Content area

Abstract

Terminal forensics in large mobile networks is a vital activity for identifying compromised devices and analyzing malicious actions. In contrast, the study described here begins with the domain of terminal forensics as the primary focus, rather than the threat itself. This paper proposes a new multi-criteria decision-making (MCDM) model that integrates complex picture fuzzy sets (CPFS) with the combinative distance-based assessment (CODAS), referred to throughout as complex picture fuzzy CODAS (CPF-CODAS). The aim is to assist in forensic analysis for detecting mobile botnet command and control (C&C) systems. The CPF-CODAS model accounts for the uncertainty, hesitation, and complex numerical values involved in expert decision-making, using degrees of membership as positive, neutral, and negative values. An illustrative forensic case study is constructed where three mobile devices are evaluated by three cybersecurity professionals based on six key parameters related to botnet activity. The results demonstrate that the model can effectively distinguish suspicious devices and support the use of the CPF-CODAS approach in terminal forensics of mobile networks. The robustness, symmetry, and advantages of this model over existing MCDM methods are confirmed through sensitivity and comparison analyses. In conclusion, this paper introduces a novel probabilistic decision-support tool that digital forensic specialists can incorporate into their workflow to proactively identify and prevent actions of mobile botnet C&C servers.

Details

1009240
Title
Terminal Forensics in Mobile Botnet Command and Control Detection Using a Novel Complex Picture Fuzzy CODAS Algorithm
Author
Niu Geng 1 ; Zhang, Fei 1 ; Guo Muyuan 1 

 Department of Information Technology, Shaanxi Police College, Xi’an 710021, China; [email protected] (F.Z.); [email protected] (M.G.), Shaanxi Provincial Key Laboratory of Intelligent Policing, Xi’an 710021, China, Key Laboratory of Digital Forensics and Analysis of Shaanxi Higher Education Institutes, Xi’an 710021, China 
Publication title
Symmetry; Basel
Volume
17
Issue
10
First page
1637
Number of pages
27
Publication year
2025
Publication date
2025
Publisher
MDPI AG
Place of publication
Basel
Country of publication
Switzerland
Publication subject
e-ISSN
20738994
Source type
Scholarly Journal
Language of publication
English
Document type
Journal Article
Publication history
 
 
Online publication date
2025-10-03
Milestone dates
2025-07-22 (Received); 2025-09-05 (Accepted)
Publication history
 
 
   First posting date
03 Oct 2025
ProQuest document ID
3265950854
Document URL
https://www.proquest.com/scholarly-journals/terminal-forensics-mobile-botnet-command-control/docview/3265950854/se-2?accountid=208611
Copyright
© 2025 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/). Notwithstanding the ProQuest Terms and Conditions, you may use this content in accordance with the terms of the License.
Last updated
2025-10-28
Database
ProQuest One Academic