# Publications

Canonical URL: https://markscanlon.co/publications/

CSL-JSON catalogue: https://markscanlon.co/publications/citations.json
Combined BibTeX: https://markscanlon.co/publications/all.bib
Combined RIS: https://markscanlon.co/publications/all.ris
Publication feed: https://markscanlon.co/publications/feed.xml

Peer-reviewed publications, theses, posters, presentations, and related research outputs.



## Objects as Universal Geolocation Cues: A Computer Vision Approach

Canonical URL: https://markscanlon.co/publications/ObjectsAsUniversalGeolocationCues
Authors: Kanwal Aftab; Mark Scanlon
Year: 2026
PDF: https://markscanlon.co/publications/ObjectsAsUniversalGeolocationCues.pdf
Summary: This paper proposes a computer vision approach to geolocation using universal visual cues, specifically electrical plug sockets, to narrow down the search space for law enforcement in combating crimes such as human trafficking and child exploitation.


## VAAS: Vision-Attention Anomaly Scoring for image manipulation detection in digital forensics

Canonical URL: https://markscanlon.co/publications/VisionAttentionAnomolyScoringImageManipulationDetection
Authors: Opeyemi Bamigbade; Mark Scanlon; John Sheppard
Year: 2026
DOI: https://doi.org/10.1016/j.fsidi.2026.302063
PDF: https://markscanlon.co/publications/VisionAttentionAnomolyScoringImageManipulationDetection.pdf
Summary: VAAS detects image manipulation using Vision Transformers and segmentation embeddings, providing a continuous anomaly score for digital forensics.


## Plug to place: Indoor multimedia geolocation from electrical sockets for digital investigation

Canonical URL: https://markscanlon.co/publications/PlugToPlace-IndoorMultimediaGeolocation
Authors: Kanwal Aftab; Graham Adams; Mark Scanlon
Year: 2026
DOI: https://doi.org/10.1016/j.fsidi.2026.302056
PDF: https://markscanlon.co/publications/PlugToPlace-IndoorMultimediaGeolocation.pdf
Summary: This paper introduces a pipeline for indoor multimedia geolocation using electrical sockets as consistent markers, aiding law enforcement in human trafficking investigations.


## Investigation of large language models, GenAI, and proprietary AI systems: Digital forensic evidence, readiness and regulation

Canonical URL: https://markscanlon.co/publications/Editorial-InvestigationofLargeLanguageModelsGenAIandProprietaryAISystems
Authors: Mark Scanlon
Year: 2026
DOI: https://doi.org/10.1016/j.fsidi.2026.302135
PDF: https://markscanlon.co/publications/Editorial-InvestigationofLargeLanguageModelsGenAIandProprietaryAISystems.pdf
Summary: This paper investigates digital forensic evidence and regulation of large language models and proprietary AI systems, highlighting the need for AI forensic readiness and examinability.


## AutoDFBench 1.0: A benchmarking framework for digital forensic tool testing and generated code evaluation

Canonical URL: https://markscanlon.co/publications/AutoDFBench1.0DigitalForensicToolTesting
Authors: Akila Wickramasekara; Tharusha Mihiranga; Aruna Withanage; Buddhima Weerasinghe; Frank Breitinger; John Sheppard; Mark Scanlon
Year: 2026
DOI: https://doi.org/10.1016/j.fsidi.2026.302055
PDF: https://markscanlon.co/publications/AutoDFBench1.0DigitalForensicToolTesting.pdf
Summary: AutoDFBench 1.0 is a benchmarking framework for digital forensic tool testing, evaluating conventional and AI-generated tools across five areas: string search, deleted file recovery, file carving, Windows registry recovery, and SQLite data recovery.


## Towards a standardized methodology and dataset for evaluating LLM-based digital forensic timeline analysis

Canonical URL: https://markscanlon.co/publications/LLM-based-Digital-Forensic-Timeline-Analysis
Authors: Hudan Studiawan; Frank Breitinger; Mark Scanlon
Year: 2025
DOI: https://doi.org/10.1016/j.fsidi.2025.301982
PDF: https://markscanlon.co/publications/LLM-based-Digital-Forensic-Timeline-Analysis.pdf
Summary: This paper proposes a standardized methodology for evaluating the performance of Large Language Models (LLMs) in digital forensic timeline analysis tasks, such as event summarization. The methodology includes a dataset, timeline generation, and ground truth development, and recommends the use of BLEU and ROUGE metrics for quantitative evaluation.


## An AI-Based Network Forensic Readiness Framework for Resource-Constrained Environments

Canonical URL: https://markscanlon.co/publications/NetworkForensicReadinessResourceContrainedEnvironments
Authors: Syed Rizvi; Mark Scanlon; Jimmy McGibney; John Sheppard
Year: 2025
DOI: https://doi.org/10.1007/978-3-032-00635-6_6
PDF: https://markscanlon.co/publications/NetworkForensicReadinessResourceContrainedEnvironments.pdf
Summary: This paper presents an AI-based network forensic readiness framework for resource-constrained environments. The framework integrates optimised artificial intelligence models to detect attacks in real-time, capturing and preserving critical forensic artefacts. It aligns with ISO/IEC 27043:2015 Digital Forensic Readiness principles, reducing time and human effort.


## Fine-Tuning Large Language Models for Digital Forensics: Case Study and General Recommendations

Canonical URL: https://markscanlon.co/publications/Fine-Tuning-Large-Language-Models-for-Digital-Forensics
Authors: Gaëtan Michelet; Hans Henseler; Harm van Beek; Mark Scanlon; Frank Breitinger
Year: 2025
DOI: https://doi.org/10.1145/3748264
PDF: https://markscanlon.co/publications/Fine-Tuning-Large-Language-Models-for-Digital-Forensics.pdf
Summary: This paper proposes recommendations for fine-tuning large language models (LLMs) for digital forensics tasks, addressing the gap in existing research. A case study on chat summarization showcases the applicability of the recommendations, evaluating multiple fine-tuned models to assess their performance. The study shares lessons learned from the case study, providing insights into the fine-tuning process, computational power issues, data challenges, and evaluation methods.


## Low-overhead and Non-invasive Electromagnetic Side-Channel Monitoring for Forensic-ready Industrial Control Systems

Canonical URL: https://markscanlon.co/publications/EM-SCAForensicReadinessICS
Authors: Buddhima Weerasinghe; Asanka Sayakkara; Kasun De Zoysa; Mark Scanlon
Year: 2025
DOI: https://doi.org/10.1145/3712716.3712722
PDF: https://markscanlon.co/publications/EM-SCAForensicReadinessICS.pdf
Summary: This paper proposes a low-overhead and non-invasive electromagnetic side-channel monitoring approach for forensic-ready industrial control systems. It uses unintentional electromagnetic radiation emitted by Ethernet network cables to detect denial of service attacks with considerable accuracy, introducing an architecture for ICS infrastructure to be forensic-ready with minimal computational resources.


## Improving Image Embeddings with Colour Features in Indoor Scene Geolocation

Canonical URL: https://markscanlon.co/publications/ImageEmbeddingsColourFeaturesIndoorGeolocation
Authors: Opeyemi Bamigbade; Mark Scanlon; John Sheppard
Year: 2025
DOI: https://doi.org/10.1109/ACCESS.2025.3564496
PDF: https://markscanlon.co/publications/ImageEmbeddingsColourFeaturesIndoorGeolocation.pdf
Summary: This paper proposes a model architecture that integrates image N-dominant colours and colour histogram vectors with image embedding from deep metric learning and classification perspectives to improve image geolocation in indoor scenes.


## AutoDFBench: A Framework for AI Generated Digital Forensic Code and Tool Testing and Evaluation

Canonical URL: https://markscanlon.co/publications/AutoDFBenchDigitalForensicCodeTesting
Authors: Akila Wickramasekara; Alanna Densmore; Frank Breitinger; Hudan Studiawan; Mark Scanlon
Year: 2025
DOI: https://doi.org/10.1145/3712716.3712718
PDF: https://markscanlon.co/publications/AutoDFBenchDigitalForensicCodeTesting.pdf
Summary: AutoDFBench is an automated framework for testing and evaluating AI-generated digital forensic code and tools. It validates AI-generated code against NIST''s Computer Forensics Tool Testing Program (CFTT) procedures and calculates a benchmarking score. The framework operates in four phases: data preparation, API handling, code execution, and result recording with score calculation.


## Exploring the Potential of Large Language Models for Improving Digital Forensic Investigation Efficiency

Canonical URL: https://markscanlon.co/publications/Survey-Large-Language-Models-Digital-Forensics
Authors: Akila Wickramasekara; Frank Breitinger; Mark Scanlon
Year: 2025
DOI: https://doi.org/10.1016/j.fsidi.2024.301859
PDF: https://markscanlon.co/publications/Survey-Large-Language-Models-Digital-Forensics.pdf
Summary: This study explores the potential of Large Language Models (LLMs) in improving digital forensic investigation efficiency, addressing challenges such as bias, explainability, censorship, and resource-intensive infrastructure. A comprehensive literature review highlights the current challenges in digital forensics and the possibilities of incorporating LLMs, with a focus on established models, methods, and key challenges.


## Pushing Network Forensic Readiness to the Edge: A Resource Constrained Artificial Intelligence Based Methodology

Canonical URL: https://markscanlon.co/publications/PushingNetworkForensicReadinessToTheEdge
Authors: Syed Rizvi; Mark Scanlon; Jimmy McGibney; John Sheppard
Year: 2024
DOI: https://doi.org/10.1109/Cyber-RCI60769.2024.10939120
PDF: https://markscanlon.co/publications/PushingNetworkForensicReadinessToTheEdge.pdf
Summary: This paper introduces the Network Forensic Readiness for Edge Devices (NetFoREdge) framework, which deploys lightweight AI models in resource-constrained environments for attack detection, evidence collection, and preservation. The framework is evaluated on two datasets, achieving accuracy rates exceeding 99.60% and 99.98% for multiclassification.


## Perceptual Colour-based Geolocation of Human Trafficking Images for Digital Forensic Investigation

Canonical URL: https://markscanlon.co/publications/PerceptualColour-BasedImageGeolocation
Authors: Jessica Herrmann; Opeyemi Bamigbade; John Sheppard; Mark Scanlon
Year: 2024
DOI: https://doi.org/10.1109/Cyber-RCI60769.2024.10941203
PDF: https://markscanlon.co/publications/PerceptualColour-BasedImageGeolocation.pdf
Summary: This study investigates the effectiveness of colour-based descriptors in Content-Based Image Retrieval (CBIR) for human trafficking image analysis. The research evaluates the impact of various parameters on image matching accuracy, achieving a Top-50 accuracy of over 95% on the Hotels-50K dataset. The approach demonstrates potential in advancing image analysis tools for human trafficking investigations and other contexts.


## Context Based Password Cracking Dictionary Expansion Using Generative Pre-trained Transformers

Canonical URL: https://markscanlon.co/publications/ContextPasswordCrackingUsingGPTs
Authors: Greta Imhof; Aikaterini Kanta; Mark Scanlon
Year: 2024
DOI: https://doi.org/10.1109/Cyber-RCI60769.2024.10939663
PDF: https://markscanlon.co/publications/ContextPasswordCrackingUsingGPTs.pdf
Summary: This paper explores the effectiveness of combining a strategic contextual approach with large language models in password cracking. The authors create context-based password dictionaries through training PassGPT models with contextual information, demonstrating improved password cracking efficiency and accuracy.


## A Comprehensive Evaluation on the Benefits of Context Based Password Cracking for Digital Forensics

Canonical URL: https://markscanlon.co/publications/BenefitsOfContextBasedPasswordCracking
Authors: Aikaterini Kanta; Iwen Coisel; Mark Scanlon
Year: 2024
DOI: https://doi.org/10.1016/j.jisa.2024.103809
PDF: https://markscanlon.co/publications/BenefitsOfContextBasedPasswordCracking.pdf
Summary: This paper evaluates the benefits of context-based password cracking for digital forensics, demonstrating that targeted approaches can increase the likelihood of success when contextual information is available. The study presents an experimental methodology and results section analyzing the approach's performance across ten datasets, proving the impact of context in password cracking.


## Revealing IoT Cryptographic Settings through Electromagnetic Side-Channel Analysis

Canonical URL: https://markscanlon.co/publications/IoTCryptoEM-SCA
Authors: Muhammad Rusyaidi Zunaidi; Asanka Sayakkara; Mark Scanlon
Year: 2024
DOI: https://doi.org/10.3390/electronics13081579
PDF: https://markscanlon.co/publications/IoTCryptoEM-SCA.pdf
Summary: This study explores the application of Electromagnetic Side-Channel Analysis (EM-SCA) for non-invasively detecting cryptographic settings in IoT devices. The researchers used a machine learning-based approach to identify key lengths and algorithms employed in IoT devices, demonstrating a notable accuracy of 94.55% in distinguishing between AES and ECC operations. This method has significant implications for digital forensic investigations, offering a novel approach for uncovering encrypted data's cryptographic settings.


## A Framework for Integrated Digital Forensic Investigation Employing AutoGen AI Agents

Canonical URL: https://markscanlon.co/publications/DigitalForensicsAutoGenAI
Authors: Akila Wickramasekara; Mark Scanlon
Year: 2024
DOI: https://doi.org/10.1109/ISDFS60797.2024.10527235
PDF: https://markscanlon.co/publications/DigitalForensicsAutoGenAI.pdf
Summary: This paper proposes an integrated framework for digital forensic investigations employing AutoGen AI agents and Large Language Models (LLMs) to alleviate investigative workload and shorten the learning curve for investigators. The framework utilizes AI agents and LLMs to perform tasks articulated in natural language by a human agent, addressing the challenges of evolving requirements and information accuracy.


## A Digital Forensic Methodology for Encryption Key Recovery from Black-Box IoT Devices

Canonical URL: https://markscanlon.co/publications/BlackBoxIoTEncryptionKeyRecovery
Authors: Muhammad Rusyaidi Zunaidi; Asanka Sayakkara; Mark Scanlon
Year: 2024
DOI: https://doi.org/10.1109/ISDFS60797.2024.10527284
PDF: https://markscanlon.co/publications/BlackBoxIoTEncryptionKeyRecovery.pdf
Summary: This paper presents a novel digital forensic methodology for recovering encryption keys from black-box IoT devices using electromagnetic side-channel analysis (EM-SCA). The approach leverages machine learning techniques to enhance the digital forensic process, reducing key space and mitigating investigative roadblocks. This automated, adaptable system preserves forensic evidence integrity and ensures wide applicability in the evolving IoT landscape.


## Ensuring Cross-Device Portability of Electromagnetic Side-Channel Analysis for Digital Forensics

Canonical URL: https://markscanlon.co/publications/CrossDevicePortabilityEMSCA
Authors: Lojenaa Navanesan; Nhien-An Le-Khac; Mark Scanlon; Kasun De Zoysa; Asanka P. Sayakkara
Year: 2024
DOI: https://doi.org/10.1016/j.fsidi.2023.301684
PDF: https://markscanlon.co/publications/CrossDevicePortabilityEMSCA.pdf
Summary: This study investigates the cross-device portability of Electromagnetic Side-Channel Analysis (EM-SCA) for digital forensics, exploring its applicability to various smart devices. The authors experiment with different devices, including iPhones and Nordic Semiconductor nRF52-DK, and demonstrate the effectiveness of transfer learning techniques in achieving high accuracy.


## DFRWS EU 10-Year Review and Future Directions in Digital Forensic Research

Canonical URL: https://markscanlon.co/publications/10YearReviewAndFutureDirectionsDigitalForensic
Authors: Frank Breitinger; Jan-Niclas Hilgert; Christopher Hargreaves; John Sheppard; Rebekah Overdorf; Mark Scanlon
Year: 2024
DOI: https://doi.org/10.1016/j.fsidi.2023.301685
PDF: https://markscanlon.co/publications/10YearReviewAndFutureDirectionsDigitalForensic.pdf
Summary: This study surveys 135 peer-reviewed articles published at the Digital Forensics Research Conference Europe (DFRWS EU) from 2014 to 2023, analyzing co-authorships, geographical spread, and citation metrics to inform future research directions in digital forensic research.


## DFPulse: The 2024 digital forensic practitioner survey

Canonical URL: https://markscanlon.co/publications/DFPulse2024DigitalForensicPractitionerSurvey
Authors: Christopher Hargreaves; Frank Breitinger; Liz Dowthwaite; Helena Webb; Mark Scanlon
Year: 2024
DOI: https://doi.org/10.1016/j.fsidi.2024.301844
PDF: https://markscanlon.co/publications/DFPulse2024DigitalForensicPractitionerSurvey.pdf
Summary: This paper presents the results of the largest digital forensic practitioner survey to date, DFPulse, conducted in 2024. The survey collected data from 122 practitioners worldwide, providing insights into their operating environments, technologies used, challenges faced, and future research directions. The study aims to improve collaboration between academia and practitioners, addressing the gap between research and practice in digital forensics.


## An Evaluation of AI-Based Network Intrusion Detection in Resource-Constrained Environments

Canonical URL: https://markscanlon.co/publications/AIIntrusionDetectionResourceConstrained
Authors: Syed Rizvi; Mark Scanlon; Jimmy McGibney; John Sheppard
Year: 2023
DOI: https://doi.org/10.1109/UEMCON59035.2023.10315971
PDF: https://markscanlon.co/publications/AIIntrusionDetectionResourceConstrained.pdf
Summary: This paper evaluates AI-based network intrusion detection in resource-constrained environments, proposing a novel approach that trains and deploys AI models on resource-constrained devices. The approach achieves high classification accuracy, identifying and recording potential malicious attacks in real-time with minimal overhead.


## Context-Based Password Cracking for Digital Investigation

Canonical URL: https://markscanlon.co/publications/PhDThesis-ContextBasedPasswordCrackingForDigitalInvestigation
Authors: Aikaterini Kanta
Year: 2023
PDF: https://markscanlon.co/publications/PhDThesis-ContextBasedPasswordCrackingForDigitalInvestigation.pdf
Summary: This thesis presents a context-based password cracking approach for digital investigation, introducing a methodology and framework for creating and assessing custom dictionary wordlists for dictionary-based password cracking attacks. The approach leverages contextual information to generate bespoke password candidate lists, achieving significant improvements over traditional approaches, with over 50% improvement in some instances.


## Harder, Better, Faster, Stronger: Optimising the Performance of Context-Based Password Cracking Dictionaries

Canonical URL: https://markscanlon.co/publications/OptimisingPasswordCrackingDictionaries
Authors: Aikaterini Kanta; Iwen Coisel; Mark Scanlon
Year: 2023
DOI: https://doi.org/10.1016/j.fsidi.2023.301507
PDF: https://markscanlon.co/publications/OptimisingPasswordCrackingDictionaries.pdf
Summary: This paper presents a methodology for optimising and ranking contextual wordlists for password cracking, tailored to the suspect in a digital forensic investigation. The approach is evaluated with data leaks from compromised online communities, demonstrating its effectiveness in finding passwords not recovered by traditional methods.


## Digital forensic investigation in the age of ChatGPT

Canonical URL: https://markscanlon.co/publications/ChatGPT
Authors: Mark Scanlon; Bruce Nikkel; Zeno Geradts
Year: 2023
DOI: https://doi.org/10.1016/j.fsidi.2023.301543
PDF: https://markscanlon.co/publications/ChatGPT.pdf
Summary: This editorial discusses the implications of ChatGPT on digital forensic investigation, highlighting both beneficial use cases and potential risks. It explores the use of Large Language Models (LLMs) in generating scripts, question answering, multilingual analysis, and automated sentiment analysis, while also addressing concerns about bias, errors, and overreliance on these systems.


## ChatGPT for digital forensic investigation: The good, the bad, and the unknown

Canonical URL: https://markscanlon.co/publications/ChatGPTforDigitalForensics
Authors: Mark Scanlon; Frank Breitinger; Christopher Hargreaves; Jan-Niclas Hilgert; John Sheppard
Year: 2023
DOI: https://doi.org/10.1016/j.fsidi.2023.301609
PDF: https://markscanlon.co/publications/ChatGPTforDigitalForensics.pdf
Summary: This paper assesses the impact of ChatGPT on digital forensics, evaluating its capabilities and risks in various use cases, including artefact understanding, evidence searching, code generation, anomaly detection, incident response, and education. The study highlights both the potential benefits and limitations of using ChatGPT in digital forensic investigations, concluding that it can be a useful supporting tool for knowledgeable users but requires careful consideration of its strengths and weaknesses.


## Deep Learning Based Network Intrusion Detection System for Resource-Constrained Environments

Canonical URL: https://markscanlon.co/publications/DLNIDS
Authors: Syed Rizvi; Mark Scanlon; Jimmy McGibney; John Sheppard
Year: 2022
DOI: https://doi.org/10.1007/978-3-031-36574-4_21
PDF: https://markscanlon.co/publications/DLNIDS.pdf
Summary: This paper presents a deep learning-based network intrusion detection system (IDS) for resource-constrained environments. The proposed 1D-Dilated Causal Neural Network (1D-DCNN) model achieves high accuracy in detecting malicious attacks, outperforming existing deep learning approaches. The model's efficiency and effectiveness make it suitable for resource-constrained environments.


## Data Exfiltration through Electromagnetic Covert Channel of Wired Industrial Control Systems

Canonical URL: https://markscanlon.co/publications/DataExfiltrationEM-SCA
Authors: Shakthi Sachintha; Nhien-An Le-Khac; Mark Scanlon; Asanka P. Sayakkara
Year: 2022
DOI: https://doi.org/10.3390/app13052928
PDF: https://markscanlon.co/publications/DataExfiltrationEM-SCA.pdf
Summary: This study demonstrates a novel attack vector on industrial control systems (ICS) that leverages electromagnetic (EM) radiation from wired Ethernet connections to exfiltrate sensitive information. The attack exploits compromised firmware to encode data into packet transmission patterns, which are then captured and demodulated by an attacker's software-defined radio. This covert channel facilitates data exfiltration from up to two meters away with a 10 bps data rate.


## Application of Artificial Intelligence to Network Forensics: Survey, Challenges and Future Directions

Canonical URL: https://markscanlon.co/publications/AIforNetworkForensics
Authors: Syed Rizvi; Mark Scanlon; Jimmy McGibney; John Sheppard
Year: 2022
DOI: https://doi.org/10.1109/ACCESS.2022.3214506
PDF: https://markscanlon.co/publications/AIforNetworkForensics.pdf
Summary: This paper provides a comprehensive survey of the application of artificial intelligence (AI) in network forensics, including expert systems, machine learning, deep learning, and ensemble/hybrid approaches. It discusses the current challenges and future directions in network forensics, covering various application areas such as network traffic analysis, intrusion detection systems, and Internet-of-Things devices.


## Security, Ethics and Privacy Issues in Remote Extended Reality for Education

Canonical URL: https://markscanlon.co/publications/SecurityEthicsXREducation
Authors: Muhammad Zahid Iqbal; Xuanhui Xu; Vivek Nallur; Mark Scanlon; Abraham G. Campbell
Year: 2022
DOI: https://doi.org/10.1007/978-981-99-4958-8_16
Summary: This chapter explores security, ethics, and privacy concerns in remote extended reality learning environments, highlighting the need for a comprehensive approach to address these issues in immersive education.


## A Novel Dictionary Generation Methodology for Contextual-Based Password Cracking

Canonical URL: https://markscanlon.co/publications/MethodologyContextual-BasedPasswordCracking
Authors: Aikaterini Kanta; Iwen Coisel; Mark Scanlon
Year: 2022
DOI: https://doi.org/10.1109/ACCESS.2022.3179701
PDF: https://markscanlon.co/publications/MethodologyContextual-BasedPasswordCracking.pdf
Summary: This paper introduces a novel dictionary generation methodology for contextual-based password cracking, enabling the creation of custom dictionary word lists for dictionary-based password cracking attacks. The approach leverages contextual information encountered during an investigation, such as user habits and personal information, to generate targeted password candidates. This methodology has the potential to expedite password cracking processes in law enforcement investigations.


## PCWQ: A Framework for Evaluating Password Cracking Wordlist Quality

Canonical URL: https://markscanlon.co/publications/PasswordCrackingWordlistQuality
Authors: Aikaterini Kanta; Iwen Coisel; Mark Scanlon
Year: 2021
DOI: https://doi.org/10.1007/978-3-031-06365-7_10
PDF: https://markscanlon.co/publications/PasswordCrackingWordlistQuality.pdf
Summary: This paper presents PCWQ, a novel framework for evaluating the quality of password cracking wordlists. The framework assesses wordlists based on several interconnecting metrics, including final percentage of passwords cracked, number of guesses until target, progress over time, size of wordlist, and better performance with stronger passwords. The authors conduct a preliminary analysis to demonstrate the framework's evaluation process.


## Identifying Internet of Things Software Activities using Deep Learning-based Electromagnetic Side-Channel Analysis

Canonical URL: https://markscanlon.co/publications/IoT-DL-EMSCA
Authors: Quan Le; Luis Miralles-Pechuán; Asanka Sayakkara; Nhien-An Le-Khac; Mark Scanlon
Year: 2021
DOI: https://doi.org/10.1016/j.fsidi.2021.301308
PDF: https://markscanlon.co/publications/IoT-DL-EMSCA.pdf
Summary: This study explores the application of machine learning techniques to identify complex activities on IoT devices using electromagnetic side-channel analysis. The researchers created a dataset by running ten sorting algorithms on an Arduino device and used it to train various classification models, including deep learning models. The results show that convolutional neural networks can accurately predict the activity being executed with a high level of accuracy (99.6%).


## How Viable is Password Cracking in Digital Forensic Investigation? Analyzing the Guessability of over 3.9 Billion Real-World Accounts

Canonical URL: https://markscanlon.co/publications/PasswordCracking3BillionAccounts
Authors: Aikaterini Kanta; Sein Coray; Iwen Coisel; Mark Scanlon
Year: 2021
DOI: https://doi.org/10.1016/j.fsidi.2021.301186
PDF: https://markscanlon.co/publications/PasswordCracking3BillionAccounts.pdf
Summary: This study analyzed over 3.9 billion real-world passwords to assess their guessability and identify patterns in password construction. The analysis reveals that certain semantic classes are more common than others, indicating the importance of user context in password selection. The study also evaluates the effectiveness of password cracking tools and techniques, providing insights for digital investigators.


## Digital Forensics: Leveraging Deep Learning Techniques in Facial Images to Assist Cybercrime Investigations

Canonical URL: https://markscanlon.co/publications/PhDThesis-DeepLearningFacialImageCybercrime
Authors: Felix Anda
Year: 2021
PDF: https://markscanlon.co/publications/PhDThesis-DeepLearningFacialImageCybercrime.pdf
Summary: This PhD thesis presents a novel approach to facial age estimation using deep learning techniques to assist cybercrime investigations. The research addresses the digital forensic backlog by proposing age estimation models that surpass the state-of-the-art facial age detectors for subjects under 25. The study evaluates the performance of various image pre-processing techniques, neural network architectures, and hyper-parameter optimisation strategies.


## Vec2UAge: Enhancing Underage Age Estimation Performance through Facial Embeddings

Canonical URL: https://markscanlon.co/publications/Vec2UAge
Authors: Felix Anda; Edward Dixon; Elias Bou-Harb; Nhien-An Le-Khac; Mark Scanlon
Year: 2021
DOI: https://doi.org/10.1016/j.fsidi.2021.301119
PDF: https://markscanlon.co/publications/Vec2UAge.pdf
Summary: This paper presents Vec2UAge, a novel regression-based model for estimating the age of underage individuals from facial embeddings. The model is trained on the VisAGe and Selfie-FV datasets and achieves a mean absolute error rate of 2.36 years. The authors evaluate the impact of random initializations, optimizers, and learning rates on the model's performance.


## TraceGen: User Activity Emulation for Digital Forensic Test Image Generation

Canonical URL: https://markscanlon.co/publications/TraceGen
Authors: Xiaoyu Du; Christopher Hargreaves; John Sheppard; Mark Scanlon
Year: 2021
DOI: https://doi.org/10.1016/j.fsidi.2021.301133
PDF: https://markscanlon.co/publications/TraceGen.pdf
Summary: This paper presents TraceGen, an automated system for generating realistic digital forensic test images through user activity emulation. The framework consists of a series of actions contained within scripts that are executed both externally and internally to a target virtual machine. TraceGen aims to address the issue of emulating user activities and behaviours, ensuring forensically realistic traces are created in the resulting test images.


## A Comparative Study of Support Vector Machine and Neural Networks for File Type Identification Using n-gram Analysis

Canonical URL: https://markscanlon.co/publications/FileIdentification
Authors: Joachim Sester; Darren Hayes; Nhien-An Le-Khac; Mark Scanlon
Year: 2021
DOI: https://doi.org/10.1016/j.fsidi.2021.301121
PDF: https://markscanlon.co/publications/FileIdentification.pdf
Summary: This study compares the performance of Support Vector Machines (SVMs) and Neural Networks (NNs) for file type identification using n-gram analysis. The authors investigate the influence of input parameters, such as learning rate and n-gram values, on the results and compare the scalability of SVMs and NNs. The study finds that SVM-based approaches perform better than NNs, but their scalability is still a challenge.


## On Offloading Network Forensic Analytics to Programmable Data Plane Switches

Canonical URL: https://markscanlon.co/publications/NetworkForensicAnalytics
Authors: Kurt Friday; Elias Bou-Harb; Jorge Crichigno; Mark Scanlon; Nicole Beebe
Year: 2021
PDF: https://markscanlon.co/publications/NetworkForensicAnalytics.pdf
Summary: This paper proposes a novel approach to network forensic analytics by leveraging programmable data plane switches to detect and mitigate Distributed Denial of Service (DDoS) attacks and Internet of Things (IoT) device misuse. The authors implement two switch-based use cases to conduct network forensics at line rate, reducing latency and improving incident response.


## A Survey Exploring Open Source Intelligence for Smarter Password Cracking

Canonical URL: https://markscanlon.co/publications/SurveyOSINTPasswordCracking
Authors: Aikaterini Kanta; Iwen Coisel; Mark Scanlon
Year: 2020
DOI: https://doi.org/10.1016/j.fsidi.2020.301075
PDF: https://markscanlon.co/publications/SurveyOSINTPasswordCracking.pdf
Summary: This paper explores the potential of Open Source Intelligence (OSINT) for more efficient password cracking in digital investigations. A comprehensive survey of password strength, cracking, and OSINT is presented, along with an analysis of password structure and demographic factors influencing password selection. The authors discuss the challenges of password cracking and the potential impact of OSINT on law enforcement.


## Retracing the Flow of the Stream: Investigating Kodi Streaming Services

Canonical URL: https://markscanlon.co/publications/Kodi-XBMC-Forensics
Authors: Samuel Todd Bromley; John Sheppard; Mark Scanlon; Nhien-An Le-Khac
Year: 2020
DOI: https://doi.org/10.1007/978-3-030-68734-2_13
PDF: https://markscanlon.co/publications/Kodi-XBMC-Forensics.pdf
Summary: This paper presents a new method for quickly locating Kodi artifacts and gathering information for successful prosecution of digital piracy and streaming of illegal content. The approach is evaluated on Windows, Android, and Linux platforms, demonstrating the location of file artifacts, databases, and viewed content history.


## Electromagnetic Side-Channel Analysis Methods for Digital Forensics on Internet of Things

Canonical URL: https://markscanlon.co/publications/PhDThesis-ElectromagneticSideChannelAnalysisIoT
Authors: Asanka Sayakkara
Year: 2020
PDF: https://markscanlon.co/publications/PhDThesis-ElectromagneticSideChannelAnalysisIoT.pdf
Summary: This thesis explores the potential of leveraging Electromagnetic Side-Channel Analysis (EM-SCA) as a forensic evidence acquisition method for Internet of Things (IoT) devices. A model for IoT forensics using EM-SCA methods is formulated, enabling investigators to perform complex forensic insight-gathering procedures without expertise in EM-SCA. A proof-of-concept, EMvidence, is implemented as an open-source software framework, utilizing a modular architecture to extract specific forensic insights from IoT devices. The thesis presents methods for acquiring forensic insights, including detecting cryptography-related events, firmware version, and malicious modifications to the firmware. Machine Learning algorithms are used to automatically identify known patterns of EM radiation with over 90% accuracy.


## Alleviating the Digital Forensic Backlog: A Methodology for Automated Digital Evidence Processing

Canonical URL: https://markscanlon.co/publications/PhDThesis-MethodologyAutomatedDigitalEvidenceProcessing
Authors: Xiaoyu Du
Year: 2020
PDF: https://markscanlon.co/publications/PhDThesis-MethodologyAutomatedDigitalEvidenceProcessing.pdf
Summary: This PhD thesis proposes a methodology for alleviating the digital forensic backlog through automated digital evidence processing. The research leverages data deduplication and automated analysis techniques to reduce redundant digital evidence data handling, enabling faster and more efficient investigations.


## SoK: Exploring the State of the Art and the Future Potential of Artificial Intelligence in Digital Forensic Investigation

Canonical URL: https://markscanlon.co/publications/SoK-AI-Forensics
Authors: Xiaoyu Du; Chris Hargreaves; John Sheppard; Felix Anda; Asanka Sayakkara; Nhien-An Le-Khac; Mark Scanlon
Year: 2020
DOI: https://doi.org/10.1145/3407023.3407068
PDF: https://markscanlon.co/publications/SoK-AI-Forensics.pdf
Summary: This systematic overview of artificial intelligence (AI) in digital forensic investigation explores the current state of the art and future potential of AI in expediting digital forensic analysis and increasing case processing capacities. The authors discuss AI applications in data discovery, device triage, and other areas, highlighting current challenges and future directions.


## Facilitating Electromagnetic Side-Channel Analysis for IoT Investigation: Evaluating the EMvidence Framework

Canonical URL: https://markscanlon.co/publications/EvaluatingEMvidence
Authors: Asanka Sayakkara; Nhien-An Le-Khac; Mark Scanlon
Year: 2020
DOI: https://doi.org/10.1016/j.fsidi.2020.301003
PDF: https://markscanlon.co/publications/EvaluatingEMvidence.pdf
Summary: This paper presents the EMvidence framework, a software tool that facilitates electromagnetic side-channel analysis for IoT investigation. The framework automates and simplifies the process of acquiring and analyzing electromagnetic signals from IoT devices, making it accessible to digital forensic investigators without specialized equipment or expertise.


## Smarter Password Guessing Techniques Leveraging Contextual Information and OSINT

Canonical URL: https://markscanlon.co/publications/SmarterPasswordGuessing
Authors: Aikaterini Kanta; Iwen Coisel; Mark Scanlon
Year: 2020
DOI: https://doi.org/10.1109/CyberSecurity49315.2020.9138870
PDF: https://markscanlon.co/publications/SmarterPasswordGuessing.pdf
Summary: This paper proposes smarter password guessing techniques that leverage contextual information and Open Source Intelligence (OSINT) to improve password recovery rates. The authors explore the use of OSINT to gather information about a suspect's online and offline life, which can be used to make educated guesses about their password. The research aims to create a bespoke, personalized dictionary list to feed into password cracking tools.


## Automated Artefact Relevancy Determination from Artefact Metadata and Associated Timeline Events

Canonical URL: https://markscanlon.co/publications/ArtefactRelevancy
Authors: Xiaoyu Du; Quan Le; Mark Scanlon
Year: 2020
DOI: https://doi.org/10.1109/CyberSecurity49315.2020.9138874
PDF: https://markscanlon.co/publications/ArtefactRelevancy.pdf
Summary: This paper presents an approach for automated artefact relevancy determination from artefact metadata and associated timeline events. The method uses a relevancy score to rank file artefacts by likely relevance, based on data reduction techniques and machine learning models. The approach is validated through experimentation with three emulated investigation scenarios, demonstrating its potential to aid investigators in the discovery and prioritisation of evidence.


## Assessing the Influencing Factors on the Accuracy of Underage Facial Age Estimation

Canonical URL: https://markscanlon.co/publications/AssessingInfluencingFactorsAgeEstimation
Authors: Felix Anda; Brett Becker; David Lillis; Nhien-An Le-Khac; Mark Scanlon
Year: 2020
DOI: https://doi.org/10.1109/CyberSecurity49315.2020.9138851
PDF: https://markscanlon.co/publications/AssessingInfluencingFactorsAgeEstimation.pdf
Summary: This study evaluates the influencing factors on the accuracy of underage facial age estimation using two cloud services, Microsoft Azure's Face API and Amazon Web Service's Rekognition service. The analysis of the VisAGe dataset reveals correlations between facial attributes and age estimation errors, identifying the most significant factors to be addressed in future age estimation modeling.


## EMvidence: A Framework for Digital Evidence Acquisition from IoT Devices through Electromagnetic Side-Channel Analysis

Canonical URL: https://markscanlon.co/publications/EMvidence
Authors: Asanka Sayakkara; Nhien-An Le-Khac; Mark Scanlon
Year: 2020
DOI: https://doi.org/10.1016/j.fsidi.2020.300907
PDF: https://markscanlon.co/publications/EMvidence.pdf
Summary: This paper presents EMvidence, a software framework for digital forensic investigators to acquire evidence from IoT devices through electromagnetic side-channel analysis. The framework automates and performs electromagnetic side-channel evidence collection, making it a practical reality for digital forensic investigators.


## DeepUAge: Improving Underage Age Estimation Accuracy to Aid CSEM Investigation

Canonical URL: https://markscanlon.co/publications/UnderageFacialAgeEstimation
Authors: Felix Anda; Nhien-An Le-Khac; Mark Scanlon
Year: 2020
DOI: https://doi.org/10.1016/j.fsidi.2020.300921
PDF: https://markscanlon.co/publications/UnderageFacialAgeEstimation.pdf
Summary: DeepUAge improves underage age estimation accuracy to aid Child Sexual Exploitation Material (CSEM) investigation. The model, trained on the VisAGe dataset, achieves state-of-the-art performance for age estimation of minors, with a mean absolute error (MAE) rate of 2.73 years. This work tackles the challenges of collecting and annotating underage facial age data, and its application can expedite digital investigations.


## Cutting through the Emissions: Feature Selection from Electromagnetic Side-Channel Data for Activity Detection

Canonical URL: https://markscanlon.co/publications/EMSideChannelFeatureSelection
Authors: Asanka Sayakkara; Luis Miralles; Nhien-An Le-Khac; Mark Scanlon
Year: 2020
DOI: https://doi.org/10.1016/j.fsidi.2020.300927
PDF: https://markscanlon.co/publications/EMSideChannelFeatureSelection.pdf
Summary: This paper presents a systematic methodology to identify information leaking frequency channels from high dimensional EM data using multiple filtering techniques and machine learning. The approach is evaluated on a dataset of EM signals from an IoT device, demonstrating its effectiveness in reducing the number of channels from 20,000 to less than 100, improving real-time analysis efficiency.


## Methodology for the Automated Metadata-Based Classification of Incriminating Digital Forensic Artefacts

Canonical URL: https://markscanlon.co/publications/AutomatedClassificationArtefacts
Authors: Xiaoyu Du; Mark Scanlon
Year: 2019
DOI: https://doi.org/10.1145/3339252.3340517
PDF: https://markscanlon.co/publications/AutomatedClassificationArtefacts.pdf
Summary: This paper proposes a methodology for automatically prioritizing suspicious file artefacts in digital forensic investigations, leveraging a supervised machine learning approach and a toolkit for data extraction from disk images. The methodology aims to reduce manual analysis effort and improve the efficiency of the investigative process.


## Improving Borderline Adulthood Facial Age Estimation through Ensemble Learning

Canonical URL: https://markscanlon.co/publications/BorderlineAdulthoodAgeEstimation
Authors: Felix Anda; David Lillis; Aikaterini Kanta; Brett Becker; Elias Bou-Harb; Nhien-An Le-Khac; Mark Scanlon
Year: 2019
DOI: https://doi.org/10.1145/3339252.3341491
PDF: https://markscanlon.co/publications/BorderlineAdulthoodAgeEstimation.pdf
Summary: This paper presents an ensemble learning approach to improve facial age estimation for borderline adulthood cases. The authors develop a deep learning model (DS13K) and fine-tune it on the Deep Expectation (DEX) model to achieve an accuracy of 68% for the age group 16-17 years old, outperforming DEX by 4 times. The study also evaluates existing cloud-based facial age prediction services.


## Leveraging Electromagnetic Side-Channel Analysis for the Investigation of IoT Devices

Canonical URL: https://markscanlon.co/publications/LeveragingEMIoT
Authors: Asanka Sayakkara; Nhien-An Le-Khac; Mark Scanlon
Year: 2019
DOI: https://doi.org/10.1016/j.diin.2019.04.012
PDF: https://markscanlon.co/publications/LeveragingEMIoT.pdf
Summary: This paper presents a novel methodology to inspect the internal software activities of IoT devices through their electromagnetic radiation emissions during live device investigation. The approach uses electromagnetic side-channel analysis (EM-SCA) to detect software activities, including cryptographic algorithms and malicious modifications, with high accuracy.


## A Survey of Electromagnetic Side-Channel Attacks and Discussion on their Case-Progressing Potential for Digital Forensics

Canonical URL: https://markscanlon.co/publications/SurveyEMSideChannelsForensics
Authors: Asanka Sayakkara; Nhien-An Le-Khac; Mark Scanlon
Year: 2019
DOI: https://doi.org/10.1016/j.diin.2019.03.002
PDF: https://markscanlon.co/publications/SurveyEMSideChannelsForensics.pdf
Summary: This paper surveys electromagnetic side-channel attacks and their potential for digital forensics on IoT devices. It discusses the challenges of analyzing encrypted data from IoT devices and explores the use of electromagnetic side-channel analysis to recover cryptographic keys and other sensitive information.


## Shining a light on Spotlight: Leveraging Apple's desktop search utility to recover deleted file metadata on macOS

Canonical URL: https://markscanlon.co/publications/SpotlightMacForensics
Authors: Tajvinder Singh Atwal; Mark Scanlon; Nhien-An Le-Khac
Year: 2019
DOI: https://doi.org/10.1016/j.diin.2019.01.019
PDF: https://markscanlon.co/publications/SpotlightMacForensics.pdf
Summary: This study examines Apple's desktop search technology, Spotlight, to recover deleted file metadata on macOS. Researchers developed a novel approach to extract persistent records of deleted files directly from the Spotlight database and recover records from deleted database pages in unused space. The study provides a proof-of-concept implementation and discusses the forensic opportunities offered by recovering records for deleted files within the database and unused space on the filesystem.


## Improving the Accuracy of Automated Facial Age Estimation to Aid CSEM Investigations

Canonical URL: https://markscanlon.co/publications/FacialAgeEstimationPoster
Authors: Felix Anda; David Lillis; Aikaterini Kanta; Brett A. Becker; Elias Bou-Harb; Nhien-An Le-Khac; M. Scanlon
Year: 2019
DOI: https://doi.org/10.1016/j.diin.2019.01.024
PDF: https://markscanlon.co/publications/FacialAgeEstimationPoster.pdf
Summary: This study evaluates existing age prediction services and introduces a deep learning model, DS13K, to improve the accuracy of underage facial age estimation in child sexual exploitation material (CSEM) investigations. The model outperforms existing services, particularly in the borderline adulthood age range (16-17 years old), with an accuracy rate of 68%.


## Solid State Drive Forensics: Where Do We Stand?

Canonical URL: https://markscanlon.co/publications/SSDForensics
Authors: John Vieyra; Mark Scanlon; Nhien-An Le-Khac
Year: 2019
DOI: https://doi.org/10.1007/978-3-030-05487-8_8
PDF: https://markscanlon.co/publications/SSDForensics.pdf
Summary: This paper examines the current state of solid-state drive (SSD) forensics, addressing the challenges posed by SSDs' background data movement and garbage collection processes. The authors investigate the impact of TRIM, data volume, and powered-on time on data recovery and provide guidance on extracting artefacts from SSDs under various conditions.


## Enabling the Non-Expert Analysis of Large Volumes of Intercepted Network Traffic

Canonical URL: https://markscanlon.co/publications/NetworkIntell
Authors: Erwin van de Weil; Mark Scanlon; Nhien-An Le-Khac
Year: 2018
DOI: https://doi.org/10.1007/978-3-319-99277-8_11
PDF: https://markscanlon.co/publications/NetworkIntell.pdf
Summary: This paper proposes a novel approach to analyze large volumes of intercepted network traffic based on network metadata, reducing analysis duration and providing insights for non-technical investigators. The approach is tested with a large sample of network traffic data and can be used to identify devices and usage behind an internet connection.


## Deduplicated Disk Image Evidence Acquisition and Forensically-Sound Reconstruction

Canonical URL: https://markscanlon.co/publications/ForensicallySoundReconstruction
Authors: Xiaoyu Du; Paul Ledwith; Mark Scanlon
Year: 2018
DOI: https://doi.org/10.1109/TrustCom/BigDataSE.2018.00249
PDF: https://markscanlon.co/publications/ForensicallySoundReconstruction.pdf
Summary: This paper presents a system for deduplicated disk image evidence acquisition and forensically-sound reconstruction, addressing the growing digital evidence backlog in law enforcement. The system enables automated, centralized acquisition and analysis, reducing storage and bandwidth requirements, and facilitating non-expert evidence processing.


## Cloud Investigations of Illegal IPTV Networks

Canonical URL: https://markscanlon.co/publications/IllegalIPTVNetworks
Authors: John Sheppard
Year: 2018
DOI: https://doi.org/10.1109/TrustCom/BigDataSE.2018.00295
PDF: https://markscanlon.co/publications/IllegalIPTVNetworks.pdf
Summary: This paper examines the Kodi software ecosystem, focusing on its role in illegal IPTV networks. It identifies key roles in the Kodi community, including users, addon authors, and distributors, and explores the relationships between them. The study uses cloud evidence to connect devices to addon distributors and investigates networks among authors and distributors using GraphQL in the GitHub cloud.


## Accuracy Enhancement of Electromagnetic Side-channel Attacks on Computer Monitors

Canonical URL: https://markscanlon.co/publications/EMAttacksComputerMonitors
Authors: Asanka Sayakkara; Nhien-An Le-Khac; Mark Scanlon
Year: 2018
DOI: https://doi.org/10.1145/3230833.3234690
PDF: https://markscanlon.co/publications/EMAttacksComputerMonitors.pdf
Summary: This paper investigates the accuracy of electromagnetic side-channel attacks on computer monitors, focusing on factors beyond sampling rate and bandwidth. The authors evaluate noise removal, image blending, and image quality adjustments to improve image reconstruction accuracy, exploring avenues for future improvements in EM side-channel attacks.


## Electromagnetic Side-Channel Attacks: Potential for Progressing Hindered Digital Forensic Analysis

Canonical URL: https://markscanlon.co/publications/EMSideChannelsForForensics
Authors: Asanka Sayakkara; Nhien-An Le-Khac; Mark Scanlon
Year: 2018
DOI: https://doi.org/10.1145/3236454.3236512
PDF: https://markscanlon.co/publications/EMSideChannelsForForensics.pdf
Summary: This paper explores the potential of electromagnetic side-channel analysis in progressing hindered digital forensic investigations. The authors argue that EM side-channel attacks can provide a hands-off approach to accessing internal device information, overcoming encryption and limited standardization of IoT devices.


## Digital Forensic Investigation of Two-Way Radio Communication Equipment and Services

Canonical URL: https://markscanlon.co/publications/TwoWayRadioForensics
Authors: Arie Kouwen; Mark Scanlon; Kim-Kwang Raymond Choo; Nhien-An Le-Khac
Year: 2018
DOI: https://doi.org/10.1016/j.diin.2018.04.007
PDF: https://markscanlon.co/publications/TwoWayRadioForensics.pdf
Summary: This paper investigates the digital forensic investigation of two-way radio communication equipment and services, including the acquisition and analysis of digital traces in modern radio communication devices. The authors propose a workflow for radio device investigation and evaluate the possibility of using popular forensic tools to acquire artefacts from radio communication equipment.


## Deep Learning at the Shallow End: Malware Classification for Non-Domain Experts

Canonical URL: https://markscanlon.co/publications/DeepLearningMalware
Authors: Quan Le; Oisín Boydell; Brian Mac Namee; Mark Scanlon
Year: 2018
DOI: https://doi.org/10.1016/j.diin.2018.04.024
PDF: https://markscanlon.co/publications/DeepLearningMalware.pdf
Summary: This paper presents a deep learning-based malware classification approach that requires no expert domain knowledge and is based on a purely data-driven approach for complex pattern and feature identification. The model achieves a high accuracy of 98.2% in classifying raw binary files into one of 9 classes of malware, with a processing time of 0.02 seconds per file.


## Evaluating Automated Facial Age Estimation Techniques for Digital Forensics

Canonical URL: https://markscanlon.co/publications/EvaluatingFacialAgeEstimation
Authors: Felix Anda; David Lillis; Nhien-An Le-Khac; Mark Scanlon
Year: 2018
DOI: https://doi.org/10.1109/SPW.2018.00028
PDF: https://markscanlon.co/publications/EvaluatingFacialAgeEstimation.pdf
Summary: This paper evaluates existing automated facial age estimation techniques for digital forensics, highlighting their limitations and proposing a dataset generator to overcome the lack of sufficient sample images in specific age ranges. The study assesses the performance of offline and cloud-based models, releasing a tool to generate uniformly distributed random images by age and gender.


## Hierarchical Bloom Filter Trees for Approximate Matching

Canonical URL: https://markscanlon.co/publications/HierarchicalBloomFilterTrees
Authors: David Lillis; Frank Breitinger; Mark Scanlon
Year: 2018
DOI: https://doi.org/10.15394/jdfsl.2018.1489
PDF: https://markscanlon.co/publications/HierarchicalBloomFilterTrees.pdf
Summary: This paper proposes the use of Hierarchical Bloom Filter Trees (HBFTs) to improve the runtime efficiency of approximate matching techniques in digital forensics. HBFTs reduce the number of pairwise comparisons required, achieving substantial speed gains while maintaining effectiveness. The authors evaluate the effectiveness of HBFTs using the MRSH-v2 algorithm and explore the effects of different configurations of HBFTs.


## Private Web Browser Forensics: A Case Study on Epic Privacy Browser

Canonical URL: https://markscanlon.co/publications/PrivateWebBrowserForensics
Authors: Alan Reed; Mark Scanlon; Nhien-An Le-Khac
Year: 2018
PDF: https://markscanlon.co/publications/PrivateWebBrowserForensics.pdf
Summary: This study examines the Epic Privacy Browser, a private web browser designed to protect users' privacy, and its potential for forensic analysis. The researchers investigate the types of evidence left behind by the browser on Windows 10 and Windows 7 operating systems, including live and post-mortem analysis. The study aims to identify the tools and methods for effective analysis of the browser's artefacts.


## Expediting MRSH-v2 Approximate Matching with Hierarchical Bloom Filter Trees

Canonical URL: https://markscanlon.co/publications/MRSHv2BloomFilterTrees
Authors: David Lillis; Frank Breitinger; Mark Scanlon
Year: 2018
DOI: https://doi.org/10.1007/978-3-319-73697-6_11
PDF: https://markscanlon.co/publications/MRSHv2BloomFilterTrees.pdf
Summary: This paper presents an improvement to the MRSH-v2 approximate matching algorithm using Hierarchical Bloom Filter Trees (HBFT) to expedite the search process for digital forensic investigators. Experiments demonstrate substantial speed gains over the original MRSH-v2 while maintaining effectiveness.


## Data Analytics for Digital Forensics and Cybersecurity

Canonical URL: https://markscanlon.co/publications/DataAnalyticsForDigitalForensicsAndCybersecurity
Authors: Mark Scanlon
Year: 2017
PDF: https://markscanlon.co/publications/DataAnalyticsForDigitalForensicsAndCybersecurity.pdf
Summary: This paper addresses the problem of information overload in digital forensics and cybersecurity by proposing a data analytics approach for intelligent, real-time, automated data processing and event categorization. The solution aims to combat the increasing frequency and sophistication of cyberattacks by reducing false positive alerts in network intrusion detection systems.


## Privileged Data within Digital Evidence

Canonical URL: https://markscanlon.co/publications/PrivilegedDataWithinDigitalEvidence
Authors: Dominique Fleurbaaij; Mark Scanlon; Nhien-An Le-Khac
Year: 2017
DOI: https://doi.org/10.1109/Trustcom/BigDataSE/ICESS.2017.307
PDF: https://markscanlon.co/publications/PrivilegedDataWithinDigitalEvidence.pdf
Summary: This paper presents a script for handling privileged data in digital forensic tools, specifically in Nuix, to minimize exposure to investigators and automate the filtering process. The script increases effectiveness by relating files based on content, addressing the limitations of traditional filtering methods.


## Integration of Ether Unpacker into Ragpicker for plugin-based Malware Analysis and Identification

Canonical URL: https://markscanlon.co/publications/EtherUnpacker
Authors: Erik Schaefer; Nhien-An Le-Khac; Mark Scanlon
Year: 2017
PDF: https://markscanlon.co/publications/EtherUnpacker.pdf
Summary: This paper presents a new approach to malware analysis by integrating Ether Unpacker into the plugin-based malware analysis tool, Ragpicker. The integration aims to improve the unpacking rate of malware samples, enabling the analysis of transferred and reused code. The authors evaluate their approach against real-world malware patterns, demonstrating its effectiveness in identifying malware variants and families.


## Forensic Analysis of Epic Privacy Browser on Windows Operating Systems

Canonical URL: https://markscanlon.co/publications/EpicPrivacyBrowser
Authors: Alan Reed; Mark Scanlon; Nhien-An Le-Khac
Year: 2017
PDF: https://markscanlon.co/publications/EpicPrivacyBrowser.pdf
Summary: This paper presents a forensic analysis of Epic Privacy Browser on Windows operating systems, focusing on the identification and analysis of artefact evidence left on Windows 10 compared to Windows 7. The study aims to establish if the introduction of Windows 10 has had an adverse effect on the browser's claim of clearing all user activity traces upon closure.


## Evaluation of Digital Forensic Process Models with Respect to Digital Forensics as a Service

Canonical URL: https://markscanlon.co/publications/ProcessModelsDFaaS
Authors: Xiaoyu Du; Nhien-An Le-Khac; Mark Scanlon
Year: 2017
PDF: https://markscanlon.co/publications/ProcessModelsDFaaS.pdf
Summary: This paper evaluates the applicability of existing digital forensic process models to a cloud-based evidence processing paradigm, specifically Digital Forensics as a Service (DFaaS). The authors analyze the characteristics of each current process model and review the benefits of DFaaS, aiming to expedite the investigative process and reduce costs.


## EviPlant: An Efficient Digital Forensic Challenge Creation, Manipulation, and Distribution Solution

Canonical URL: https://markscanlon.co/publications/EviPlant
Authors: Mark Scanlon; Xiaoyu Du; David Lillis
Year: 2017
DOI: https://doi.org/10.1016/j.diin.2017.01.010
PDF: https://markscanlon.co/publications/EviPlant.pdf
Summary: EviPlant is a system designed to efficiently create, manipulate, store, and distribute digital forensic challenges for education and training. It allows educators to create evidence packages that can be integrated with base images, reducing the need for large, full-image files and making it easier to distribute challenges to students.


## Behavioral Service Graphs: A Formal Data-Driven Approach for Prompt Investigation of Enterprise and Internet-wide Infections

Canonical URL: https://markscanlon.co/publications/BehavioralServiceGraphsFormal
Authors: Elias Bou-Harb; Mark Scanlon
Year: 2017
DOI: https://doi.org/10.1016/j.diin.2017.02.002
PDF: https://markscanlon.co/publications/BehavioralServiceGraphsFormal.pdf
Summary: This paper proposes Behavioral Service Graphs, a formal data-driven approach for prompt investigation of enterprise and internet-wide infections. It leverages probing activities to rapidly infer infections and models infected machines as graphs to infer and correlate distributed groups of infected machines.


## Towards the Leveraging of Data Deduplication to Break the Disk Acquisition Speed Limit

Canonical URL: https://markscanlon.co/publications/TowardsDataDeduplication
Authors: Hannah Wolahan; Claudio Chico Lorenzo; Elias Bou-Harb; Mark Scanlon
Year: 2016
DOI: https://doi.org/10.1109/NTMS.2016.7792486
PDF: https://markscanlon.co/publications/TowardsDataDeduplication.pdf
Summary: This paper proposes a data deduplication system to expedite digital forensic evidence acquisition and analysis. The system leverages a deduplicated forensic data storage system to eliminate unnecessary reacquisition and analysis of previously processed data, reducing acquisition time and improving the overall efficiency of the digital forensic process.


## Behavioral Service Graphs: A Big Data Approach for Prompt Investigation of Internet-wide Infections

Canonical URL: https://markscanlon.co/publications/BehavioralServiceGraphs
Authors: Elias Bou-Harb; Mark Scanlon; Claude Fachkha
Year: 2016
DOI: https://doi.org/10.1109/NTMS.2016.7792437
PDF: https://markscanlon.co/publications/BehavioralServiceGraphs.pdf
Summary: This paper proposes Behavioral Service Graphs, a proactive approach to generating network-based evidence for network forensic investigation. It leverages big data behavioral analytics and graph theoretical concepts to infer and correlate groups of compromised network machines, providing actionable insights for prompt mitigation and further analysis.


## IPv6 Security and Forensics

Canonical URL: https://markscanlon.co/publications/IPv6SecurityAndForensics
Authors: Vincent Nicolls; Nhien-An Le-Khac; Lei Chen; Mark Scanlon
Year: 2016
DOI: https://doi.org/10.1109/INTECH.2016.7845143
PDF: https://markscanlon.co/publications/IPv6SecurityAndForensics.pdf
Summary: This paper presents a new approach to investigate IPv6 network attacks with case studies, focusing on IPv6 security and forensics. It discusses different types of IPv6 attacks and provides a comprehensive overview of IPv6 network attack techniques, including reconnaissance, exploitation, and mitigation strategies.


## Battling the Digital Forensic Backlog through Data Deduplication

Canonical URL: https://markscanlon.co/publications/BattlingTheBacklogDataDeduplication
Authors: Mark Scanlon
Year: 2016
DOI: https://doi.org/10.1109/INTECH.2016.7845139
PDF: https://markscanlon.co/publications/BattlingTheBacklogDataDeduplication.pdf
Summary: This paper proposes a novel solution to combat the digital forensic backlog through data deduplication. The solution leverages a centralized storage system to store a single copy of each object, eliminating redundant storage and reanalysis of previously processed data. This approach can reduce storage requirements, expedite digital forensic processing, and facilitate collaborative examination and sharing of digital evidence.


## Battling the Digital Forensic Backlog

Canonical URL: https://markscanlon.co/publications/BattlingTheDigitalForensicBacklog
Authors: Mark Scanlon
Year: 2016
Summary: This paper discusses the growing digital forensic backlog faced by law enforcement agencies due to the increasing number of digital devices involved in investigations. It highlights the challenges in identifying, acquiring, storing, and analyzing digital evidence from various sources, including cloud-based services and IoT devices. The author proposes future research directions to improve the efficiency of the digital forensic process.


## An Analytical Approach to the Recovery of Data From 3rd Party Proprietary CCTV File Systems

Canonical URL: https://markscanlon.co/publications/AnalyticalApproachToTheRecoveryOfDataFromCCTVFileSystems
Authors: Richard Gomm; Nhien-An Le-Khac; Mark Scanlon; M-Tahar Kechadi
Year: 2016
DOI: https://doi.org/10.13140/RG.2.2.31446.65601
PDF: https://markscanlon.co/publications/AnalyticalApproachToTheRecoveryOfDataFromCCTVFileSystems.pdf
Summary: This paper presents an analytical approach to recovering data from 3rd party proprietary CCTV file systems, focusing on a Ganz CCTV DVR model C-MPDVR-16. The authors reverse engineer the proprietary file system, enabling the retrieval of the oldest video footage possible. The method is evaluated using a case study, demonstrating the feasibility of recovering video footage from a DVR with no initial knowledge or documentation available.


## Current Challenges and Future Research Areas for Digital Forensic Investigation

Canonical URL: https://markscanlon.co/publications/CurrentChallengesAndFutureResearchAreas
Authors: David Lillis; Brett Becker; Tadhg O'Sullivan; Mark Scanlon
Year: 2016
DOI: https://doi.org/10.13140/RG.2.2.34898.76489
PDF: https://markscanlon.co/publications/CurrentChallengesAndFutureResearchAreas.pdf
Summary: This paper explores the current challenges in digital forensic investigations, including the digital evidence backlog, and outlines future research areas to improve the process. The authors discuss the increasing complexity, diversity, and volume of digital evidence, as well as the need for standardization and automation in digital forensic tools and processes.


## On the Benefits of Information Retrieval and Information Extraction Techniques Applied to Digital Forensics

Canonical URL: https://markscanlon.co/publications/OnTheBenefitsOfInformationRetrievalToDigitalForensics
Authors: David Lillis; Mark Scanlon
Year: 2016
DOI: https://doi.org/10.1007/978-981-10-1536-6_83
PDF: https://markscanlon.co/publications/OnTheBenefitsOfInformationRetrievalToDigitalForensics.pdf
Summary: This paper explores the application of Information Retrieval (IR) and Information Extraction (IE) techniques to digital forensics, highlighting their potential to improve the efficiency and effectiveness of investigations. The authors discuss the benefits of cloud-based digital forensic investigation platforms and the importance of precision and recall in different stages of an investigation.


## Increasing Digital Investigator Availability through Efficient Workflow Management and Automation

Canonical URL: https://markscanlon.co/publications/IncreasingDigitalInvestigatorAvailability
Authors: Ronald In de Braekt; Nhien-An Le-Khac; Jason Farina; Mark Scanlon; Mohand-Tahar Kechadi
Year: 2016
DOI: https://doi.org/10.1109/ISDFS.2016.7473525
PDF: https://markscanlon.co/publications/IncreasingDigitalInvestigatorAvailability.pdf
Summary: This paper proposes a workflow management automation framework to streamline digital investigation workflows, reducing time spent on acquisition and preparation steps, and increasing efficiency of forensic software and hardware use. The framework is evaluated in a real-world scenario, demonstrating its benefits and robustness.


## Tiered Forensic Methodology Model for Digital Field Triage by Non-Digital Evidence Specialists

Canonical URL: https://markscanlon.co/publications/TieredForensicMethodologyModelForDigitalFieldTriage
Authors: Ben Hitchcock; Nhien-An Le-Khac; Mark Scanlon
Year: 2016
DOI: https://doi.org/10.1016/j.diin.2016.01.010
PDF: https://markscanlon.co/publications/TieredForensicMethodologyModelForDigitalFieldTriage.pdf
Summary: This paper presents a tiered forensic methodology model for digital field triage by non-digital evidence specialists. The model aims to increase investigation efficiency and reduce the backlog of digital evidence waiting for analysis by trained specialists. The authors propose a framework for training front-line investigators to conduct digital field triage, allowing them to provide actionable information quickly and maintain the integrity of digital evidence.


## An Evaluation of Google Plus Communities as an Active Learning Journal Alternative to Improve Learning Efficacy

Canonical URL: https://markscanlon.co/publications/GooglePlusCommunities-ActiveLearningJournalAlternative
Authors: Mark Scanlon; Brett Becker
Year: 2015
PDF: https://markscanlon.co/publications/GooglePlusCommunities-ActiveLearningJournalAlternative.pdf
Summary: This study evaluates Google Plus Communities as an active learning journal alternative to improve learning efficacy. The authors present guidelines for deploying G+ Communities in educational settings, highlighting their potential to foster collaborative learning, social interaction, and community engagement.


## Network Investigation Methodology for BitTorrent Sync: A Peer-to-Peer Based File Synchronisation Service

Canonical URL: https://markscanlon.co/publications/NetworkInvestigationMethodologyForBitTorrentSync
Authors: Mark Scanlon; Jason Farina; M-Tahar Kechadi
Year: 2015
DOI: https://doi.org/10.1016/j.cose.2015.05.003
PDF: https://markscanlon.co/publications/NetworkInvestigationMethodologyForBitTorrentSync.pdf
Summary: This paper proposes a network investigation methodology for BitTorrent Sync, a peer-to-peer file synchronization service, to aid in the control of data flow across security perimeters. The methodology includes recommendations for investigating various scenarios, including legitimate and illicit activities.


## Forensic Analysis and Remote Evidence Recovery from Syncthing: An Open Source Decentralised File Synchronisation Utility

Canonical URL: https://markscanlon.co/publications/ForensicAnalysisAndRemoteEvidenceRecoveryFromSyncthing
Authors: Conor Quinn; Mark Scanlon; Jason Farina; M-Tahar Kechadi
Year: 2015
DOI: https://doi.org/10.1007/978-3-319-25512-5_7
PDF: https://markscanlon.co/publications/ForensicAnalysisAndRemoteEvidenceRecoveryFromSyncthing.pdf
Summary: This paper presents a forensic analysis and remote evidence recovery techniques for Syncthing, an open-source decentralized file synchronization utility. The authors outline the entry points for a Syncthing investigation, describe the network communication protocol, and develop a proof-of-concept tool for remote evidence recovery. The study addresses the need for digital forensics procedures to keep pace with decentralized services like Syncthing.


## Project Maelstrom: Forensic Analysis of the BitTorrent-Powered Browser

Canonical URL: https://markscanlon.co/publications/ProjectMaelstrom
Authors: Jason Farina; M-Tahar Kechadi; Mark Scanlon
Year: 2015
DOI: https://doi.org/10.15394/jdfsl.2015.1216
PDF: https://markscanlon.co/publications/ProjectMaelstrom.pdf
Summary: This paper presents a forensic analysis of Project Maelstrom, a decentralized web browser powered by BitTorrent. The authors explore the browser's functionality, forensic value, and the evidence it leaves behind, including installation and configuration files, user data, and torrent-related settings.


## Towards the Forensic Identification and Investigation of Cloud Hosted Servers through Noninvasive Wiretaps

Canonical URL: https://markscanlon.co/publications/TowardsTheForensicIdentificationAndInvestigationOfCloudHostedServers
Authors: Hessel Schut; Mark Scanlon; Jason Farina; Nhien-An Le-Khac
Year: 2015
DOI: https://doi.org/10.1109/ARES.2015.77
PDF: https://markscanlon.co/publications/TowardsTheForensicIdentificationAndInvestigationOfCloudHostedServers.pdf
Summary: This paper presents a new approach to rapidly and reliably identify cloud-hosted servers through non-invasive wiretaps. A handheld device composed of an embedded computer and a method of undetectable Ethernet-based communication interception is developed and tested. The device captures minimal information and only stores relevant data, with an audit log of operator actions for reporting.


## Remote Evidence Acquisition

Canonical URL: https://markscanlon.co/publications/RemoteEvidenceAcquisition
Authors: Mark Scanlon
Year: 2015
Summary: This paper presents a novel approach to remote evidence acquisition in digital forensics. The authors propose a method for collecting and preserving digital evidence from remote locations, addressing the challenges of on-site collection. The contribution is a framework for secure and efficient evidence transfer, enhancing the integrity and admissibility of digital evidence in investigations.


## Overview of the Forensic Investigation of Cloud Services

Canonical URL: https://markscanlon.co/publications/OverviewOfTheForensicInvestigationOfCloudServices
Authors: Jason Farina; Mark Scanlon; Nhien-An Le-Khac; M-Tahar Kechadi
Year: 2015
DOI: https://doi.org/10.1109/ARES.2015.81
PDF: https://markscanlon.co/publications/OverviewOfTheForensicInvestigationOfCloudServices.pdf
Summary: This paper provides an overview of the forensic investigation of cloud services, discussing the challenges and opportunities of cloud computing in digital forensics. It examines the state-of-the-art in cloud-focused digital forensic practices, including the collection and analysis of evidence, and the potential use of cloud technologies to provide Digital Forensics as a Service.


## HTML5 Zero Configuration Covert Channels: Security Risks and Challenges

Canonical URL: https://markscanlon.co/publications/HTML5ZeroConfigurationCovertChannels
Authors: Jason Farina; Mark Scanlon; Stephen Kohlmann; Nhien-An Le Khac; M-Tahar Kechadi
Year: 2015
PDF: https://markscanlon.co/publications/HTML5ZeroConfigurationCovertChannels.pdf
Summary: This paper explores the security risks and challenges of HTML5 zero-configuration covert channels, including the potential for cybercriminals to use these services for illegal activities. The authors analyze the forensic consequences of these services and propose methods for retrieving evidence.


## Leveraging Decentralisation to Extend the Digital Evidence Acquisition Window: Case Study on BitTorrent Sync

Canonical URL: https://markscanlon.co/publications/LeveragingDecentralisationToExtendTheDigitalEvidenceAcquisitionWindow
Authors: Mark Scanlon; Jason Farina; Nhien-An Le Khac; M-Tahar Kechadi
Year: 2014
DOI: https://doi.org/10.15394/jdfsl.2014.1173
PDF: https://markscanlon.co/publications/LeveragingDecentralisationToExtendTheDigitalEvidenceAcquisitionWindow.pdf
Summary: This paper presents a methodology for the remote recovery and verification of digital evidence from decentralized file synchronization services, specifically BitTorrent Sync. The authors outline a proof-of-concept implementation and discuss the challenges and opportunities of remote digital evidence retrieval in the context of mobile devices and cloud-based services.


## BitTorrent Sync: Network Investigation Methodology

Canonical URL: https://markscanlon.co/publications/BitTorrentSyncNetworkInvestigationMethodology
Authors: Mark Scanlon; Jason Farina; M-Tahar Kechadi
Year: 2014
DOI: https://doi.org/10.1109/ARES.2014.11
PDF: https://markscanlon.co/publications/BitTorrentSyncNetworkInvestigationMethodology.pdf
Summary: This paper presents a network investigation methodology for BitTorrent Sync, a decentralized file replication utility, to aid digital forensic investigations. The authors propose a framework for retrieving digital evidence from the network and provide results from a proof-of-concept investigation.


## An analysis of BitTorrent cross-swarm peer participation and geolocational distribution

Canonical URL: https://markscanlon.co/publications/AnAnalysisOfBitTorrentCrossSwarmPeerParticipation
Authors: Mark Scanlon; Huijie Shen
Year: 2014
DOI: https://doi.org/10.1109/ICCCN.2014.6911846
PDF: https://markscanlon.co/publications/AnAnalysisOfBitTorrentCrossSwarmPeerParticipation.pdf
Summary: This paper analyzes BitTorrent cross-swarm peer participation and geolocational distribution. The authors collected 2 terabytes of data from 16 swarms of popular TV shows, identifying 6.3 million distinct IPs. The study found significant cross-swarm participation and geolocational distribution, with Australia, Europe, and North America playing a crucial role in influencing swarm size. The results can aid in network usage prediction, bandwidth provisioning, and future network design.


## Digital Evidence Bag Selection for P2P Network Investigation

Canonical URL: https://markscanlon.co/publications/DigitalEvidenceBagSelectionForP2PNetworkInvestigation
Authors: Mark Scanlon; M-Tahar Kechadi
Year: 2014
DOI: https://doi.org/10.1007/978-3-642-40861-8_44
PDF: https://markscanlon.co/publications/DigitalEvidenceBagSelectionForP2PNetworkInvestigation.pdf
Summary: This paper proposes a new digital evidence bag format for P2P network investigations, addressing the limitations of existing formats in handling network traffic and metadata. The proposed format incorporates network byte streams and on-the-fly metadata generation to expedite identification and analysis.


## The Case for a Collaborative Universal Peer-to-Peer Botnet Investigation Framework

Canonical URL: https://markscanlon.co/publications/TheCaseForACollaborativeUniversalP2PBotnetInvestigationFramework
Authors: Mark Scanlon; M-Tahar Kechadi
Year: 2014
PDF: https://markscanlon.co/publications/TheCaseForACollaborativeUniversalP2PBotnetInvestigationFramework.pdf
Summary: This paper proposes a collaborative universal peer-to-peer botnet investigation framework to fast-track the investigative process through collaboration between key stakeholders. The framework exploits common attributes of P2P networks, including intra-peer communication, self-propagation, and node maintenance, to identify and record communication patterns. This enables the elimination of duplicated work by forensic investigators and facilitates the investigation of any known botnet and adaptation to new networks.


## BitTorrent Sync: First Impressions and Digital Forensic Implications

Canonical URL: https://markscanlon.co/publications/BitTorrentSyncFirstImpressionsAndDigitalForensicImplications
Authors: Jason Farina; Mark Scanlon; M-Tahar Kechadi
Year: 2014
DOI: https://doi.org/10.1016/j.diin.2014.03.010
PDF: https://markscanlon.co/publications/BitTorrentSyncFirstImpressionsAndDigitalForensicImplications.pdf
Summary: This paper presents a forensic analysis of BitTorrent Sync, a decentralized file synchronization service, and its implications for digital investigations. The authors examine the client application, network traffic, and artefacts created during installation and use, providing valuable insights for digital forensic investigators.


## Study of Peer-to-Peer Network Based Cybercrime Investigation: Application on Botnet Technologies

Canonical URL: https://markscanlon.co/publications/StudyOfPeer-to-PeerNetworkBasedCybercrimeInvestigation
Authors: Mark Scanlon
Year: 2013
PDF: https://markscanlon.co/publications/StudyOfPeer-to-PeerNetworkBasedCybercrimeInvestigation.pdf
Summary: This PhD thesis explores the investigation of Peer-to-Peer (P2P) networks, which are vulnerable to cybercrimes such as botnet propagation and malware distribution. The Universal P2P Network Investigation Framework (UP2PNIF) is introduced to facilitate faster and more efficient investigations of P2P networks.


## Universal Peer-to-Peer Network Investigation Framework

Canonical URL: https://markscanlon.co/publications/UniversalPeerToPeerNetworkInvestigationFramework
Authors: Mark Scanlon; M-Tahar Kechadi
Year: 2013
DOI: https://doi.org/10.1109/ARES.2013.91
PDF: https://markscanlon.co/publications/UniversalPeerToPeerNetworkInvestigationFramework.pdf
Summary: This paper introduces the Universal Peer-to-Peer Network Investigation Framework (UP2PNIF), a tool for investigating P2P networks. The framework exploits common attributes of P2P networks to enable faster and less labor-intensive investigations. It can be used for various investigation types, including evidence collection, anatomy, wide-area measurement, and takeover.


## Investigating Cybercrimes That Occur on Documented P2P Networks

Canonical URL: https://markscanlon.co/publications/InvestigatingCybercrimesThatOccurOnDocumentedP2PNetworks2013
Authors: Mark Scanlon; Alan Hannaway; Tahar Kechadi
Year: 2013
DOI: https://doi.org/10.4018/978-1-4666-2041-4.ch010
PDF: https://markscanlon.co/publications/InvestigatingCybercrimesThatOccurOnDocumentedP2PNetworks2013.pdf
Summary: This paper presents a methodology for investigating cybercrimes on documented P2P networks, specifically BitTorrent, by analyzing the top 100 most popular swarms over a one-week period. The investigation aims to quantify the scale of unauthorized distribution of copyrighted material and identify the geographical distribution of peers involved.


## Peer-to-Peer Botnet Investigation: A Review

Canonical URL: https://markscanlon.co/publications/P2PBotnetInvestigationAReview
Authors: Mark Scanlon; M-Tahar Kechadi
Year: 2012
DOI: https://doi.org/10.1007/978-94-007-5064-7_33
PDF: https://markscanlon.co/publications/P2PBotnetInvestigationAReview.pdf
Summary: This paper reviews the state-of-the-art in Peer-to-Peer (P2P) botnet investigation, highlighting the challenges and obstacles faced by investigators. It discusses the evolution of botnet design from traditional client/server to decentralized P2P networks, and the implications for investigation and takedown. The paper outlines three main approaches to P2P botnet investigation and presents case studies of the Nugache, Storm, and Waledec botnets.


## Investigating Cybercrimes That Occur on Documented P2P Networks

Canonical URL: https://markscanlon.co/publications/InvestigatingCybercrimesThatOccurOnDocumentedP2PNetworks
Authors: Mark Scanlon; Alan Hannaway; M-Tahar Kechadi
Year: 2011
DOI: https://doi.org/10.4018/jaci.2011040104
PDF: https://markscanlon.co/publications/InvestigatingCybercrimesThatOccurOnDocumentedP2PNetworks.pdf
Summary: This paper presents a methodology for investigating cybercrimes on documented P2P networks, specifically BitTorrent, by analyzing the top 100 most popular swarms over a one-week period. The investigation aims to quantify the scale of unauthorized distribution of copyrighted material through BitTorrent.


## A week in the Life of the Most Popular BitTorrent Swarms

Canonical URL: https://markscanlon.co/publications/AWeekInTheLifeOfTheMostPopularBitTorrentSwarms
Authors: Mark Scanlon; Alan Hannaway; M-Tahar Kechadi
Year: 2010
PDF: https://markscanlon.co/publications/AWeekInTheLifeOfTheMostPopularBitTorrentSwarms.pdf
Summary: This paper presents an analysis of the most popular BitTorrent swarms over a week, focusing on the scale of unauthorized distribution of copyrighted material. The investigation collected data on 8,489,287 unique IP addresses, with 50.6% of files split into smaller chunks for distribution. The results show a global distribution of peers, with the US, UK, India, and Canada being the top countries detected.


## Online Acquisition of Digital Forensic Evidence

Canonical URL: https://markscanlon.co/publications/OnlineAcquisitionOfDigitalForensicEvidence
Authors: Mark Scanlon; M-Tahar Kechadi
Year: 2009
DOI: https://doi.org/10.1007/978-3-642-11534-9_12
PDF: https://markscanlon.co/publications/OnlineAcquisitionOfDigitalForensicEvidence.pdf
Summary: This paper introduces RAFT, a remote forensic hard drive imaging tool designed to reduce the time wasted by forensic investigators in collecting digital evidence. RAFT enables law enforcement officers to remotely transfer images of suspect computers to a forensic laboratory for analysis, ensuring court-admissible evidence through secure and verifiable client/server imaging architecture.


## Enabling the Remote Acquisition of Digital Forensic Evidence through Secure Data Transmission and Verification

Canonical URL: https://markscanlon.co/publications/EnablingRemoteEvidenceAcquisition
Authors: Mark Scanlon
Year: 2009
PDF: https://markscanlon.co/publications/EnablingRemoteEvidenceAcquisition.pdf
Summary: This thesis presents RAFT, a system for remote acquisition of digital forensic evidence through secure data transmission and verification. RAFT enables law enforcement officers to transfer images from suspect computers to forensic labs for analysis, reducing investigation time and ensuring court-admissible evidence.


