{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,25]],"date-time":"2026-03-25T14:25:57Z","timestamp":1774448757592,"version":"3.50.1"},"reference-count":75,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2020,1,1]],"date-time":"2020-01-01T00:00:00Z","timestamp":1577836800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Access"],"published-print":{"date-parts":[[2020]]},"DOI":"10.1109\/access.2020.2976885","type":"journal-article","created":{"date-parts":[[2020,2,27]],"date-time":"2020-02-27T22:16:57Z","timestamp":1582841817000},"page":"48477-48490","source":"Crossref","is-referenced-by-count":30,"title":["Database Forensic Investigation Process Models: A Review"],"prefix":"10.1109","volume":"8","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-0729-2654","authenticated-orcid":false,"given":"Arafat","family":"Al-dhaqm","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8824-6069","authenticated-orcid":false,"given":"Shukor","family":"Abd Razak","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7912-3908","authenticated-orcid":false,"given":"Siti Hajar","family":"Othman","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7921-8990","authenticated-orcid":false,"given":"Abdulalem","family":"Ali","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1468-0655","authenticated-orcid":false,"given":"Fuad A.","family":"Ghaleb","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2308-0299","authenticated-orcid":false,"given":"Arieff Salleh","family":"Rosman","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1299-6864","authenticated-orcid":false,"given":"Nurazmallail","family":"Marni","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref73","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2017.2762693"},{"key":"ref72","doi-asserted-by":"publisher","DOI":"10.1371\/journal.pone.0170793"},{"key":"ref71","first-page":"139","article-title":"Arguments and methods for database data model forensics","author":"beyers","year":"2012","journal-title":"Proc WDFIA"},{"key":"ref70","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-24212-0_7"},{"key":"ref74","doi-asserted-by":"publisher","DOI":"10.1109\/Trustcom\/BigDataSE\/ICESS.2017.299"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2016.03.003"},{"key":"ref75","doi-asserted-by":"publisher","DOI":"10.1109\/ICIMTech.2018.8528177"},{"key":"ref38","author":"susaimanickam","year":"2010","journal-title":"A Workflow to Support Forensic Database Analysis"},{"key":"ref33","author":"bogen","year":"2006","journal-title":"Selecting keyword search terms in computer forensics examinations using domain analysis and modeling"},{"key":"ref32","first-page":"27","article-title":"A road map for digital forensic research","author":"palmer","year":"2001","journal-title":"Proc Digital Forensic Res Workshop"},{"key":"ref31","author":"kruse","year":"2001","journal-title":"Computer Forensics Incident Response Essentials"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/ISSA.2015.7335071"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/ARES.2010.62"},{"key":"ref36","author":"casey","year":"2009","journal-title":"Handbook of Digital Forensics and Investigation"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.IR.7617"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/ICMCS.2012.6320265"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1109\/SYSOSE.2016.7542951"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1109\/CSA.2009.5404202"},{"key":"ref61","article-title":"System and method for investigating a data operation performed on a database","author":"wong","year":"2005"},{"key":"ref63","article-title":"Applied metamodelling: A foundation for language driven development (third edition)","author":"clark","year":"2015","journal-title":"arXiv 1505 00149"},{"key":"ref28","author":"ogutu","year":"2017","journal-title":"A Methodology to Test the Richness of Forensic Evidence of Database Storage Engine Analysis of MySQL Update Operation in InnoDB and MyISAM Storage Engines"},{"key":"ref64","article-title":"Formal verification of relational model transformations using an intermediate verification language","author":"cheng","year":"2012"},{"key":"ref27","author":"lawrence","year":"2014","journal-title":"Forensic Investigation of MySQL Database Management System"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1007\/11786160_15"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1109\/ASE.2001.989813"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/ISSA.2015.7335071"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-45068-8_92"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1109\/CSA.2009.5404202"},{"key":"ref69","first-page":"126","article-title":"Methods for efficient digital evidences collecting of business proceses and users activity in eLearning enviroments","author":"azemovi?","year":"2010","journal-title":"Proc Int Conf e-Educ e-Bus e-Manage e-Learn"},{"key":"ref2","author":"fowler","year":"2008","journal-title":"SQL Server Forensic Analysis"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2008.10.001"},{"key":"ref20","year":"2007","journal-title":"A Real World Scenario of A SQL Server 2005 Database Forensics Investigation"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.24297\/ijct.v7i3.3446"},{"key":"ref21","author":"basu","year":"2006","journal-title":"Forensic Tamper Detection in SQL Server"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/AINA.2010.152"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-33962-2_19"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1016\/j.istr.2013.02.003"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/ARES.2012.50"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2017.06.006"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2017.11.001"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2017.2762693"},{"key":"ref58","doi-asserted-by":"crossref","first-page":"164","DOI":"10.1007\/978-3-642-22339-6_20","article-title":"The method of database server detection and investigation in the enterprise environment","author":"son","year":"2011","journal-title":"Secure and Trust Computing Data Management and Applications"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1109\/CSA.2009.5404235"},{"key":"ref56","article-title":"Oracle forensics part 4: Live response","author":"litchfield","year":"2019"},{"key":"ref55","article-title":"Oracle database forensics using LogMiner","author":"wright","year":"2014"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2019.04.001"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-44952-3_8"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/AINS.2018.8631468"},{"key":"ref10","author":"litchfield","year":"2007","journal-title":"Oracle forensics part 4 Live response"},{"key":"ref11","author":"litchfield","year":"2007","journal-title":"Oracle forensics part 5 Finding evidence of data theft in the absence of auditing"},{"key":"ref40","first-page":"1","article-title":"Database forensic analysis with DBCarver","author":"wagner","year":"2017","journal-title":"Proc CIDR"},{"key":"ref12","author":"litchfield","year":"2007","journal-title":"Oracle forensics part 6 Examining undo segments flashback and the oracle recycle bin"},{"key":"ref13","author":"litchfield","year":"2007","journal-title":"Oracle forensics part 7 Using the Oracle system change number in forensic investigations"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.4236\/jis.2012.32014"},{"key":"ref15","article-title":"System and method for investigating a data operation performed on a database","author":"wong","year":"2004"},{"key":"ref16","author":"wright","year":"2007","journal-title":"Using Oracle Forensics to determine vulnerability to Zero Day exploits"},{"key":"ref17","year":"2005","journal-title":"Oracle Database Forensics Using LogMiner"},{"key":"ref18","first-page":"97","article-title":"On dimensions of reconstruction in database forensics","author":"fasan","year":"2012","journal-title":"Proc WDFIA"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-22339-6_20"},{"key":"ref4","author":"beyers","year":"2014","journal-title":"Database forensics Investigating compromised database management systems"},{"key":"ref3","first-page":"27","article-title":"A framework for database forensic analysis","volume":"2","author":"khanuja","year":"2012","journal-title":"International Journal of Computational Engineering Science"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2014.12.002"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2015.05.013"},{"key":"ref8","author":"litchfield","year":"2007","journal-title":"Oracle forensics part 2 Locating dropped objects"},{"key":"ref7","author":"litchfield","year":"2007","journal-title":"Oracle forensics part 1 Dissecting the redo logs"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/FTC.2016.7821727"},{"key":"ref9","author":"litchfield","year":"2007","journal-title":"Oracle forensics Part 3 isolating evidence of attacks against the authentication mechanism"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/FGCN.2007.106"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/ISBAST.2014.7013142"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1016\/B978-012088469-8\/50046-2"},{"key":"ref47","first-page":"322","article-title":"Efficient model for detection data and data scheme tempering with purpose of valid forensic analysis","author":"azemovi?","year":"2009","journal-title":"Proc Int Conf Comput Eng Appl (ICCEA)"},{"key":"ref42","first-page":"457","article-title":"Role of metadata in forensic analysis of database attacks","author":"khanuja","year":"2014","journal-title":"Proc IEEE Int Advance Comput Conf (IACC)"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2014.09.003"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1145\/3183399.3183426"},{"key":"ref43","first-page":"336","article-title":"Oracle database forensics using LogMiner","author":"wright","year":"2004","journal-title":"Proc SANS Inst"}],"container-title":["IEEE Access"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/6287639\/8948470\/09016047.pdf?arnumber=9016047","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,1,12]],"date-time":"2022-01-12T01:09:20Z","timestamp":1641949760000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9016047\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020]]},"references-count":75,"URL":"https:\/\/doi.org\/10.1109\/access.2020.2976885","relation":{},"ISSN":["2169-3536"],"issn-type":[{"value":"2169-3536","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020]]}}}