A generic Digital Forensic Readiness model for BYOD using honeypot technology

Victor Rigworo Kebande, Nickson M. Karie, Hein S. Venter · 2016

Proliferation and mobility trends on digital devices has seen a significant realization of Bring Your Own Device (BYOD) which is a phenomenon that allows employees in an organizational enterprise network to access computing resources through their personal mobile devices irrespective of their location. This technology has enabled cost effectiveness in organizations through increased accessibility of digital devices in daily business activities. However, the development of this technology faces a number of security challenges due to lack of effective proactive security model with digital forensic capability that is able to plan and prepare before potential security incidents occur in an organization that has allowed BYOD. It is on this premise that the authors have proposed a generic Digital Forensic Readiness (DFR) model that uses honeypot technology to detect and trap potential security incidents. In this paper, therefore, a significant security model with DFR capability has been proposed. The model is aimed at harvesting, encrypting and digitally preserving potential digital evidence (PDE) based on the DFR processes and guidelines that have been highlighted in the ISO/IEC 27043: 2015 international standard for information technology, security techniques, incident investigation principles and processes. Finally, the proposed model is meant to reduce the effort required to conduct Digital Forensic Investigation (DFI) by capturing potential digital evidence and make it available when needed by digital forensic investigators which eventually saves cost and time. A generic DFR model for BYOD using honeypot technology is the main focus of this paper.

Read the paper · More papers on PaperTik