Amazon Cloud Drive forensic analysis

被引:40
作者
Hale, Jason S. [1 ]
机构
[1] One Source Discovery, Louisville, KY 40222 USA
关键词
Amazon; Cloud Drive; Computer forensics; Digital forensics; Forensic analysis;
D O I
10.1016/j.diin.2013.04.006
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cloud storage is becoming increasingly popular among individuals and businesses. Amazon Cloud Drive is a flavor of cloud-based storage that allows users to transfer files to and from multiple computers, with or without the use of a separate application that must be installed on the user's machine. This paper discusses the digital artifacts left behind after an Amazon Cloud Drive has been accessed or manipulated from a computer. Methods available to a forensic examiner that can be used to determine file transfers that occurred to and from an Amazon Cloud Drive on a computer, as well as retrieving relevant Cloud Drive artifacts from unallocated space is discussed in this paper. Two Perl scripts are also introduced to help automate the process of retrieving information from Amazon Cloud Drive artifacts. (C) 2013 Elsevier Ltd. All rights reserved.
引用
收藏
页码:259 / 265
页数:7
相关论文
共 1 条
  • [1] The SQLite database file format, SQLITE DAT FIL FORM