Dropbox analysis: Data remnants on user machines

被引:123
作者
Quick, Darren [1 ]
Choo, Kim-Kwang Raymond [1 ]
机构
[1] Univ S Australia, Adv Comp Res Ctr, Informat Assurance Res Grp, Mawson Lakes, SA 5095, Australia
关键词
Cloud storage; Cloud forensics; Dropbox analysis; Computer forensics; Digital forensics; Mobile forensics;
D O I
10.1016/j.diin.2013.02.003
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cloud storage has been identified as an emerging challenge to digital forensic researchers and practitioners in a range of literature. There are various types of cloud storage services with each type having a potentially different use in criminal activity. One area of difficulty is the identification, acquisition, and preservation of evidential data when disparate services can be utilised by criminals. Not knowing if a cloud service is being used, or which cloud service, can potentially impede an investigation. It would take additional time to contact all service providers to determine if data is being stored within their cloud service. Using Dropbox (TM) as a case study, research was undertaken to determine the data remnants on a Windows 7 computer and an Apple iPhone 3G when a user undertakes a variety of methods to store, upload, and access data in the cloud. By determining the data remnants on client devices, we contribute to a better understanding of the types of terrestrial artifacts that are likely to remain for digital forensics practitioners and examiners. Potential information sources identified during the research include client software files, prefetch files, link files, network traffic capture, and memory captures, with many data remnants available subsequent to the use of Dropbox by a user. (c) 2013 Elsevier Ltd. All rights reserved.
引用
收藏
页码:3 / 18
页数:16
相关论文
共 25 条
[1]  
[Anonymous], EL CRIM SCEN INV GUI
[2]  
[Anonymous], TUTORIAL UNDERSTANDI
[3]  
[Anonymous], 2012, FORENSIC MAG
[4]  
[Anonymous], GOOD PRACT GUID COMP
[5]  
[Anonymous], IEF TRIAG
[6]  
[Anonymous], DROPB READ V1 1
[7]  
[Anonymous], 522022MSUP1 USDOD
[8]  
[Anonymous], CLOUD COMPUTINGS ROL
[9]  
[Anonymous], MICROSOFT SYSINTERNA
[10]  
[Anonymous], 2004, NIJ SPECIAL REPORT, DOI DOI 10.3408/JAFST.7.95