اعتبارسنجی یک مدل آمادگی فارنزیکی برای پیشگیری از جرایم سایبری در شبکه‌های اجتماعی

نوع مقاله : مقاله پژوهشی

نویسندگان

1 گروه مدیریت فن آوری اطلاعات ، واحد بین المللی کیش، دانشگاه آزاد اسلامی، کیش، ایران

2 گروه مدیریت فناوری اطلاعات، دانشکده مدیریت و اقتصاد، واحد علوم و تحقیقات، دانشگاه آزاد اسلامی، تهران، ایران.

3 گروه مدیریت صنعتی، دانشکده مدیریت، دانشگاه آزاد اسلامی، واحد کرج، دانشگاه آزاد اسلامی، واحد کرج، ایران

10.22091/stim.2026.15482.2340

چکیده

گسترش فزاینده استفاده از شبکه‌های اجتماعی در ایران، این بسترها را به یکی از اصلی‌ترین محیط‌های وقوع و بازتولید جرایم سایبری تبدیل کرده است. ویژگی‌هایی نظیر ناپایداری داده‌های دیجیتال، امکان حذف یا دست‌کاری سریع محتوا، پراکندگی شواهد در زیرساخت‌های پلتفرم‌محور و وابستگی به ارائه‌دهندگان خدمات خارجی، فرآیند کشف جرم، جمع‌آوری ادله و انتساب فنی را با پیچیدگی‌های جدی مواجه ساخته است. در رویه عملی نظام قضایی ایران، رویکرد غالب در رسیدگی به جرایم سایبری، ماهیتی پس‌واقعه‌ای دارد؛ بدین معنا که اقدامات فنی و کارشناسی عمدتاً پس از وقوع جرم و طرح شکایت آغاز می‌شود. این وضعیت در بسیاری از پرونده‌های مرتبط با شبکه‌های اجتماعی به از دست رفتن شواهد دیجیتال، تضعیف زنجیره نگهداشت ادله و کاهش قابلیت استناد گزارش‌های کارشناسی انجامیده است. در ادبیات فارنزیک دیجیتال، مفهوم «آمادگی فارنزیکی» به‌عنوان رویکردی پیشینی و ساختاری مطرح شده است که هدف آن فراهم‌سازی الزامات فنی، حقوقی و سازمانی لازم برای حفظ قابلیت جمع‌آوری، نگهداشت و تحلیل شواهد دیجیتال پیش از وقوع جرم است. با وجود توسعه چارچوب‌های مفهومی متعدد در سطح بین‌المللی، بخش قابل توجهی از این مدل‌ها یا فاقد اعتبارسنجی تجربی هستند یا بدون توجه به اقتضائات نهادی و حقوقی ایران طراحی شده‌اند. در ادبیات داخلی نیز تمرکز غالب بر تحلیل‌های حقوقی یا توصیفی پسینی بوده و خلأ یک مدل بومی آمادگی فارنزیکی که به‌صورت تجربی استخراج و کمی اعتبارسنجی شده باشد، به‌طور محسوسی مشاهده می‌شود.

پژوهش حاضر با هدف اعتبارسنجی یک مدل بومی آمادگی فارنزیکی برای پیشگیری ثانویه و بازدارنده از جرایم سایبری در شبکه‌های اجتماعی در بستر نهادی ایران انجام شد. این مطالعه با رویکرد آمیخته اکتشافی–اعتبارسنجی طراحی گردید. در مرحله کیفی، ۴۸ مصاحبه نیمه‌ساخت‌یافته با قضات رسیدگی‌کننده به پرونده‌های جرایم سایبری، وکلای فعال در این حوزه و کارشناسان رسمی دادگستری انجام شد. داده‌های حاصل با استفاده از تحلیل مضمون در سه مرحله کدگذاری باز، محوری و انتخابی تحلیل گردید و در نهایت ۶۴ کد اولیه استخراج شد که پس از ادغام موارد هم‌پوشان، به ۲۶ مؤلفه مفهومی و سه بُعد اصلی شامل الزامات فنی، الزامات حقوقی و الزامات سازمانی تقلیل یافت. بر مبنای این مؤلفه‌ها، پرسشنامه‌ای محقق‌ساخته طراحی و پس از ارزیابی روایی محتوایی توسط خبرگان و انجام پیش‌آزمون، در مرحله کمی میان ۲۱۴ نفر از جامعه هدف توزیع شد. داده‌ها با استفاده از مدل‌سازی معادلات ساختاری مبتنی بر حداقل مربعات جزئی (PLS-SEM) در نرم‌افزار SmartPLS تحلیل گردید.

نتایج ارزیابی مدل اندازه‌گیری نشان داد که تمامی سازه‌ها از پایایی و روایی مطلوب برخوردارند؛ به‌گونه‌ای که مقادیر آلفای کرونباخ بالاتر از ۰.۸۴، پایایی ترکیبی بیش از ۰.۸۹ و میانگین واریانس استخراج‌شده (AVE) بیشتر از ۰.۵۸ گزارش شد. همچنین مقادیر نسبت HTMT برای تمامی زوج‌سازه‌ها کمتر از ۰.۸۵ بود که بیانگر کفایت روایی واگراست. در مدل ساختاری، شاخص‌های برازش حاکی از تناسب مناسب مدل با داده‌ها بود (SRMR=۰.۰۶۱؛ NFI=۰.۹۱). تمامی ضرایب مسیر میان ابعاد مستقل و سازه آمادگی فارنزیکی مثبت و معنادار بودند (الزامات فنی β=۰.۳۸؛ الزامات سازمانی β=۰.۳۴؛ الزامات حقوقی β=۰.۲۹؛ ۰.۰۰۱>p). مقدار ضریب تعیین برای سازه وابسته برابر با ۰.۶۲ به‌دست آمد که نشان‌دهنده توان تبیین قابل توجه مدل در توضیح سطح آمادگی فارنزیکی است.

یافته‌های پژوهش نشان می‌دهد که آمادگی فارنزیکی در شبکه‌های اجتماعی پدیده‌ای چندبعدی است که تحقق آن مستلزم هم‌ترازی هم‌زمان زیرساخت‌های فنی ثبت و نگهداشت داده، چارچوب‌های حقوقی استنادپذیری ادله و سازوکارهای سازمانی هماهنگ است. نوآوری پژوهش در استخراج تجربی مؤلفه‌های مدل از داده‌های میدانی واقعی و اعتبارسنجی کمی ساختار آن نهفته است؛ رویکردی که شکاف میان مدل‌های انتزاعی خارجی و نیازهای اجرایی نظام قضایی ایران را کاهش می‌دهد. از منظر کاربردی، مدل پیشنهادی می‌تواند به‌عنوان چارچوبی بومی برای طراحی رویه‌های پیشینی مدیریت شواهد دیجیتال، تقویت زنجیره نگهداشت ادله و ارتقای کارآمدی پلیس فناورمحور در رسیدگی به جرایم سایبری شبکه‌های اجتماعی مورد استفاده قرار گیرد. پیشگیری مورد نظر در این پژوهش ماهیتی ثانویه و بازدارنده دارد و از مسیر افزایش قابلیت کشف و انتساب فنی جرم محقق می‌شود. پیشنهاد می‌شود پژوهش‌های

کلیدواژه‌ها

موضوعات


عنوان مقاله [English]

Validation of a Forensic Readiness Model for the Prevention of Cybercrimes in Social Media

نویسندگان [English]

  • davod godarzi 1
  • ladan riazai 2
  • ALIREZA porebrahimi 3
1 Department of Information Technology Management, Faculty of Management and Economics, Science and Research Branch, Islamic Azad University, Tehran, Iran.
2 Department of Information Technology Management, Faculty of Management and Economics, Science and Research Branch, Islamic Azad University, Tehran, Iran.
3 Department of Industrial Management, Faculty of Management, Islamic Azad University, Karaj Branch, Karaj, Iran
چکیده [English]

The rapid expansion of social media usage in Iran has transformed these platforms into primary environments for the occurrence and proliferation of cybercrimes. Characteristics such as data volatility, the ease of deleting or manipulating digital content, the platform-based dispersion of evidence, and dependency on third-party service providers significantly complicate crime detection, digital evidence preservation, and forensic attribution. In the practical context of Iran’s judicial system, cybercrime investigations largely follow a reactive, post-incident approach, where technical and forensic actions are initiated only after a complaint has been filed. In many social media-related cases, this reactive orientation has resulted in the loss of critical digital traces, weakened chain-of-custody integrity, and reduced evidentiary reliability in court proceedings. Within digital forensics literature, forensic readiness is conceptualized as a proactive and structured approach aimed at establishing the necessary technical, legal, and organizational prerequisites for preserving and managing potential digital evidence before an incident occurs. Despite the development of several international conceptual frameworks, many lack empirical validation or fail to account for the institutional and legal specificities of non-Western jurisdictions such as Iran. Domestically, prior studies have primarily focused on descriptive or legal analyses of cybercrime, with limited integration of technical forensic preparedness and almost no empirically validated indigenous model tailored to social media environments. This gap highlights the need for a context-sensitive and empirically tested forensic readiness framework.

The present study aimed to validate a localized forensic readiness model designed to enhance secondary and deterrent prevention of cybercrimes in social media within Iran’s institutional context. A mixed exploratory–validation research design was adopted. In the qualitative phase, 48 semi-structured interviews were conducted with cybercrime judges, specialized attorneys, and certified digital forensic experts. Thematic analysis was performed through open, axial, and selective coding. A total of 64 initial codes were identified and subsequently consolidated into 26 conceptual components, which were organized into three principal dimensions: technical requirements, legal requirements, and organizational requirements. Based on these findings, a researcher-developed questionnaire was constructed. Content validity was assessed by expert review, and a pilot study confirmed preliminary reliability. In the quantitative phase, the final instrument was distributed among 214 targeted respondents with professional experience in cybercrime adjudication and digital evidence assessment. Data were analyzed using Partial Least Squares Structural Equation Modeling (PLS-SEM) with SmartPLS software.

The measurement model demonstrated strong reliability and validity indicators. Cronbach’s alpha values exceeded 0.84 across all constructs, composite reliability (CR) values were above 0.89, and Average Variance Extracted (AVE) values surpassed the recommended threshold of 0.50, ranging above 0.58. Discriminant validity was confirmed using both the Fornell–Larcker criterion and the HTMT ratio, with HTMT values below 0.85 for all construct pairs. Factor loadings ranged from 0.71 to 0.89, indicating adequate indicator reliability. The structural model exhibited acceptable fit indices (SRMR = 0.061; NFI = 0.91), reflecting a satisfactory model-data fit within established PLS-SEM evaluation criteria. All hypothesized paths were positive and statistically significant at p < 0.001. Technical requirements demonstrated the strongest effect on forensic readiness (β = 0.38), followed by organizational requirements (β = 0.34) and legal requirements (β = 0.29). The coefficient of determination (R² = 0.62) indicated substantial explanatory power, suggesting that the three dimensions collectively account for 62% of the variance in forensic readiness.

The findings confirm that forensic readiness in social media environments is inherently multidimensional and requires the simultaneous alignment of technological infrastructure, legal admissibility frameworks, and coordinated organizational mechanisms. The primary contribution of this study lies in the empirical extraction of model components from real-world judicial and forensic experiences and the subsequent quantitative validation of its structural integrity. By bridging the gap between abstract theoretical frameworks and practical institutional needs, the proposed model offers a contextually grounded structure suitable for Iran’s cybercrime investigation ecosystem. From a policy and operational perspective, the validated model can serve as a foundation for designing proactive digital evidence management procedures, strengthening chain-of-custody practices, and supporting technology-driven and intelligent cyber policing strategies. The preventive dimension addressed in this study is conceptualized as secondary and deterrent prevention, achieved not through direct technical suppression of criminal activity but by enhancing the probability of detection, attribution, and effective prosecution. Future research is recommended to examine the operational implementation of the model across diverse institutional settings, conduct cross-national comparative validation, and integrate emerging technological variables such as AI-driven forensic automation to further refine and extend the framework.

کلیدواژه‌ها [English]

  • Forensic Readiness
  • Cybercrime
  • Social Media
  • Digital Forensics
  • Cyber Police
  • Digital Crime Investigation
CAPTCHA Image