Detailed Information

Cited 0 time in webofscience Cited 0 time in scopus
Metadata Downloads

CBR-Based Decision Support Methodology for Cybercrime Investigation: Focused on the Data-Driven Website Defacement Analysis

Authors
Han, Mee LanKwak, Byung IlKim, Huy Kang
Issue Date
20-12월-2019
Publisher
WILEY-HINDAWI
Citation
SECURITY AND COMMUNICATION NETWORKS, v.2019
Indexed
SCIE
SCOPUS
Journal Title
SECURITY AND COMMUNICATION NETWORKS
Volume
2019
URI
https://scholar.korea.ac.kr/handle/2021.sw.korea/60888
DOI
10.1155/2019/1901548
ISSN
1939-0114
Abstract
Criminal pro,ling is a useful technique to identify the most plausible suspects based on the evidence discovered at the crime scene. Similar to offline criminal pro,ling, in-depth pro,ling for cybercrime investigation is useful in analysing cyberattacks and for speculating on the identities of the criminals. Every cybercrime committed by the same hacker or hacking group has unique traits such as attack purpose, attack methods, and target. These unique traits are revealed in the evidence of cybercrime; in some cases, these unique traits are well hidden in the evidence such that it cannot be easily perceived. Therefore, a complete analysis of several factors concerning cybercrime can provide an investigator with concrete evidence to attribute the attacks and narrow down the scope of the criminal data and grasp the criminals in the end. We herein propose a decision support methodology based on the case-based reasoning (CBR) for cybercrime investigation. This study focuses on the massive data-driven analysis of website defacement. Our primary aim in this study is to demonstrate the practicality of the proposed methodology as a proof of concept. The assessment of website defacement was performed through the similarity measure and the clustering processing in the reasoning engine based on the CBR. Our results show that the proposed methodology that focuses on the investigation enables a better understanding and interpretation of website defacement and assists in inferring the hacker's behavioural traits from the available evidence concerning website defacement. The results of the case studies demonstrate that our proposed methodology is beneficial for understanding the behaviour and motivation of the hacker and that our proposed data-driven analytic methodology can be utilized as a decision support system for cybercrime investigation.
Files in This Item
There are no files associated with this item.
Appears in
Collections
School of Cyber Security > Department of Information Security > 1. Journal Articles

qrcode

Items in ScholarWorks are protected by copyright, with all rights reserved, unless otherwise indicated.

Altmetrics

Total Views & Downloads

BROWSE