2022-05-18},<br \/>\r\njournal = {Computers & Security},<br \/>\r\npages = {102754},<br \/>\r\nabstract = {Digital information and telecommunication technologies have not only become essential to individuals' daily lives but also to a nation's sustained economic growth, societal well-being, critical infrastructure resilience, and national security. Consequently, the protection of a nation's cyber sovereignty from malicious acts is a major concern. This signifies the importance of cybersecurity education in facilitating the creation of a resilient cybersecurity ecosystem and in supporting cyber sovereignty. This study reviews a sample from world-leading countries National Cybersecurity Strategic Plans (NCSPs) and analyzes the associated existing cybersecurity education and training improvement initiatives. Furthermore, a proposal to adopt the Goal-Question-Outcomes(GQO)+Strategies paradigm into cybersecurity education and training programs curricula improvement to national cybersecurity strategic goals is presented. The proposal maps cybersecurity strategic goals to cybersecurity skills and competencies using the National Initiative for Cybersecurity Education (NICE) framework. The newly proposed cybersecurity education and training programs' curricula learning outcomes were generated from the GQO+Strategies paradigm based on the three major cybersecurity strategic goals: Development of secure digital and information technology infrastructure and services, defending from sophisticated cyber threats, and enrichment of individuals' cybersecurity maturity and awareness. It is highly recommended that cybersecurity university program administrators utilize the proposed GQO+Strategies to align their program's curriculum to NCSP. Hence, closing the gap that exists with the relevant skills and sustain national cybersecurity workforces.},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {article}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('838','tp_bibtex')\">Close<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_838\" style=\"display:none;\"><div class=\"tp_abstract_entry\">Digital information and telecommunication technologies have not only become essential to individuals' daily lives but also to a nation's sustained economic growth, societal well-being, critical infrastructure resilience, and national security. Consequently, the protection of a nation's cyber sovereignty from malicious acts is a major concern. This signifies the importance of cybersecurity education in facilitating the creation of a resilient cybersecurity ecosystem and in supporting cyber sovereignty. This study reviews a sample from world-leading countries National Cybersecurity Strategic Plans (NCSPs) and analyzes the associated existing cybersecurity education and training improvement initiatives. Furthermore, a proposal to adopt the Goal-Question-Outcomes(GQO)+Strategies paradigm into cybersecurity education and training programs curricula improvement to national cybersecurity strategic goals is presented. The proposal maps cybersecurity strategic goals to cybersecurity skills and competencies using the National Initiative for Cybersecurity Education (NICE) framework. The newly proposed cybersecurity education and training programs' curricula learning outcomes were generated from the GQO+Strategies paradigm based on the three major cybersecurity strategic goals: Development of secure digital and information technology infrastructure and services, defending from sophisticated cyber threats, and enrichment of individuals' cybersecurity maturity and awareness. It is highly recommended that cybersecurity university program administrators utilize the proposed GQO+Strategies to align their program's curriculum to NCSP. Hence, closing the gap that exists with the relevant skills and sustain national cybersecurity workforces.<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('838','tp_abstract')\">Close<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_838\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"fas fa-globe\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/www.sciencedirect.com\/science\/article\/pii\/S0167404822001493\" title=\"https:\/\/www.sciencedirect.com\/science\/article\/pii\/S0167404822001493\" target=\"_blank\">https:\/\/www.sciencedirect.com\/science\/article\/pii\/S0167404822001493<\/a><\/li><li><i class=\"ai ai-doi\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/dx.doi.org\/10.1016\/j.cose.2022.102754\" title=\"Follow DOI:10.1016\/j.cose.2022.102754\" target=\"_blank\">doi:10.1016\/j.cose.2022.102754<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('838','tp_links')\">Close<\/a><\/p><\/div><\/td><\/tr><tr class=\"tp_publication tp_publication_inproceedings\"><td class=\"tp_pub_number\">35.<\/td><td class=\"tp_pub_info\"><p class=\"tp_pub_author\"> Coates, Peter;  Breitinger, Frank<\/p><p class=\"tp_pub_title\"><a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('839','tp_links')\" style=\"cursor:pointer;\">Identifying document similarity using a fast estimation of the Levenshtein Distance based on compression and signatures<\/a> (<span class=\"tp_pub_type tp_  inproceedings\">Proceedings Article<\/span>)<\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_in\">In: <\/span><span class=\"tp_pub_additional_booktitle\">Proceedings of the Digital Forensics Research Conference Europe (DFRWS EU), <\/span><span class=\"tp_pub_additional_year\">2022<\/span>.<\/p><p class=\"tp_pub_menu\">(<span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_839\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('839','tp_abstract')\" title=\"Show abstract\" style=\"cursor:pointer;\">Abstract<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_839\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('839','tp_links')\" title=\"Show links and resources\" style=\"cursor:pointer;\">Links<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_839\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('839','tp_bibtex')\" title=\"Show BibTeX entry\" style=\"cursor:pointer;\">BibTeX<\/a><\/span>)<\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_839\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@inproceedings{CB2022,<br \/>\r\ntitle = {Identifying document similarity using a fast estimation of the Levenshtein Distance based on compression and signatures},<br \/>\r\nauthor = {Peter Coates and Frank Breitinger},<br \/>\r\nurl = {https:\/\/www.researchgate.net\/publication\/359961968_Identifying_document_similarity_using_a_fast_estimation_of_the_Levenshtein_Distance_based_on_compression_and_signatures},<br \/>\r\ndoi = {10.48550\/arXiv.2307.11496},<br \/>\r\nyear  = {2022},<br \/>\r\ndate = {2022-03-31},<br \/>\r\nbooktitle = {Proceedings of the Digital Forensics Research Conference Europe (DFRWS EU)},<br \/>\r\nabstract = {Identifying document similarity has many applications, e.g., source code analysis or plagiarism detection. However, identifying similarities is not trivial and can be time complex. For instance, the Levenshtein Distance is a common metric to define the similarity between two documents but has quadratic runtime which makes it impractical for large documents where large starts with a few hundred kilobytes. In this paper, we present a novel concept that allows estimating the Levenshtein Distance: the algorithm first compresses documents to signatures (similar to hash values) using a user-defined compression ratio. Signatures can then be compared against each other (some constrains apply) where the outcome is the estimated Levenshtein Distance. Our evaluation shows promising results in terms of runtime efficiency and accuracy. In addition, we introduce a significance score allowing examiners to set a threshold and identify related documents.},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {inproceedings}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('839','tp_bibtex')\">Close<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_839\" style=\"display:none;\"><div class=\"tp_abstract_entry\">Identifying document similarity has many applications, e.g., source code analysis or plagiarism detection. However, identifying similarities is not trivial and can be time complex. For instance, the Levenshtein Distance is a common metric to define the similarity between two documents but has quadratic runtime which makes it impractical for large documents where large starts with a few hundred kilobytes. In this paper, we present a novel concept that allows estimating the Levenshtein Distance: the algorithm first compresses documents to signatures (similar to hash values) using a user-defined compression ratio. Signatures can then be compared against each other (some constrains apply) where the outcome is the estimated Levenshtein Distance. Our evaluation shows promising results in terms of runtime efficiency and accuracy. In addition, we introduce a significance score allowing examiners to set a threshold and identify related documents.<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('839','tp_abstract')\">Close<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_839\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"fas fa-globe\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/www.researchgate.net\/publication\/359961968_Identifying_document_similarity_using_a_fast_estimation_of_the_Levenshtein_Distance_based_on_compression_and_signatures\" title=\"https:\/\/www.researchgate.net\/publication\/359961968_Identifying_document_similari[...]\" target=\"_blank\">https:\/\/www.researchgate.net\/publication\/359961968_Identifying_document_similari[...]<\/a><\/li><li><i class=\"ai ai-doi\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/dx.doi.org\/10.48550\/arXiv.2307.11496\" title=\"Follow DOI:10.48550\/arXiv.2307.11496\" target=\"_blank\">doi:10.48550\/arXiv.2307.11496<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('839','tp_links')\">Close<\/a><\/p><\/div><\/td><\/tr><tr class=\"tp_publication tp_publication_inproceedings\"><td class=\"tp_pub_number\">36.<\/td><td class=\"tp_pub_info\"><p class=\"tp_pub_author\"> Ottmann, Jenny;  Breitinger, Frank;  Freiling, Felix<\/p><p class=\"tp_pub_title\"><a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('840','tp_links')\" style=\"cursor:pointer;\">Defining Atomicity (and Integrity) for Snapshots of Storage in Forensic Computing<\/a> (<span class=\"tp_pub_type tp_  inproceedings\">Proceedings Article<\/span>)<\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_in\">In: <\/span><span class=\"tp_pub_additional_booktitle\">Proceedings of the Digital Forensics Research Conference Europe (DFRWS EU), <\/span><span class=\"tp_pub_additional_year\">2022<\/span>.<\/p><p class=\"tp_pub_menu\">(<span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_840\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('840','tp_abstract')\" title=\"Show abstract\" style=\"cursor:pointer;\">Abstract<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_840\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('840','tp_links')\" title=\"Show links and resources\" style=\"cursor:pointer;\">Links<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_840\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('840','tp_bibtex')\" title=\"Show BibTeX entry\" style=\"cursor:pointer;\">BibTeX<\/a><\/span>)<\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_840\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@inproceedings{OBF2022,<br \/>\r\ntitle = {Defining Atomicity (and Integrity) for Snapshots of Storage in Forensic Computing},<br \/>\r\nauthor = {Jenny Ottmann and Frank Breitinger and Felix Freiling},<br \/>\r\nurl = {https:\/\/www.researchgate.net\/publication\/359962048_Defining_Atomicity_and_Integrity_for_Snapshots_of_Storage_in_Forensic_Computing},<br \/>\r\nyear  = {2022},<br \/>\r\ndate = {2022-03-31},<br \/>\r\nbooktitle = {Proceedings of the Digital Forensics Research Conference Europe (DFRWS EU)},<br \/>\r\nabstract = {The acquisition of data from main memory or from hard disk storage is usually one of the first steps in a forensic investigation. We revisit the discussion on quality criteria for ``forensically sound'' acquisition of such storage and propose a new way to capture the intent to acquire an instantaneous snapshot from a single target system. The idea of our definition is to allow a certain flexibility into when individual portions of memory are acquired, but at the same time require being consistent with causality (i.e., cause\/effect relations). Our concept is much stronger than the original notion of atomicity defined by V\u00f6mel and Freiling (2012) but still attainable using copy-on-write mechanisms. As a minor result, we also fix a conceptual problem within the original definition of integrity.},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {inproceedings}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('840','tp_bibtex')\">Close<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_840\" style=\"display:none;\"><div class=\"tp_abstract_entry\">The acquisition of data from main memory or from hard disk storage is usually one of the first steps in a forensic investigation. We revisit the discussion on quality criteria for ``forensically sound'' acquisition of such storage and propose a new way to capture the intent to acquire an instantaneous snapshot from a single target system. The idea of our definition is to allow a certain flexibility into when individual portions of memory are acquired, but at the same time require being consistent with causality (i.e., cause\/effect relations). Our concept is much stronger than the original notion of atomicity defined by V\u00f6mel and Freiling (2012) but still attainable using copy-on-write mechanisms. As a minor result, we also fix a conceptual problem within the original definition of integrity.<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('840','tp_abstract')\">Close<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_840\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"fas fa-globe\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/www.researchgate.net\/publication\/359962048_Defining_Atomicity_and_Integrity_for_Snapshots_of_Storage_in_Forensic_Computing\" title=\"https:\/\/www.researchgate.net\/publication\/359962048_Defining_Atomicity_and_Integr[...]\" target=\"_blank\">https:\/\/www.researchgate.net\/publication\/359962048_Defining_Atomicity_and_Integr[...]<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('840','tp_links')\">Close<\/a><\/p><\/div><\/td><\/tr><tr class=\"tp_publication tp_publication_article\"><td class=\"tp_pub_number\">37.<\/td><td class=\"tp_pub_info\"><p class=\"tp_pub_author\"> Huck, Jan;  Breitinger, Frank<\/p><p class=\"tp_pub_title\"><a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('841','tp_links')\" style=\"cursor:pointer;\">Wake Up Digital Forensics' Community and Help Combating Ransomware<\/a> (<span class=\"tp_pub_type tp_  article\">Journal Article<\/span>)<\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_in\">In: <\/span><span class=\"tp_pub_additional_journal\">IEEE Security &amp; Privacy, <\/span><span class=\"tp_pub_additional_number\">no. 01, <\/span><span class=\"tp_pub_additional_pages\">pp. 2-11, <\/span><span class=\"tp_pub_additional_year\">2022<\/span>, <span class=\"tp_pub_additional_issn\">ISSN: 1558-4046<\/span>.<\/p><p class=\"tp_pub_menu\">(<span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_841\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('841','tp_abstract')\" title=\"Show abstract\" style=\"cursor:pointer;\">Abstract<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_841\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('841','tp_links')\" title=\"Show links and resources\" style=\"cursor:pointer;\">Links<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_841\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('841','tp_bibtex')\" title=\"Show BibTeX entry\" style=\"cursor:pointer;\">BibTeX<\/a><\/span>)<\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_841\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@article{huck2022wake,<br \/>\r\ntitle = {Wake Up Digital Forensics' Community and Help Combating Ransomware},<br \/>\r\nauthor = {Jan Huck and Frank Breitinger},<br \/>\r\nurl = {https:\/\/ieeexplore.ieee.org\/document\/9682529},<br \/>\r\ndoi = {10.1109\/MSEC.2021.3137018},<br \/>\r\nissn = {1558-4046},<br \/>\r\nyear  = {2022},<br \/>\r\ndate = {2022-01-14},<br \/>\r\njournal = {IEEE Security & Privacy},<br \/>\r\nnumber = {01},<br \/>\r\npages = {2-11},<br \/>\r\npublisher = {IEEE Computer Society},<br \/>\r\naddress = {Los Alamitos, CA, USA},<br \/>\r\nabstract = {To combat ransomware, organizations, literature, and research efforts focus on technical measures and neglect procedural countermeasures. We argue that detailed case studies and best practices need to be shared to allow companies to adapt their strategies to be better prepared.},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {article}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('841','tp_bibtex')\">Close<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_841\" style=\"display:none;\"><div class=\"tp_abstract_entry\">To combat ransomware, organizations, literature, and research efforts focus on technical measures and neglect procedural countermeasures. We argue that detailed case studies and best practices need to be shared to allow companies to adapt their strategies to be better prepared.<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('841','tp_abstract')\">Close<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_841\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"fas fa-globe\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/ieeexplore.ieee.org\/document\/9682529\" title=\"https:\/\/ieeexplore.ieee.org\/document\/9682529\" target=\"_blank\">https:\/\/ieeexplore.ieee.org\/document\/9682529<\/a><\/li><li><i class=\"ai ai-doi\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/dx.doi.org\/10.1109\/MSEC.2021.3137018\" title=\"Follow DOI:10.1109\/MSEC.2021.3137018\" target=\"_blank\">doi:10.1109\/MSEC.2021.3137018<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('841','tp_links')\">Close<\/a><\/p><\/div><\/td><\/tr><tr class=\"tp_publication tp_publication_article\"><td class=\"tp_pub_number\">38.<\/td><td class=\"tp_pub_info\"><p class=\"tp_pub_author\"> Wu, Tina;  Breitinger, Frank;  Niemann, Stephen<\/p><p class=\"tp_pub_title\"><a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('842','tp_links')\" style=\"cursor:pointer;\">IoT network traffic analysis: Opportunities and challenges for forensic investigators?<\/a> (<span class=\"tp_pub_type tp_  article\">Journal Article<\/span>)<\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_in\">In: <\/span><span class=\"tp_pub_additional_journal\">Forensic Science International: Digital Investigation, <\/span><span class=\"tp_pub_additional_volume\">vol. 38, <\/span><span class=\"tp_pub_additional_pages\">pp. 301123, <\/span><span class=\"tp_pub_additional_year\">2021<\/span>, <span class=\"tp_pub_additional_issn\">ISSN: 2666-2817<\/span>.<\/p><p class=\"tp_pub_menu\">(<span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_842\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('842','tp_abstract')\" title=\"Show abstract\" style=\"cursor:pointer;\">Abstract<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_842\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('842','tp_links')\" title=\"Show links and resources\" style=\"cursor:pointer;\">Links<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_842\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('842','tp_bibtex')\" title=\"Show BibTeX entry\" style=\"cursor:pointer;\">BibTeX<\/a><\/span>)<\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_842\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@article{WU2021301123,<br \/>\r\ntitle = {IoT network traffic analysis: Opportunities and challenges for forensic investigators?},<br \/>\r\nauthor = {Tina Wu and Frank Breitinger and Stephen Niemann},<br \/>\r\nurl = {https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281721000214},<br \/>\r\ndoi = {10.1016\/j.fsidi.2021.301123},<br \/>\r\nissn = {2666-2817},<br \/>\r\nyear  = {2021},<br \/>\r\ndate = {2021-11-23},<br \/>\r\njournal = {Forensic Science International: Digital Investigation},<br \/>\r\nvolume = {38},<br \/>\r\npages = {301123},<br \/>\r\nabstract = {As IoT devices become more incorporated into our daily lives, their always on approach makes them an ideal source of evidence. While these devices should use encryption to protect sensitive information, in reality this is not always the case e.g. some expose sensitive data like credentials in cleartext. In this paper, we have conducted an extensive analysis on the communications channels of 32 IoT consumer devices. Our experiments consisted of four main parts; first we carried out a port scan to determine if any ports can be exploited and thus gain remote access. Second, we looked at whether any of the devices used encryption and if not what type of content was exposed. Third, we used the network traffic `metadata' to identify the destination the data terminated. Finally, we examined the communication between the mobile app and the cloud to see if it can be easily exploited using a proxy server. Our findings show that the majority of devices have remote access unavailable. We found the Shannon entropy test a useful pre-test in identifying unencrypted content. Although many devices encrypted their data, we found several in particular smart cameras would send data in cleartext when they detected motion or during updates. We found the majority of data transverses to the US and stored on Amazon servers with most devices contacting multiple destination. Lastly, we discovered many of the IoT device's mobile apps can be easily exploited using a HTTP Proxy.},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {article}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('842','tp_bibtex')\">Close<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_842\" style=\"display:none;\"><div class=\"tp_abstract_entry\">As IoT devices become more incorporated into our daily lives, their always on approach makes them an ideal source of evidence. While these devices should use encryption to protect sensitive information, in reality this is not always the case e.g. some expose sensitive data like credentials in cleartext. In this paper, we have conducted an extensive analysis on the communications channels of 32 IoT consumer devices. Our experiments consisted of four main parts; first we carried out a port scan to determine if any ports can be exploited and thus gain remote access. Second, we looked at whether any of the devices used encryption and if not what type of content was exposed. Third, we used the network traffic `metadata' to identify the destination the data terminated. Finally, we examined the communication between the mobile app and the cloud to see if it can be easily exploited using a proxy server. Our findings show that the majority of devices have remote access unavailable. We found the Shannon entropy test a useful pre-test in identifying unencrypted content. Although many devices encrypted their data, we found several in particular smart cameras would send data in cleartext when they detected motion or during updates. We found the majority of data transverses to the US and stored on Amazon servers with most devices contacting multiple destination. Lastly, we discovered many of the IoT device's mobile apps can be easily exploited using a HTTP Proxy.<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('842','tp_abstract')\">Close<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_842\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"fas fa-globe\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281721000214\" title=\"https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281721000214\" target=\"_blank\">https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281721000214<\/a><\/li><li><i class=\"ai ai-doi\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/dx.doi.org\/10.1016\/j.fsidi.2021.301123\" title=\"Follow DOI:10.1016\/j.fsidi.2021.301123\" target=\"_blank\">doi:10.1016\/j.fsidi.2021.301123<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('842','tp_links')\">Close<\/a><\/p><\/div><\/td><\/tr><tr class=\"tp_publication tp_publication_article\"><td class=\"tp_pub_number\">39.<\/td><td class=\"tp_pub_info\"><p class=\"tp_pub_author\"> Zhang, Xiaolu;  Breitinger, Frank;  Luechinger, Engelbert;  O'Shaughnessy, Stephen<\/p><p class=\"tp_pub_title\"><a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('843','tp_links')\" style=\"cursor:pointer;\">Android application forensics: A survey of obfuscation, obfuscation detection and deobfuscation techniques and their impact on investigations<\/a> (<span class=\"tp_pub_type tp_  article\">Journal Article<\/span>)<\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_in\">In: <\/span><span class=\"tp_pub_additional_journal\">Forensic Science International: Digital Investigation, <\/span><span class=\"tp_pub_additional_volume\">vol. 39, <\/span><span class=\"tp_pub_additional_pages\">pp. 301285, <\/span><span class=\"tp_pub_additional_year\">2021<\/span>, <span class=\"tp_pub_additional_issn\">ISSN: 2666-2817<\/span>.<\/p><p class=\"tp_pub_menu\">(<span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_843\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('843','tp_abstract')\" title=\"Show abstract\" style=\"cursor:pointer;\">Abstract<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_843\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('843','tp_links')\" title=\"Show links and resources\" style=\"cursor:pointer;\">Links<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_843\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('843','tp_bibtex')\" title=\"Show BibTeX entry\" style=\"cursor:pointer;\">BibTeX<\/a><\/span>)<\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_843\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@article{Zhang2021android,<br \/>\r\ntitle = {Android application forensics: A survey of obfuscation, obfuscation detection and deobfuscation techniques and their impact on investigations},<br \/>\r\nauthor = {Xiaolu Zhang and Frank Breitinger and Engelbert Luechinger and Stephen O'Shaughnessy},<br \/>\r\nurl = {https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281721002031},<br \/>\r\ndoi = {10.1016\/j.fsidi.2021.301285},<br \/>\r\nissn = {2666-2817},<br \/>\r\nyear  = {2021},<br \/>\r\ndate = {2021-10-06},<br \/>\r\njournal = {Forensic Science International: Digital Investigation},<br \/>\r\nvolume = {39},<br \/>\r\npages = {301285},<br \/>\r\nabstract = {Android obfuscation techniques include not only classic code obfuscation techniques that were adapted to Android, but also obfuscation methods that target the Android platform specifically. This work examines the status-quo of Android obfuscation, obfuscation detection and deobfuscation. Specifically, it first summarizes obfuscation approaches that are commonly used by app developers for code optimization, to protect their software against code theft and code tampering but are also frequently misused by malware developers to circumvent anti-malware products. Secondly, the article focuses on obfuscation detection techniques and presents various available tools and current research. Thirdly, deobfuscation (which aims at reinstating the original state before obfuscation) is discussed followed by a brief discussion how this impacts forensic investigation. We conclude that although obfuscation is widely used in Android app development (benign and malicious), available tools and the practices on how to deal with obfuscation are not standardized, and so are inherently lacking from a forensic standpoint.},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {article}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('843','tp_bibtex')\">Close<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_843\" style=\"display:none;\"><div class=\"tp_abstract_entry\">Android obfuscation techniques include not only classic code obfuscation techniques that were adapted to Android, but also obfuscation methods that target the Android platform specifically. This work examines the status-quo of Android obfuscation, obfuscation detection and deobfuscation. Specifically, it first summarizes obfuscation approaches that are commonly used by app developers for code optimization, to protect their software against code theft and code tampering but are also frequently misused by malware developers to circumvent anti-malware products. Secondly, the article focuses on obfuscation detection techniques and presents various available tools and current research. Thirdly, deobfuscation (which aims at reinstating the original state before obfuscation) is discussed followed by a brief discussion how this impacts forensic investigation. We conclude that although obfuscation is widely used in Android app development (benign and malicious), available tools and the practices on how to deal with obfuscation are not standardized, and so are inherently lacking from a forensic standpoint.<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('843','tp_abstract')\">Close<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_843\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"fas fa-globe\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281721002031\" title=\"https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281721002031\" target=\"_blank\">https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281721002031<\/a><\/li><li><i class=\"ai ai-doi\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/dx.doi.org\/10.1016\/j.fsidi.2021.301285\" title=\"Follow DOI:10.1016\/j.fsidi.2021.301285\" target=\"_blank\">doi:10.1016\/j.fsidi.2021.301285<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('843','tp_links')\">Close<\/a><\/p><\/div><\/td><\/tr><tr class=\"tp_publication tp_publication_article\"><td class=\"tp_pub_number\">40.<\/td><td class=\"tp_pub_info\"><p class=\"tp_pub_author\"> O'Shaughnessy, Stephen;  Breitinger, Frank<\/p><p class=\"tp_pub_title\"><a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('845','tp_links')\" style=\"cursor:pointer;\">Malware family classification via efficient Huffman features<\/a> (<span class=\"tp_pub_type tp_  article\">Journal Article<\/span>)<\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_in\">In: <\/span><span class=\"tp_pub_additional_journal\">Forensic Science International: Digital Investigation, <\/span><span class=\"tp_pub_additional_volume\">vol. 37, <\/span><span class=\"tp_pub_additional_pages\">pp. 301192, <\/span><span class=\"tp_pub_additional_year\">2021<\/span>, <span class=\"tp_pub_additional_issn\">ISSN: 2666-2817<\/span>.<\/p><p class=\"tp_pub_menu\">(<span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_845\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('845','tp_abstract')\" title=\"Show abstract\" style=\"cursor:pointer;\">Abstract<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_845\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('845','tp_links')\" title=\"Show links and resources\" style=\"cursor:pointer;\">Links<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_845\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('845','tp_bibtex')\" title=\"Show BibTeX entry\" style=\"cursor:pointer;\">BibTeX<\/a><\/span>)<\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_845\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@article{OShaughnessy2021malware,<br \/>\r\ntitle = {Malware family classification via efficient Huffman features},<br \/>\r\nauthor = {Stephen O'Shaughnessy and Frank Breitinger},<br \/>\r\nurl = {https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281721001001},<br \/>\r\ndoi = {10.1016\/j.fsidi.2021.301192},<br \/>\r\nissn = {2666-2817},<br \/>\r\nyear  = {2021},<br \/>\r\ndate = {2021-07-14},<br \/>\r\nbooktitle = {Proceedings of the Twenty First Annual DFRWS USA},<br \/>\r\njournal = {Forensic Science International: Digital Investigation},<br \/>\r\nvolume = {37},<br \/>\r\npages = {301192},<br \/>\r\nabstract = {As malware evolves and becomes more complex, researchers strive to develop detection and classification schemes that abstract away from the internal intricacies of binary code to represent malware without the need for architectural knowledge or invasive analysis procedures. Such approaches can reduce the complexities of feature generation and simplify the analysis process. In this paper, we present efficient Huffman features (eHf), a novel compression-based approach to feature construction, based on Huffman encoding, where malware features are represented in a compact format, without the need for intrusive reverse-engineering or dynamic analysis processes. We demonstrate the viability of eHf as a solution for classifying malware into their respective families on a large malware corpus of 15 k samples, indicative of the current threat landscape. We evaluate eHf against current compression-based alternatives and show that our method is comparable or superior for classification accuracy, while exhibiting considerably greater runtime efficiency. Finally we demonstrate that eHf is resilient against code reordering obfuscation.},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {article}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('845','tp_bibtex')\">Close<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_845\" style=\"display:none;\"><div class=\"tp_abstract_entry\">As malware evolves and becomes more complex, researchers strive to develop detection and classification schemes that abstract away from the internal intricacies of binary code to represent malware without the need for architectural knowledge or invasive analysis procedures. Such approaches can reduce the complexities of feature generation and simplify the analysis process. In this paper, we present efficient Huffman features (eHf), a novel compression-based approach to feature construction, based on Huffman encoding, where malware features are represented in a compact format, without the need for intrusive reverse-engineering or dynamic analysis processes. We demonstrate the viability of eHf as a solution for classifying malware into their respective families on a large malware corpus of 15 k samples, indicative of the current threat landscape. We evaluate eHf against current compression-based alternatives and show that our method is comparable or superior for classification accuracy, while exhibiting considerably greater runtime efficiency. Finally we demonstrate that eHf is resilient against code reordering obfuscation.<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('845','tp_abstract')\">Close<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_845\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"fas fa-globe\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281721001001\" title=\"https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281721001001\" target=\"_blank\">https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281721001001<\/a><\/li><li><i class=\"ai ai-doi\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/dx.doi.org\/10.1016\/j.fsidi.2021.301192\" title=\"Follow DOI:10.1016\/j.fsidi.2021.301192\" target=\"_blank\">doi:10.1016\/j.fsidi.2021.301192<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('845','tp_links')\">Close<\/a><\/p><\/div><\/td><\/tr><tr class=\"tp_publication tp_publication_article\"><td class=\"tp_pub_number\">41.<\/td><td class=\"tp_pub_info\"><p class=\"tp_pub_author\"> Hranick\u00fd, Radek;  Breitinger, Frank;  Ry\u0161av\u00fd, Ond\u0159ej;  Sheppard, John;  Schaedler, Florin;  Morgenstern, Holger;  Malik, Simon<\/p><p class=\"tp_pub_title\"><a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('846','tp_links')\" style=\"cursor:pointer;\">What do incident response practitioners need to know? A skillmap for the years ahead<\/a> (<span class=\"tp_pub_type tp_  article\">Journal Article<\/span>)<\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_in\">In: <\/span><span class=\"tp_pub_additional_journal\">Forensic Science International: Digital Investigation, <\/span><span class=\"tp_pub_additional_volume\">vol. 37, <\/span><span class=\"tp_pub_additional_pages\">pp. 301184, <\/span><span class=\"tp_pub_additional_year\">2021<\/span>, <span class=\"tp_pub_additional_issn\">ISSN: 2666-2817<\/span>.<\/p><p class=\"tp_pub_menu\">(<span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_846\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('846','tp_abstract')\" title=\"Show abstract\" style=\"cursor:pointer;\">Abstract<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_846\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('846','tp_links')\" title=\"Show links and resources\" style=\"cursor:pointer;\">Links<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_846\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('846','tp_bibtex')\" title=\"Show BibTeX entry\" style=\"cursor:pointer;\">BibTeX<\/a><\/span>)<\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_846\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@article{hranicky2021what,<br \/>\r\ntitle = {What do incident response practitioners need to know? A skillmap for the years ahead},<br \/>\r\nauthor = {Radek Hranick\u00fd and Frank Breitinger and Ond\u0159ej Ry\u0161av\u00fd and John Sheppard and Florin Schaedler and Holger Morgenstern and Simon Malik},<br \/>\r\nurl = {https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281721000925},<br \/>\r\ndoi = {10.1016\/j.fsidi.2021.301184},<br \/>\r\nissn = {2666-2817},<br \/>\r\nyear  = {2021},<br \/>\r\ndate = {2021-07-14},<br \/>\r\nbooktitle = {Proceedings of the Twenty First Annual DFRWS USA},<br \/>\r\njournal = {Forensic Science International: Digital Investigation},<br \/>\r\nvolume = {37},<br \/>\r\npages = {301184},<br \/>\r\nabstract = {Digital forensics incident response (DFIR) specialists are expected to possess multidisciplinary skills including expert knowledge of computer-related principles and technology. On the other hand, recent studies suggest that existing training and study programs may not fully address the needs of future DFIR professionals. To reveal possible gaps in practitioners education and identify the most needed skills, we built a skillmap for DFIR where we followed a threefold approach: (1) an online survey among DFIR experts; (2) a review of training programs; and (3) an analysis of job listings on LinkedIn. Each source was first analyzed on its own and the findings were merged into a DFIR skillmap which is the main contribution of this article. The results show that network forensics and incident handling are the most demanded domains of skills. While these are covered by existing courses the newly desired skills, in particular, cloud forensics and encrypted data, need to get more space in training and education. We hope that this article provides educators with information on ways to improve in the years ahead.},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {article}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('846','tp_bibtex')\">Close<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_846\" style=\"display:none;\"><div class=\"tp_abstract_entry\">Digital forensics incident response (DFIR) specialists are expected to possess multidisciplinary skills including expert knowledge of computer-related principles and technology. On the other hand, recent studies suggest that existing training and study programs may not fully address the needs of future DFIR professionals. To reveal possible gaps in practitioners education and identify the most needed skills, we built a skillmap for DFIR where we followed a threefold approach: (1) an online survey among DFIR experts; (2) a review of training programs; and (3) an analysis of job listings on LinkedIn. Each source was first analyzed on its own and the findings were merged into a DFIR skillmap which is the main contribution of this article. The results show that network forensics and incident handling are the most demanded domains of skills. While these are covered by existing courses the newly desired skills, in particular, cloud forensics and encrypted data, need to get more space in training and education. We hope that this article provides educators with information on ways to improve in the years ahead.<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('846','tp_abstract')\">Close<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_846\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"fas fa-globe\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281721000925\" title=\"https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281721000925\" target=\"_blank\">https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281721000925<\/a><\/li><li><i class=\"ai ai-doi\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/dx.doi.org\/10.1016\/j.fsidi.2021.301184\" title=\"Follow DOI:10.1016\/j.fsidi.2021.301184\" target=\"_blank\">doi:10.1016\/j.fsidi.2021.301184<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('846','tp_links')\">Close<\/a><\/p><\/div><\/td><\/tr><tr class=\"tp_publication tp_publication_article\"><td class=\"tp_pub_number\">42.<\/td><td class=\"tp_pub_info\"><p class=\"tp_pub_author\"> Mart\u00edn-P\u00e9rez, Miguel;  Rodr\u00edguez, Ricardo J.;  Breitinger, Frank<\/p><p class=\"tp_pub_title\"><a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('844','tp_links')\" style=\"cursor:pointer;\">Bringing order to approximate matching: Classification and attacks on similarity digest algorithms<\/a> (<span class=\"tp_pub_type tp_  article\">Journal Article<\/span>)<\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_in\">In: <\/span><span class=\"tp_pub_additional_journal\">Forensic Science International: Digital Investigation, <\/span><span class=\"tp_pub_additional_pages\">pp. 301120, <\/span><span class=\"tp_pub_additional_year\">2021<\/span>, <span class=\"tp_pub_additional_issn\">ISSN: 2666-2817<\/span>.<\/p><p class=\"tp_pub_menu\">(<span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_844\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('844','tp_abstract')\" title=\"Show abstract\" style=\"cursor:pointer;\">Abstract<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_844\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('844','tp_links')\" title=\"Show links and resources\" style=\"cursor:pointer;\">Links<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_844\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('844','tp_bibtex')\" title=\"Show BibTeX entry\" style=\"cursor:pointer;\">BibTeX<\/a><\/span>)<\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_844\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@article{martinperez2021bringing,<br \/>\r\ntitle = {Bringing order to approximate matching: Classification and attacks on similarity digest algorithms},<br \/>\r\nauthor = {Miguel Mart\u00edn-P\u00e9rez and Ricardo J. Rodr\u00edguez and Frank Breitinger},<br \/>\r\nurl = {https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281721000172},<br \/>\r\ndoi = {10.1016\/j.fsidi.2021.301120},<br \/>\r\nissn = {2666-2817},<br \/>\r\nyear  = {2021},<br \/>\r\ndate = {2021-03-30},<br \/>\r\njournal = {Forensic Science International: Digital Investigation},<br \/>\r\npages = {301120},<br \/>\r\nabstract = {Fuzzy hashing or similarity hashing (a.k.a. bytewise approximate matching) converts digital artifacts into an intermediate representation to allow an efficient (fast) identification of similar objects, e.g., for blacklisting. They gained a lot of popularity over the past decade with new algorithms being developed and released to the digital forensics community. When releasing algorithms (e.g., as part of a scientific article), they are frequently compared with other algorithms to outline the benefits and sometimes also the weaknesses of the proposed approach. However, given the wide variety of algorithms and approaches, it is impossible to provide direct comparisons with all existing algorithms. In this paper, we present the first classification of approximate matching algorithms which allows an easier description and comparisons. Therefore, we first reviewed existing literature to understand the techniques various algorithms use and to familiarize ourselves with the common terminology. Our findings allowed us to develop a categorization relying heavily on the terminology proposed by NIST SP 800-168. In addition to the categorization, this article presents an abstract set of attacks against algorithms and why they are feasible. Lastly, we detail the characteristics needed to build robust algorithms to prevent attacks. We believe that this article helps newcomers, practitioners, and experts alike to better compare algorithms, understand their potential, as well as characteristics and implications they may have on forensic investigations.},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {article}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('844','tp_bibtex')\">Close<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_844\" style=\"display:none;\"><div class=\"tp_abstract_entry\">Fuzzy hashing or similarity hashing (a.k.a. bytewise approximate matching) converts digital artifacts into an intermediate representation to allow an efficient (fast) identification of similar objects, e.g., for blacklisting. They gained a lot of popularity over the past decade with new algorithms being developed and released to the digital forensics community. When releasing algorithms (e.g., as part of a scientific article), they are frequently compared with other algorithms to outline the benefits and sometimes also the weaknesses of the proposed approach. However, given the wide variety of algorithms and approaches, it is impossible to provide direct comparisons with all existing algorithms. In this paper, we present the first classification of approximate matching algorithms which allows an easier description and comparisons. Therefore, we first reviewed existing literature to understand the techniques various algorithms use and to familiarize ourselves with the common terminology. Our findings allowed us to develop a categorization relying heavily on the terminology proposed by NIST SP 800-168. In addition to the categorization, this article presents an abstract set of attacks against algorithms and why they are feasible. Lastly, we detail the characteristics needed to build robust algorithms to prevent attacks. We believe that this article helps newcomers, practitioners, and experts alike to better compare algorithms, understand their potential, as well as characteristics and implications they may have on forensic investigations.<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('844','tp_abstract')\">Close<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_844\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"fas fa-globe\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281721000172\" title=\"https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281721000172\" target=\"_blank\">https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281721000172<\/a><\/li><li><i class=\"ai ai-doi\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/dx.doi.org\/10.1016\/j.fsidi.2021.301120\" title=\"Follow DOI:10.1016\/j.fsidi.2021.301120\" target=\"_blank\">doi:10.1016\/j.fsidi.2021.301120<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('844','tp_links')\">Close<\/a><\/p><\/div><\/td><\/tr><tr class=\"tp_publication tp_publication_article\"><td class=\"tp_pub_number\">43.<\/td><td class=\"tp_pub_info\"><p class=\"tp_pub_author\"> Pluskal, Jan;  Breitinger, Frank;  Ry\u0161av\u00fd, Ond\u0159ej<\/p><p class=\"tp_pub_title\"><a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('847','tp_links')\" style=\"cursor:pointer;\">Netfox detective: A novel open-source network forensics analysis tool<\/a> (<span class=\"tp_pub_type tp_  article\">Journal Article<\/span>)<\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_in\">In: <\/span><span class=\"tp_pub_additional_journal\">Forensic Science International: Digital Investigation, <\/span><span class=\"tp_pub_additional_volume\">vol. 35, <\/span><span class=\"tp_pub_additional_pages\">pp. 301019, <\/span><span class=\"tp_pub_additional_year\">2020<\/span>, <span class=\"tp_pub_additional_issn\">ISSN: 2666-2817<\/span>.<\/p><p class=\"tp_pub_menu\">(<span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_847\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('847','tp_abstract')\" title=\"Show abstract\" style=\"cursor:pointer;\">Abstract<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_847\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('847','tp_links')\" title=\"Show links and resources\" style=\"cursor:pointer;\">Links<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_847\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('847','tp_bibtex')\" title=\"Show BibTeX entry\" style=\"cursor:pointer;\">BibTeX<\/a><\/span>)<\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_847\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@article{pluskal2020netfox,<br \/>\r\ntitle = {Netfox detective: A novel open-source network forensics analysis tool},<br \/>\r\nauthor = {Jan Pluskal and Frank Breitinger and Ond\u0159ej Ry\u0161av\u00fd},<br \/>\r\nurl = {http:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281720300871},<br \/>\r\ndoi = {10.1016\/j.fsidi.2020.301019},<br \/>\r\nissn = {2666-2817},<br \/>\r\nyear  = {2020},<br \/>\r\ndate = {2020-09-17},<br \/>\r\njournal = {Forensic Science International: Digital Investigation},<br \/>\r\nvolume = {35},<br \/>\r\npages = {301019},<br \/>\r\nabstract = {Network forensics is a major sub-discipline of digital forensics which becomes more and more important in an age where everything is connected. In order to cope with the amounts of data and other challenges within networks, practitioners require powerful tools that support them. In this paper, we highlight a novel open-source network forensic tool named \u2013 Netfox Detective \u2013 that outperforms existing tools such as Wireshark or NetworkMiner in certain areas. For instance, it provides a heuristically based engine for traffic processing that can be easily extended. Using robust parsers (we are not solely relying on the RFC description but use heuristics), our application tolerates malformed or missing conversation segments. Besides outlining the tool's architecture and basic processing concepts, we also explain how it can be extended. Lastly, a comparison with other similar tools is presented as well as a real-world scenario is discussed.},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {article}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('847','tp_bibtex')\">Close<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_847\" style=\"display:none;\"><div class=\"tp_abstract_entry\">Network forensics is a major sub-discipline of digital forensics which becomes more and more important in an age where everything is connected. In order to cope with the amounts of data and other challenges within networks, practitioners require powerful tools that support them. In this paper, we highlight a novel open-source network forensic tool named \u2013 Netfox Detective \u2013 that outperforms existing tools such as Wireshark or NetworkMiner in certain areas. For instance, it provides a heuristically based engine for traffic processing that can be easily extended. Using robust parsers (we are not solely relying on the RFC description but use heuristics), our application tolerates malformed or missing conversation segments. Besides outlining the tool's architecture and basic processing concepts, we also explain how it can be extended. Lastly, a comparison with other similar tools is presented as well as a real-world scenario is discussed.<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('847','tp_abstract')\">Close<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_847\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"fas fa-globe\"><\/i><a class=\"tp_pub_list\" href=\"http:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281720300871\" title=\"http:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281720300871\" target=\"_blank\">http:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281720300871<\/a><\/li><li><i class=\"ai ai-doi\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/dx.doi.org\/10.1016\/j.fsidi.2020.301019\" title=\"Follow DOI:10.1016\/j.fsidi.2020.301019\" target=\"_blank\">doi:10.1016\/j.fsidi.2020.301019<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('847','tp_links')\">Close<\/a><\/p><\/div><\/td><\/tr><tr class=\"tp_publication tp_publication_article\"><td class=\"tp_pub_number\">44.<\/td><td class=\"tp_pub_info\"><p class=\"tp_pub_author\"> Breitinger, Frank;  Tully-Doyle, Ryan;  Przyborski, Kristen;  Beck, Lauren;  Harichandran, Ronald S.<\/p><p class=\"tp_pub_title\"><a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('848','tp_links')\" style=\"cursor:pointer;\">First year students' experience in a Cyber World course \u2013 an evaluation<\/a> (<span class=\"tp_pub_type tp_  article\">Journal Article<\/span>)<\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_in\">In: <\/span><span class=\"tp_pub_additional_journal\">Education and Information Technologies, <\/span><span class=\"tp_pub_additional_year\">2020<\/span>, <span class=\"tp_pub_additional_isbn\">ISBN: 1573-7608<\/span>.<\/p><p class=\"tp_pub_menu\">(<span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_848\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('848','tp_abstract')\" title=\"Show abstract\" style=\"cursor:pointer;\">Abstract<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_848\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('848','tp_links')\" title=\"Show links and resources\" style=\"cursor:pointer;\">Links<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_848\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('848','tp_bibtex')\" title=\"Show BibTeX entry\" style=\"cursor:pointer;\">BibTeX<\/a><\/span>)<\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_848\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@article{Breitinger2020,<br \/>\r\ntitle = {First year students' experience in a Cyber World course \u2013 an evaluation},<br \/>\r\nauthor = {Frank Breitinger and Ryan Tully-Doyle and Kristen Przyborski and Lauren Beck and Ronald S. Harichandran},<br \/>\r\nurl = {https:\/\/link.springer.com\/article\/10.1007\/s10639-020-10327-9},<br \/>\r\ndoi = {10.1007\/s10639-020-10274-5},<br \/>\r\nisbn = {1573-7608},<br \/>\r\nyear  = {2020},<br \/>\r\ndate = {2020-09-11},<br \/>\r\njournal = {Education and Information Technologies},<br \/>\r\nabstract = {Although cybersecurity is a major present concern, it is not a required subject in University. In response, we developed Cyber World which introduces students to eight highly important cybersecurity topics (primarily taught by none cybersecurity experts). We embedded it into our critical thinking Common Course (core curriculum) which is a team-taught first-year experience required for all students. Cyber World was first taught in Fall 2018 to a cohort of over 150 students from various majors at the University of New Haven. This article presents the evaluation of our Fall taught course. In detail, we compare the performance of Cyber World students to other Common Course sections that ran in parallel and conclude that despite the higher workload students performed equally well. Furthermore, we assess the students' development throughout the course with respect to their cybersecurity knowledge where our results indicate a significant gain of knowledge. Note, this article also presents the idea and topics of Cyber World; however a detailed explanation has been released previously.},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {article}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('848','tp_bibtex')\">Close<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_848\" style=\"display:none;\"><div class=\"tp_abstract_entry\">Although cybersecurity is a major present concern, it is not a required subject in University. In response, we developed Cyber World which introduces students to eight highly important cybersecurity topics (primarily taught by none cybersecurity experts). We embedded it into our critical thinking Common Course (core curriculum) which is a team-taught first-year experience required for all students. Cyber World was first taught in Fall 2018 to a cohort of over 150 students from various majors at the University of New Haven. This article presents the evaluation of our Fall taught course. In detail, we compare the performance of Cyber World students to other Common Course sections that ran in parallel and conclude that despite the higher workload students performed equally well. Furthermore, we assess the students' development throughout the course with respect to their cybersecurity knowledge where our results indicate a significant gain of knowledge. Note, this article also presents the idea and topics of Cyber World; however a detailed explanation has been released previously.<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('848','tp_abstract')\">Close<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_848\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"fas fa-globe\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/link.springer.com\/article\/10.1007\/s10639-020-10327-9\" title=\"https:\/\/link.springer.com\/article\/10.1007\/s10639-020-10327-9\" target=\"_blank\">https:\/\/link.springer.com\/article\/10.1007\/s10639-020-10327-9<\/a><\/li><li><i class=\"ai ai-doi\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/dx.doi.org\/10.1007\/s10639-020-10274-5\" title=\"Follow DOI:10.1007\/s10639-020-10274-5\" target=\"_blank\">doi:10.1007\/s10639-020-10274-5<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('848','tp_links')\">Close<\/a><\/p><\/div><\/td><\/tr><tr class=\"tp_publication tp_publication_article\"><td class=\"tp_pub_number\">45.<\/td><td class=\"tp_pub_info\"><p class=\"tp_pub_author\"> Wu, Tina;  Breitinger, Frank;  O'Shaughnessy, Stephen<\/p><p class=\"tp_pub_title\"><a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('851','tp_links')\" style=\"cursor:pointer;\">Digital forensic tools: Recent advances and enhancing the status quo<\/a> (<span class=\"tp_pub_type tp_  article\">Journal Article<\/span>)<\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_in\">In: <\/span><span class=\"tp_pub_additional_journal\">Forensic Science International: Digital Investigation, <\/span><span class=\"tp_pub_additional_volume\">vol. 34, <\/span><span class=\"tp_pub_additional_pages\">pp. 300999, <\/span><span class=\"tp_pub_additional_year\">2020<\/span>, <span class=\"tp_pub_additional_issn\">ISSN: 2666-2817<\/span>.<\/p><p class=\"tp_pub_menu\">(<span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_851\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('851','tp_abstract')\" title=\"Show abstract\" style=\"cursor:pointer;\">Abstract<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_851\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('851','tp_links')\" title=\"Show links and resources\" style=\"cursor:pointer;\">Links<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_851\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('851','tp_bibtex')\" title=\"Show BibTeX entry\" style=\"cursor:pointer;\">BibTeX<\/a><\/span>)<\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_851\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@article{WBS20,<br \/>\r\ntitle = {Digital forensic tools: Recent advances and enhancing the status quo},<br \/>\r\nauthor = {Tina Wu and Frank Breitinger and Stephen O'Shaughnessy},<br \/>\r\nurl = {http:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281720301864},<br \/>\r\ndoi = {10.1016\/j.fsidi.2020.300999},<br \/>\r\nissn = {2666-2817},<br \/>\r\nyear  = {2020},<br \/>\r\ndate = {2020-08-14},<br \/>\r\njournal = {Forensic Science International: Digital Investigation},<br \/>\r\nvolume = {34},<br \/>\r\npages = {300999},<br \/>\r\nabstract = {Publications in the digital forensics domain frequently come with tools \u2013 a small piece of functional software. These tools are often released to the public for others to reproduce results or use them for their own purposes. However, there has been no study on the tools to understand better what is available and what is missing. For this paper we analyzed almost 800 articles from pertinent venues from 2014 to 2019 to answer the following three questions (1) what tools (i.e., in which domains of digital forensics): have been released; (2) are they still available, maintained, and documented; and (3) are there possibilities to enhance the status quo? We found 62 different tools which we categorized according to digital forensics subfields. Only 33 of these tools were found to be publicly available, the majority of these were not maintained after development. In order to enhance the status quo, one recommendation is a centralized repository specifically for tested tools. This will require tool researchers (developers) to spend more time on code documentation and preferably develop plugins instead of stand-alone tools.},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {article}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('851','tp_bibtex')\">Close<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_851\" style=\"display:none;\"><div class=\"tp_abstract_entry\">Publications in the digital forensics domain frequently come with tools \u2013 a small piece of functional software. These tools are often released to the public for others to reproduce results or use them for their own purposes. However, there has been no study on the tools to understand better what is available and what is missing. For this paper we analyzed almost 800 articles from pertinent venues from 2014 to 2019 to answer the following three questions (1) what tools (i.e., in which domains of digital forensics): have been released; (2) are they still available, maintained, and documented; and (3) are there possibilities to enhance the status quo? We found 62 different tools which we categorized according to digital forensics subfields. Only 33 of these tools were found to be publicly available, the majority of these were not maintained after development. In order to enhance the status quo, one recommendation is a centralized repository specifically for tested tools. This will require tool researchers (developers) to spend more time on code documentation and preferably develop plugins instead of stand-alone tools.<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('851','tp_abstract')\">Close<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_851\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"fas fa-globe\"><\/i><a class=\"tp_pub_list\" href=\"http:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281720301864\" title=\"http:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281720301864\" target=\"_blank\">http:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281720301864<\/a><\/li><li><i class=\"ai ai-doi\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/dx.doi.org\/10.1016\/j.fsidi.2020.300999\" title=\"Follow DOI:10.1016\/j.fsidi.2020.300999\" target=\"_blank\">doi:10.1016\/j.fsidi.2020.300999<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('851','tp_links')\">Close<\/a><\/p><\/div><\/td><\/tr><tr class=\"tp_publication tp_publication_article\"><td class=\"tp_pub_number\">46.<\/td><td class=\"tp_pub_info\"><p class=\"tp_pub_author\"> Palmbach, David;  Breitinger, Frank<\/p><p class=\"tp_pub_title\"><a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('852','tp_links')\" style=\"cursor:pointer;\">Artifacts for detecting timestamp manipulation in NTFS on Windows and their reliability<\/a> (<span class=\"tp_pub_type tp_  article\">Journal Article<\/span>)<\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_in\">In: <\/span><span class=\"tp_pub_additional_journal\">Forensic Science International: Digital Investigation, <\/span><span class=\"tp_pub_additional_volume\">vol. 32, <\/span><span class=\"tp_pub_additional_pages\">pp. 300920, <\/span><span class=\"tp_pub_additional_year\">2020<\/span>, <span class=\"tp_pub_additional_issn\">ISSN: 2666-2817<\/span>.<\/p><p class=\"tp_pub_menu\">(<span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_852\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('852','tp_abstract')\" title=\"Show abstract\" style=\"cursor:pointer;\">Abstract<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_852\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('852','tp_links')\" title=\"Show links and resources\" style=\"cursor:pointer;\">Links<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_852\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('852','tp_bibtex')\" title=\"Show BibTeX entry\" style=\"cursor:pointer;\">BibTeX<\/a><\/span>)<\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_852\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@article{PB20,<br \/>\r\ntitle = {Artifacts for detecting timestamp manipulation in NTFS on Windows and their reliability},<br \/>\r\nauthor = {David Palmbach and Frank Breitinger},<br \/>\r\nurl = {http:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281720300159},<br \/>\r\ndoi = {10.1016\/j.fsidi.2020.300920},<br \/>\r\nissn = {2666-2817},<br \/>\r\nyear  = {2020},<br \/>\r\ndate = {2020-06-04},<br \/>\r\njournal = {Forensic Science International: Digital Investigation},<br \/>\r\nvolume = {32},<br \/>\r\npages = {300920},<br \/>\r\nabstract = {Timestamps have proven to be an expedient source of evidence for examiners in the reconstruction of computer crimes. Consequently, active adversaries and malware have implemented timestomping techniques (i.e., mechanisms to alter timestamps) to hide their traces. Previous research on detecting timestamp manipulation primarily focused on two artifacts: the $MFT as well as the records in the $LogFile. In this paper, we present a new use of four existing windows artifacts \u2013 the $USNjrnl, link files, prefetch files, and Windows event logs \u2013 that can provide valuable information during investigations and diversify the artifacts available to examiners. These artifacts contain either information about executed programs or additional timestamps which, when inconsistencies occur, can be used to prove timestamp forgery. Furthermore, we examine the reliability of artifacts being used to detect timestamp manipulation, i.e., testing their ability to retain information against users actively trying to alter or delete them. Based on our findings we conclude that none of the artifacts analyzed can withstand active exploitation.},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {article}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('852','tp_bibtex')\">Close<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_852\" style=\"display:none;\"><div class=\"tp_abstract_entry\">Timestamps have proven to be an expedient source of evidence for examiners in the reconstruction of computer crimes. Consequently, active adversaries and malware have implemented timestomping techniques (i.e., mechanisms to alter timestamps) to hide their traces. Previous research on detecting timestamp manipulation primarily focused on two artifacts: the $MFT as well as the records in the $LogFile. In this paper, we present a new use of four existing windows artifacts \u2013 the $USNjrnl, link files, prefetch files, and Windows event logs \u2013 that can provide valuable information during investigations and diversify the artifacts available to examiners. These artifacts contain either information about executed programs or additional timestamps which, when inconsistencies occur, can be used to prove timestamp forgery. Furthermore, we examine the reliability of artifacts being used to detect timestamp manipulation, i.e., testing their ability to retain information against users actively trying to alter or delete them. Based on our findings we conclude that none of the artifacts analyzed can withstand active exploitation.<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('852','tp_abstract')\">Close<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_852\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"fas fa-globe\"><\/i><a class=\"tp_pub_list\" href=\"http:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281720300159\" title=\"http:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281720300159\" target=\"_blank\">http:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281720300159<\/a><\/li><li><i class=\"ai ai-doi\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/dx.doi.org\/10.1016\/j.fsidi.2020.300920\" title=\"Follow DOI:10.1016\/j.fsidi.2020.300920\" target=\"_blank\">doi:10.1016\/j.fsidi.2020.300920<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('852','tp_links')\">Close<\/a><\/p><\/div><\/td><\/tr><tr class=\"tp_publication tp_publication_misc\"><td class=\"tp_pub_number\">47.<\/td><td class=\"tp_pub_info\"><p class=\"tp_pub_author\"> Laskov, Pavel;  Breitinger, Frank<\/p><p class=\"tp_pub_title\">Blockchain-Technologien und deren Anwendungen im \u00f6ffentlichen Sektor (<span class=\"tp_pub_type tp_  misc\">Miscellaneous<\/span>)<\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_howpublished\">Workshop Liechtensteinische Landesverwaltung, <\/span><span class=\"tp_pub_additional_year\">2020<\/span><span class=\"tp_pub_additional_note\">, (Vaduz, Liechtenstein)<\/span>.<\/p><p class=\"tp_pub_menu\">(<span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_935\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('935','tp_bibtex')\" title=\"Show BibTeX entry\" style=\"cursor:pointer;\">BibTeX<\/a><\/span>)<\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_935\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@misc{work-BC,<br \/>\r\ntitle = {Blockchain-Technologien und deren Anwendungen im \u00f6ffentlichen Sektor},<br \/>\r\nauthor = {Pavel Laskov and Frank Breitinger},<br \/>\r\nyear  = {2020},<br \/>\r\ndate = {2020-02-19},<br \/>\r\nhowpublished = {Workshop Liechtensteinische Landesverwaltung},<br \/>\r\nnote = {Vaduz, Liechtenstein},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {misc}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('935','tp_bibtex')\">Close<\/a><\/p><\/div><\/td><\/tr><tr class=\"tp_publication tp_publication_article\"><td class=\"tp_pub_number\">48.<\/td><td class=\"tp_pub_info\"><p class=\"tp_pub_author\"> Moia, Vitor Hugo Galhardo;  Breitinger, Frank;  Henriques, Marco Aur\u00e9lio Amaral<\/p><p class=\"tp_pub_title\"><a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('853','tp_links')\" style=\"cursor:pointer;\">The impact of excluding common blocks for approximate matching<\/a> (<span class=\"tp_pub_type tp_  article\">Journal Article<\/span>)<\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_in\">In: <\/span><span class=\"tp_pub_additional_journal\">Computers &amp; Security, <\/span><span class=\"tp_pub_additional_volume\">vol. 89, <\/span><span class=\"tp_pub_additional_pages\">pp. 101676, <\/span><span class=\"tp_pub_additional_year\">2019<\/span>, <span class=\"tp_pub_additional_issn\">ISSN: 0167-4048<\/span>.<\/p><p class=\"tp_pub_menu\">(<span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_853\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('853','tp_abstract')\" title=\"Show abstract\" style=\"cursor:pointer;\">Abstract<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_853\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('853','tp_links')\" title=\"Show links and resources\" style=\"cursor:pointer;\">Links<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_853\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('853','tp_bibtex')\" title=\"Show BibTeX entry\" style=\"cursor:pointer;\">BibTeX<\/a><\/span>)<\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_853\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@article{MOIA2020101676,<br \/>\r\ntitle = {The impact of excluding common blocks for approximate matching},<br \/>\r\nauthor = {Vitor Hugo Galhardo Moia and Frank Breitinger and Marco Aur\u00e9lio Amaral Henriques},<br \/>\r\nurl = {http:\/\/www.sciencedirect.com\/science\/article\/pii\/S0167404819302159},<br \/>\r\ndoi = {10.1016\/j.cose.2019.101676},<br \/>\r\nissn = {0167-4048},<br \/>\r\nyear  = {2019},<br \/>\r\ndate = {2019-11-28},<br \/>\r\njournal = {Computers & Security},<br \/>\r\nvolume = {89},<br \/>\r\npages = {101676},<br \/>\r\nabstract = {Approximate matching functions allow the identification of similarity (bytewise level) in a very efficient way, by creating and comparing compact representations of objects (a.k.a digests). However, many similarity matches occur due to common data that repeats over many different files and consist of inner structure, header and footer information, color tables, font specifications, etc.; data created by applications and not generated by users. Most of the times, this sort of information is less relevant from an investigator perspective and should be avoided. In this work, we show how the common data can be identified and filtered out by using approximate matching, as well as how they are spread over different file types and their frequency. We assess the impact on similarity when removing it (i.e., in the number of matches) and the effects on performance. Our results show that for a small price on performance, a reduction about 87% on the number of matches can be achieved when removing such data.},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {article}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('853','tp_bibtex')\">Close<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_853\" style=\"display:none;\"><div class=\"tp_abstract_entry\">Approximate matching functions allow the identification of similarity (bytewise level) in a very efficient way, by creating and comparing compact representations of objects (a.k.a digests). However, many similarity matches occur due to common data that repeats over many different files and consist of inner structure, header and footer information, color tables, font specifications, etc.; data created by applications and not generated by users. Most of the times, this sort of information is less relevant from an investigator perspective and should be avoided. In this work, we show how the common data can be identified and filtered out by using approximate matching, as well as how they are spread over different file types and their frequency. We assess the impact on similarity when removing it (i.e., in the number of matches) and the effects on performance. Our results show that for a small price on performance, a reduction about 87% on the number of matches can be achieved when removing such data.<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('853','tp_abstract')\">Close<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_853\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"fas fa-globe\"><\/i><a class=\"tp_pub_list\" href=\"http:\/\/www.sciencedirect.com\/science\/article\/pii\/S0167404819302159\" title=\"http:\/\/www.sciencedirect.com\/science\/article\/pii\/S0167404819302159\" target=\"_blank\">http:\/\/www.sciencedirect.com\/science\/article\/pii\/S0167404819302159<\/a><\/li><li><i class=\"ai ai-doi\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/dx.doi.org\/10.1016\/j.cose.2019.101676\" title=\"Follow DOI:10.1016\/j.cose.2019.101676\" target=\"_blank\">doi:10.1016\/j.cose.2019.101676<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('853','tp_links')\">Close<\/a><\/p><\/div><\/td><\/tr><tr class=\"tp_publication tp_publication_article\"><td class=\"tp_pub_number\">49.<\/td><td class=\"tp_pub_info\"><p class=\"tp_pub_author\"> Breitinger, Frank;  Tully-Doyle, Ryan;  Hassenfeldt, Courtney<\/p><p class=\"tp_pub_title\"><a class=\"tp_title_link\" onclick=\"teachpress_pub_showhide('855','tp_links')\" style=\"cursor:pointer;\">A survey on smartphone user's security choices, awareness and education<\/a> (<span class=\"tp_pub_type tp_  article\">Journal Article<\/span>)<\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_in\">In: <\/span><span class=\"tp_pub_additional_journal\">Computers &amp; Security, <\/span><span class=\"tp_pub_additional_volume\">vol. 88, <\/span><span class=\"tp_pub_additional_pages\">pp. 101647, <\/span><span class=\"tp_pub_additional_year\">2019<\/span>, <span class=\"tp_pub_additional_issn\">ISSN: 0167-4048<\/span>.<\/p><p class=\"tp_pub_menu\">(<span class=\"tp_abstract_link\"><a id=\"tp_abstract_sh_855\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('855','tp_abstract')\" title=\"Show abstract\" style=\"cursor:pointer;\">Abstract<\/a><\/span> | <span class=\"tp_resource_link\"><a id=\"tp_links_sh_855\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('855','tp_links')\" title=\"Show links and resources\" style=\"cursor:pointer;\">Links<\/a><\/span> | <span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_855\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('855','tp_bibtex')\" title=\"Show BibTeX entry\" style=\"cursor:pointer;\">BibTeX<\/a><\/span>)<\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_855\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@article{BTH20,<br \/>\r\ntitle = {A survey on smartphone user's security choices, awareness and education},<br \/>\r\nauthor = {Frank Breitinger and Ryan Tully-Doyle and Courtney Hassenfeldt},<br \/>\r\nurl = {http:\/\/www.sciencedirect.com\/science\/article\/pii\/S0167404819301919},<br \/>\r\ndoi = {10.1016\/j.cose.2019.101647},<br \/>\r\nissn = {0167-4048},<br \/>\r\nyear  = {2019},<br \/>\r\ndate = {2019-10-11},<br \/>\r\njournal = {Computers & Security},<br \/>\r\nvolume = {88},<br \/>\r\npages = {101647},<br \/>\r\nabstract = {Smartphones contain a significant amount of personal data. Additionally, they are always in the user's possession, which allows them to be abused for tracking (e.g., GPS, Bluetooth or WiFi tracking). In order to not reveal private information, smartphone users should secure their devices by setting lock screen protection, using third party security applications, and choosing appropriate security settings (often, default settings are inadequate). In this paper, we mount a survey to explore user choices, awareness and education with respect to cybersecurity. In comparison with prior work, we take the user's cybersecurity familiarity into consideration in the analysis of user practices as well as have a strong focus on the younger generations, Y and Z. Our survey findings suggest that most users have appropriate lock screen settings to protect their phones from physical access; however, they disregard other security best practices, e.g., not using a VPN when connecting to a public WiFi or turning off unused features (regardless of level of expertise). Compared to desktop computers, smartphones are less secured and fewer third party security products are installed.},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {article}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('855','tp_bibtex')\">Close<\/a><\/p><\/div><div class=\"tp_abstract\" id=\"tp_abstract_855\" style=\"display:none;\"><div class=\"tp_abstract_entry\">Smartphones contain a significant amount of personal data. Additionally, they are always in the user's possession, which allows them to be abused for tracking (e.g., GPS, Bluetooth or WiFi tracking). In order to not reveal private information, smartphone users should secure their devices by setting lock screen protection, using third party security applications, and choosing appropriate security settings (often, default settings are inadequate). In this paper, we mount a survey to explore user choices, awareness and education with respect to cybersecurity. In comparison with prior work, we take the user's cybersecurity familiarity into consideration in the analysis of user practices as well as have a strong focus on the younger generations, Y and Z. Our survey findings suggest that most users have appropriate lock screen settings to protect their phones from physical access; however, they disregard other security best practices, e.g., not using a VPN when connecting to a public WiFi or turning off unused features (regardless of level of expertise). Compared to desktop computers, smartphones are less secured and fewer third party security products are installed.<\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('855','tp_abstract')\">Close<\/a><\/p><\/div><div class=\"tp_links\" id=\"tp_links_855\" style=\"display:none;\"><div class=\"tp_links_entry\"><ul class=\"tp_pub_list\"><li><i class=\"fas fa-globe\"><\/i><a class=\"tp_pub_list\" href=\"http:\/\/www.sciencedirect.com\/science\/article\/pii\/S0167404819301919\" title=\"http:\/\/www.sciencedirect.com\/science\/article\/pii\/S0167404819301919\" target=\"_blank\">http:\/\/www.sciencedirect.com\/science\/article\/pii\/S0167404819301919<\/a><\/li><li><i class=\"ai ai-doi\"><\/i><a class=\"tp_pub_list\" href=\"https:\/\/dx.doi.org\/10.1016\/j.cose.2019.101647\" title=\"Follow DOI:10.1016\/j.cose.2019.101647\" target=\"_blank\">doi:10.1016\/j.cose.2019.101647<\/a><\/li><\/ul><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('855','tp_links')\">Close<\/a><\/p><\/div><\/td><\/tr><tr class=\"tp_publication tp_publication_misc\"><td class=\"tp_pub_number\">50.<\/td><td class=\"tp_pub_info\"><p class=\"tp_pub_author\"> Breitinger, Frank<\/p><p class=\"tp_pub_title\">IT-Sicherheit im Finanzsektor (<span class=\"tp_pub_type tp_  misc\">Miscellaneous<\/span>)<\/p><p class=\"tp_pub_additional\"><span class=\"tp_pub_additional_howpublished\">7. Sorgfaltspflichttag Liechtenstein, <\/span><span class=\"tp_pub_additional_year\">2019<\/span><span class=\"tp_pub_additional_note\">, (Schaan, Liechtenstein)<\/span>.<\/p><p class=\"tp_pub_menu\">(<span class=\"tp_bibtex_link\"><a id=\"tp_bibtex_sh_936\" class=\"tp_show\" onclick=\"teachpress_pub_showhide('936','tp_bibtex')\" title=\"Show BibTeX entry\" style=\"cursor:pointer;\">BibTeX<\/a><\/span>)<\/p><div class=\"tp_bibtex\" id=\"tp_bibtex_936\" style=\"display:none;\"><div class=\"tp_bibtex_entry\"><pre>@misc{pres-SPG,<br \/>\r\ntitle = {IT-Sicherheit im Finanzsektor},<br \/>\r\nauthor = {Frank Breitinger},<br \/>\r\nyear  = {2019},<br \/>\r\ndate = {2019-10-01},<br \/>\r\nhowpublished = {7. Sorgfaltspflichttag Liechtenstein},<br \/>\r\nnote = {Schaan, Liechtenstein},<br \/>\r\nkeywords = {},<br \/>\r\npubstate = {published},<br \/>\r\ntppubtype = {misc}<br \/>\r\n}<br \/>\r\n<\/pre><\/div><p class=\"tp_close_menu\"><a class=\"tp_close\" onclick=\"teachpress_pub_showhide('936','tp_bibtex')\">Close<\/a><\/p><\/div><\/td><\/tr><\/table><div class=\"tablenav\"><div class=\"tablenav-pages\"><span class=\"displaying-num\">120 entries<\/span> <a class=\"page-numbers button disabled\">&laquo;<\/a> <a class=\"page-numbers button disabled\">&lsaquo;<\/a> 1 of 3 <a href=\"https:\/\/fbreitinger.de\/?page_id=297&amp;limit=2&amp;tgid=&amp;yr=&amp;type=&amp;usr=&amp;auth=&amp;tsr=\" title=\"next page\" class=\"page-numbers button\">&rsaquo;<\/a> <a href=\"https:\/\/fbreitinger.de\/?page_id=297&amp;limit=3&amp;tgid=&amp;yr=&amp;type=&amp;usr=&amp;auth=&amp;tsr=\" title=\"last page\" class=\"page-numbers button\">&raquo;<\/a> <\/div><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"","protected":false},"author":1,"featured_media":0,"parent":15,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"page-full-width.php","meta":{"footnotes":""},"class_list":["post-297","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/fbreitinger.de\/index.php?rest_route=\/wp\/v2\/pages\/297","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fbreitinger.de\/index.php?rest_route=\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/fbreitinger.de\/index.php?rest_route=\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/fbreitinger.de\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/fbreitinger.de\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=297"}],"version-history":[{"count":14,"href":"https:\/\/fbreitinger.de\/index.php?rest_route=\/wp\/v2\/pages\/297\/revisions"}],"predecessor-version":[{"id":1105,"href":"https:\/\/fbreitinger.de\/index.php?rest_route=\/wp\/v2\/pages\/297\/revisions\/1105"}],"up":[{"embeddable":true,"href":"https:\/\/fbreitinger.de\/index.php?rest_route=\/wp\/v2\/pages\/15"}],"wp:attachment":[{"href":"https:\/\/fbreitinger.de\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=297"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}