Frank Breitinger

dblp:66/9068 · DBLP profile ↗
← Back
22ranked-venue papers
7as first author
3since 2021 · last 2024
0000-0001-5261-4600ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 22 · 7 first-author · 3 since 2021
YearPublicationVenuePosition
2024 An Experimental Assessment of Inconsistencies in Memory Forensics
abstract
Memory forensics is concerned with the acquisition and analysis of copies of volatile memory (memory dumps). Based on an empirical assessment of observable inconsistencies in 360 memory dumps of a running Linux system, we confirm a state of overwhelming inconsistency in memory forensics: almost a third of these dumps had an empty process list and was therefore obviously incomplete. Out of those dumps that were analyzable, almost every second dump showed some form of inconsistency that potentially impacts the interpretation of the dump in a forensic investigation. These results are based on a new way to estimate the level of causal consistency of a memory dump. The factors influencing these inconsistencies are less clear but in general correlate with the level of concurrency (system load and number of threads).
Jenny Ottmann, Frank Breitinger, Felix C. Freiling
ACM Trans. Priv. Secur.2
2023 Towards AI forensics: Did the artificial intelligence system do it?
abstract
Artificial intelligence (AI) makes decisions impacting our daily lives in an increasingly autonomous manner. Their actions might cause accidents, harm, or, more generally, violate regulations. Determining whether an AI caused a specific event and, if so, what triggered the AI’s action, are key forensic questions. We provide a conceptualization of the problems and strategies for forensic investigation. We focus on AI that is potentially “malicious by design” and gray box analysis. Our evaluation using convolutional neural networks illustrates challenges and ideas for identifying malicious AI.
Johannes Schneider 0002, Frank Breitinger
J. Inf. Secur. Appl.2
2022 The role of national cybersecurity strategies on the improvement of cybersecurity education
Saleh H. Aldaajeh, Heba Saleous, Saed Alrabaee, Ezedin Barka, Frank Breitinger, Kim-Kwang Raymond Choo
Comput. Secur.5
2020 A survey on smartphone user's security choices, awareness and education
Frank Breitinger, Ryan Tully-Doyle, Courtney Hassenfeldt
Comput. Secur.1
2020 The impact of excluding common blocks for approximate matching
Vitor Hugo Galhardo Moia, Frank Breitinger, Marco Aurélio Amaral Henriques
Comput. Secur.2
2019 IoT Ignorance is Digital Forensics Research Bliss: A Survey to Understand IoT Forensics Definitions, Challenges and Future Research Directions
abstract
Interactions with IoT devices generates vast amounts of personal data that can be used as a source of evidence in digital investigations. Currently, there are many challenges in IoT forensics such as the difficulty in acquiring and analysing IoT data/devices and the lack IoT forensic tools. Besides technical challenges, there are many concepts in IoT forensics that have yet to be explored such as definitions, experience and capability in the analysis of IoT data/devices and current/future challenges. A deeper understanding of these various concepts will help progress the field. To achieve this goal, we conducted a survey which received 70 responses and provided the following results: (1) IoT forensics is a sub-domain of digital forensics, but it is undecided what domains are included; (2) practitioners are already having to examine IoT devices even though they felt undertrained; (3) requirements for technical training, software and education are non-existent; (4) high priority on research should be to develop IoT forensic tools, how to preserve volatile data and methods to identify and acquire data from the cloud; (5) improvements to forensic tools should be aimed at data acquisition (imaging) and device disassembly / forensic process; (6) practitioners’ perspectives on research direction differ slightly to non-practitioners in that the focus should be on breaking encryption on IoT devices rather than focus on cloud data forensics; (7) future research should focus on developing initiatives and strategies to overcome data encryption and trail obfuscation in the cloud and ongoing development of IoT forensic tools. The responses to the survey question on the definition of IoT forensics helped us formulate a working definition. This has provided a clearer understanding of the subject, which will help further advance the research area.
Tina Wu, Frank Breitinger, Ibrahim M. Baggili
ARES2
2018 Digital Forensics in the Next Five Years
abstract
Cyber forensics has encountered major obstacles over the last decade and is at a crossroads. This paper presents data that was obtained during the National Workshop on Redefining Cyber Forensics (NWRCF) on May 23-24, 2017 supported by the National Science Foundation and organized by the University of New Haven. Qualitative and quantitative data were analyzed from twenty-four cyber forensics expert panel members. This work identified important themes that need to be addressed by the community, focusing on (1) where the domain currently is; (2) where it needs to go and; (3) steps needed to improve it. Furthermore, based on the results, we articulate (1) the biggest anticipated challenges the domain will face in the next five years; (2) the most important cyber forensics research opportunities in the next five years and; (3) the most important job-ready skills that need to be addressed by higher education curricula over the next five years. Lastly, we present the key issues and recommendations deliberated by the expert panel. Overall results indicated that a more active and coherent group needs to be formed in the cyber forensics community, with opportunities for continuous reassessment and improvement processes in place.
Laoise Luciano, Ibrahim M. Baggili, Mateusz Topor, Peter Casey, Frank Breitinger
ARES5
2018 If I Had a Million Cryptos: Cryptowallet Application Analysis and a Trojan Proof-of-Concept
Trevor Haigh, Frank Breitinger, Ibrahim M. Baggili
ICDF2C2
2018 AndroParse - An Android Feature Extraction Framework and Dataset
Robert Schmicker, Frank Breitinger, Ibrahim M. Baggili
ICDF2C2
2017 Forensic State Acquisition from Internet of Things (FSAIoT): A general framework and practical approach for IoT forensics through IoT device state acquisition
abstract
IoT device forensics is a difficult problem given that manufactured IoT devices are not standardized, many store little to no historical data, and are always connected; making them extremely volatile. The goal of this paper was to address these challenges by presenting a primary account for a general framework and practical approach we term Forensic State Acquisition from Internet of Things (FSAIoT). We argue that by leveraging the acquisition of the state of IoT devices (e.g. if an IoT lock is open or locked), it becomes possible to paint a clear picture of events that have occurred. To this end, FSAIoT consists of a centralized Forensic State Acquisition Controller (FSAC) employed in three state collection modes: controller to IoT device, controller to cloud, and controller to controller. We present a proof of concept implementation using openHAB -- a device agnostic open source IoT device controller -- and self-created scripts, to resemble a FSAC implementation. Our proof of concept employed an Insteon IP Camera as a controller to device test, an Insteon Hub as a controller to controller test, and a nest thermostat for a a controller to cloud test. Our findings show that it is possible to practically pull forensically relevant state data from IoT devices. Future work and open research problems are shared.
Christopher Meffert, Devon Clark, Ibrahim M. Baggili, Frank Breitinger
ARES4
2017 An Overview of the Usage of Default Passwords
Brandon Knieriem, Philip Levine, Frank Breitinger, Ibrahim M. Baggili
ICDF2C4
2017 Expediting MRSH-v2 Approximate Matching with Hierarchical Bloom Filter Trees
David Lillis, Frank Breitinger, Mark Scanlon
ICDF2C2
2017 Breaking into the vault: Privacy, security and forensic analysis of Android vault applications
Ibrahim M. Baggili, Frank Breitinger
Comput. Secur.3
2016 A cyber forensics needs analysis survey: Revisiting the domain's needs a decade later
Vikram S. Harichandran, Frank Breitinger, Ibrahim M. Baggili, Andrew Marrington
Comput. Secur.2
2015 Watch What You Wear: Preliminary Forensic Analysis of Smart Watches
abstract
This work presents preliminary forensic analysis of two popular smart watches, the Samsung Gear 2 Neo and LG G. These wearable computing devices have the form factor of watches and sync with smart phones to display notifications, track footsteps and record voice messages. We posit that as smart watches are adopted by more users, the potential for them becoming a haven for digital evidence will increase thus providing utility for this preliminary work. In our work, we examined the forensic artifacts that are left on a Samsung Galaxy S4 Active phone that was used to sync with the Samsung Gear 2 Neo watch and the LG G watch. We further outline a methodology for physically acquiring data from the watches after gaining root access to them. Our results show that we can recover a swath of digital evidence directly form the watches when compared to the data on the phone that is synced with the watches. Furthermore, to root the LG G watch, the watch has to be reset to its factory settings which is alarming because the process may delete data of forensic relevance. Although this method is forensically intrusive, it may be used for acquiring data from already rooted LG watches. It is our observation that the data at the core of the functionality of at least the two tested smart watches, messages, health and fitness data, e-mails, contacts, events and notifications are accessible directly from the acquired images of the watches, which affirms our claim that the forensic value of evidence from smart watches is worthy of further study and should be investigated both at a high level and with greater specificity and granularity.
Ibrahim M. Baggili, Jeff Oduro, Kyle Anthony, Frank Breitinger, Glenn McGee
ARES4
2015 How Cuckoo Filter Can Improve Existing Approximate Matching Techniques
Frank Breitinger
ICDF2C2
2014 Using Approximate Matching to Reduce the Volume of Digital Data
Frank Breitinger, Christian Winter 0001, York Yannikos, Tobias Fink, Michael Seefried
IFIP Int. Conf. Digital Forensics1
2014 Similarity Hashing Based on Levenshtein Distances
Frank Breitinger, Georg Ziroff, Steffen Lange, Harald Baier
IFIP Int. Conf. Digital Forensics1
2013 Towards a Process Model for Hash Functions in Digital Forensics
Frank Breitinger, Huajian Liu, Christian Winter 0001, Harald Baier, Alexey Rybalchenko, Martin Steinebach
ICDF2C1
2013 Reducing the Time Required for Hashing Operations
Frank Breitinger, Kaloyan Petrov
IFIP Int. Conf. Digital Forensics1
2012 Similarity Preserving Hashing: Eligible Properties and a New Algorithm MRSH-v2
Frank Breitinger, Harald Baier
ICDF2C1
2011 Performance Issues About Context-Triggered Piecewise Hashing
Frank Breitinger, Harald Baier
ICDF2C1