{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,18]],"date-time":"2026-06-18T17:57:58Z","timestamp":1781805478164,"version":"3.54.5"},"reference-count":86,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2017,1,1]],"date-time":"2017-01-01T00:00:00Z","timestamp":1483228800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/OAPA.html"}],"funder":[{"DOI":"10.13039\/501100005417","name":"Universiti Teknologi Malaysia","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100005417","id-type":"DOI","asserted-by":"publisher"}]},{"name":"MOHE through FRGS","award":["R.J130000.7813.4F193"],"award-info":[{"award-number":["R.J130000.7813.4F193"]}]},{"DOI":"10.13039\/501100005417","name":"Universiti Teknologi Malaysia (GUP)","doi-asserted-by":"publisher","award":["Q.J130000.2513.18H31"],"award-info":[{"award-number":["Q.J130000.2513.18H31"]}],"id":[{"id":"10.13039\/501100005417","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Access"],"published-print":{"date-parts":[[2017]]},"DOI":"10.1109\/access.2017.2762693","type":"journal-article","created":{"date-parts":[[2017,10,13]],"date-time":"2017-10-13T14:37:43Z","timestamp":1507905463000},"page":"24401-24416","source":"Crossref","is-referenced-by-count":41,"title":["CDBFIP: Common Database Forensic Investigation Processes for Internet of Things"],"prefix":"10.1109","volume":"5","author":[{"given":"Arafat","family":"Al-Dhaqm","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shukor","family":"Razak","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Siti Hajar","family":"Othman","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9208-5336","authenticated-orcid":false,"given":"Kim-Kwang Raymond","family":"Choo","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"William Bradley","family":"Glisson","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Abdulalem","family":"Ali","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mohammad","family":"Abrar","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref73","first-page":"1","article-title":"An approach to examine the metadata and data of a database management system by making use of a forensic comparison tool","author":"beyers","year":"2011","journal-title":"Proc ISSSA"},{"key":"ref72","article-title":"Detecting database attacks using computer forensics tools","author":"fatima","year":"2011"},{"key":"ref71","first-page":"126","article-title":"Methods for efficient digital evidences collecting of business proceses and users activity in eLearning enviroments","author":"azemovi?","year":"2010","journal-title":"Proc Int Conf e-Edu e-Bus e-Manag e-Learn"},{"key":"ref70","first-page":"83","article-title":"Efficient model for detection data and data scheme tempering with purpose of valid forensic analysis","author":"azemovi?","year":"2009","journal-title":"Proc Int Conf Comput Eng Appl (ICCEA)"},{"key":"ref76","doi-asserted-by":"publisher","DOI":"10.4304\/jcp.9.10.2294-2302"},{"key":"ref77","first-page":"163","article-title":"Mapping process of digital forensic investigation framework","volume":"8","author":"selamat","year":"2008","journal-title":"Int J Comput Sci Netw Secur"},{"key":"ref74","doi-asserted-by":"publisher","DOI":"10.1109\/CSNT.2011.74"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2014.09.002"},{"key":"ref75","doi-asserted-by":"publisher","DOI":"10.1109\/EIDWT.2012.22"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1371\/journal.pone.0138449"},{"key":"ref78","doi-asserted-by":"publisher","DOI":"10.5121\/ijcsit.2011.3302"},{"key":"ref79","article-title":"Verification and validation of simulation models","author":"sargent","year":"0"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/MCC.2016.5"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1016\/j.compeleceng.2016.08.020"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1080\/00450618.2016.1153714"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1002\/cpe.3855"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1371\/journal.pone.0150300"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1007\/s10586-016-0553-1"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1002\/spe.2414"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1111\/1556-4029.13164"},{"key":"ref60","first-page":"97","article-title":"On dimensions of reconstruction in database forensics","author":"fasan","year":"2012","journal-title":"Proc WDFIA"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2014.09.003"},{"key":"ref61","first-page":"457","article-title":"&#x2018;Role of metadata in forensic analysis of database attacks","author":"khanuja","year":"2014","journal-title":"Proc IEEE Int Adv Comput Conf (IACC)"},{"key":"ref63","article-title":"Forensic tamper detection in SQL server","author":"basu","year":"2006"},{"key":"ref28","author":"quick","year":"2013","journal-title":"Cloud Storage Forensics"},{"key":"ref64","article-title":"Oracle forensics part 5: Finding evidence of data theft in the absence of auditing","author":"litchfield","year":"2007"},{"key":"ref27","article-title":"Reconstruction in database forensics","author":"adedayo","year":"2015"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1109\/FGCN.2007.106"},{"key":"ref66","first-page":"5078","article-title":"Enriching forensic analysis process for tampered data in database","volume":"3","author":"abhonkar","year":"2012","journal-title":"Int J Comput Sci Inf Technol"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1007\/s11042-016-3718-2"},{"key":"ref67","first-page":"1","article-title":"Arguments and methods for database data model forensics","author":"beyers","year":"2012","journal-title":"Proceedings of the 7th International Workshop on Digital Forensics and Incident Analysis"},{"key":"ref68","first-page":"57","article-title":"An improved framework for tamper detection in databases","volume":"6","author":"kambire","year":"2015","journal-title":"Int J Comput Sci Inf Technol"},{"key":"ref69","first-page":"1","article-title":"Oracle database forensic using log-miner","author":"wright","year":"2005","journal-title":"Proc Jan 10th 2005 London Jun 2004 Conf"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/HICSS.2013.366"},{"key":"ref1","article-title":"Investigating the impact of global positioning system (GPS) evidence in court cases","author":"berman","year":"0"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1145\/2487259.2487264"},{"key":"ref22","doi-asserted-by":"crossref","first-page":"654","DOI":"10.24297\/ijct.v7i3.3446","article-title":"Forensic analysis of databases by combining multiple evidences","volume":"7","author":"khanuja","year":"2013","journal-title":"Int J Comput Technol"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/ICDEW.2012.37"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/ARES.2012.50"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/AINA.2010.152"},{"key":"ref26","article-title":"Forensic investigation of MySQL database management system","author":"lawrence","year":"2014"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1016\/j.istr.2013.02.003"},{"key":"ref50","doi-asserted-by":"crossref","first-page":"75","DOI":"10.2307\/25148625","article-title":"Design science in information systems research","volume":"28","author":"von alan","year":"2004","journal-title":"MIS Quart"},{"key":"ref51","first-page":"1","article-title":"Metamodelling approach to support disaster management knowledge sharing","author":"othman","year":"2010","journal-title":"Proc 21st Australasian Conf Inf Syst (ACIS)"},{"key":"ref59","article-title":"A workflow to support forensic database analysis","author":"susaimanickam","year":"2012"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1109\/CSA.2009.5404202"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1109\/CSA.2009.5404235"},{"key":"ref56","article-title":"Oracle forensics part 4: Live response","author":"litchfield","year":"2007"},{"key":"ref55","first-page":"141","article-title":"Extraction of common concepts for the mobile forensics domain","author":"ali","year":"2017","journal-title":"Proc Int Conf Inf Commun Technol"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/MS.2009.109"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2009.34"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1016\/0167-9236(94)00041-2"},{"key":"ref10","author":"fowler","year":"2008","journal-title":"SQL Server Forensic Analysis"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-33962-2_19"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2013.07.001"},{"key":"ref12","article-title":"System and method for investigating a data operation performed on a database","author":"wong","year":"2005"},{"key":"ref13","article-title":"Oracle database forensics using LogMiner","author":"wright-gsec","year":"2005"},{"key":"ref14","article-title":"Oracle forensics part 2: Locating dropped objects","author":"litchfield","year":"2007"},{"key":"ref15","author":"wright","year":"2008","journal-title":"Oracle Forensics Oracle Security Best Practices"},{"key":"ref82","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-24212-0_7"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.4236\/jis.2012.32014"},{"key":"ref81","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4471-5634-5_6"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-22339-6_20"},{"key":"ref84","first-page":"220","article-title":"On the completeness of reconstructed data for database forensics","author":"adedayo","year":"2012","journal-title":"Digital Forensics and Cyber Crime"},{"key":"ref18","article-title":"A real world scenario of a SQL server 2005 database forensics investigation","author":"fowler","year":"2007"},{"key":"ref83","article-title":"Oracle forensics part 2: Locating dropped objects","author":"litchfield","year":"2007"},{"key":"ref19","author":"basu","year":"2006","journal-title":"Forensic Tamper Detection in SQL Server"},{"key":"ref80","doi-asserted-by":"publisher","DOI":"10.1057\/jos.2012.20"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2015.05.013"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.5121\/cseij.2012.2303"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1016\/j.clsr.2013.01.006"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2014.12.002"},{"key":"ref85","first-page":"439","article-title":"Database tampering and detection of data fraud by using the forensic scrutiny technique","volume":"3","author":"gawali","year":"2013","journal-title":"Int J Emerg Technol Adv Eng"},{"key":"ref8","doi-asserted-by":"crossref","first-page":"386","DOI":"10.19026\/rjaset.12.2377","article-title":"Conceptual investigation process model for managing database forensic investigation knowledge","volume":"12","author":"razak","year":"2016","journal-title":"Res J Appl Sci Eng Technol"},{"key":"ref86","doi-asserted-by":"publisher","DOI":"10.1145\/1412331.1412342"},{"key":"ref7","article-title":"Database forensics: Investigating compromised database management systems","author":"beyers","year":"2014"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1371\/journal.pone.0176223"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2008.10.001"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/ISSA.2015.7335071"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1002\/cpe.3868"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1371\/journal.pone.0170793"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/ISBAST.2014.7013142"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/Trustcom.2015.488"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/MCC.2015.71"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2014.08.002"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/TrustCom.2014.124"}],"container-title":["IEEE Access"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/6287639\/7859429\/08067454.pdf?arnumber=8067454","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,1,12]],"date-time":"2022-01-12T11:30:06Z","timestamp":1641987006000},"score":1,"resource":{"primary":{"URL":"http:\/\/ieeexplore.ieee.org\/document\/8067454\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017]]},"references-count":86,"URL":"https:\/\/doi.org\/10.1109\/access.2017.2762693","relation":{},"ISSN":["2169-3536"],"issn-type":[{"value":"2169-3536","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017]]}}}