• DocumentCode
    2696003
  • Title

    VoIP evidence model: A new forensic method for investigating VoIP malicious attacks

  • Author

    Ibrahim, Mohammed ; Abdullah, Mohd Taufik ; Dehghantanha, Ali

  • Author_Institution
    Fac. of Comput. Sci. & Inf. Technol., Univ. Putra Malaysia, Serdang, Malaysia
  • fYear
    2012
  • fDate
    26-28 June 2012
  • Firstpage
    201
  • Lastpage
    206
  • Abstract
    Although the invention of Voice over Internet Protocol (VoIP) in communication technology created significant attractive services for its users, it also brings new security threats. Criminals exploit these security threats to perform illegal activities such as VoIP malicious attacks, this will require digital forensic investigators to detect and provide digital evidence. Finding digital evidence in VoIP malicious attacks is the most difficult task, due to its associated features with converged network. In this paper, a Model of investigating VoIP malicious attacks is proposed for forensic analysis. The model formalizes hypotheses through information gathering and adopt a Secure Temporal Logic of Action(S-TLA+) in the process of reconstructing potential attack scenario. Through this processes, investigators can uncover unknown attack scenario executed in the process of attack. Subsequently, it is expected that the findings of this paper will provide clear description of attacks as well as generation of more specified evidences.
  • Keywords
    Internet telephony; computer forensics; computer network security; temporal logic; S-TLA+; VoIP evidence model; VoIP malicious attacks; Voice over Internet protocol; digital evidence; digital forensic investigators; forensic analysis; forensic method; information gathering; potential attack scenario reconstruction; secure temporal logic of action; security threats; Computational modeling; Digital forensics; Internet telephony; Protocols; Security; Unsolicited electronic mail; Evidence Generation; Investigation; Malicious attack; S-TLA+; SIP; Scenario Fragment; Voice over IP;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Cyber Security, Cyber Warfare and Digital Forensic (CyberSec), 2012 International Conference on
  • Conference_Location
    Kuala Lumpur
  • Print_ISBN
    978-1-4673-1425-1
  • Type

    conf

  • DOI
    10.1109/CyberSec.2012.6246116
  • Filename
    6246116