Cloud Evidence Tracing System: An integrated forensics investigation system for large-scale public cloud platform

被引:3
|
作者
Wu, Songyang [1 ]
Sun, Wenqi [1 ]
Ding, Zhiguo [1 ]
Liu, Shanjun [1 ]
机构
[1] Minist Publ Secur, Third Res Inst, Shanghai, Peoples R China
来源
FORENSIC SCIENCE INTERNATIONAL-DIGITAL INVESTIGATION | 2022年 / 41卷
关键词
Integrated forensics; Large-scale cloud; Virtual machine; FRAMEWORK; TOOLS;
D O I
10.1016/j.fsidi.2022.301391
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
With the rise of cloud computing, many systems are migrating to public cloud platforms. Numerous crimes are committed in the cloud, including the establishment of illegal websites and the storage of illegal data. Using virtualization technology, data can be logically stored in the same virtual host, but also physically distributed across multiple hard drives, clusters, or even countries. In these circumstances, using the traditional forensic method of physical preservation will consume a great deal of resources, which will clog the forensic process. In order to develop an effective cloud investigation solution, two challenges must be overcome. First, the difficulty of collecting data consistently when the VMs (Virtual Machines) involved are deployed across multiple CSPs. Second, the difficulty of keeping track of all the files created during the forensic workflow. We developed CETS (Cloud Evidence Tracing System), which utilizes CSP's existing API to perform a variety of forensic operations including acquisition, preservation, and emulation, as well as data analysis and file management. To evaluate the system, we created three cloud environments in the laboratory, including a forensic target cloud, a preservation cloud, and an emulation cloud, and conducted a series of forensic experiments. CETS was shown to significantly increase the investigator's investigative efficiency and reduce the investigation workflow's resource consumption. Currently, CETS has collected data exceeding 2 PB, rerun more than 2000 virtual hosts, including servers and databases, supported more than 300 investigation cases related to cloud platforms. CETS can be an example system for efficient forensic investigation in large-scale cloud environment.(c) 2022 Elsevier Ltd. All rights reserved.
引用
收藏
页数:10
相关论文
共 50 条
  • [22] A lightweight and robust authentication scheme for the healthcare system using public cloud server
    Abbasi, Irshad Ahmed
    Jan, Saeed Ullah
    Alqahtani, Abdulrahman Saad
    Khan, Adnan Shahid
    Algarni, Fahad
    PLOS ONE, 2024, 19 (01):
  • [23] Cloud-based ubiquitous object sharing platform for heterogeneous logistics system integration
    Li, Ming
    Lin, Peng
    Xu, Gangyan
    Huang, George Q.
    ADVANCED ENGINEERING INFORMATICS, 2018, 38 : 343 - 356
  • [24] Cloud and Big Data Security System's Review Principles: A Decisive Investigation
    Mishra, KamtaNath
    Bhattacharjee, Vandana
    Saket, Shashwat
    Mishra, Shivam P.
    WIRELESS PERSONAL COMMUNICATIONS, 2022, 126 (02) : 1013 - 1050
  • [25] Partitional Decoupling Method for Fast Calculation of Energy Flow in a Large-Scale Heat and Electricity Integrated Energy System
    Zhang, Suhan
    Gu, Wei
    Yao, Shuai
    Lu, Shuai
    Zhou, Suyang
    Wu, Zhi
    IEEE TRANSACTIONS ON SUSTAINABLE ENERGY, 2021, 12 (01) : 501 - 513
  • [26] Design of Hypervisor-based Integrated Intrusion Detection System in Cloud Computing Environment
    Wang, Chih-Hung
    Chen, Xuan-Liang
    INTELLIGENT SYSTEMS AND APPLICATIONS (ICS 2014), 2015, 274 : 972 - 981
  • [27] An optimized novel public cloud system to secure the medical record from third parties
    Singh, Kishan Kumar
    Jha, Vijay Kumar
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2023, 35 (19):
  • [28] QMLFD Based RSA Cryptosystem for Enhancing Data Security in Public Cloud Storage System
    Kaliyamoorthy, Priyadharshini
    Ramalingam, Aroul Canessane
    WIRELESS PERSONAL COMMUNICATIONS, 2022, 122 (01) : 755 - 782
  • [29] Pipeline image haze removal system using dark channel prior on cloud processing platform
    Li, Ce
    He, Tan
    Wang, Yingheng
    Zhang, Liguo
    Liu, Ruili
    Zheng, Jing
    INTERNATIONAL JOURNAL OF COMPUTATIONAL SCIENCE AND ENGINEERING, 2020, 22 (01) : 84 - 95
  • [30] A Two-stage Load Balancing Method for HLA Simulation System on Cloud Simulation Platform
    Ding, Peng
    Song, Xiao
    Shi, Wen
    Zhou, Feng
    Zhang, Shaoyun
    2014 IEEE CHINESE GUIDANCE, NAVIGATION AND CONTROL CONFERENCE (CGNCC), 2014, : 2192 - 2197