SKRAM Model
Forensic Computing:
The SKRAM Model
It is a model created in 1998 by Donn Parker and proposed in his
Fighting Computer Crime: a New Framework for Protecting
Informationy has established itself as a very valuable tool for
start the investigation into the possible suspects in the execution of
a cyber attack.
The initials of the SKRAM model come from the words Skill
skill
access
essential for generating a profile of a cybercriminal.
I was recently asked where to find detailed information.
about the SKRA model and noticing that we had little information about it
this model in the community, I set out to search for both the book
by Donn Parker, as a paper titled Can S.K.R.A.M. Support
Quantified Risk Analysis of Computer Related Crime written by Steve
Frank in 2003 was inspired by the work done by Donn Parker
with the SKRAM model
Fighting Computer Crime: a
New Framework for
Protecting Information
(SKRAM Model)
Can S.K.R.A.M. Support
Quantified Risk Analysis of
Computer Related Crime?
Model SKRAM
It is necessary to understand the individual components of the model of
SKRAM. Parker reveals that the SKRAM model is a sum of
supposed ability of a suspect, knowledge, resources, the
authority and motivation (Parker, 1998, 136-138).
SKRAM stands for:
Skills
Knowledge
Resources
Authority
Motive
Skills: The first component of the SKRAM model,
skills refer to the aptitude of a suspect with the
computers and technology. To determine the level of competence
from a suspect and their skills, an investigator can begin
for the work experience exam of the said suspect.
They are usually competent in using computers for
committing cyber crimes. They have technical training in
network creation, hardware knowledge, software packages,
operating systems, security systems, software development,
databases and systems administration are key areas that must
to be examined by a researcher.
Knowledge: At first glance, knowledge looks very much like the
skills. Unlike skills, knowledge is a
more general measure of the specific skills acquired by a
suspicious and that are fundamental to perpetrate the attack
computer scientist in question. The knowledge includes the ability of a
suspected of planning and predicting the actions of his victims, his
the objective is computational infrastructure and a solid understanding of
what they are looking for. Researchers must try to identify who
has the body of specific knowledge to carry out the
cybercrime under investigation.
Resources: A qualified and knowledgeable suspect is unable to
commit a crime if you do not have the necessary resources. The resources
include both the physical components as well as the contacts that the
the suspect has at their disposal. When examining the resources of a
suspicious, the investigators should not overlook the partners
commercials of a suspect, their membership in clubs and the network of
friends can be identified.
Authority: Authority is a measure of access of the suspect and
helps to exercise control over the information necessary to commit
a crime. A suspect may be the information administrator
vital, like password files and therefore have easy
access to commit a crime using that information. The
investigators must determine the relationship of a suspect with the
necessary data to commit a computer crime.
Reason: All the technical knowledge in the world may not be
sufficient to determine that a suspect has committed a crime
computer scientist. Independent of technical skill and knowledge, the
motivation is perhaps one of the most important general criteria to
evaluate. The reason could be emotional, social, political, economic or
extortionate. A highly motivated criminal is capable of convincing.
to other technically more experienced criminals to help them carry out
the crime is completed. It has been suggested that investigators look for
anomalies such as: "excessive or unjustified absenteeism, hours
extraordinary, the persistent late arrival of work, the low
sudden decline in quality and low performance in production, the complaints
and postpone the vacation" (Duyn, p. 102).
Data Collection and Methodology
To date, no work model is known for the
quantification of the potential threat of a person based on
his skill set and the motivation to commit the crime. Without
embargo, the Parker model establishes a base of attributes and
qualities that can potentially be examined through
profiling techniques that could later be compared with the
suspects.
Sources:The blogspot of dirkmarvin/ Dragonjar/ Methodology of
Analysis of a Case with SKRAM/