Cloud Forensics: Evidence Collection and Preliminary Analysis

被引:0
作者
Saibharath, S. [1 ]
Geethakumari, G. [1 ]
机构
[1] BITS Pilani, Dept Comp Sci & Informat Syst, Hyderabad Campus, Hyderabad, Andhra Pradesh, India
来源
2015 IEEE INTERNATIONAL ADVANCE COMPUTING CONFERENCE (IACC) | 2015年
关键词
Cloud forensics; OpenStack cloud; Digital forensics;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Cloud computing systems host most of today's commercial business applications yielding it high revenue which makes it a target of cyber attacks. This emphasizes the need for a digital forensic mechanism for the cloud environment. Conventional digital forensics cannot be directly presented as a cloud forensic solution due to the multi tenancy and virtualization of resources prevalent in cloud. While we do cloud forensics, the data to be inspected are cloud component logs, virtual machine disk images, volatile memory dumps, console logs and network captures. In this paper, we have come up with a remote evidence collection and pre-processing framework using Struts and Hadoop distributed file system. Collection of VM disk images, logs etc., are initiated through a pull model when triggered by the investigator, whereas cloud node periodically pushes network captures to HDFS. Preprocessing steps such as clustering and correlation of logs and VM disk images are carried out through Mahout and Weka to implement cross drive analysis.
引用
收藏
页码:464 / 467
页数:4
相关论文
共 7 条
[1]   FACE: Automated digital evidence discovery and correlation [J].
Case, Andrew ;
Cristina, Andrew ;
Marziale, Lodovico ;
Richard, Golden G. ;
Roussev, Vassil .
DIGITAL INVESTIGATION, 2008, 5 :S65-S75
[2]  
Decherchi S, 2009, ADV INTEL SOFT COMPU, V63, P29
[3]  
Dykstra J, 13 ANN DIG FOR RES W, V10, pS87
[4]   Forensic feature extraction and cross-drive analysis [J].
Garfinkel, Simson L. .
DIGITAL INVESTIGATION, 2006, SUPPL. (71-81) :S71-S81
[5]  
Nassif, 2013, IEEE T INFORM FORENS, P8
[6]  
Ruan Keyun, 6 ADFSL C DIG FOR SE
[7]  
Saibharath S, 2014, INT WORKSH CLOUD SEC