The analyst mindset : a cognitive skills assessment of digital forensic analysts.

dc.contributor.advisorCooper, Sandra Bennett.
dc.creatorSanders, Chris (Christopher Dean), 1986-
dc.date.accessioned2022-01-28T14:48:52Z
dc.date.available2022-01-28T14:48:52Z
dc.date.created2021-12
dc.date.issued2021-09-24
dc.date.submittedDecember 2021
dc.date.updated2022-01-28T14:48:53Z
dc.description.abstractDespite significant investment in cyber security, the industry is unable to stem the tide of damaging attacks against computer networks. This unfortunate situation is, in part, because cyber security exists in a state of cognitive crisis defined by tacit knowledge and poorly understood processes. At the heart of the crisis are digital forensic analysts that identify and investigate intrusions. Unfortunately, even skilled analysts in these roles are often unable to explain how they go about the process of finding intruders and assessing their foothold on a network. Without this knowledge, professional and academic educators are unable to build a standardized industry-accepted curriculum for the identification and training of new analysts. While there have been some attempts to inventory the skills, processes, and knowledge required to serve in the digital forensic analyst role, no current efforts provide a thorough, research-backed accounting of the profession with consideration for cognitive skill elements. This problem of practice study details a cognitive skills assessment of the digital forensic analyst profession by leveraging two Cognitive Task Analysis (CTA) research methods. The Simplified Precursor, Action, Result, Interpretation (PARI) method provided a framework for eliciting procedural skills, and the Critical Decision Method (CDM) supported the discovery of decision-making skills. Using these techniques, interviews conducted with expert analyst practitioners revealed four unique procedural skill categories, characteristics of two significant facets of analyst decision making, and numerous subcategory elements that describe additional dimensions of expert analyst performance. The results converged on a model of diagnostic inquiry that represents the relationships between how analysts formed investigative questions, interpreted evidence, assessed the disposition of events, and chose their next investigative actions. These findings establish explicit knowledge that provides a foundational understanding of how skilled analysts perform investigations. They also lay new groundwork for cyber security’s emergence from its cognitive crisis, with implications for educators and practitioners alike.
dc.format.mimetypeapplication/pdf
dc.identifier.urihttps://hdl.handle.net/2104/11721
dc.language.isoen
dc.rights.accessrightsWorldwide access
dc.subjectDigital forensics. Cognitive task analysis. Intrusion analysis. Computer forensics. Cyber security. Incident response. Cognitive task. Intrusion detection. Security operation center. SOC. Investigator. Analyst. CDM. PARI. Diagnostic inquiry. Digital evidence. Investigation theory. CSIRT. CERT.
dc.titleThe analyst mindset : a cognitive skills assessment of digital forensic analysts.
dc.typeThesis
dc.type.materialtext
thesis.degree.departmentBaylor University. Dept. of Curriculum & Instruction.
thesis.degree.grantorBaylor University
thesis.degree.levelDoctoral
thesis.degree.nameEd.D.

Files

Original bundle

Now showing 1 - 5 of 7
Loading...
Thumbnail Image
Name:
SANDERS-DISSERTATION-2021.pdf
Size:
1.22 MB
Format:
Adobe Portable Document Format
No Thumbnail Available
Name:
Sanders, Chris Thesis Copyright Availability Form.pdf
Size:
582.99 KB
Format:
Adobe Portable Document Format
Description:
No Thumbnail Available
Name:
Figure 1.1 - PLSclear Free of Charge licence [43559].pdf
Size:
270.84 KB
Format:
Adobe Portable Document Format
Description:
No Thumbnail Available
Name:
Figure 2.2 - Cooper.pdf
Size:
45.9 KB
Format:
Adobe Portable Document Format
Description:
No Thumbnail Available
Name:
Figure 3.2 - MIT.pdf
Size:
66.52 KB
Format:
Adobe Portable Document Format
Description:

License bundle

Now showing 1 - 1 of 1
No Thumbnail Available
Name:
LICENSE.txt
Size:
1.96 KB
Format:
Plain Text
Description: