Exploring the Use of Graph Databases to Catalog Artifacts for Client Forensics

Rose K. Shumba · Scholarly Commons (Embry–Riddle Aeronautical University) · 2018

Cloud computing has revolutionized the methods by which digital data is stored, processed, and transmitted. It is providing users with data storage and processing services, enabling access to resources through multiple devices. Although organizations continue to embrace the advantages of flexibility and scalability offered by cloud computing, insider threats are becoming a serious concern as cited by security researchers. Insiders can use authorized access to steal sensitive information, calling for the need for an investigation. This concept paper describes research in progress towards developing a Neo4j graph database tool to enhance client forensics. The tool, with a Python interface, allows for the location of evidential artifacts promptly. Initially, the database contains artifacts from existing research that can be used to prove usage. The ultimate goal is to create an Open Source collaborative environment for researchers and practitioners to add artifacts as we go along. The reasons for choosing a graph database are presented in the paper.

Read the paper · More papers on PaperTik