A Federated Distributed Digital Forensic Readiness Model for the Cloud

被引:0
作者
Koen, Renico [1 ]
Venter, Hein [1 ]
机构
[1] Univ Pretoria, Pretoria, South Africa
来源
PROCEEDINGS OF THE 19TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY, ICCWS 2024 | 2024年 / 19卷
关键词
Digital forensic readiness; Digital forensics; Cloud computing; Information silos;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Digital forensics in modern, cloud-based, microservice-based applications are complicated by multiple layers of abstraction, thereby making it difficult to accurately capture and correlate events that occur across these layers due to filtering caused by abstraction. The complexities linked to each layer of abstraction are primarily invisible to subsequent layers. Similarly, software services are often composed of one or more services provided by various service providers across the globe. Investigators are often faced with situations where breaches span over multiple service provider boundaries where not all digital forensic readiness evidence artefacts are captured by the service provider's forensic readiness processes. Instead, digital evidence artefacts are scattered across multiple service provider domains. This paper presents a novel, federated distributed digital forensic readiness model suitable for use in software-as-service, platform-as-service and infrastructure-as-service provider scenarios. The proposed model enables a service provider to capture and inspect forensic readiness artefacts in environments with various layers of abstraction. More importantly, the model also offers a way to share and access forensic readiness artefacts in a forensically sound manner to ultimately ensure that investigators can obtain a clear view of digital forensic events as they occur between amalgamated services provided by one or more separate service providers.
引用
收藏
页码:472 / 480
页数:9
相关论文
共 22 条
[1]   The Impact of Cloud Forensic Readiness on Security [J].
Alenezi, Ahmed ;
Zulkipli, Nurul H. N. ;
Atlam, Hany F. ;
Walters, Robert J. ;
Wills, Gary B. .
CLOSER: PROCEEDINGS OF THE 7TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING AND SERVICES SCIENCE, 2017, :511-517
[2]  
Alenezi AM, 2023, Arxiv, DOI arXiv:2305.03059
[3]  
AlKhateeb Haya, 2019, Proceedings of the International Conferences. Interfaces and Human Computer Interaction 2019, Game and Entertainment Technologies 2019, Computer Graphics, Visualization, Computer Vision and Image Processing 2019, P149
[4]   A View of Cloud Computing [J].
Armbrust, Michael ;
Fox, Armando ;
Griffith, Rean ;
Joseph, Anthony D. ;
Katz, Randy ;
Konwinski, Andy ;
Lee, Gunho ;
Patterson, David ;
Rabkin, Ariel ;
Stoica, Ion ;
Zaharia, Matei .
COMMUNICATIONS OF THE ACM, 2010, 53 (04) :50-58
[5]   From data to disruption [J].
Duijn, P. A. C. ;
Sloot, P. M. A. .
DIGITAL INVESTIGATION, 2015, 15 :39-45
[6]   AlmaNebula: a computer forensics framework for the Cloud [J].
Federici, Corrado .
4TH INTERNATIONAL CONFERENCE ON AMBIENT SYSTEMS, NETWORKS AND TECHNOLOGIES (ANT 2013), THE 3RD INTERNATIONAL CONFERENCE ON SUSTAINABLE ENERGY INFORMATION TECHNOLOGY (SEIT-2013), 2013, 19 :139-146
[7]   Novel digital forensic readiness technique in the cloud environment [J].
Kebande, Victor R. ;
Venter, H. S. .
AUSTRALIAN JOURNAL OF FORENSIC SCIENCES, 2018, 50 (05) :552-591
[8]  
Lillis D, 2016, Arxiv, DOI [arXiv:1604.03850, 10.48550/arXiv.1604.03850]
[9]  
Liu F., 2011, NIST Cloud Computing Reference Architecture
[10]  
Mell P, 2010, COMMUN ACM, V53, P50