The Use of Artificial Intelligence in Digital Forensics and Incident Response in a Constrained Environment
Authors: Dipo Dunsin, Mohamed C. Ghanem, Karim Ouazzane
Abstract:
Digital investigators often have a hard time spotting evidence in digital information. It has become hard to determine which source of proof relates to a specific investigation. A growing concern is that the various processes, technology, and specific procedures used in the digital investigation are not keeping up with criminal developments. Therefore, criminals are taking advantage of these weaknesses to commit further crimes. In digital forensics investigations, artificial intelligence (AI) is invaluable in identifying crime. Providing objective data and conducting an assessment is the goal of digital forensics and digital investigation, which will assist in developing a plausible theory that can be presented as evidence in court. This research paper aims at developing a multiagent framework for digital investigations using specific intelligent software agents (ISAs). The agents communicate to address particular tasks jointly and keep the same objectives in mind during each task. The rules and knowledge contained within each agent are dependent on the investigation type. A criminal investigation is classified quickly and efficiently using the case-based reasoning (CBR) technique. The proposed framework development is implemented using the Java Agent Development Framework, Eclipse, Postgres repository, and a rule engine for agent reasoning. The proposed framework was tested using the Lone Wolf image files and datasets. Experiments were conducted using various sets of ISAs and VMs. There was a significant reduction in the time taken for the Hash Set Agent to execute. As a result of loading the agents, 5% of the time was lost, as the File Path Agent prescribed deleting 1,510, while the Timeline Agent found multiple executable files. In comparison, the integrity check carried out on the Lone Wolf image file using a digital forensic tool kit took approximately 48 minutes (2,880 ms), whereas the MADIK framework accomplished this in 16 minutes (960 ms). The framework is integrated with Python, allowing for further integration of other digital forensic tools, such as AccessData Forensic Toolkit (FTK), Wireshark, Volatility, and Scapy.
Keywords: Artificial intelligence, computer science, criminal investigation, digital forensics.
Procedia APA BibTeX Chicago EndNote Harvard JSON MLA RIS XML ISO 690 PDF Downloads 1291References:
[1] Adams, R., 2013. The Emergence of Cloud Storage and the Need for a New Digital Forensic Process Model. Cybercrime and Cloud Forensics, pp.79-104.
[2] Agarwal, R. and Karahanna, E., 2000. Time Flies When You're Having Fun: Cognitive Absorption and Beliefs about Information Technology Usage. MIS Quarterly, 24(4), p.665
[3] Biggs, S. and Vidalis, S., 2009. Cloud Computing: The impact on digital forensic investigations. 2009 International Conference for Internet Technology and Secured Transactions, (ICITST),.
[4] Damshenas, M., Dehghantanha, A., Mahmoud, R. and bin Shamsuddin, S., 2012. Forensics investigation challenges in cloud computing environments. Proceedings Title: 2012 International Conference on Cyber Security, Cyber Warfare and Digital Forensic (CyberSec),.
[5] Grosz, B. and Stone, P., 2018. A century-long commitment to assessing artificial intelligence and its impact on society. Communications of the ACM, 61(12), pp.68-73.
[6] Hoelz, B., Ralha, C. and Geeverghese, R., 2009. Artificial intelligence applied to computer forensics. Proceedings of the 2009 ACM symposium on Applied Computing - SAC '09.
[7] Ieong, R., 2006. FORZA – Digital forensics investigation framework that incorporate legal issues. Digital Investigation, 3, pp.29-36.
[8] Iqbal, S. and Abed Alharbi, S., 2020. Advancing Automation in Digital Forensic Investigations Using Machine Learning Forensics. Digital Forensic Science.
[9] Kelly, L., Sachan, S., Ni, L., Almaghrabi, F., Allmendinger, R. and Chen, Y., 2020. Explainable Artificial Intelligence for Digital Forensics: Opportunities, Challenges and a Drug Testing Case Study. Digital Forensic Science.
[10] Kim, T., Hooker, J. and Donaldson, T., 2021. Taking Principles Seriously: A Hybrid Approach to Value Alignment in Artificial Intelligence. Journal of Artificial Intelligence Research, 70, pp.871-890.
[11] Mittal, U. and Sharma, D., 2021. Artificial Intelligence and its Application in Different Areas of Indian Economy. International Journal of Advanced Research in Science, Communication and Technology, pp.160-163.
[12] Yan, D., Zhou, Q., Wang, J. and Zhang, N., 2016. Bayesian regularisation neural network based on artificial intelligence optimisation. International Journal of Production Research, 55(8), pp.2266-2287.