Training for Digital Forensics and Incident Response

Marko Schuba, Tim Höner, Sacha Hack

Human Interaction & Emerging Technologies (IHIET 2023): Artificial Intelligence & Future Applications AHFE International(2023)

引用 0|浏览0
暂无评分
摘要
The work of an digital forensics expert is far more extensive and varied today than it was just a few years ago. Especially after hacking attacks on organizations, experts in DFIR (Digital Forensics and Incident Response) come into play. In this paper, we present a learning platform that enables people to learn DFIR from scratch. To achieve this goal, the content of the learning platform was defined, evaluated and prepared with the help of experts from industry and government. For this purpose, expert interviews were conducted, which were subsequently evaluated. The results of these interviews were incorporated into initial scenarios that were implemented in individual modules on the learning platform Ilias, with a distinction being made between the basics and the main DFIR part. In the basic part, an introduction to IT forensics is offered, which is supplemented by further technical modules. This includes training in the use of the Linux operating system, which is frequently used in digital forensics, as well as the acquisition and analysis of RAM iand hard disk images. In the main part, the focus is to apply the learnings from the basic sections and to enhance them with incident related knowledge for DFIR projects, in which digital forensics experts gather and analyse evidence on various systems of the attacked organizations by searching and gathering so-called IoCs (Indicators of Compromise) from log files and other sources. Once the analysis part is complete, and all evidence has been collected, cleanup, recovery and restart of systems may take place, which is handled in the last section of the main training module.
更多
查看译文
关键词
digital forensics,training
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要