{"id":"https://openalex.org/W2162512897","doi":"https://doi.org/10.1109/icitst.2009.5402640","title":"Metrics for network forensics conviction evidence","display_name":"Metrics for network forensics conviction evidence","publication_year":2009,"publication_date":"2009-11-01","ids":{"openalex":"https://openalex.org/W2162512897","doi":"https://doi.org/10.1109/icitst.2009.5402640","mag":"2162512897"},"language":"en","primary_location":{"id":"doi:10.1109/icitst.2009.5402640","is_oa":false,"landing_page_url":"https://doi.org/10.1109/icitst.2009.5402640","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2009 International Conference for Internet Technology and Secured Transactions, (ICITST)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5026441580","display_name":"Ahmad Roshidi Amran","orcid":"https://orcid.org/0000-0003-2285-8000"},"institutions":[{"id":"https://openalex.org/I143804889","display_name":"Loughborough University","ror":"https://ror.org/04vg4w365","country_code":"GB","type":"education","lineage":["https://openalex.org/I143804889"]}],"countries":["GB"],"is_corresponding":true,"raw_author_name":"A.R. Amran","raw_affiliation_strings":["Department of Electronic & Electrical Engineering, Loughborough University, UK"],"affiliations":[{"raw_affiliation_string":"Department of Electronic & Electrical Engineering, Loughborough University, UK","institution_ids":["https://openalex.org/I143804889"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5066166428","display_name":"Rapha\u00ebl C.\u2010W. Phan","orcid":"https://orcid.org/0000-0001-7448-4595"},"institutions":[{"id":"https://openalex.org/I143804889","display_name":"Loughborough University","ror":"https://ror.org/04vg4w365","country_code":"GB","type":"education","lineage":["https://openalex.org/I143804889"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"R.C.-W. Phan","raw_affiliation_strings":["Department of Electronic & Electrical Engineering, Loughborough University, UK"],"affiliations":[{"raw_affiliation_string":"Department of Electronic & Electrical Engineering, Loughborough University, UK","institution_ids":["https://openalex.org/I143804889"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5111581791","display_name":"David J. Parish","orcid":null},"institutions":[{"id":"https://openalex.org/I143804889","display_name":"Loughborough University","ror":"https://ror.org/04vg4w365","country_code":"GB","type":"education","lineage":["https://openalex.org/I143804889"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"D.J. Parish","raw_affiliation_strings":["Department of Electronic & Electrical Engineering, Loughborough University, UK"],"affiliations":[{"raw_affiliation_string":"Department of Electronic & Electrical Engineering, Loughborough University, UK","institution_ids":["https://openalex.org/I143804889"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5026441580"],"corresponding_institution_ids":["https://openalex.org/I143804889"],"apc_list":null,"apc_paid":null,"fwci":1.7142,"has_fulltext":false,"cited_by_count":11,"citation_normalized_percentile":{"value":0.86583588,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":96},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"8"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9995999932289124,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12034","display_name":"Digital and Cyber Forensics","score":0.9995999932289124,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8011950254440308},{"id":"https://openalex.org/keywords/credibility","display_name":"Credibility","score":0.7966718673706055},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.6250606775283813},{"id":"https://openalex.org/keywords/network-forensics","display_name":"Network forensics","score":0.6049569845199585},{"id":"https://openalex.org/keywords/vulnerability","display_name":"Vulnerability (computing)","score":0.5713751912117004},{"id":"https://openalex.org/keywords/process","display_name":"Process (computing)","score":0.5518921613693237},{"id":"https://openalex.org/keywords/conviction","display_name":"Conviction","score":0.532053530216217},{"id":"https://openalex.org/keywords/digital-evidence","display_name":"Digital evidence","score":0.5095329880714417},{"id":"https://openalex.org/keywords/damages","display_name":"Damages","score":0.5052798390388489},{"id":"https://openalex.org/keywords/network-security","display_name":"Network security","score":0.48368579149246216},{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.47510823607444763},{"id":"https://openalex.org/keywords/network-packet","display_name":"Network packet","score":0.4646560549736023},{"id":"https://openalex.org/keywords/redress","display_name":"Redress","score":0.44757819175720215},{"id":"https://openalex.org/keywords/adversary","display_name":"Adversary","score":0.4376613199710846},{"id":"https://openalex.org/keywords/sample","display_name":"Sample (material)","score":0.42937517166137695},{"id":"https://openalex.org/keywords/digital-forensics","display_name":"Digital forensics","score":0.24670663475990295},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.22854551672935486}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8011950254440308},{"id":"https://openalex.org/C2780224610","wikidata":"https://www.wikidata.org/wiki/Q1530061","display_name":"Credibility","level":2,"score":0.7966718673706055},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.6250606775283813},{"id":"https://openalex.org/C50747538","wikidata":"https://www.wikidata.org/wiki/Q7001032","display_name":"Network forensics","level":3,"score":0.6049569845199585},{"id":"https://openalex.org/C95713431","wikidata":"https://www.wikidata.org/wiki/Q631425","display_name":"Vulnerability (computing)","level":2,"score":0.5713751912117004},{"id":"https://openalex.org/C98045186","wikidata":"https://www.wikidata.org/wiki/Q205663","display_name":"Process (computing)","level":2,"score":0.5518921613693237},{"id":"https://openalex.org/C2777278149","wikidata":"https://www.wikidata.org/wiki/Q2916183","display_name":"Conviction","level":2,"score":0.532053530216217},{"id":"https://openalex.org/C2781357168","wikidata":"https://www.wikidata.org/wiki/Q5276084","display_name":"Digital evidence","level":3,"score":0.5095329880714417},{"id":"https://openalex.org/C2777381055","wikidata":"https://www.wikidata.org/wiki/Q308922","display_name":"Damages","level":2,"score":0.5052798390388489},{"id":"https://openalex.org/C182590292","wikidata":"https://www.wikidata.org/wiki/Q989632","display_name":"Network security","level":2,"score":0.48368579149246216},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.47510823607444763},{"id":"https://openalex.org/C158379750","wikidata":"https://www.wikidata.org/wiki/Q214111","display_name":"Network packet","level":2,"score":0.4646560549736023},{"id":"https://openalex.org/C2776515129","wikidata":"https://www.wikidata.org/wiki/Q7306218","display_name":"Redress","level":2,"score":0.44757819175720215},{"id":"https://openalex.org/C41065033","wikidata":"https://www.wikidata.org/wiki/Q2825412","display_name":"Adversary","level":2,"score":0.4376613199710846},{"id":"https://openalex.org/C198531522","wikidata":"https://www.wikidata.org/wiki/Q485146","display_name":"Sample (material)","level":2,"score":0.42937517166137695},{"id":"https://openalex.org/C84418412","wikidata":"https://www.wikidata.org/wiki/Q3246940","display_name":"Digital forensics","level":2,"score":0.24670663475990295},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.22854551672935486},{"id":"https://openalex.org/C124952713","wikidata":"https://www.wikidata.org/wiki/Q8242","display_name":"Literature","level":1,"score":0.0},{"id":"https://openalex.org/C17744445","wikidata":"https://www.wikidata.org/wiki/Q36442","display_name":"Political science","level":0,"score":0.0},{"id":"https://openalex.org/C185592680","wikidata":"https://www.wikidata.org/wiki/Q2329","display_name":"Chemistry","level":0,"score":0.0},{"id":"https://openalex.org/C142362112","wikidata":"https://www.wikidata.org/wiki/Q735","display_name":"Art","level":0,"score":0.0},{"id":"https://openalex.org/C43617362","wikidata":"https://www.wikidata.org/wiki/Q170050","display_name":"Chromatography","level":1,"score":0.0},{"id":"https://openalex.org/C199539241","wikidata":"https://www.wikidata.org/wiki/Q7748","display_name":"Law","level":1,"score":0.0},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/icitst.2009.5402640","is_oa":false,"landing_page_url":"https://doi.org/10.1109/icitst.2009.5402640","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2009 International Conference for Internet Technology and Secured Transactions, (ICITST)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","score":0.4099999964237213,"id":"https://metadata.un.org/sdg/16"}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":14,"referenced_works":["https://openalex.org/W30922450","https://openalex.org/W1482856640","https://openalex.org/W1506790772","https://openalex.org/W1520025831","https://openalex.org/W2067701334","https://openalex.org/W2077937403","https://openalex.org/W2103777149","https://openalex.org/W2113739228","https://openalex.org/W2122415709","https://openalex.org/W2136674011","https://openalex.org/W2138644293","https://openalex.org/W2159280848","https://openalex.org/W2170673199","https://openalex.org/W2628526097"],"related_works":["https://openalex.org/W2489557937","https://openalex.org/W4238452393","https://openalex.org/W3116833198","https://openalex.org/W4288054537","https://openalex.org/W4287547497","https://openalex.org/W2532563258","https://openalex.org/W2480188389","https://openalex.org/W4240498326","https://openalex.org/W2035643924","https://openalex.org/W1685415006"],"abstract_inverted_index":{"Evaluation":[0],"of":[1,13,21,45,60,78,89,134,142,163],"forensics":[2,83,127],"evidence":[3,49,79,99,146,151],"is":[4,68],"an":[5,14,52,57],"essential":[6],"step":[7,32],"in":[8,81,92],"proving":[9],"the":[10,19,22,116,132,145,160,176],"malicious":[11],"intents":[12],"attacker":[15],"or":[16],"adversary":[17],"and":[18,54,110,165],"severity":[20,133],"damages":[23],"caused":[24],"to":[25,41,47,56,94,123,144,156,159,168],"any":[26],"network.":[27],"This":[28,148],"paper":[29],"takes":[30],"a":[31,43,76,101,126,140],"forward":[33],"showing":[34],"how":[35],"security":[36],"metrics":[37,122,128],"can":[38],"be":[39,153],"used":[40],"sustain":[42],"sense":[44],"credibility":[46,143],"network":[48,82,135],"gathered":[50],"as":[51,70,98],"elaboration":[53],"extension":[55],"embedded":[58],"feature":[59],"Network":[61],"Forensic":[62],"Readiness":[63],"(NFR)":[64],"-":[65],"Redress":[66],"that":[67,125],"defined":[69],"holding":[71],"intruders":[72],"responsible.":[73],"We":[74,113],"propose":[75],"procedure":[77],"acquisition":[80],"where":[84],"we":[85],"then":[86,114],"analyse":[87],"sample":[88],"packet":[90],"data":[91],"order":[93],"extract":[95],"useful":[96],"information":[97],"through":[100],"formalised":[102],"intuitive":[103],"model,":[104],"based":[105],"on":[106,175],"capturing":[107],"adversarial":[108],"behaviour":[109],"layer":[111],"analysis.":[112],"apply":[115],"Common":[117],"Vulnerability":[118],"Scoring":[119],"System":[120],"(CVSS)":[121],"show":[124],"system":[129],"could":[130,152],"assess":[131],"attacks":[136],"committed,":[137],"thus":[138],"giving":[139],"degree":[141],"gathered.":[147],"way,":[149],"hard":[150],"objectively":[154],"collected":[155],"lend":[157],"support":[158],"resource-intensive":[161],"process":[162],"investigation":[164],"litigation,":[166],"leading":[167],"successful":[169],"conviction,":[170],"while":[171],"reducing":[172],"effort":[173],"expended":[174],"process.":[177]},"counts_by_year":[{"year":2024,"cited_by_count":1},{"year":2021,"cited_by_count":1},{"year":2016,"cited_by_count":1},{"year":2015,"cited_by_count":2},{"year":2013,"cited_by_count":1},{"year":2012,"cited_by_count":2}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
