MARATTO

article · International Conference on Cyber Warfare and Security

Digital Forensic Readiness to Mitigate Insider Threats in the SaaS Cloud Environment

2026Open accessUniversity of Pretoria

Abstract

Insider threats continue to pose significant risks in Software-as-a-Service (SaaS) environments, wherelegitimate users hold varying levels of access and control. Existing mitigation measures remain largely reactive,focusing on post-incident investigation and evidence recovery, which often result in delayed detection andincomplete forensics. A proactive and forensically sound approach is therefore required to identify and containinsider activity before major compromise occurs. This paper presents the Digital Forensic Readiness to Bust Insider Threats (DFR-BUST) model, a framework that embeds forensic readiness principles within SaaS environments to enable early detection, secure evidencecapture, and legally defensible investigations. The model is aligned with the ISO/IEC 27043 digital investigation process, operationalising its readiness, acquisitive, and concurrent process classes. The model was evaluated using an experimental setup based on publicly available insider-threat datasets to demonstrate its readiness and detection capability. The evaluation confirmed that the proposed architecture supports proactive evidence generation, integrity verification, and traceable anomaly detection within acontrolled environment. Unlike conventional reactive approaches, DFR-BUST provides a proactive, evidence-centric mechanism that enhances both detection accuracy and forensic admissibility. Its modular design ensures adaptability across cloud platforms while maintaining compliance with international forensic investigation standards. Overall, this work bridges the gap between intelligent analytics and digital forensic readiness. By ensuring that insider detection outputs are accompanied by verified, admissible evidence, the framework contributes a practical foundation for developing forensic-aware, cloud-based security systems.

Research topics

  • Digital and Cyber Forensics
  • Information and Cyber Security
  • Security and Verification in Computing

Read the original research

This page summarises published work. The authoritative version sits with the publisher.

DOI: 10.34190/iccws.21.1.4508

Is something wrong with this record? Report it or request removal.

Discussion

Discuss this research

Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.

No discussion yet. Open the first thread.