{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,30]],"date-time":"2026-01-30T21:27:28Z","timestamp":1769808448668,"version":"3.49.0"},"reference-count":56,"publisher":"MDPI AG","issue":"4","license":[{"start":{"date-parts":[[2025,11,26]],"date-time":"2025-11-26T00:00:00Z","timestamp":1764115200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["JCP"],"abstract":"<jats:p>Small and Medium-sized Enterprises (SMEs) face disproportionately high risks from Advanced Persistent Threats (APTs), which often evade traditional cybersecurity measures. Existing frameworks catalogue adversary tactics and defensive solutions but provide limited quantitative guidance for allocating limited resources under uncertainty, a challenge amplified by the growing use of AI in both offensive operations and digital forensics. This paper proposes a game-theoretic model for improving digital forensic readiness (DFR) in SMEs. The approach integrates the MITRE ATT&amp;CK and D3FEND frameworks to map APT behaviors to defensive countermeasures and defines 32 custom DFR metrics, weighted using the Analytic Hierarchy Process (AHP), to derive utility functions for both attackers and defenders. The main analysis considers a non-zero-sum attacker\u2013defender bimatrix game and yields a single Nash equilibrium in which the attacker concentrates on Impact-oriented tactics and the defender on Detect-focused controls. In a synthetic calibration across ten organizational profiles, the framework achieves a median readiness improvement of 18.0% (95% confidence interval: 16.3% to 19.7%) relative to pre-framework baselines, with targeted improvements in logging and forensic preservation typically reducing key attacker utility components by around 15\u201330%. A zero-sum variant of the game is also analyzed as a robustness check and exhibits consistent tactical themes, but all policy conclusions are drawn from the empirical non-zero-sum model. Despite relying on expert-driven AHP weights and synthetic profiles, the framework offers SMEs actionable, equilibrium-informed guidance for strengthening forensic preparedness against advanced cyber threats.<\/jats:p>","DOI":"10.3390\/jcp5040105","type":"journal-article","created":{"date-parts":[[2025,11,26]],"date-time":"2025-11-26T13:56:34Z","timestamp":1764165394000},"page":"105","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["A Game-Theoretic Approach for Quantification of Strategic Behaviors in Digital Forensic Readiness"],"prefix":"10.3390","volume":"5","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-3928-9561","authenticated-orcid":false,"given":"Mehrnoush","family":"Vaseghipanah","sequence":"first","affiliation":[{"name":"Department of Computer, NT.C., Islamic Azad University, Tehran 1651153511, Iran"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5168-5271","authenticated-orcid":false,"given":"Sam","family":"Jabbehdari","sequence":"additional","affiliation":[{"name":"Department of Computer, NT.C., Islamic Azad University, Tehran 1651153511, Iran"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1072-8786","authenticated-orcid":false,"given":"Hamidreza","family":"Navidi","sequence":"additional","affiliation":[{"name":"Department of Mathematics and Computer Sciences, Shahed University, Tehran 3319118651, Iran"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2025,11,26]]},"reference":[{"key":"ref_1","unstructured":"Chen, P., Desmet, L., and Huygens, C. (2014, January 25\u201326). A study on advanced persistent threats. Proceedings of the Communications and Multimedia Security: 15th IFIP TC 6\/TC 11 International Conference, CMS 2014, Aveiro, Portugal. Proceedings 15."},{"key":"ref_2","first-page":"1","article-title":"A ten step process for forensic readiness","volume":"2","author":"Rowlingson","year":"2004","journal-title":"Int. J. Digit. Evid."},{"key":"ref_3","unstructured":"Google Mandiant (2025). M-Trends 2025: Executive Edition, Google LLC. Available online: https:\/\/services.google.com\/fh\/files\/misc\/m-trends-2025-executive-edition-en.pdf."},{"key":"ref_4","unstructured":"IBM (2025). Cost of a Data Breach Report 2025: The AI Oversight Gap, IBM Corporation. Based on IBM analysis of research data independently compiled by Ponemon Institute."},{"key":"ref_5","unstructured":"Bonderud, D. (2025, November 10). Cost of a Data Breach 2024: Financial Industry. Available online: https:\/\/www.ibm.com\/think\/insights\/cost-of-a-data-breach-2024-financial-industry."},{"key":"ref_6","unstructured":"Johnson, R. (2025, November 10). 60 Percent of Small Companies Close Within 6 Months of Being Hacked. Available online: https:\/\/cybersecurityventures.com\/60-percent-of-small-companies-close-within-6-months-of-being-hacked."},{"key":"ref_7","unstructured":"Baker, P. (2025, November 10). The SolarWinds Hack Timeline: Who Knew What, and When?. Available online: https:\/\/www.csoonline.com\/article\/570537\/the-solarwinds-hack-timeline-who-knew-what-and-when.html."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"3265","DOI":"10.1007\/s43681-024-00653-w","article-title":"AI governance: A systematic literature review","volume":"5","author":"Batool","year":"2025","journal-title":"AI Ethics"},{"key":"ref_9","unstructured":"Wrightson, T. (2014). Advanced Persistent Threat Hacking: The Art and Science of Hacking Any Organization, McGraw-Hill Education Group."},{"key":"ref_10","unstructured":"\u00c5rnes, A. (2017). Digital Forensics, John Wiley & Sons."},{"key":"ref_11","unstructured":"Griffith, S.B. (1963). Sun Tzu: The Art of War, Oxford University Press."},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Myerson, R.B. (2013). Game Theory, Harvard University Press.","DOI":"10.2307\/j.ctvjsf522"},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Belton, V., and Stewart, T. (2002). Multiple Criteria Decision Analysis: An Integrated Approach, Springer Science & Business Mediar.","DOI":"10.1007\/978-1-4615-1495-4"},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"71","DOI":"10.1007\/s10207-004-0060-x","article-title":"Game strategies in network security","volume":"4","author":"Lye","year":"2005","journal-title":"Int. J. Inf. Secur."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Roy, S., Ellis, C., Shiva, S., Dasgupta, D., Shandilya, V., and Wu, Q. (2010, January 5\u20138). A survey of game theory as applied to network security. Proceedings of the 2010 43rd Hawaii International Conference on System Sciences (HICSS), Honolulu, HI, USA.","DOI":"10.1109\/HICSS.2010.35"},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"46","DOI":"10.1109\/MCS.2014.2364710","article-title":"Game-theoretic methods for robustness, security, and resilience of cyberphysical control systems: Games-in-games principle for optimal cross-layer resilient control systems","volume":"35","author":"Zhu","year":"2015","journal-title":"IEEE Control Syst. Mag."},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Kent, K., Chevalier, S., and Grance, T. (2006). Guide to Integrating Forensic Techniques into Incident Response, National Institute of Standards and Technology. NIST Special Publication 800-86.","DOI":"10.6028\/NIST.SP.800-86"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Alpcan, T., and Ba\u015far, T. (2010). Network Security: A Decision and Game-Theoretic Approach, Cambridge University Press.","DOI":"10.1017\/CBO9780511760778"},{"key":"ref_19","unstructured":"Casey, E. (2011). Digital Evidence and Computer Crime: Forensic Science, Computers, and the Internet, Academic Press."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/2480741.2480742","article-title":"Game theory meets network security and privacy","volume":"45","author":"Manshaei","year":"2013","journal-title":"ACM Comput. Surv. (CSUR)"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Nisioti, A., Loukas, G., Rass, S., and Panaousis, E. (2021). Game-theoretic decision support for cyber forensic investigations. Sensors, 21.","DOI":"10.3390\/s21165300"},{"key":"ref_22","first-page":"200909","article-title":"A game-theoretic defensive approach for forensic investigators against rootkits","volume":"33","author":"Hasanabadi","year":"2020","journal-title":"Forensic Sci. Int. Digit. Investig."},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Karabiyik, U., and Karabiyik, T. (2020). A game theoretic approach for digital forensic tool selection. Mathematics, 8.","DOI":"10.3390\/math8050774"},{"key":"ref_24","first-page":"301214","article-title":"A memory-based game-theoretic defensive approach for digital forensic investigators","volume":"38","author":"Hasanabadi","year":"2021","journal-title":"Forensic Sci. Int. Digit. Investig."},{"key":"ref_25","unstructured":"Caporusso, N., Chea, S., and Abukhaled, R. (2018, January 21\u201325). A game-theoretical model of ransomware. Proceedings of the Advances in Human Factors in Cybersecurity: Proceedings of the AHFE 2018 International Conference on Human Factors in Cybersecurity, Orlando, FL, USA. Loews Sapphire Falls Resort at Universal Studios."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"552","DOI":"10.1080\/00450618.2016.1267797","article-title":"Novel digital forensic readiness technique in the cloud environment","volume":"50","author":"Kebande","year":"2018","journal-title":"Aust. J. Forensic Sci."},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"e151","DOI":"10.1002\/spy2.151","article-title":"Digital forensic readiness intelligence crime repository","volume":"4","author":"Kebande","year":"2021","journal-title":"Secur. Priv."},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"4895","DOI":"10.1007\/s11276-018-01920-5","article-title":"Towards a capability maturity model for digital forensic readiness","volume":"26","author":"Englbrecht","year":"2020","journal-title":"Wirel. Netw."},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"73","DOI":"10.1016\/j.cose.2012.09.008","article-title":"The architecture of a digital forensic readiness management system","volume":"32","author":"Reddy","year":"2013","journal-title":"Comput. Secur."},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Grobler, C.P., and Louwrens, C. (2007). Digital forensic readiness as a component of information security best practice. Proceedings of the IFIP International Information Security Conference, Springer.","DOI":"10.1007\/978-0-387-72367-9_2"},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Lakhdhar, Y., Rekhis, S., and Sabir, E. (2020, January 17\u201319). A Game Theoretic Approach For Deploying Forensic Ready Systems. Proceedings of the 2020 International Conference on Software, Telecommunications and Computer Networks (SoftCOM), Split, Croatia.","DOI":"10.23919\/SoftCOM50211.2020.9238276"},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"70","DOI":"10.1016\/j.cose.2015.04.003","article-title":"Digital forensic readiness: Expert perspectives on a theoretical framework","volume":"52","author":"Elyas","year":"2015","journal-title":"Comput. Secur."},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Baiquni, I.Z., and Amiruddin, A. (2022, January 16\u201317). A case study of digital forensic readiness level measurement using DiFRI model. Proceedings of the 2022 International Conference on Informatics, Multimedia, Cyber and Information System (ICIMCIS), Jakarta, Indonesia.","DOI":"10.1109\/ICIMCIS56303.2022.10017686"},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Rawindaran, N., Jayal, A., and Prakash, E. (2025). Cybersecurity Framework: Addressing Resiliency in Welsh SMEs for Digital Transformation and Industry 5.0. J. Cybersecur. Priv., 5.","DOI":"10.3390\/jcp5020017"},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Trenwith, P.M., and Venter, H.S. (2013, January 14\u201316). Digital forensic readiness in the cloud. Proceedings of the 2013 Information Security for South Africa, Johannesburg, South Africa.","DOI":"10.1109\/ISSA.2013.6641055"},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"3196","DOI":"10.1109\/TSC.2023.3290474","article-title":"Adaptive Observability for Forensic-Ready Microservice Systems","volume":"16","author":"Monteiro","year":"2023","journal-title":"IEEE Trans. Serv. Comput."},{"key":"ref_37","doi-asserted-by":"crossref","first-page":"157","DOI":"10.1007\/s10270-021-00898-7","article-title":"Cyber security threat modeling based on the MITRE Enterprise ATT&CK Matrix","volume":"21","author":"Xiong","year":"2022","journal-title":"Softw. Syst. Model."},{"key":"ref_38","unstructured":"Wang, J., and Neil, M. (2021). A Bayesian-network-based cybersecurity adversarial risk analysis framework with numerical examples. arXiv."},{"key":"ref_39","doi-asserted-by":"crossref","first-page":"124","DOI":"10.1016\/j.future.2021.01.004","article-title":"Intelligent dynamic malware detection using machine learning in IP reputation for forensics data analytics","volume":"118","author":"Usman","year":"2021","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_40","doi-asserted-by":"crossref","first-page":"406","DOI":"10.1016\/j.future.2020.09.038","article-title":"LEChain: A blockchain-based lawful evidence management scheme for digital forensics","volume":"115","author":"Li","year":"2021","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_41","first-page":"301484","article-title":"Detecting the software usage on a compromised system: A triage solution for digital forensics","volume":"44","author":"Soltani","year":"2023","journal-title":"Forensic Sci. Int. Digit. Investig."},{"key":"ref_42","doi-asserted-by":"crossref","first-page":"805","DOI":"10.3390\/jcp4040038","article-title":"Reversing File Access Control Using Disk Forensics on Low-Level Flash Memory","volume":"4","author":"Rother","year":"2024","journal-title":"J. Cybersecur. Priv."},{"key":"ref_43","doi-asserted-by":"crossref","first-page":"133","DOI":"10.1016\/j.diin.2017.07.002","article-title":"Registration Data Access Protocol (RDAP) for digital forensic investigators","volume":"22","author":"Nikkel","year":"2017","journal-title":"Digit. Investig."},{"key":"ref_44","first-page":"200908","article-title":"Fintech forensics: Criminal investigation and digital evidence in financial technologies","volume":"33","author":"Nikkel","year":"2020","journal-title":"Forensic Sci. Int. Digit. Investig."},{"key":"ref_45","doi-asserted-by":"crossref","first-page":"9467","DOI":"10.1007\/s11227-023-05045-1","article-title":"Digital forensic investigation framework for the metaverse","volume":"79","author":"Seo","year":"2023","journal-title":"J. Supercomput."},{"key":"ref_46","doi-asserted-by":"crossref","unstructured":"Malhotra, S. (2023). Digital forensics meets ai: A game-changer for the 4th industrial revolution. Artificial Intelligence and Blockchain in Digital Forensics, River Publishers.","DOI":"10.1201\/9781003374671-1"},{"key":"ref_47","first-page":"301540","article-title":"Identifying threats, cybercrime and digital forensic opportunities in Smart City Infrastructure via threat modeling","volume":"45","author":"Tok","year":"2023","journal-title":"Forensic Sci. Int. Digit. Investig."},{"key":"ref_48","doi-asserted-by":"crossref","first-page":"113912","DOI":"10.1016\/j.dss.2022.113912","article-title":"Security defense against long-term and stealthy cyberattacks","volume":"166","author":"Han","year":"2023","journal-title":"Decis. Support Syst."},{"key":"ref_49","doi-asserted-by":"crossref","first-page":"100467","DOI":"10.1016\/j.accinf.2020.100467","article-title":"A taxonomy of cybercrime: Theory and design","volume":"38","author":"Chandra","year":"2020","journal-title":"Int. J. Account. Inf. Syst."},{"key":"ref_50","doi-asserted-by":"crossref","first-page":"14","DOI":"10.1016\/j.diin.2017.08.002","article-title":"Advancing coordinated cyber-investigations and tool interoperability using a community developed specification language","volume":"22","author":"Casey","year":"2017","journal-title":"Digit. Investig."},{"key":"ref_51","doi-asserted-by":"crossref","unstructured":"Boyd, S., and Vandenberghe, L. (2004). Convex Optimization, Cambridge University Press.","DOI":"10.1017\/CBO9780511804441"},{"key":"ref_52","doi-asserted-by":"crossref","first-page":"904","DOI":"10.21105\/joss.00904","article-title":"Nashpy: A Python library for the computation of Nash equilibria","volume":"3","author":"Knight","year":"2018","journal-title":"J. Open Source Softw."},{"key":"ref_53","doi-asserted-by":"crossref","unstructured":"Zopounidis, C., and Pardalos, P.M. (2010). Handbook of Multicriteria Analysis, Springer Science & Business Media.","DOI":"10.1007\/978-3-540-92828-7"},{"key":"ref_54","doi-asserted-by":"crossref","unstructured":"Saaty, T.L. (2013). Analytic hierarchy process. Encyclopedia of Operations Research and Management Science, Springer.","DOI":"10.1007\/978-1-4419-1153-7_31"},{"key":"ref_55","unstructured":"Joint Committee for Guides in Metrology (JCGM) (2008). Evaluation of Measurement Data\u2014Supplement 1: Propagation of Distributions Using a Monte Carlo Method, JCGM. JCGM 101:2008."},{"key":"ref_56","unstructured":"The MITRE Corporation (2025, November 10). MITRE ATT&CK STIX Data. Available online: https:\/\/github.com\/mitre-attack\/attack-stix-data."}],"container-title":["Journal of Cybersecurity and Privacy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/4\/105\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,1,30]],"date-time":"2026-01-30T08:44:55Z","timestamp":1769762695000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/4\/105"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11,26]]},"references-count":56,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2025,12]]}},"alternative-id":["jcp5040105"],"URL":"https:\/\/doi.org\/10.3390\/jcp5040105","relation":{},"ISSN":["2624-800X"],"issn-type":[{"value":"2624-800X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,11,26]]}}}