A novel ontology for cyber-attack attribution and investigation
The rise in cyber-attacks has intensified the challenges faced by digital forensics and security analysts, who must investigate complex incidents quickly while handling large volumes of heterogeneous evidence. Current tools lack standardisation, resulting in incomplete representations and poor interoperability. Ontologies address this by providing structured vocabularies that ensure consistency, enable integration, and support structured and AI-assisted reasoning. In this paper, we introduce OCAI, a novel ontology for cyber-attack attribution and investigation. Built on the widely adopted STIX 2.1 standard, OCAI extends it with investigation- and attribution-specific knowledge. We add new objects, relationships, and axioms that deliver richer, more consistent, and extensible knowledge representation useful for the investigation and attribution process. Through empirical evaluation on real-world cyber-attacks, we refined OCAI to address critical gaps and ensure broader representational coverage. Comparative analysis shows that OCAI provides a broader and more comprehensive representation of cyber-attack investigation and attribution than existing ontologies. Moreover, its integration into a reasoning-based attribution tool demonstrates improvements in knowledge representation and reasoning capabilities. Our novel ontology establishes a robust foundation for advancing cyber-attack investigations and attribution. • The paper introduces OCAI, the first ontology for cyber-attack investigation and attribution. • OCAI extends STIX 2.1 with investigation and attribution knowledge. • The paper enhances ontology expressiveness through real-world cyber-attack case studies. • Demonstrates applicability through integration into a reasoning-based attribution tool.
- Research Article
6
- 10.3390/jcp2020020
- May 31, 2022
- Journal of Cybersecurity and Privacy
Security analysts working in the modern threat landscape face excessive events and alerts, a high volume of false-positive alerts, significant time constraints, innovative adversaries, and a staggering volume of unstructured data. Organizations thus risk data breach, loss of valuable human resources, reputational damage, and impact to revenue when excessive security alert volume and a lack of fidelity degrade detection services. This study examined tactics to reduce security data fatigue, increase detection accuracy, and enhance security analysts’ experience using security alert output generated via data science and machine learning models. The research determined if security analysts utilizing this security alert data perceive a statistically significant difference in usability between security alert output that is visualized versus that which is text-based. Security analysts benefit two-fold: the efficiency of results derived at scale via ML models, with the additional benefit of quality alert results derived from these same models. This quantitative, quasi-experimental, explanatory study conveys survey research performed to understand security analysts’ perceptions via the Technology Acceptance Model. The population studied was security analysts working in a defender capacity, analyzing security monitoring data and alerts. The more specific sample was security analysts and managers in Security Operation Center (SOC), Digital Forensic and Incident Response (DFIR), Detection and Response Team (DART), and Threat Intelligence (TI) roles. Data analysis indicated a significant difference in security analysts’ perception of usability in favor of visualized alert output over text alert output. The study’s results showed how organizations can more effectively combat external threats by emphasizing visual rather than textual alerts.
- Conference Article
3
- 10.1109/compsac54236.2022.00025
- Jun 1, 2022
This paper presents a systematic approach to designing a series of digital forensics instructional materials to address the severe shortage of active learning materials in the digital forensics community. The materials include real-world scenario-based case studies, a set of hands-on problem-driven labs for each case study, and an integrated forensic investigation environment. In this paper, we first clarify some fundamental concepts related to digital forensics, such as digital forensic artifacts, artifact generators, and evidence. We then re-categorize knowledge units of digital forensics based on the artifact generators for measuring the coverage of learning outcomes and topics. Finally, we utilize a real-world cybercrime scenario to demonstrate how knowledge units, digital forensics topics, concepts, artifacts, and investigation tools can be infused into each lab through active learning. The repository of the instructional materials is publicly available on GitHub. It has gained nearly 600 stars and 22k views within several months.
- Conference Article
35
- 10.1109/isdfs52919.2021.9486354
- Jun 28, 2021
Over the years, there is an increase in the use of Artificial Intelligence (AI) by digital forensics and cybersecurity professionals to combat cybercrime. Natural Language Processing (NLP) and AI applications for digital forensics and cybersecurity include data mining, knowledge representation, pattern recognition, and expert systems. This research paper focuses on a literature review of NLP-based systems in digital forensics and cybersecurity: role, applications, challenges, and future directions. This article serves as a guide for researchers and practitioners on the current state of cybersecurity and digital forensics and as well provides a roadmap for the future.
- Research Article
2
- 10.22624/aims/cisdi/v15n1p1x
- Mar 31, 2024
- Advances in Multidisciplinary and scientific Research Journal Publication
The use of digital forensic tools and techniques has continued to evolve as the security community makes efforts to stay ahead and mitigate cyber crimes. These tools and techniques are assisting cybersecurity experts and law enforcement in identifying fraudsters and protecting data by utilizing techniques such as digital traces left by data processing and storage. This paper identifies the peculiarities of digital forensics as a field of study, explores trends, challenges and opportunities presented by digital forensic tools in investigating cyber crimes. We carried out a systematic literature review of applicable tools and techniques. Our research identified challenges affecting the use of digital forensics in investigating cybercrime, and capture comprehensively the pulse of the domain. Recommendations were made that digital forensics lack a unified formal representation of standardized procedures and knowledge for analyzing and gathering digital artifacts. This inevitably causes incompatibility and conflict within various digital forensics tools. This leads to errors in the interpretation and analysis of digital artifacts due to lack of standardized or formalized procedure for analyzing, preserving, and collecting digital evidence is absent. Keywords: Cybercrimes, Police, Cyber Security, Challenges, Techniques CISDI Journal Reference Format Adams Terrence Addey (2024): Trends, Challenges and Opportunities of Engaging Digital Forensics for Cybercrime Investigations – A Review. Computing, Information Systems, Development Informatics & Allied Research Journal. Vol 15 No 1, Pp 1-.8. dx.doi.org/10.22624/AIMS/CISDI/V15N1P1x. Available online at www.isteams.net/cisdijournal
- Research Article
3
- 10.1108/ijwis-03-2021-0031
- Sep 6, 2021
- International Journal of Web Information Systems
PurposeKnowledge- and communication-intensive domains still long for a better support of creativity that considers legal requirements, compliance rules and administrative tasks as well, because current systems focus either on knowledge representation or business process management. The purpose of this paper is to discuss our model of integrated knowledge and business process representation and its presentation to users.Design/methodology/approachThe authors follow a design science approach in the environment of patent prosecution, which is characterized by a highly standardized, legally prescribed process and individual knowledge study. Thus, the research is based on knowledge study, BPM, graph-based knowledge representation and user interface design. The authors iteratively designed and built a model and a prototype. To evaluate the approach, the authors used analytical proof of concept, real-world test scenarios and case studies in real-world settings, where the authors conducted observations and open interviews.FindingsThe authors designed a model and implemented a prototype for evolving and storing static and dynamic aspects of knowledge. The proposed solution leverages the flexibility of a graph-based model to enable open and not only continuously developing user-centered processes but also pre-defined ones. The authors further propose a user interface concept which supports users to benefit from the richness of the model but provides sufficient guidance.Originality/valueThe balanced integration of the data and task perspectives distinguishes the model significantly from other approaches such as BPM or knowledge graphs. The authors further provide a sophisticated user interface design, which allows the users to effectively and efficiently use the graph-based knowledge representation in their daily study.
- Research Article
1
- 10.22624/aims/cisdi/v15n1p1
- Mar 8, 2024
- Advances in Multidisciplinary & Scientific Research Journal Publication
The use of digital forensic tools and techniques has continued to evolve as the security community makes efforts to stay ahead and mitigate cyber crimes. These tools and techniques are assisting cybersecurity experts and law enforcement in identifying fraudsters and protecting data by utilizing techniques such as digital traces left by data processing and storage. This paper identifies the peculiarities of digital forensics as a field of study, explores trends, challenges and opportunities presented by digital forensic tools in investigating cyber crimes. We carried out a systematic literature review of applicable tools and techniques. Our research identified challenges affecting the use of digital forensics in investigating cybercrime, and capture comprehensively the pulse of the domain. Recommendations were made that digital forensics lack a unified formal representation of standardized procedures and knowledge for analyzing and gathering digital artifacts. This inevitably causes incompatibility and conflict within various digital forensics tools. This leads to errors in the interpretation and analysis of digital artifacts due to lack of standardized or formalized procedure for analyzing, preserving, and collecting digital evidence is absent. Keywords: Cybercrimes, Police, Cyber Security, Challenges, Techniques
- Research Article
2
- 10.32628/cseit251451
- Feb 5, 2025
- International Journal of Scientific Research in Computer Science, Engineering and Information Technology
Digital forensics is a rapidly evolving field that plays a critical role in investigating cybercrime, data breaches, and illicit activities across various domains, including blockchain, cryptocurrency, and the dark web. This paper explores key areas of digital forensics, including computer forensics, mobile forensics, network forensics, cloud forensics, IoT forensics, and embedded system forensics. Emerging trends such as drone and satellite forensics highlight the increasing scope of forensic investigations beyond traditional computing environments. Additionally, the study delves into blockchain forensics, which focuses on tracing cryptocurrency transactions to combat money laundering, ransomware payments, and illicit trading on the dark web. Advanced tools such as Chainalysis, Maltego, and SpiderFoot are employed in forensic methodologies to track digital evidence effectively. The paper also addresses challenges such as encryption, data volatility, jurisdictional barriers, and anti-forensics techniques used by cybercriminals. Legal and compliance issues, including GDPR, HIPAA, and ISO 27037, are also discussed in the context of admissibility and cross-border investigations. By analyzing real-world case studies—including the Silk Road takedown, Sony Pictures hack, and AlphaBay shutdown—this paper provides insight into the role of forensic experts in digital investigations. With advancements in artificial intelligence and machine learning, digital forensics continues to evolve, offering law enforcement and cybersecurity professionals new techniques to trace digital footprints and counter cyber threats effectively.
- Research Article
21
- 10.34028/iajit/20/4/11
- Jan 1, 2023
- The International Arab Journal of Information Technology
The research work presented in this paper aims to review Digital Forensics (DF) techniques and trends. As computer technology advances day by day, the chances of data being misused and tampered with are also growing daily. The advancement in technology results in various cyber-attacks on computers and mobile devices. DF plays a vital role in the investigation and prevention of cyber-attacks. DF can be used to find the shreds of evidence and prevent attacks from happening in the future. Earlier presented reviews highlighted specific issues in DF only. This paper explores deeply DF issues by highlighting domain-specific issues and possible helpful areas for DF. This article highlights the investigation process framework and related approaches for the digital investigation process. The cognitive and human factors that affect the DF process are also presented to strengthen the investigation process. Nowadays, many DF tools are available in the industry that helps in DF investigation. A comparative analysis of the four DF tools is also presented. Finally DF performance is discussed. The submitted work may help the researchers go deeper into DF and apply the best tools and models according to their requirements
- Research Article
- 10.55041/ijsrem59232
- Apr 5, 2026
- INTERNATIONAL JOURNAL OF SCIENTIFIC RESEARCH IN ENGINEERING AND MANAGEMENT
Purpose: With the widespread adoption of AI-based content generation tools, the boundaries between authentic and synthetic media have blurred considerably. Fabricated video and image content — commonly referred to as deepfakes — now represent a tangible threat to individual privacy, electoral integrity, and institutional trust. This study addresses that challenge by proposing a detection framework capable of identifying forged visual media with high precision. Design/Methodology: A hybrid architecture is developed that unites the spatial discriminative power of Convolutional Neural Networks (CNNs) with the sequential reasoning capability of Long Short-Term Memory (LSTM) units. The CNN backbone — instantiated as a fine-tuned ResNeXt model — extracts rich frame-level feature representations, while the LSTM layer models temporal patterns across video frames. Findings: On the FaceForensics++ benchmark, the integrated architecture attains an overall detection accuracy of approximately 94%, surpassing both standalone CNN and standalone LSTM baselines by a clear margin. Explainability mechanisms are additionally incorporated to make predictions interpretable for end users and security analysts. Practical Implications: The system is designed for deployment in cybersecurity platforms, digital forensics workflows, and social media content moderation pipelines. Its modular design supports both cloud hosting and edge inference, making it suitable for diverse real-world environments. Keywords: Synthetic Media Detection, Deepfake Identification, Hybrid CNN-LSTM, Transfer Learning with ResNeXt, Temporal Forgery Analysis, Digital Forensics, Explainable Artificial Intelligence, Cybersecurity.
- Research Article
- 10.1504/ijesdf.2020.10028501
- Jan 1, 2020
- International Journal of Electronic Security and Digital Forensics
The android market has gained lot of popularity in the past recent years. The operating system stack is open source, many security analysts and hacker's has the platform to perform research on digital forensics and further enhance their exploiting in finding weakness and modifying the software attack. Our goal in this paper is to perform reversing android malicious applications henceforth audit the vulnerabilities. We reverse using the tools like apktool, dex2jar and jd-gui. Static and dynamic analysis is done with the help of sandboxing environment achieving the goal of reverse engineering. We monitor the activities, services, broadcast receiver's, shared preferences, intents and content providers. Many vulnerable apps uses content provider leakage to store and query data within the phone helpful in auditing purpose. Mobile forensics is about acquisition of information about app installed in platform. In the paper, we perform attack surface and analysis malicious features inside application by exporting its features.
- Research Article
20
- 10.1016/j.jvcir.2018.04.002
- Apr 13, 2018
- Journal of Visual Communication and Image Representation
Connecting the dots: Toward accountable machine-learning printer attribution methods
- Conference Article
- 10.1145/3711896.3737600
- Aug 3, 2025
In an era where justice and accountability increasingly depend on digital evidence, Large Language Models (LLMs) offer transformative potential for digital forensics. This three-hour Hands-on tutorial explores how LLMs can automate investigations, reveal hidden insights, and enhance evidence analysis. Through real-world case studies, interactive exercises, and hands-on labs, participants will learn to leverage LLMs for tasks such as entity identification, evidence processing, and knowledge graph reconstruction. Designed for professionals, researchers, and students, this collaborative learning experience equips attendees with practical skills to innovate in digital forensics. As LLMs reshape the field, this tutorial underscores their role in improving justice outcomes, strengthening accountability, and advancing the future of digital investigations.
- Book Chapter
5
- 10.4018/979-8-3373-0857-9.ch002
- Dec 30, 2024
The increasing reliance on Artificial Intelligence (AI) in digital forensic investigations has brought forward significant advancements in the identification, analysis, and interpretation of digital evidence. However, one of the major challenges remains the “black-box” nature of many AI models, which often hinder trust, accountability, and transparency. Explainable AI (XAI) emerges as a critical solution, providing clarity into the decision-making processes of AI systems. In the context of digital forensics, XAI facilitates investigators' understanding of AI-driven tools, ensuring that conclusions drawn from automated analyses are interpretable, verifiable, and legally admissible. This chapter explores the role of XAI in digital forensics, highlighting its potential to enhance the reliability and transparency of AI-based forensic systems, while addressing key challenges and ethical considerations. We examine the integration of XAI in forensic workflows, discuss various techniques for explainability, and evaluate real-world case studies where XAI has contributed to improved forensic outcomes.
- Research Article
10
- 10.2478/jdis-2020-0002
- Feb 1, 2020
- Journal of Data and Information Science
Purpose This paper compares the paradigmatic differences between knowledge organization (KO) in library and information science and knowledge representation (KR) in AI to show the convergence in KO and KR methods and applications. Methodology The literature review and comparative analysis of KO and KR paradigms is the primary method used in this paper. Findings A key difference between KO and KR lays in the purpose of KO is to organize knowledge into certain structure for standardizing and/or normalizing the vocabulary of concepts and relations, while KR is problem-solving oriented. Differences between KO and KR are discussed based on the goal, methods, and functions. Research limitations This is only a preliminary research with a case study as proof of concept. Practical implications The paper articulates on the opportunities in applying KR and other AI methods and techniques to enhance the functions of KO. Originality/value: Ontologies and linked data as the evidence of the convergence of KO and KR paradigms provide theoretical and methodological support to innovate KO in the AI era.
- Research Article
- 10.1016/j.atech.2026.101977
- Aug 1, 2026
- Smart Agricultural Technology
• Systematic review of livestock health ontologies for disease surveillance. • PRISMA 2020 and AI-assisted screening ensure transparent literature selection. • Comparison of active vs. inactive ontologies reveals access and usability barriers. • Gaps identified in active ontologies coverage of major contagious respiratory diseases in terrestrial and aquatic livestock species. • Recommendations for improving interoperability and PLF-ready surveillance systems. Livestock farming faces persistent challenges in animal health management, particularly in the surveillance and management of infectious diseases in terrestrial and aquatic species. These diseases affect productivity, economic sustainability, and food security. While smart agriculture and precision livestock farming (PLF) generate large volumes of animal health data, issues such as data fragmentation, poor interoperability, security concerns, and low farmer adoption limit their use. Ontologies as explicit representations of domain knowledge offer a promising way to standardize and integrate heterogeneous data. However, existing literature lacks a comprehensive analysis of their applicability and limitations in livestock disease surveillance. This examines data integration challenges, the role of ontologies, and their limitations in covering livestock diseases. A systematic literature review was conducted following PRISMA 2020 guidelines and supported by a machine learning–based screening tool (ASReview) to ensure transparency, reproducibility, and efficiency in identifying relevant literature. Ontology-based and non-ontology-based approaches were reviewed, with ontologies categorized as active or inactive and assessed for scope, availability, species coverage, and terminological depth. A total of 286 records were screened, of which 100 were included in the final review. Among 32 identified ontologies, 15 remain active while 17 are inactive or no longer publicly accessible, reducing practical use. Active ones often lack full disease coverage across species. Common challenges include system complexity, maintenance, low adoption, and limited domain representation. The review also discusses initiatives such as DECIDE, which illustrate how ontology-driven surveillance can be strengthened through open access, training, and collaborative tools. These findings highlight the urgent need to improve interoperability and develop ontology-driven surveillance systems for livestock.