VLDB 2026 Research / reviewers in the wild / expert
Ibrahim M. Baggili
dblp:87/5617 · also Ibrahim Abe Baggili, Ibrahim Baggili
· DBLP profile ↗
40ranked-venue papers
5as first author
18since 2021 · last 2026
0000-0002-9574-9537ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 38 · 5 first-author · 17 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 since 2021Artificial intelligence and machine learning · 1Databases, data management, data science and information retrieval · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Liar, Liar, Headset on Fire: Understanding the Effects of Deception Attacks on Decision-Making in a Mixed Reality GameabstractWe examine the impact of deception in Mixed Reality (MR), focusing on how subversive elements affect user behavior and decision-making. In a controlled experiment with 250 participants playing a Whac-A-Mole MR game, we introduced three types of deception attacks: (1) a Physiological Spoofing Attack intended to foster false beliefs about bodily state; (2) a Gaslighting Attack that evokes false interpretations about bodily state by inducing doubt; and (3) a Disinformation Attack that presents false information by mimicking game- and system-level notifications to influence decision-making. We measured the effects on game performance, cognitive load, and behavioral responses. Results reveal that Physiological Spoofing and Gaslighting Attacks led to behavioral adjustments, though these effects diminished over time. Alternatively, false information presented in the Disinformation Attack adversely influenced decision-making. Our findings highlight the vulnerability of MR users to deception attacks and emphasize the need for adaptive security measures to mitigate these risks. Ali Teymourian, Taha Gharaibeh, Ibrahim M. Baggili, Andrew M. Webb 0001 |
CHI | 3 |
| 2025 | SoK: Come Together - Unifying Security, Information Theory, and Cognition for a Mixed Reality Deception Attack Ontology & Analysis Framework
Ali Teymourian, Andrew M. Webb 0001, Taha Gharaibeh, Arushi Ghildiyal, Ibrahim M. Baggili |
USENIX Security Symposium | 5 |
| 2024 | Give Me Steam: A Systematic Approach for Handling Stripped Symbols in Memory Forensics of the Steam DeckabstractThe Steam Deck, developed by Valve, combines handheld gaming with desktop functionality, creating unique challenges for digital forensics due to its Linux-based SteamOS and its stripped symbol tables. This research addresses how to conduct reliable memory forensics on the Steam Deck. Employing the Linux Memory Extractor (LiME) and Volatility 3, we acquire and analyze volatile memory, a process complicated by Steam’s stripped symbol table that obscures forensic reconstruction of memory structures. Our approach reconstructs these symbols and adapts forensic tools to the Steam Deck’s architecture. Our results include the successful generation and validation of symbol tables and the patching of profiles to align with system configurations. During gameplay, we observed a significant increase in platform-related and game-related processes, highlighting the system’s dynamic operation while gaming. These findings contribute to improving forensic methodologies for similar Linux-based devices, enhancing our capability to extract valuable forensic data from modern gaming consoles. Ruba Alsmadi, Taha Gharaibeh, Andrew M. Webb 0001, Ibrahim M. Baggili |
ARES | 4 |
| 2024 | Blue Skies from (X?s) Pain: A Digital Forensic Analysis of Threads and BlueskyabstractThis paper presents a comprehensive digital forensic analysis of the social media platforms Threads and Bluesky, juxtaposing their unique architectures and functionalities against X. This research fills a gap in the extant literature by offering a novel forensic analysis of Threads and Bluesky, based on established techniques. Mobile forensic analysis of both platforms yielded few results. Network analysis produced a variety of artifacts for Bluesky, including plaintext passwords. Threads proved to be robust, and a presentation of its security and API flow is presented. A detailed depiction of the forensic analysis performed for this paper is presented to aid future investigators. Joseph Brown, Abdur Rahman Onik, Ibrahim M. Baggili |
ARES | 3 |
| 2024 | Don't, Stop, Drop, Pause: Forensics of CONtainer CheckPOINTs (ConPoint)abstractIn the rapidly evolving landscape of cloud computing, containerization technologies such as Docker and Kubernetes have become instrumental in deploying, scaling, and managing applications. However, these containers pose unique challenges for memory forensics due to their ephemeral nature. As memory forensics is a crucial aspect of incident response, our work combats these challenges by developing a deeper understanding of the containers, leading to the development of a novel, scalable tool for container memory forensics. Through experimental and computational analyses, our work investigates the forensic capabilities of container checkpoints, which capture a container’s state at a specific moment in time. We introduce ConPoint, a tool created for the collection of these checkpoints. We focused on three primary research questions: What is the most forensically sound approach for checkpointing a container’s memory and filesystem?, How long does the volatile memory evidence reside in memory?, and How long does the checkpoint process take on average to complete? Our approach successfully captured checkpoints and retrieved artifacts generated at runtime from container checkpoints. We found that digital evidence in a container’s volatile memory can persist during idle states, yet gradually diminishes over time and is entirely lost when the container shuts down. Our experiments determined the average time for checkpointing a container to be 0.537 seconds by acquiring a total of (n = 45) checkpoints from containers running different databases. The proposed work demonstrates the pragmatic feasibility of implementing checkpointing as an overarching strategy for container memory forensics and incident response. Taha Gharaibeh, Steven Seiden 0002, Mohamed Abouelsaoud, Elias Bou-Harb, Ibrahim M. Baggili |
ARES | 5 |
| 2024 | Forensic Analysis of Artifacts from Microsoft's Multi-Agent LLM Platform AutoGenabstractInnovations in technology bring new challenges that need to be addressed, especially in the field of technical artifact discovery and analysis that enables digital forensic practitioners. Digital forensic analysis of these innovations is a constant challenge for digital investigators. In the rapidly evolving landscape of Artificial Intelligence (AI), keeping up with the digital forensic analysis of each new tool is a difficult task. New, advanced Large Language Model (LLM)s can produce human-like artifacts because of their complex textual processing capabilities. One of the newest innovations is a multi-agent Large Language Model (LLM) framework by Microsoft called AutoGen. AutoGen enables the creation of a team of specialist Large Language Model (LLM)-backed agents where the agents "chat" with each other to plan, iterate, and determine when a given task is complete. Typically one of the agents represents the human user while the other agents work autonomously after the human gives each agent a responsibility on the team. Thus, from a digital forensics perspective, it is necessary to determine which artifacts are created by the human user and which artifacts are created by the autonomous agents. Analysis in this work indicates that the current implementation of AutoGen has little in artifacts for attribution outside of particular memory artifacts, yet has strong indicators of usage in disk and network artifacts. Our research provides the initial account on the digital artifacts of the Large Language Model (LLM) technology AutoGen and first artifact examination for a Large Language Model (LLM) framework. Clinton Walker, Taha Gharaibeh, Ruba Alsmadi, Cory Lloyd Hall, Ibrahim M. Baggili |
ARES | 5 |
| 2023 | Memory Forensics of the OpenDaylight Software-Defined Networking (SDN) ControllerabstractSoftware-Defined Networking (SDN) abstracts the underlying networking hardware by keeping the control plane and the data separated. SDNs use the control plane to direct network traffic, while OpenFlow switches and routers play a passive role in the system by forwarding packets. The centralization of the control plane on virtualized systems provide Digital Forensics (DF) an opportunity at acquiring and analyzing the memory of a controller. This provides forensically relevant data regarding the SDN’s operation. In our work, we examined the OpenDaylight (ODL) SDN controller to determine what forensically relevant information may be extracted from the controller’s memory. This was accomplished by creating controller memory samples with different networking configurations, and analyzing the memory samples, then constructing an SDN-Controller-Network-Discovery-Tool (SCoNDT). SCoNDT searches a memory dump for the ODL controller’s host tracker service. This service holds information on each host connected to the network, such as its internal IP address, MAC address, and the dates and times of its first and last network connections. It then generates an HTML report. SCoNDT was evaluated on memory samples with various network configurations and showed high efficacy in reconstructing the host IPs, the usernames, and hashed passwords. Abdullah Alshaya, Adam Kardorff, Christian Facundus, Ibrahim M. Baggili, Golden G. Richard III |
ARES | 4 |
| 2023 | Retruth Reconnaissance: A Digital Forensic Analysis of Truth Social
Joseph Brown, Ibrahim M. Baggili |
ICDF2C (1) | 2 |
| 2023 | Catch Me if You Can: Analysis of Digital Devices and Artifacts Used in Murder Cases
John Jankura, Hannah Catallo-Stooks, Ibrahim M. Baggili, Golden G. Richard III |
ICDF2C (1) | 3 |
| 2023 | I've Got You, Under My Skin: Biohacking Augmentation Implant Forensics
Steven Seiden 0002, Ibrahim M. Baggili, Aisha I. Ali-Gombe |
ICDF2C (2) | 2 |
| 2023 | Decoding HDF5: Machine Learning File Forensics and Data Injection
Clinton Walker, Ibrahim M. Baggili |
ICDF2C (1) | 2 |
| 2023 | Rise of the Metaverse's Immersive Virtual Reality Malware and the Man-in-the-Room Attack & Defenses
Martin Vondrácek, Ibrahim M. Baggili, Peter Casey, Mehdi Mekni |
Comput. Secur. | 2 |
| 2022 | A Quantitative Analysis of Offensive Cyber Operation (OCO) Automation ToolsabstractThe ecosystem for automated offensive security tools has grown in recent years. As more tools automate offensive security techniques via Artificial Intelligence (AI) and Machine Learning (ML), it may result in vulnerabilities due to adversarial attacks. Therefore, it is imperative that research is conducted to help understand the techniques used by these security tools. Our work explores the current state of the art in offensive security tools. First, we employ an abstract model that can be used to understand what phases of an Offensive Cyber Operation (OCO) can be automated. We then adopt a generalizable taxonomy, and apply it to automation tools (such as normal automation and the use of artificial intelligence in automation). We then curated a dataset of tools and research papers and quantitatively analyzed it. Our work resulted in a public dataset that includes analysis of (n=57) papers and OCO tools that are mapped to the the MITRE ATT&CK Framework enterprise techniques, applicable phases of our OCO model, and the details of the automation technique. The results show a need for a granular expansion on the ATT&CK Exploit Public-Facing application technique. A critical finding is that most OCO tools employed Simple Rule Based automation, hinting at a lucrative research opportunity for the use of Artificial Intelligence (AI) and Machine Learning (ML) in future OCO tooling. Samuel Zurowski, George Lord, Ibrahim M. Baggili |
ARES | 3 |
| 2021 | Forensic Artifact Finder (ForensicAF): An Approach & Tool for Leveraging Crowd-Sourced Curated Forensic ArtifactsabstractCurrent methods for artifact analysis and understanding depend on investigator expertise. Experienced and technically savvy examiners spend a lot of time reverse engineering applications while attempting to find crumbs they leave behind on systems. This takes away valuable time from the investigative process, and slows down forensic examination. Furthermore, when specific artifact knowledge is gained, it stays within the respective forensic units. To combat these challenges, we present ForensicAF, an approach for leveraging curated, crowd-sourced artifacts from the Artifact Genome Project (AGP). The approach has the overarching goal of uncovering forensically relevant artifacts from storage media. We explain our approach and construct it as an Autopsy Ingest Module. Our implementation focused on both File and Registry artifacts. We evaluated ForensicAF using systematic and random sampling experiments. While ForensicAF showed consistent results with registry artifacts across all experiments, it also revealed that deeper folder traversal yields more File Artifacts during data source ingestion. When experiments were conducted on case scenario disk images without apriori knowledge, ForensicAF uncovered artifacts of forensic relevance that help in solving those scenarios. We contend that ForensicAF is a promising approach for artifact extraction from storage media, and its utility will advance as more artifacts are crowd-sourced by AGP. Tyler Balon, Krikor Herlopian, Ibrahim M. Baggili, Cinthya Grajeda |
ARES | 3 |
| 2021 | Forensicast: A Non-intrusive Approach & Tool For Logical Forensic Acquisition & Analysis of The Google Chromecast TVabstractThe era of traditional cable Television (TV) is swiftly coming to an end. People today subscribe to a multitude of streaming services. Smart TVs have enabled a new generation of entertainment, not only limited to constant on-demand streaming as they now offer other features such as web browsing, communication, gaming etc. These functions have recently been embedded into a small IoT device that can connect to any TV with High Definition Multimedia Interface (HDMI) input known as Google Chromecast TV. Its wide adoption makes it a treasure trove for potential digital evidence. Our work is the primary source on forensically interrogating Chromecast TV devices. We found that the device is always unlocked, allowing extraction of application data through the backup feature of Android Debug Bridge (ADB) without device root access. We take advantage of this minimal access and demonstrate how a series of artifacts can stitch together a detailed timeline, and we automate the process by constructing Forensicast – a Chromecast TV forensic acquisition and timelining tool. Our work targeted (n=112) of the most popular Android TV applications including 69% (77/112) third party applications and 31% (35/112) system applications. 65% (50/77) third party applications allowed backup, and of those 90% (45/50) contained time-based identifiers, 40% (20/50) invoked some form of logs/activity monitoring, 50% (25/50) yielded some sort of token/cookie, 8% (4/50) resulted in a device ID, 26% (13/50) produced a user ID, and 24% (12/50) created other information. 26% (9/35) system applications provided meaningful artifacts, 78% (7/9) provided time based identifiers, 22% (2/9) involved some form of logs/activity monitoring, 22% (2/9) yielded some form of token/cookie data, 22% (2/9) resulted in a device ID, 44% (4/9) provided a user ID, and 33% (3/9) created other information. Our findings also illustrated common artifacts found in applications that are related to developer and advertising utilities, mainly WebView, Firebase, and Facebook Analytics. Future work and open research problems are shared. Alex Sitterer, Nicholas Dubois, Ibrahim M. Baggili |
ARES | 3 |
| 2021 | On Exploring the Sub-domain of Artificial Intelligence (AI) Model Forensics
Tiffanie Edwards, Syria McCullough, Mohamed Nassar 0001, Ibrahim M. Baggili |
ICDF2C | 4 |
| 2021 | Auto-Parser: Android Auto and Apple CarPlay Forensics
Andrew Mahr, Robert Serafin, Cinthya Grajeda, Ibrahim M. Baggili |
ICDF2C | 4 |
| 2021 | Immersive Virtual Reality Attacks and the Human JoystickabstractThis is one of the first accounts for the security analysis of consumer immersive Virtual Reality (VR) systems. This work breaks new ground, coins new terms, and constructs proof of concept implementations of attacks related to immersive VR. Our work used the two most widely adopted immersive VR systems, the HTC Vive, and the Oculus Rift. More specifically, we were able to create attacks that can potentially disorient users, turn their Head Mounted Display (HMD) camera on without their knowledge, overlay images in their field of vision, and modify VR environmental factors that force them into hitting physical objects and walls. Finally, we illustrate through a human participant deception study the success of being able to exploit VR systems to control immersed users and move them to a location in physical space without their knowledge. We term this the Human Joystick Attack. We conclude our work with future research directions and ways to enhance the security of these systems. Peter Casey, Ibrahim M. Baggili, Ananya Yarramreddy |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2019 | Map My Murder: A Digital Forensic Study of Mobile Health and Fitness ApplicationsabstractThe ongoing popularity of health and fitness applications catalyzes the need for exploring forensic artifacts produced by them. Sensitive Personal Identifiable Information (PII) is requested by the applications during account creation. Augmenting that with ongoing user activities, such as the user's walking paths, could potentially create exculpatory or inculpatory digital evidence. We conducted extensive manual analysis and explored forensic artifacts produced by (n = 13) popular Android mobile health and fitness applications. We also developed and implemented a tool that aided in the timely acquisition and identification of artifacts from the examined applications. Additionally, our work explored the type of data that may be collected from health and fitness web platforms, and Web Scraping mechanisms for data aggregation. The results clearly show that numerous artifacts may be recoverable, and that the tested web platforms pose serious privacy threats. Courtney Hassenfeldt, Shabana Baig, Ibrahim M. Baggili |
ARES | 3 |
| 2019 | IoT Ignorance is Digital Forensics Research Bliss: A Survey to Understand IoT Forensics Definitions, Challenges and Future Research DirectionsabstractInteractions with IoT devices generates vast amounts of personal data that can be used as a source of evidence in digital investigations. Currently, there are many challenges in IoT forensics such as the difficulty in acquiring and analysing IoT data/devices and the lack IoT forensic tools. Besides technical challenges, there are many concepts in IoT forensics that have yet to be explored such as definitions, experience and capability in the analysis of IoT data/devices and current/future challenges. A deeper understanding of these various concepts will help progress the field. To achieve this goal, we conducted a survey which received 70 responses and provided the following results: (1) IoT forensics is a sub-domain of digital forensics, but it is undecided what domains are included; (2) practitioners are already having to examine IoT devices even though they felt undertrained; (3) requirements for technical training, software and education are non-existent; (4) high priority on research should be to develop IoT forensic tools, how to preserve volatile data and methods to identify and acquire data from the cloud; (5) improvements to forensic tools should be aimed at data acquisition (imaging) and device disassembly / forensic process; (6) practitioners’ perspectives on research direction differ slightly to non-practitioners in that the focus should be on breaking encryption on IoT devices rather than focus on cloud data forensics; (7) future research should focus on developing initiatives and strategies to overcome data encryption and trail obfuscation in the cloud and ongoing development of IoT forensic tools. The responses to the survey question on the definition of IoT forensics helped us formulate a working definition. This has provided a clearer understanding of the subject, which will help further advance the research area. Tina Wu, Frank Breitinger, Ibrahim M. Baggili |
ARES | 3 |
| 2018 | I Know What You Did Last Summer: Your Smart Home Internet of Things and Your iPhone Forensically Ratting You OutabstractThe adoption of smart home Internet of Things (IoT) devices continues to grow. What if your devices can snitch on you and let us know where you are at any given point in time? In this work we examined the forensic artifacts produced by Nest devices, and in specific, we examined the logical backup structure of an iPhone used to control a Nest thermostat, Nest Indoor Camera and a Nest Outdoor Camera. We also integrated the Google Home Mini as another method of controlling the studied Smart Home devices. Our work is the primary account for the examination of Nest artifacts produced by an iPhone, and is also the first open source research to produce a usable forensics tool we name the Forensic Evidence Acquisition and Analysis System (FEAAS). FEAAS consolidates evidentiary data into a readable report that can infer user events (like entering or leaving a home) and what triggered an event (whether it was the Google Assistant through a voice command, or the use of an iPhone application). Our results are important for the advancement of digital forensics, as there are cases starting to emerge in which smart home IoT devices have already been used as culpatory evidence. Gokila Dorai, Shiva Houshmand, Ibrahim M. Baggili |
ARES | 3 |
| 2018 | Digital Forensics in the Next Five YearsabstractCyber forensics has encountered major obstacles over the last decade and is at a crossroads. This paper presents data that was obtained during the National Workshop on Redefining Cyber Forensics (NWRCF) on May 23-24, 2017 supported by the National Science Foundation and organized by the University of New Haven. Qualitative and quantitative data were analyzed from twenty-four cyber forensics expert panel members. This work identified important themes that need to be addressed by the community, focusing on (1) where the domain currently is; (2) where it needs to go and; (3) steps needed to improve it. Furthermore, based on the results, we articulate (1) the biggest anticipated challenges the domain will face in the next five years; (2) the most important cyber forensics research opportunities in the next five years and; (3) the most important job-ready skills that need to be addressed by higher education curricula over the next five years. Lastly, we present the key issues and recommendations deliberated by the expert panel. Overall results indicated that a more active and coherent group needs to be formed in the cyber forensics community, with opportunities for continuous reassessment and improvement processes in place. Laoise Luciano, Ibrahim M. Baggili, Mateusz Topor, Peter Casey, Frank Breitinger |
ARES | 2 |
| 2018 | If I Had a Million Cryptos: Cryptowallet Application Analysis and a Trojan Proof-of-Concept
Trevor Haigh, Frank Breitinger, Ibrahim M. Baggili |
ICDF2C | 3 |
| 2018 | AndroParse - An Android Feature Extraction Framework and Dataset
Robert Schmicker, Frank Breitinger, Ibrahim M. Baggili |
ICDF2C | 3 |
| 2017 | Forensic State Acquisition from Internet of Things (FSAIoT): A general framework and practical approach for IoT forensics through IoT device state acquisitionabstractIoT device forensics is a difficult problem given that manufactured IoT devices are not standardized, many store little to no historical data, and are always connected; making them extremely volatile. The goal of this paper was to address these challenges by presenting a primary account for a general framework and practical approach we term Forensic State Acquisition from Internet of Things (FSAIoT). We argue that by leveraging the acquisition of the state of IoT devices (e.g. if an IoT lock is open or locked), it becomes possible to paint a clear picture of events that have occurred. To this end, FSAIoT consists of a centralized Forensic State Acquisition Controller (FSAC) employed in three state collection modes: controller to IoT device, controller to cloud, and controller to controller. We present a proof of concept implementation using openHAB -- a device agnostic open source IoT device controller -- and self-created scripts, to resemble a FSAC implementation. Our proof of concept employed an Insteon IP Camera as a controller to device test, an Insteon Hub as a controller to controller test, and a nest thermostat for a a controller to cloud test. Our findings show that it is possible to practically pull forensically relevant state data from IoT devices. Future work and open research problems are shared. Christopher Meffert, Devon Clark, Ibrahim M. Baggili, Frank Breitinger |
ARES | 3 |
| 2017 | An Overview of the Usage of Default Passwords
Brandon Knieriem, Philip Levine, Frank Breitinger, Ibrahim M. Baggili |
ICDF2C | 5 |
| 2017 | Breaking into the vault: Privacy, security and forensic analysis of Android vault applications
Ibrahim M. Baggili, Frank Breitinger |
Comput. Secur. | 2 |
| 2016 | A cyber forensics needs analysis survey: Revisiting the domain's needs a decade later
Vikram S. Harichandran, Frank Breitinger, Ibrahim M. Baggili, Andrew Marrington |
Comput. Secur. | 3 |
| 2015 | Watch What You Wear: Preliminary Forensic Analysis of Smart WatchesabstractThis work presents preliminary forensic analysis of two popular smart watches, the Samsung Gear 2 Neo and LG G. These wearable computing devices have the form factor of watches and sync with smart phones to display notifications, track footsteps and record voice messages. We posit that as smart watches are adopted by more users, the potential for them becoming a haven for digital evidence will increase thus providing utility for this preliminary work. In our work, we examined the forensic artifacts that are left on a Samsung Galaxy S4 Active phone that was used to sync with the Samsung Gear 2 Neo watch and the LG G watch. We further outline a methodology for physically acquiring data from the watches after gaining root access to them. Our results show that we can recover a swath of digital evidence directly form the watches when compared to the data on the phone that is synced with the watches. Furthermore, to root the LG G watch, the watch has to be reset to its factory settings which is alarming because the process may delete data of forensic relevance. Although this method is forensically intrusive, it may be used for acquiring data from already rooted LG watches. It is our observation that the data at the core of the functionality of at least the two tested smart watches, messages, health and fitness data, e-mails, contacts, events and notifications are accessible directly from the acquired images of the watches, which affirms our claim that the forensic value of evidence from smart watches is worthy of further study and should be investigated both at a high level and with greater specificity and granularity. Ibrahim M. Baggili, Jeff Oduro, Kyle Anthony, Frank Breitinger, Glenn McGee |
ARES | 1 |
| 2014 | Performance of a Logical, Five- Phase, Multithreaded, Bootable Triage Tool
Ibrahim M. Baggili, Andrew Marrington, Yasser Jafar |
IFIP Int. Conf. Digital Forensics | 1 |
| 2013 | Towards a unified agent-based approach for real time computer forensic evidence collectionabstractIn this paper we present preliminary results for a real time computer forensics agent that logs computer activity on a Windows computer system for subsequent forensic investigation. The agent, which is developed using the .NET 2010 framework includes six modules. Each module is dedicated to keep track and record a specific category of user activities. For instance, the Windows Event Watcher logs the Windows OS events and the Removable Devices Detector logs any external devices that are plugged in or removed from a system. Currently, the aforementioned two modules are implemented and tested with carefully designed scenarios using Windows XP and Windows 7 operating systems. Shadi Al Awawdeh, Ibrahim M. Baggili, Andrew Marrington, Farkhund Iqbal |
ASONAM | 2 |
| 2013 | Amazon Kindle Fire HD Forensics
Asif Iqbal 0003, Hanan Al Obaidli, Andrew Marrington, Ibrahim M. Baggili |
ICDF2C | 4 |
| 2013 | Computer Profiling for Preliminary Forensic Examination
Andrew Marrington, Farkhund Iqbal, Ibrahim M. Baggili |
ICDF2C | 3 |
| 2012 | Research Trends in Digital Forensic Science: An Empirical Analysis of Published Research
Ibrahim M. Baggili, Afrah BaAbdallah, Deena Al-Safi, Andrew Marrington |
ICDF2C | 1 |
| 2012 | Cybercrime, Censorship, Perception and Bypassing Controls: An Exploratory Study
Ibrahim M. Baggili, Moza Al Shamlan, Bedoor Al Jabri, Ayesha Al Zaabi |
ICDF2C | 1 |
| 2012 | BlackBerry PlayBook Backup Forensic Analysis
Mohamed Al Marzougy, Ibrahim M. Baggili, Andrew Marrington |
ICDF2C | 2 |
| 2010 | Defining a Standard for Reporting Digital Evidence Items in Computer Forensic Tools
Hamda Bariki, Mariam Hashmi, Ibrahim M. Baggili |
ICDF2C | 3 |
| 2010 | A Simple Cost-Effective Framework for iPhone Forensic Analysis
Mohammad Iftekhar Husain, Ibrahim M. Baggili, Ramalingam Sridhar |
ICDF2C | 2 |
| 2010 | Towards More Secure Biometric Readers for Effective Digital Forensic Investigation
Zouheir Trabelsi, Mohamed Al-Hemairy, Ibrahim M. Baggili, Saad Ali Amin |
ICDF2C | 3 |
| 2009 | SMIRK: SMS Management and Information Retrieval Kit
Ibrahim M. Baggili, Ashwin Mohan, Marcus K. Rogers |
ICDF2C | 1 |