Sign in to use this feature.

Years

Between: -

Subjects

remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline

Journals

Article Types

Countries / Regions

Search Results (45)

Search Parameters:
Keywords = cloud forensics

Order results
Result details
Results per page
Select all
Export citation of selected articles as:
23 pages, 4307 KB  
Article
The Sphenoid Sinus as a Biometric Marker: AI-Based Automated Segmentation in CT Imaging for Forensic Identification
by Victoriia Alekseeva, Marcus Krüger, Florian Zwicker, Tom Graner, Vlad Krasnikov, Parsa Lavasanifar, Marcus Frohme, Vitaliy Gargin and Alina Nechyporenko
Electronics 2026, 15(17), 3805; https://doi.org/10.3390/electronics15173805 - 25 Aug 2026
Abstract
Reliable personal identification remains a major challenge in forensic medicine, particularly in cases involving decomposition, thermal injury, or absence of DNA and dental records. In this context, anatomically protected and morphologically unique structures such as the sphenoid sinus may serve as valuable biometric [...] Read more.
Reliable personal identification remains a major challenge in forensic medicine, particularly in cases involving decomposition, thermal injury, or absence of DNA and dental records. In this context, anatomically protected and morphologically unique structures such as the sphenoid sinus may serve as valuable biometric markers. The aim of this study was to evaluate the forensic applicability of sphenoid sinus morphology using computed tomography (CT), automated segmentation, and three-dimensional (3D) computational analysis. The proposed framework integrates CT-based image preprocessing, automated 3D segmentation using nnU-Net architecture, and geometric comparison of reconstructed sphenoid sinus models through point cloud analysis and deep learning approaches. Morphological variability, spatial configuration, and structural stability of the sphenoid sinus were analyzed as discriminative biometric features. The GSA-Net–based identification model demonstrated high recognition performance, achieving Top-1 accuracies exceeding 97.8% and Top-3 accuracies up to 100% in controlled datasets. The results support the concept that the sphenoid sinus possesses sufficient individuality and anatomical preservation to enable reliable ante-mortem and post-mortem identification. The study highlights the potential of integrating automated segmentation and AI-driven 3D analysis into forensic workflows and emphasizes the importance of standardized imaging protocols and larger annotated datasets for future clinical and forensic implementation. Full article
(This article belongs to the Section Artificial Intelligence)
Show Figures

Figure 1

72 pages, 5284 KB  
Review
Portable Sensing Systems in Biological and Chemical Analyses: A Review of Sensor Technologies, Miniaturized Platforms, Data Processing, and Field Applications
by Hsuan-Yu Chen and Chiachung Chen
Micromachines 2026, 17(7), 863; https://doi.org/10.3390/mi17070863 - 21 Jul 2026
Viewed by 398
Abstract
Portable sensing systems are increasingly important in biological and chemical analyses because they can provide analytical information at the point of decision-making. While traditional laboratory methods remain crucial for reference measurements, regulatory validation, and high-precision quantification, portable systems emphasize rapid response, convenience, cost-effectiveness, [...] Read more.
Portable sensing systems are increasingly important in biological and chemical analyses because they can provide analytical information at the point of decision-making. While traditional laboratory methods remain crucial for reference measurements, regulatory validation, and high-precision quantification, portable systems emphasize rapid response, convenience, cost-effectiveness, robustness, and relevance to decision-making. This paper views portable sensing systems as integrated analytical platforms rather than isolated sensing elements. The paper discusses recognition elements, including enzymes, antibodies, nucleic acid probes, aptamers, molecularly imprinted polymers, nanomaterials, and hybrid recognition interfaces, as well as electrochemical, optical, mass-sensitive, thermal, field-effect, and hybrid sensing technologies. Furthermore, this paper reviews platform designs, including paper-based analytical devices, chip lab systems, smartphone-assisted sensors, wearable and flexible sensors, handheld instruments, and wireless sensor networks. It explores their applications in sample handling, calibration, data processing, and field deployment. Applications of this technology include point-of-care diagnostics, pathogen detection, wearable health monitoring, agriculture, veterinary medicine, environmental monitoring, food safety, industrial process control, forensic analysis, public safety, and occupational exposure assessment. The report focuses on sample acquisition, miniaturized preparation, reagent storage, matrix interference, calibration transfer, signal conditioning, machine learning, cloud platforms, analytical validation, and decision support. Furthermore, it identifies key obstacles to translating academic prototypes into industrial products, including reproducibility, stability, manufacturability, ease of use, cybersecurity, regulatory approval, and market acceptance. Future development requires fully integrated sample-to-result systems, multimodal sensing, artificial intelligence, sustainable single-use materials, self-powered devices, and system-level validation under real-world operating conditions. Full article
(This article belongs to the Special Issue Portable Sensing Systems in Biological and Chemical Analysis)
Show Figures

Figure 1

25 pages, 471 KB  
Systematic Review
A Systematic Review of Industrial IoT Anomaly Detection and the Forensic Interpretability Gap
by Mohamed Aziz Ben Haha, Afef Bohli, Naoufel Haddour and Ridha Bouallegue
Electronics 2026, 15(11), 2240; https://doi.org/10.3390/electronics15112240 - 22 May 2026
Viewed by 728
Abstract
The deployment of Deep Learning (DL) for anomaly detection in Industrial IoT (IIoT) is critically hampered by the non-stationary nature of industrial data streams and the lack of forensic-grade explainability. This systematic review synthesizes 48 peer-reviewed studies (2021–2025) to quantify the performance collapse [...] Read more.
The deployment of Deep Learning (DL) for anomaly detection in Industrial IoT (IIoT) is critically hampered by the non-stationary nature of industrial data streams and the lack of forensic-grade explainability. This systematic review synthesizes 48 peer-reviewed studies (2021–2025) to quantify the performance collapse of static models under concept drift and to establish operational criteria distinguishing post hoc feature attribution (Type A XAI) from forensic root-cause diagnosis (Type B XAI). Our analysis reveals three critical findings: (1) static DL models suffer a 15–22% F1-score degradation across wastewater, manufacturing, and energy sectors when deployed in non-stationary environments, rendering them operationally non-viable without continuous adaptation; (2) the current literature remains saturated with Type A explainability (80% of corpus through 2023), creating a Forensic Gap where operators receive statistical correlations but lack actionable maintenance directives; and (3) emerging 2024–2025 research marks a paradigm shift toward Type B methodologies, yet no unified framework bridges real-time detection with deep causal reasoning. To address these gaps, we contribute the following: (1) a validated operational taxonomy (Cohen’s κ=0.84) with reproducible five-criterion rubric enabling forensic XAI classification; (2) the first quantitative synthesis of drift penalties in industrial deployments; and (3) a three-tier Edge-Cloud Forensic XAI architecture that achieves 70% communication payload reduction via compressed latent vectors while integrating tnGAN-based data imputation (handling 20–30% missing data) and physics-guided causal reasoning engines. Our framework decouples millisecond-level edge detection from 1–3 s cloud-based forensic diagnosis, ensuring both operational responsiveness and actionable industrial insight. We conclude that the future of safety-critical IIoT demands “Forensic-by-Design” architectures leveraging machine unlearning for drift adaptation and LLM-based natural language interfaces for operator-facing explanations, positioning Industry 5.0 to bridge the gap between algorithmic detection and human-centered decision support. Full article
Show Figures

Figure 1

41 pages, 3607 KB  
Review
The Hardware Isolation Gap: A Systematic Survey of BitLocker Forensics in the TPM 2.0 Era
by Vinay Kumar Sankalagere Ramesh, Sapna Vikram Mewundi, Prasad Balakrishna Honnavalli, Shashidhar Thoreshattalli Kenchaiah and Venkatesh Murthy Krishna Murthy
Electronics 2026, 15(9), 1959; https://doi.org/10.3390/electronics15091959 - 6 May 2026
Viewed by 2478
Abstract
BitLocker Drive Encryption has evolved from an optional feature into a hardware-integrated encryption framework widely deployed on modern Windows systems with TPM-based device encryption enabled by default. This survey is an in-depth analysis of the architecture and Trusted Platform Module (TPM) incorporation of [...] Read more.
BitLocker Drive Encryption has evolved from an optional feature into a hardware-integrated encryption framework widely deployed on modern Windows systems with TPM-based device encryption enabled by default. This survey is an in-depth analysis of the architecture and Trusted Platform Module (TPM) incorporation of BitLocker and 18-years of attack vector development (2006–2025). We record a progressive loss of forensic practicability: the reported attack success rates are now down to less than 5% in current TPM 2.0 defended systems as compared to the 60–70% success rates reported in early software based implementations. We name and define the Hardware Isolation Gap—a paradigm shift in architecture where encryption keys are implanted into hardware, and where the traditional offline and memory based forensic methods do not work anymore by design. To the best of our knowledge, this is the first version-correlated attack taxonomy, which shows that the practical attack surface size is reduced by approximately 80%. We also provide exploratory empirical validation using controlled experiments on a single Intel-based Windows 11 platform (Dell Precision 5570 (Xiamen, China), Intel Core i7-12800H with firmware TPM); while these results directionally confirm literature-reported forensic success rates below 5% against default TPM 2.0 settings, they represent preliminary single-platform observations and may not generalize to AMD Ryzen, Microsoft Pluton, or other OEM hardware configurations. We have found that forensic inaccessibility today is not the failure of tooling but rather the intentional result of security engineering. Literature suggests that cloud-based recovery and weak-password cracking remain the only viable strategies against default Windows 11 settings; however, cloud-based recovery was not empirically tested in this study due to ethical and legal constraints and is characterized based on secondary literature analysis. We determine the existence of crucial methodological gaps and suggest a failure-conscious forensic research agenda that can act within the hard cryptographic constraints. Full article
(This article belongs to the Special Issue New Technologies for Cybersecurity)
Show Figures

Figure 1

25 pages, 1873 KB  
Article
An Empirical Assessment of Digital Forensic Process Reliability Using Integrated ISO/IEC 27037 and 27041 Standards
by Zlatan Morić, Vedran Dakić and Ivana Ogrizek Biškupić
J. Cybersecur. Priv. 2026, 6(2), 57; https://doi.org/10.3390/jcp6020057 - 30 Mar 2026
Cited by 1 | Viewed by 2863
Abstract
The escalating scale and complexity of cybercrime necessitate standardized digital forensic protocols to ensure the integrity and admissibility of digital evidence. This study empirically assesses the use of ISO/IEC 27037 and ISO/IEC 27041 through three real-world digital forensic case studies conducted in organizational [...] Read more.
The escalating scale and complexity of cybercrime necessitate standardized digital forensic protocols to ensure the integrity and admissibility of digital evidence. This study empirically assesses the use of ISO/IEC 27037 and ISO/IEC 27041 through three real-world digital forensic case studies conducted in organizational settings. A multi-case methodology was employed, encompassing a multinational corporate criminal investigation, an internal employee misbehaviour probe, and an examination into mobile- and cloud-based data leaks. The effect of synchronized standard implementation was evaluated using audit-based and quantitative indicators that measure forensic process quality as a system attribute. The findings demonstrate that the systematic implementation of ISO/IEC 27037 and ISO/IEC 27041 improves investigative traceability, documentation quality, and evidentiary robustness. In the worldwide case study, documentation completeness increased by 18%, and all digital evidence was deemed admissible in judicial proceedings, surpassing the institutional baseline admissibility rate of 82%. In other instances, evidence gathered within the same framework was acknowledged in organizational or disciplinary review processes, resulting in similar enhancements in documentation quality and procedural consistency, notwithstanding technological and organizational limitations. The paper develops and empirically substantiates an integrated procedural validation model that connects evidence-handling practices with method and instrument validation. The results indicate that the synchronized implementation of ISO/IEC forensic standards improves the transparency, dependability, and auditability of digital forensic investigations. Full article
(This article belongs to the Section Security Engineering & Applications)
Show Figures

Figure 1

16 pages, 618 KB  
Article
Agentless and Automated Acquisition of Digital Evidence in Corporate and Industrial Networks: Architecture, Validation, and Compliance
by David García Fernández, Llanos Tobarra, Antonio Robles-Gómez and Rafael Pastor Vargas
Electronics 2026, 15(4), 744; https://doi.org/10.3390/electronics15040744 - 10 Feb 2026
Cited by 1 | Viewed by 1122
Abstract
The growing complexity of corporate, cloud, and industrial environments has increased the difficulty of acquiring digital evidence, particularly volatile data such as memory and transient network artifacts. Manual forensic procedures and agent-based solutions often introduce operational risks, scalability constraints, and legal challenges in [...] Read more.
The growing complexity of corporate, cloud, and industrial environments has increased the difficulty of acquiring digital evidence, particularly volatile data such as memory and transient network artifacts. Manual forensic procedures and agent-based solutions often introduce operational risks, scalability constraints, and legal challenges in critical infrastructures. This paper proposes an agentless and automated framework for the remote acquisition of digital evidence in heterogeneous networks. The solution is defined as code and orchestrated using Ansible, enabling reproducible, traceable, and minimally intrusive acquisition without requiring permanent software installation on target systems. It supports the collection of volatile memory, system artifacts, and network evidence across on-premise, cloud (AWS), and industrial control system (ICS) environments. The framework is validated through experimental evaluation and a comparative analysis with an agent-based forensic platform (Velociraptor), focusing on scalability, acquisition time, integrity, and operational impact. Compliance with international forensic standards and recent European regulations is also discussed. The results indicate that agentless automation is a viable and flexible approach for digital forensic acquisition in modern hybrid environments. Full article
Show Figures

Figure 1

22 pages, 840 KB  
Article
A Comparative Evaluation of Snort and Suricata for Detecting Data Exfiltration Tunnels in Cloud Environments
by Mahmoud H. Qutqut, Ali Ahmed, Mustafa K. Taqi, Jordan Abimanyu, Erika Thea Ajes and Fatima Alhaj
J. Cybersecur. Priv. 2026, 6(1), 17; https://doi.org/10.3390/jcp6010017 - 8 Jan 2026
Cited by 3 | Viewed by 4680
Abstract
Data exfiltration poses a major cybersecurity challenge because it involves the unauthorized transfer of sensitive information. Intrusion Detection Systems (IDSs) are vital security controls in identifying such attacks; however, their effectiveness in cloud computing environments remains limited, particularly against covert channels such as [...] Read more.
Data exfiltration poses a major cybersecurity challenge because it involves the unauthorized transfer of sensitive information. Intrusion Detection Systems (IDSs) are vital security controls in identifying such attacks; however, their effectiveness in cloud computing environments remains limited, particularly against covert channels such as Internet Control Message Protocol (ICMP) and Domain Name System (DNS) tunneling. This study compares two widely used IDSs, Snort and Suricata, in a controlled cloud computing environment. The assessment focuses on their ability to detect data exfiltration techniques implemented via ICMP and DNS tunneling, using DNSCat2 and Iodine. We evaluate detection performance using standard classification metrics, including Recall, Precision, Accuracy, and F1-Score. Our experiments were conducted on Amazon Web Services (AWS) Elastic Compute Cloud (EC2) instances, where IDS instances monitored simulated exfiltration traffic generated by DNSCat2, Iodine, and Metasploit. Network traffic was mirrored via AWS Virtual Private Cloud (VPC) Traffic Mirroring, with the ELK Stack integrated for centralized logging and visual analysis. The findings indicate that Suricata outperformed Snort in detecting DNS-based exfiltration, underscoring the advantages of multi-threaded architectures for managing high-volume cloud traffic. For DNS tunneling, Suricata achieved 100% detection (recall) for both DNSCat2 and Iodine, whereas Snort achieved 85.7% and 66.7%, respectively. Neither IDS detected ICMP tunneling using Metasploit, with both recording 0% recall. It is worth noting that both IDSs failed to detect ICMP tunneling under default configurations, highlighting the limitations of signature-based detection in isolation. These results emphasize the need to combine signature-based and behavior-based analytics, supported by centralized logging frameworks, to strengthen cloud-based intrusion detection and enhance forensic visibility. Full article
(This article belongs to the Special Issue Cloud Security and Privacy)
Show Figures

Figure 1

35 pages, 20479 KB  
Article
Comprehensive Forensic Tool for Crime Scene and Traffic Accident 3D Reconstruction
by Alejandra Ospina-Bohórquez, Esteban Ruiz de Oña, Roy Yali, Emmanouil Patsiouras, Katerina Margariti and Diego González-Aguilera
Algorithms 2025, 18(11), 707; https://doi.org/10.3390/a18110707 - 7 Nov 2025
Cited by 4 | Viewed by 3911
Abstract
This article presents a comprehensive forensic tool for crime scene and traffic accident investigations, integrating advanced 3D reconstruction and semantic and dynamic analyses; the tool facilitates the accurate documentation and preservation of crime scenes through photogrammetric techniques, producing detailed 3D models based on [...] Read more.
This article presents a comprehensive forensic tool for crime scene and traffic accident investigations, integrating advanced 3D reconstruction and semantic and dynamic analyses; the tool facilitates the accurate documentation and preservation of crime scenes through photogrammetric techniques, producing detailed 3D models based on images or video captured under specified protocols. The system includes modules for semantic analysis, enabling object detection and classification in 3D point clouds and 2D images. By employing machine learning methods such as the Random Forest model for point cloud classification and the YOLOv8 architecture for object detection, the tool enhances the accuracy and reliability of forensic analysis. Furthermore, a dynamic analysis module supports ballistic trajectory calculations for crime scene investigations and the vehicle impact speed estimation using the Equivalent Barrier Speed (EBS) model for traffic accidents. These capabilities are integrated into a single, user-friendly platform offering significant improvements over existing forensic tools, which often focus on singular tasks and require expertise. This tool provides a robust, accessible solution for law enforcement agencies, enabling more efficient and precise forensic investigations across different scenarios. Full article
(This article belongs to the Special Issue Modern Algorithms for Image Processing and Computer Vision)
Show Figures

Figure 1

19 pages, 4890 KB  
Article
Classifying Sex from MSCT-Derived 3D Mandibular Models Using an Adapted PointNet++ Deep Learning Approach in a Croatian Population
by Eva Shimkus, Ivana Kružić, Saša Mladenović, Iva Perić, Marija Jurić Gunjača, Tade Tadić, Krešimir Dolić, Šimun Anđelinović, Željana Bašić and Ivan Jerković
J. Imaging 2025, 11(10), 328; https://doi.org/10.3390/jimaging11100328 - 24 Sep 2025
Viewed by 9068
Abstract
Accurate sex estimation is critical in forensic anthropology for developing biological profiles, with the mandible serving as a valuable alternative when crania or pelvic bones are unavailable. This study aims to enhance mandibular sex estimation using deep learning on 3D models in a [...] Read more.
Accurate sex estimation is critical in forensic anthropology for developing biological profiles, with the mandible serving as a valuable alternative when crania or pelvic bones are unavailable. This study aims to enhance mandibular sex estimation using deep learning on 3D models in a southern Croatian population. A dataset of 254 MSCT-derived 3D mandibular models (127 male, 127 female) was processed to generate 4096-point clouds, analyzed using an adapted PointNet++ architecture. The dataset was split into training (60%), validation (20%), and test (20%) sets. Unsupervised analysis employed an autoencoder with t-SNE visualization, while supervised classification used logistic regression on extracted features, evaluated by accuracy, sensitivity, specificity, PPV, NPV, and MCC. The model achieved 93% cross-validation accuracy and 92% test set accuracy, with saliency maps highlighting key sexually dimorphic regions like the chin, gonial, and condylar areas. A user-friendly Gradio web application was developed for real-time sex classification from STL files, enhancing forensic applicability. This approach outperformed traditional mandibular sex estimation methods and could have potential as a robust, automated tool for forensic practice, broader population studies and integration with diverse 3D data sources. Full article
(This article belongs to the Section Medical Imaging)
Show Figures

Figure 1

18 pages, 3408 KB  
Article
Enhancing Traditional Reactive Digital Forensics to a Proactive Digital Forensics Standard Operating Procedure (P-DEFSOP): A Case Study of DEFSOP and ISO 27035
by Hung-Cheng Yang, I-Long Lin and Yung-Hung Chao
Appl. Sci. 2025, 15(18), 9922; https://doi.org/10.3390/app15189922 - 10 Sep 2025
Cited by 4 | Viewed by 4667
Abstract
With the growing intensity of global cybersecurity threats and the rapid advancement of attack techniques, strengthening enterprise information and communication technology (ICT) infrastructures and enhancing digital forensics have become critical imperatives. Cloud environments, in particular, present substantial challenges due to the limited availability [...] Read more.
With the growing intensity of global cybersecurity threats and the rapid advancement of attack techniques, strengthening enterprise information and communication technology (ICT) infrastructures and enhancing digital forensics have become critical imperatives. Cloud environments, in particular, present substantial challenges due to the limited availability of effective forensic tools and the pressing demand for impartial and legally admissible digital evidence. To address these challenges, we propose a proactive digital forensics mechanism (P-DFM) designed for emergency incident management in enterprise settings. This mechanism integrates a range of forensic tools to identify and preserve critical digital evidence. It also incorporates the MITRE ATT&CK framework with Security Information and Event Management (SIEM) and Managed Detection and Response (MDR) systems to enable comprehensive and timely threat detection and analysis. The principal contribution of this study is the formulation of a novel Proactive Digital Evidence Forensics Standard Operating Procedure (P-DEFSOP), which enhances the accuracy and efficiency of security threat detection and forensic analysis while ensuring that digital evidence remains legally admissible. This advancement significantly reinforces the cybersecurity posture of enterprise networks. Our approach is systematically grounded in the Digital Evidence Forensics Standard Operating Procedure (DEFSOP) framework and complies with internationally recognized digital forensic standards, including ISO/IEC 27035 and ISO/IEC 27037, to ensure the integrity, reliability, validity, and legal admissibility of digital evidence throughout the forensic process. Given the complexity of cloud computing infrastructures—such as Chunghwa Telecom HiCloud, Amazon Web Services (AWS), Google Cloud, and Microsoft Azure—we underscore the critical importance of impartial and standardized digital forensic services in cloud-based environments. Full article
(This article belongs to the Section Computing and Artificial Intelligence)
Show Figures

Figure 1

36 pages, 21603 KB  
Article
Forensic Joint Photographic Experts Group (JPEG) Watermarking for Disk Image Leak Attribution: An Adaptive Discrete Cosine Transform–Discrete Wavelet Transform (DCT-DWT) Approach
by Belinda I. Onyeashie, Petra Leimich, Sean McKeown and Gordon Russell
Electronics 2025, 14(9), 1800; https://doi.org/10.3390/electronics14091800 - 28 Apr 2025
Cited by 3 | Viewed by 4560
Abstract
This paper presents a novel forensic watermarking method for digital evidence distribution in non-cloud environments. The approach addresses the critical need for the secure sharing of Joint Photographic Experts Group (JPEG) images in forensic investigations. The method utilises an adaptive Discrete Cosine Transform–Discrete [...] Read more.
This paper presents a novel forensic watermarking method for digital evidence distribution in non-cloud environments. The approach addresses the critical need for the secure sharing of Joint Photographic Experts Group (JPEG) images in forensic investigations. The method utilises an adaptive Discrete Cosine Transform–Discrete Wavelet Transform (DCT-DWT) domain technique to embed a 64-bit watermark in both stand-alone JPEGs and those within forensic disk images. This occurs without alterations to disk structure or complications to the chain of custody. The system implements uniform secure randomisation and recipient-specific watermarks to balance security with forensic workflow efficiency. This work presents the first implementation of forensic watermarking at the disk image level that preserves structural integrity and enables precise leak source attribution. It addresses a critical gap in secure evidence distribution methodologies. The evaluation occurred on extensive datasets: 1124 JPEGs in a forensic disk image, 10,000 each of BOSSBase 256 × 256 and 512 × 512 greyscale images, and 10,000 COCO2017 coloured images. The results demonstrate high imperceptibility with average Peak Signal-to-Noise Ratio (PSNR) values ranging from 46.13 dB to 49.37 dB across datasets. The method exhibits robust performance against geometric attacks with perfect watermark recovery (Bit Error Rate (BER) = 0) for rotations up to 90° and scaling factors between 0.6 and 1.5. The approach maintains compatibility with forensic tools like Forensic Toolkit FTK and Autopsy. It performs effectively under attacks including JPEG compression (QF ≥ 60), filtering, and noise addition. The technique achieves high feature match ratios between 0.684 and 0.690 for a threshold of 0.70, with efficient processing times (embedding: 0.0347 s to 0.1187 s; extraction: 0.0077 s to 0.0366 s). This watermarking technique improves forensic investigation processes, particularly those that involve sensitive JPEG files. It supports leak source attribution, preserves evidence integrity, and provides traceability throughout forensic procedures. Full article
(This article belongs to the Special Issue Advances in Cyber-Security and Machine Learning)
Show Figures

Figure 1

15 pages, 783 KB  
Article
On Microservice-Based Architecture for Digital Forensics Applications: A Competition Policy Perspective
by Fragkiskos Ninos, Konstantinos Karalas, Dimitrios Dechouniotis and Michael Polemis
Future Internet 2025, 17(4), 137; https://doi.org/10.3390/fi17040137 - 23 Mar 2025
Cited by 1 | Viewed by 1830
Abstract
Digital forensics systems are complex applications consisting of numerous individual components that demand substantial computing resources. By adopting the concept of microservices, forensics applications can be divided into smaller, independently managed services. In this context, cloud resource orchestration platforms like Kubernetes provide augmented [...] Read more.
Digital forensics systems are complex applications consisting of numerous individual components that demand substantial computing resources. By adopting the concept of microservices, forensics applications can be divided into smaller, independently managed services. In this context, cloud resource orchestration platforms like Kubernetes provide augmented functionalities, such as resource scaling, load balancing, and monitoring, supporting every stage of the application’s lifecycle. This article explores the deployment of digital forensics applications over a microservice-based architecture. Leveraging resource scaling and persistent storage mechanisms, we introduce a vertical scaling mechanism for compute-intensive forensics applications. A practical evaluation of digital forensics applications in competition investigations was performed using datasets from the private cloud of the Hellenic Competition Commission. The numerical results illustrate that the processing time of CPU-intensive tasks is reduced significantly using dynamic resource scaling, while data integrity and security requirements are fulfilled. Full article
Show Figures

Figure 1

30 pages, 5036 KB  
Article
Chaotic Hénon–Logistic Map Integration: A Powerful Approach for Safeguarding Digital Images
by Abeer Al-Hyari, Mua’ad Abu-Faraj, Charlie Obimbo and Moutaz Alazab
J. Cybersecur. Priv. 2025, 5(1), 8; https://doi.org/10.3390/jcp5010008 - 18 Feb 2025
Cited by 15 | Viewed by 5409
Abstract
This paper presents an integrated chaos-based algorithm for image encryption that combines the chaotic Hénon map and chaotic logistic map (CLM) to enhance the security of digital image communication. The proposed method leverages chaos theory to generate cryptographic keys, utilizing a 1D key [...] Read more.
This paper presents an integrated chaos-based algorithm for image encryption that combines the chaotic Hénon map and chaotic logistic map (CLM) to enhance the security of digital image communication. The proposed method leverages chaos theory to generate cryptographic keys, utilizing a 1D key from the logistic map generator and a 2D key from the chaotic Hénon map generator. These chaotic maps produce highly unpredictable and complex keys essential for robust encryption. Extensive experiments demonstrate the algorithm’s resilience against various attacks, including chosen-plaintext, noise, clipping, occlusion, and known-plaintext attacks. Performance evaluation in terms of encryption time, throughput, and image quality metrics validates the effectiveness of the proposed integrated approach. The results indicate that the chaotic Hénon–logistic map integration provides a powerful and secure method for safeguarding digital images during transmission and storage with a key space that reaches up to 2200. Moreover, the algorithm has potential applications in secure image sharing, cloud storage, and digital forensics, inspiring new possibilities. Full article
(This article belongs to the Special Issue Cybersecurity in the Age of AI and IoT: Challenges and Innovations)
Show Figures

Figure 1

24 pages, 4357 KB  
Article
Investigation of Smart Machines with DNAs in SpiderNet
by Mo Adda and Nancy Scheidt
Future Internet 2025, 17(2), 92; https://doi.org/10.3390/fi17020092 - 17 Feb 2025
Cited by 3 | Viewed by 2292
Abstract
The advancement of Internet of Things (IoT), robots, drones, and vehicles signifies ongoing progress, accompanied by increasing complexities and challenges in forensic investigations. Globally, investigators encounter obstacles when extracting evidence from these vast landscapes, which include diverse devices, networks, and cloud environments. Of [...] Read more.
The advancement of Internet of Things (IoT), robots, drones, and vehicles signifies ongoing progress, accompanied by increasing complexities and challenges in forensic investigations. Globally, investigators encounter obstacles when extracting evidence from these vast landscapes, which include diverse devices, networks, and cloud environments. Of particular concern is the process of evidence collection, especially regarding fingerprints and facial recognition within the realm of vehicle forensics. Moreover, ensuring the integrity of forensic evidence is a critical issue, as it is vulnerable to attacks targeting data centres and server farms. Mitigating these challenges, along with addressing evidence mobility, presents additional complexities. This paper introduces a groundbreaking infrastructure known as SpiderNet, which is based on cloud computing principles. We will illustrate how this architecture facilitates the identification of devices, secures the integrity of evidence both at its source and during transit, and enables investigations into individuals involved in criminal activities. Through case studies, we will demonstrate the potential of SpiderNet to assist law enforcement agencies in addressing crimes perpetrated within IoT environments. Full article
(This article belongs to the Special Issue Security and Privacy Issues in the Internet of Cloud)
Show Figures

Graphical abstract

27 pages, 1840 KB  
Article
Retrieving and Identifying Remnants of Artefacts on Local Devices Using Sync.com Cloud
by Abdulghani Ali Ahmed, Khalid Farhan, Mohd Izuan Hafez Ninggal and Ghadir Alselwi
Sensors 2025, 25(1), 106; https://doi.org/10.3390/s25010106 - 27 Dec 2024
Viewed by 4632
Abstract
Most current research in cloud forensics is focused on tackling the challenges encountered by forensic investigators in identifying and recovering artifacts from cloud devices. These challenges arise from the diverse array of cloud service providers as each has its distinct rules, guidelines, and [...] Read more.
Most current research in cloud forensics is focused on tackling the challenges encountered by forensic investigators in identifying and recovering artifacts from cloud devices. These challenges arise from the diverse array of cloud service providers as each has its distinct rules, guidelines, and requirements. This research proposes an investigation technique for identifying and locating data remnants in two main stages: artefact collection and evidence identification. In the artefacts collection stage, the proposed technique determines the location of the artefacts in cloud storage and collects them for further investigation in the next stage. In the evidence identification stage, the collected artefacts are investigated to identify the evidence relevant to the cybercrime currently being investigated. These two stages perform an integrated process for mitigating the difficulty of locating the artefacts and reducing the time of identifying the relevant evidence. The proposed technique is implemented and tested by applying a forensics investigation algorithm on Sync.com cloud storage using the Microsoft Windows 10 operating system. Full article
(This article belongs to the Section Sensor Networks)
Show Figures

Figure 1

Back to TopTop