scispace - formally typeset
Proceedings ArticleDOI

Digital forensics investigations in the Cloud

TLDR
The results indicate that the relation between the time taken for image acquisition and different storage volumes is not linear, owing to several factors affecting remote acquisition, especially over the Internet.
Abstract
The essentially infinite storage space offered by Cloud Computing is quickly becoming a problem for forensics investigators in regards to evidence acquisition, forensic imaging and extended time for data analysis. It is apparent that the amount of stored data will at some point become impossible to practically image for the forensic investigators to complete a full investigation. In this paper, we address these issues by determining the relationship between acquisition times on the different storage capacities, using remote acquisition to obtain data from virtual machines in the cloud. A hypothetical case study is used to investigate the importance of using a partial and full approach for acquisition of data from the cloud and to determine how each approach affects the duration and accuracy of the forensics investigation and outcome. Our results indicate that the relation between the time taken for image acquisition and different storage volumes is not linear, owing to several factors affecting remote acquisition, especially over the Internet. Performing the acquisition using cloud resources showed a considerable reduction in time when compared to the conventional imaging method. For a 30GB storage volume, the least time was recorded for the snapshot functionality of the cloud and dd command. The time using this method is reduced by almost 77 percent. FTK Remote Agent proved to be most efficient showing an almost 12 percent reduction in time over other methods of acquisition. Furthermore, the timelines produced with the help of the case study, showed that the hybrid approach should be preferred to complete approach for performing acquisition from the cloud, especially in time critical scenarios.

read more

Citations
More filters
Journal ArticleDOI

A survey of information security incident handling in the cloud

TL;DR: A conceptual cloud incident handling model is proposed that brings together incident handling, digital forensic and the Capability Maturity Model for Services to more effectively handle incidents for organisations using the cloud.
Book

Cloud Storage Forensics

TL;DR: In this paper, the authors present the first evidence-based cloud forensic framework, which can be used to undertake research into the data remnants on both cloud storage servers and client devices when a user undertakes a variety of methods to store, upload, and access data in the cloud.
Journal ArticleDOI

Forensic investigation of P2P cloud storage services and backbone for IoT networks

TL;DR: The cloud forensics framework of Martini and Choo is extended to provide a forensically sound investigation methodology for the newer BitTorrent Sync applications, suggesting that artefacts relating to the installation, uninstallation, log-in,log-off, and file synchronisation could be recovered, which are potential sources of IoT forensics.
Journal ArticleDOI

SugarSync forensic analysis

TL;DR: Research was undertaken to determine the types and nature of volatile and non-volatile data that can be recovered from Windows 8, Mac OS X 10.9, Android 4 and iOS 7 devices when a user has carried out different activities such as upload and download of files and folders.
Posted Content

Current Challenges and Future Research Areas for Digital Forensic Investigation

TL;DR: In this paper, the authors explore the current challenges contributing to the backlog in digital forensics from a technical standpoint and outline a number of future research topics that could greatly contribute to a more efficient digital forensic process.
References
More filters

Guide to Integrating Forensic Techniques into Incident Response | NIST

TL;DR: In this paper, the authors describe the processes for performing effective forensics activities and provide advice regarding different data sources, including files, operating systems (OS), network traffic, and applications.
ReportDOI

Guide to Integrating Forensic Techniques into Incident Response

TL;DR: The guide presents forensics from an IT view, not a law enforcement view, and provides advice regarding different data sources, including files, operating systems (OS), network traffic, and applications.
Journal ArticleDOI

Acquiring forensic evidence from infrastructure-as-a-service cloud computing: Exploring and evaluating tools, trust, and techniques

TL;DR: A model to show the layers of trust required in the cloud is created and for the first time an evaluation of popular forensic acquisition tools are provided, showing that they can successfully return volatile and non-volatile data from the cloud.
Journal ArticleDOI

An integrated conceptual digital forensic framework for cloud computing

TL;DR: An integrated (iterative) conceptual digital forensic framework is proposed, which emphasises the differences in the preservation of forensic data and the collection of cloud computing data for forensic purposes, and discusses cloud computing digital forensic issues.
Proceedings ArticleDOI

Technical Issues of Forensic Investigations in Cloud Computing Environments

TL;DR: This paper focuses on the technical aspects of digital forensics in distributed cloud environments by assessing whether it is possible for the customer of cloud computing services to perform a traditional digital investigation from a technical point of view.
Related Papers (5)