EDBT 2026 Demo / reviewers in the wild / expert
Mark Scanlon
dblp:88/9673
· DBLP profile ↗
19ranked-venue papers
5as first author
3since 2021 · last 2024
0000-0002-6581-7164ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 18 · 4 first-author · 3 since 2021Computer networks · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | A comprehensive evaluation on the benefits of context based password cracking for digital forensicsabstractPassword-based authentication systems have many weaknesses, yet they remain overwhelmingly used and their announced disappearance is still undated. The system admin overcomes the imperfection by skilfully enforcing a strong password policy and sane password management on the server side. But in the end, the user behind the password is still responsible for the password’s strength. A poor choice can have dramatic consequences for the user or even for the service behind, especially considering critical infrastructure. On the other hand, law enforcement can benefit from a suspect’s weak decisions to recover digital content stored in an encrypted format. Generic password cracking procedures can support law enforcement in this matter — however, these approaches quickly demonstrate their limitations. This article proves that more targeted approaches can be used in combination with traditional strategies to increase the likelihood of success when contextual information is available and can be exploited. Aikaterini Kanta, Iwen Coisel, Mark Scanlon |
J. Inf. Secur. Appl. | 3 |
| 2022 | Deep Learning Based Network Intrusion Detection System for Resource-Constrained Environments
Syed Rizvi 0002, Mark Scanlon, Jimmy McGibney, John Sheppard 0002 |
ICDF2C | 2 |
| 2021 | PCWQ: A Framework for Evaluating Password Cracking Wordlist Quality
Aikaterini Kanta, Iwen Coisel, Mark Scanlon |
ICDF2C | 3 |
| 2020 | SoK: exploring the state of the art and the future potential of artificial intelligence in digital forensic investigationabstractMulti-year digital forensic backlogs have become commonplace in law enforcement agencies throughout the globe. Digital forensic investigators are overloaded with the volume of cases requiring their expertise compounded by the volume of data to be processed. Artificial intelligence is often seen as the solution to many big data problems. This paper summarises existing artificial intelligence based tools and approaches in digital forensics. Automated evidence processing leveraging artificial intelligence based techniques shows great promise in expediting the digital forensic analysis process while increasing case processing capacities. For each application of artificial intelligence highlighted, a number of current challenges and future potential impact is discussed. Xiaoyu Du 0003, Christopher James Hargreaves, John Sheppard 0002, Felix Anda, Asanka P. Sayakkara, Nhien-An Le-Khac, Mark Scanlon |
ARES | 7 |
| 2020 | Retracing the Flow of the Stream: Investigating Kodi Streaming Services
Samuel Todd Bromley, John Sheppard 0002, Mark Scanlon, Nhien-An Le-Khac |
ICDF2C | 3 |
| 2019 | Improving Borderline Adulthood Facial Age Estimation through Ensemble LearningabstractAchieving high performance for facial age estimation with subjects in the borderline between adulthood and non-adulthood has always been a challenge. Several studies have used different approaches from the age of a baby to an elder adult and different datasets have been employed to measure the mean absolute error (MAE) ranging between 1.47 to 8 years. The weakness of the algorithms specifically in the borderline has been a motivation for this paper. In our approach, we have developed an ensemble technique that improves the accuracy of underage estimation in conjunction with our deep learning model (DS13K) that has been fine-tuned on the Deep Expectation (DEX) model. We have achieved an accuracy of 68% for the age group 16 to 17 years old, which is 4 times better than the DEX accuracy for such age range. We also present an evaluation of existing cloud-based and offline facial age prediction services, such as Amazon Rekognition, Microsoft Azure Cognitive Services, How-Old.net and DEX. Felix Anda, David Lillis, Aikaterini Kanta, Brett A. Becker, Elias Bou-Harb, Nhien-An Le-Khac, Mark Scanlon |
ARES | 7 |
| 2019 | Methodology for the Automated Metadata-Based Classification of Incriminating Digital Forensic ArtefactsabstractThe ever increasing volume of data in digital forensic investigation is one of the most discussed challenges in the field. Usually, most of the file artefacts on seized devices are not pertinent to the investigation. Manually retrieving suspicious files relevant to the investigation is akin to finding a needle in a haystack. In this paper, a methodology for the automatic prioritisation of suspicious file artefacts (i.e., file artefacts that are pertinent to the investigation) is proposed to reduce the manual analysis effort required. This methodology is designed to work in a human-in-the-loop fashion. In other words, it predicts/recommends that an artefact is likely to be suspicious rather than giving the final analysis result. A supervised machine learning approach is employed, which leverages the recorded results of previously processed cases. The process of features extraction, dataset generation, training and evaluation are presented in this paper. In addition, a toolkit for data extraction from disk images is outlined, which enables this method to be integrated with the conventional investigation process and work in an automated fashion. Xiaoyu Du 0003, Mark Scanlon |
ARES | 2 |
| 2018 | Accuracy Enhancement of Electromagnetic Side-Channel Attacks on Computer MonitorsabstractElectromagnetic noise emitted from running computer displays modulates information about the picture frames being displayed on screen. Attacks have been demonstrated on eavesdropping computer displays by utilising these emissions as a side-channel vector. The accuracy of reconstructing a screen image depends on the emission sampling rate and bandwidth of the attackers signal acquisition hardware. The cost of radio frequency acquisition hardware increases with increased supported frequency range and bandwidth. A number of enthusiast-level, affordable software defined radio equipment solutions are currently available facilitating a number of radio-focused attacks at a more reasonable price point. This work investigates three accuracy influencing factors, other than the sample rate and bandwidth, namely noise removal, image blending, and image quality adjustments, that affect the accuracy of monitor image reconstruction through electromagnetic side-channel attacks. Asanka P. Sayakkara, Nhien-An Le-Khac, Mark Scanlon |
ARES | 3 |
| 2018 | Solid State Drive Forensics: Where Do We Stand?
John Vieyra, Mark Scanlon, Nhien-An Le-Khac |
ICDF2C | 2 |
| 2018 | Enabling Non-Expert Analysis OF Large Volumes OF Intercepted Network Traffic
Erwin van de Wiel, Mark Scanlon, Nhien-An Le-Khac |
IFIP Int. Conf. Digital Forensics | 2 |
| 2017 | Expediting MRSH-v2 Approximate Matching with Hierarchical Bloom Filter Trees
David Lillis, Frank Breitinger, Mark Scanlon |
ICDF2C | 3 |
| 2015 | Overview of the Forensic Investigation of Cloud ServicesabstractCloud Computing is a commonly used, yet ambiguous term, which can be used to refer to a multitude of differing dynamically allocated services. From a law enforcement and forensic investigation perspective, cloud computing can be thought of as a double edged sword. While on one hand, the gathering of digital evidence from cloud sources can bring with it complicated technical and cross-jurisdictional legal challenges. On the other, the employment of cloud storage and processing capabilities can expedite the forensics process and focus the investigation onto pertinent data earlier in an investigation. This paper examines the state-of-the-art in cloud-focused, digital forensic practises for the collection and analysis of evidence and an overview of the potential use of cloud technologies to provide Digital Forensics as a Service. Jason Farina, Mark Scanlon, Nhien-An Le-Khac, M. Tahar Kechadi |
ARES | 2 |
| 2015 | Towards the Forensic Identification and Investigation of Cloud Hosted Servers through Non-Invasive WiretapsabstractWhen conducting modern cybercrime investigations, evidence has often to be gathered from computer systems located at cloud-based data centres of hosting providers. In cases where the investigation cannot rely on the cooperation of the hosting provider, or where documentation is not available, investigators can often find the identification of which distinct server among many is of interest difficult and extremely time consuming. To address the problem of identifying these servers, in this paper a new approach to rapidly and reliably identify these cloud hosting computer systems is presented. In the outlined approach, a handheld device composed of an embedded computer combined with a method of undetectable interception of Ethernet based communications is presented. This device is tested and evaluated, and a discussion is provided on its usefulness in identifying of server of interest to an investigation. Hessel Schut, Mark Scanlon, Jason Farina, Nhien-An Le-Khac |
ARES | 2 |
| 2015 | Forensic Analysis and Remote Evidence Recovery from Syncthing: An Open Source Decentralised File Synchronisation Utility
Conor Quinn, Mark Scanlon, Jason Farina, M. Tahar Kechadi |
ICDF2C | 2 |
| 2015 | Network investigation methodology for BitTorrent Sync: A Peer-to-Peer based file synchronisation service
Mark Scanlon, Jason Farina, M. Tahar Kechadi |
Comput. Secur. | 1 |
| 2014 | BitTorrent Sync: Network Investigation MethodologyabstractThe volume of personal information and data most Internet users find themselves amassing is ever increasing, and the fast pace of the modern world results in most people requiring instant access to their files. Millions of these users turn to cloudbased file synchronisation services, such as Dropbox, Microsoft SkyDrive, Apple iCloud and Google Drive, to enable "alwayson" access to their most up-to-date data from any computer or mobile device with an Internet connection. The prevalence of recent articles regarding invasion of privacy issues and data protection breaches in the media has caused many to review their online personal data security practices. To provide an alternative to cloud-based file backup and synchronisation, BitTorrent Inc. released an alternative cloudless file backup and synchronisation service, named BitTorrent Sync in April 2013. BitTorrent Sync's popularity rose dramatically throughout 2013, reaching over two million active users by the end of the year. This paper outlines a number of scenarios where the network investigation of the service may prove invaluable as part of a digital forensic investigation. An investigation methodology is proposed outlining the required steps involved in retrieving digital evidence from the network and the results from a proof of concept investigation are presented. Mark Scanlon, Jason Farina, M. Tahar Kechadi |
ARES | 1 |
| 2014 | An analysis of BitTorrent cross-swarm peer participation and geolocational distributionabstractPeer-to-Peer (P2P) file-sharing is becoming increasingly popular in recent years. In 2012, it was reported that P2P traffic consumed over 5,374 petabytes per month, which accounted for approximately 20.5% of consumer internet traffic. TV is the popular content type on The Pirate Bay (the world's largest BitTorrent indexing website). In this paper, an analysis of the swarms of the most popular pirated TV shows is conducted. The purpose of this data gathering exercise is to enumerate the peer distribution at different geolocational levels, to measure the temporal trend of the swarm and to discover the amount of cross-swarm peer participation. Snapshots containing peer related information involved in the unauthorised distribution of this content were collected at a high frequency resulting in a more accurate landscape of the total involvement. The volume of data collected throughout the monitoring of the network exceeded 2 terabytes. The presented analysis and the results presented can aid in network usage prediction, bandwidth provisioning and future network design. Mark Scanlon, Huijie Shen |
ICCCN | 1 |
| 2013 | Universal Peer-to-Peer Network Investigation FrameworkabstractPeer-to-Peer (P2P) networking has fast become a useful technological advancement for a vast range of cyber criminal activities. Cyber crimes from copyright infringement and spamming, to serious, high financial impact crimes, such as fraud, distributed denial of service attacks (DDoS) and phishing can all be aided by applications and systems based on the technology. The requirement for investigating P2P based systems is not limited to the more well known cyber crimes listed above, as many more legitimate P2P based applications may also be pertinent to a digital forensic investigation, e.g., VoIP and instant messaging communications, etc. Investigating these networks has become increasingly difficult due to the broad range of network topologies and the ever increasing and evolving range of P2P based applications. This paper introduces the Universal Peer-to-Peer Network Investigation Framework (UP2PNIF), a framework which enables significantly faster and less labour intensive investigation of newly discovered P2P networks through the exploitation of the commonalities in network functionality. In combination with a reference database of known network protocols and characteristics, it is envisioned that any known P2P network can be instantly investigated using the framework. The framework can intelligently determine the best methodology dependant on the focus of the investigation resulting in a significantly expedited evidence gathering process. Mark Scanlon, M. Tahar Kechadi |
ARES | 1 |
| 2009 | Online Acquisition of Digital Forensic Evidence
Mark Scanlon, M. Tahar Kechadi |
ICDF2C | 1 |