Cloud Evidence Tracing System: An integrated forensics investigation system for large-scale public cloud platform

被引:3
|
作者
Wu, Songyang [1 ]
Sun, Wenqi [1 ]
Ding, Zhiguo [1 ]
Liu, Shanjun [1 ]
机构
[1] Minist Publ Secur, Third Res Inst, Shanghai, Peoples R China
来源
FORENSIC SCIENCE INTERNATIONAL-DIGITAL INVESTIGATION | 2022年 / 41卷
关键词
Integrated forensics; Large-scale cloud; Virtual machine; FRAMEWORK; TOOLS;
D O I
10.1016/j.fsidi.2022.301391
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
With the rise of cloud computing, many systems are migrating to public cloud platforms. Numerous crimes are committed in the cloud, including the establishment of illegal websites and the storage of illegal data. Using virtualization technology, data can be logically stored in the same virtual host, but also physically distributed across multiple hard drives, clusters, or even countries. In these circumstances, using the traditional forensic method of physical preservation will consume a great deal of resources, which will clog the forensic process. In order to develop an effective cloud investigation solution, two challenges must be overcome. First, the difficulty of collecting data consistently when the VMs (Virtual Machines) involved are deployed across multiple CSPs. Second, the difficulty of keeping track of all the files created during the forensic workflow. We developed CETS (Cloud Evidence Tracing System), which utilizes CSP's existing API to perform a variety of forensic operations including acquisition, preservation, and emulation, as well as data analysis and file management. To evaluate the system, we created three cloud environments in the laboratory, including a forensic target cloud, a preservation cloud, and an emulation cloud, and conducted a series of forensic experiments. CETS was shown to significantly increase the investigator's investigative efficiency and reduce the investigation workflow's resource consumption. Currently, CETS has collected data exceeding 2 PB, rerun more than 2000 virtual hosts, including servers and databases, supported more than 300 investigation cases related to cloud platforms. CETS can be an example system for efficient forensic investigation in large-scale cloud environment.(c) 2022 Elsevier Ltd. All rights reserved.
引用
收藏
页数:10
相关论文
共 50 条
  • [31] A quick and intelligent screening method for large-scale retired batteries based on cloud-edge collaborative architecture
    Gu, Xin
    Li, Jinglun
    Zhu, Yuhao
    Wang, Yue
    Mao, Ziheng
    Shang, Yunlong
    ENERGY, 2023, 285
  • [32] A Virtual Resource Pricing Mechanism Based on Three-Side Gaming Model in Large-Scale Cloud Environments
    Xiao, Peng
    INTERNATIONAL JOURNAL OF E-COLLABORATION, 2020, 16 (03) : 17 - 32
  • [33] Reproducible Large-Scale Neuroimaging Studies with the OpenMOLE Workflow Management System
    Passerat-Palmbach, Jonathan
    Reuillon, Romain
    Leclaire, Mathieu
    Makropoulos, Antonios
    Robinson, Emma C.
    Parisot, Sarah
    Rueckert, Daniel
    FRONTIERS IN NEUROINFORMATICS, 2017, 11
  • [34] A Stochastic Performance Model and Mobility Analysis in the Integrated Cloud-Fog-Edge Computing System
    Kirsal, Yonal
    MOBILE NETWORKS & APPLICATIONS, 2023, 29 (5): : 1529 - 1550
  • [35] An Improved Interval AHP Method for Assessment of Cloud Platform-based Electrical Safety Monitoring System
    Wang, Shou-Xiang
    Ge, Lei-Jiao
    Cai, Sheng-Xia
    Zhang, Dong
    JOURNAL OF ELECTRICAL ENGINEERING & TECHNOLOGY, 2017, 12 (02) : 959 - 968
  • [36] A Systematic Mapping Study of Cloud Large-Scale Foundation-Big Data, IoT, and Real-Time Analytics
    Odun-Ayo, Isaac
    Goddy-Worlu, Rowland
    Abayomi-Zannu, Temidayo
    Grant, Emanuel
    DATA MANAGEMENT, ANALYTICS AND INNOVATION, ICDMAI 2019, VOL 1, 2020, 1042 : 339 - 363
  • [37] An Intrusion Detection Game in Access Control System for the M2M Local Cloud Platform
    Anggorojati, Bayu
    Prasad, Neeli Rashmi
    Prasad, Ramjee
    2013 19TH ASIA-PACIFIC CONFERENCE ON COMMUNICATIONS (APCC): SMART COMMUNICATIONS TO ENHANCE THE QUALITY OF LIFE, 2013, : 345 - 350
  • [38] Complexity profiles: A large-scale review of energy system models in terms of complexity
    Ridha, Elias
    Nolting, Lars
    Praktiknjo, Aaron
    ENERGY STRATEGY REVIEWS, 2020, 30
  • [39] BVFLEMR: an integrated federated learning and blockchain technology for cloud-based medical records recommendation system
    Hai, Tao
    Zhou, Jincheng
    Srividhya, S. R.
    Jain, Sanjiv Kumar
    Young, Praise
    Agrawal, Shweta
    JOURNAL OF CLOUD COMPUTING-ADVANCES SYSTEMS AND APPLICATIONS, 2022, 11 (01):
  • [40] Survey of external memory large-scale graph processing on a multi-core system
    Huang, Jianqiang
    Qin, Wei
    Wang, Xiaoying
    Chen, Wenguang
    JOURNAL OF SUPERCOMPUTING, 2020, 76 (01): : 549 - 579