Universiti Teknologi Malaysia Institutional Repository

Digital forensics investigation procedures of smart grid environment

Mohd. Abdullah, Haris Iskandar and Ibrahim, Zul Azri and Abdul Rahim, Fiza and Fadzil, Hafizuddin Shahril and Sharul Nizam, Saiful Amin and Mustaffa, Muhammad Zulhusni (2022) Digital forensics investigation procedures of smart grid environment. International Journal of Computing and Digital Systems, 11 (1). pp. 1071-1082. ISSN 2210-142X

[img]
Preview
PDF
1MB

Official URL: http://dx.doi.org/10.12785/ijcds/110186

Abstract

Smart grids have been widely used around the world. The security of this system is debatable among the researchers because this area requires an improvement in order to reassure the grid is secured from cyberattacks. However, many malware were found attacking the smart grid systems such as Stuxnet, Flames, Triton, etc. Some of them are designed to avoid being tracked by a forensic investigator. The perpetrators used the fragility of digital evidence as an advantage to launch an attack on the smart grid without leaving traces. Technology development gives challenges to digital forensic procedures because the data volume is much higher. Thus, the digital forensic procedure needs to be redesigned, modified, and improved to capture traces and handle digital evidence. This paper aims to propose a digital forensic procedure to guide investigators to perform the digital forensic investigation, especially in a smart grid environment. This paper has discussed several suitable tools and techniques in digital forensic investigation to solve the problem or the challenges. This study discussed two cyberattacks examples and simulated the attack using a testbed to guide forensic investigators based on the proposed digital forensic procedure. Examples of cyberattacks are Distributed Denial of Service and False Data Injection attacks. This paper presented an appropriate methodology and relevant forensic tools to ensure the evidence's integrity during collection and analysis as legal evidence in court.

Item Type:Article
Uncontrolled Keywords:cyber-physical system, dead digital forensic, forensic, framework, live digital forensic, network forensic, process
Subjects:Q Science > QA Mathematics > QA75 Electronic computers. Computer science
T Technology > T Technology (General)
Divisions:Razak School of Engineering and Advanced Technology
ID Code:98583
Deposited By: Yanti Mohd Shah
Deposited On:21 Jan 2023 01:10
Last Modified:21 Jan 2023 01:10

Repository Staff Only: item control page