2018
DOI: 10.1007/978-3-319-74872-6_4
|View full text |Cite
|
Sign up to set email alerts
|

The Evolution of Expressing and Exchanging Cyber-Investigation Information in a Standardized Form

Abstract: Motivation This paper describes the evolution of a community-developed, standardized specification language for representing and exchanging information in the broadest possible range of cyber-investigation domains, including digital forensic science, incident response, and counter terrorism. This initiative was originally called the Digital Forensic Analysis eXpression (DFAX), which has evolved into the Cyber-investigation Analysis Standard Expression (CASE). These standardization efforts include development o… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1

Citation Types

0
4
0

Year Published

2020
2020
2024
2024

Publication Types

Select...
3
2
1

Relationship

0
6

Authors

Journals

citations
Cited by 7 publications
(4 citation statements)
references
References 10 publications
0
4
0
Order By: Relevance
“…Few approaches exist for representing and exchanging cyber-investigation data when combining data sources from diverse organizations or dealing with large amounts of data from multiple tools. Casey et al [ 31 ] used an open community-developed specification language called Cyber-Investigation Analysis Standard Expression (CASE) to address this need for information exchange and tool interoperability. The outcome demonstrated a proof-of-concept Application Program Interface (API) to facilitate CASE tool implementation.…”
Section: Related Workmentioning
confidence: 99%
See 1 more Smart Citation
“…Few approaches exist for representing and exchanging cyber-investigation data when combining data sources from diverse organizations or dealing with large amounts of data from multiple tools. Casey et al [ 31 ] used an open community-developed specification language called Cyber-Investigation Analysis Standard Expression (CASE) to address this need for information exchange and tool interoperability. The outcome demonstrated a proof-of-concept Application Program Interface (API) to facilitate CASE tool implementation.…”
Section: Related Workmentioning
confidence: 99%
“…The outcome demonstrated a proof-of-concept Application Program Interface (API) to facilitate CASE tool implementation. Thus, community members can develop and implement CASE and the Unified Cyber Ontology (UCO) [ 31 ]. However, these approaches are focused on unifying and structuring the evidence data for exchange purposes.…”
Section: Related Workmentioning
confidence: 99%
“…Indeed AI techniques could potentially assist any time there is a need to correlate data from multiple sources, either from multiple suspects, devices or cases. Non-AI based efforts such as standard form of representations, e.g., CASE [18] will be critical for such efforts.…”
Section: Future Directionsmentioning
confidence: 99%
“…The CASE framework and its compatibility with the underlying Unified Cyber Ontology (UCO) [29] are based on years long effort for enabling open ICT ecosystems in different security domains and the development of knowledge-based tools 6 .…”
Section: III Semantic Interoperability: Case and Wandamentioning
confidence: 99%