Identifying Evidence for Implementing a Cloud Forensic Analysis Framework

نویسندگان

  • Changwei Liu
  • Anoop Singhal
  • Duminda Wijesekera
چکیده

Cloud computing provides several benefits to organizations such as increased flexibility, scalability and reduced cost. However, it provides several challenges for digital forensics and criminal investigation. Some of these challenges are the dependence of forensically valuable data on the deployment model, multiple virtual machines running on a single physical machine and multiple tenancies of clients. In this paper, we show what evidence from the cloud would be useful to construct the attack scenario by using a Prolog logic based forensic analysis tool. We propose to implement and design a forensic enabled cloud, which includes installing forensic tools in the cloud environment and logging all the activities from both the application layer and lower layers. Such an implementation can provide evidence for a Prolog based forensic tool, which can automate correlating the evidence from both the clients and the cloud service provider to construct attack steps and therefore re-create the attack scenarios on the cloud. Keyword: Digital forensic analysis, cloud forensics, attack scenario, OpenStack

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Network forensic investigation in OpenFlow networks with ForCon

To resolve the challenges of forensic investigation in virtual networks, we present a new forensic framework called “Virtual Network Forensic Process”. Based on this framework we present the design, implementation and workflow of ForCon d a forensic controller to implement network investigation in OpenFlow controlled networks using Open vSwitch. Current trends bear out that virtualization techn...

متن کامل

Cloud Computing Implications to Digital Forensics a New Methodology Proposal

This paper deals with a novel approach to digital investigations, aimed at optimizing law enforcement’s tasks, concerning digital evidence acquisition, examination, analysis and reporting, and reducing investigation complexity and operational costs. In the face of Internet’s pervasiveness and massive market penetration of high-performing and low-cost handset devices, resulting in a worldwide di...

متن کامل

Digital Forensic Framework for a Cloud Environment

The advent of cloud computing provides good opportunities for both good and malicious use. Cloud computing is at its infancy stage and its security is still an open research issue. Malicious users take advantage of the current lack of advanced security mechanisms in the cloud. Cloud computing paradigm enables users to access computing resources without necessarily owning physical infrastructure...

متن کامل

Cloud Computing Log Evidence Forensic Examination Analysis

Forensic analysis in the context of physical evidence is a relatively mature field. The computerization of society has led to the emergence of digital forensics and now the popularity of cloud computing has sparked interest into cloud forensics. Our goal in this paper is to enable cloud forensics, by using the theory of abstraction layers to describe the purpose and goals of virtual machine (VM...

متن کامل

Pypette: A Framework for the Evaluation of Live Digital Forensic Acquisition Techniques

With the increasing scale of digital forensic investigations, there is a need for approaches that are capable of reducing the quantities of data forensic examiners are required to search. As this trend continues, traditional quiescent digital forensic analysis is in some cases becoming impractical; examiners must often rely on an in-situ investigation of the live computing environment. Numerous...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2016