DocumentCode
3101482
Title
Cloud forensics: Evidence collection and preliminary analysis
Author
Saibharath, S. ; Geethakumari, G.
Author_Institution
Dept. of Comput. Sci. & Inf. Syst., BITS-Pilani, Hyderabad, India
fYear
2015
fDate
12-13 June 2015
Firstpage
464
Lastpage
467
Abstract
Cloud computing systems host most of today´s commercial business applications yielding it high revenue which makes it a target of cyber attacks. This emphasizes the need for a digital forensic mechanism for the cloud environment. Conventional digital forensics cannot be directly presented as a cloud forensic solution due to the multi tenancy and virtualization of resources prevalent in cloud. While we do cloud forensics, the data to be inspected are cloud component logs, virtual machine disk images, volatile memory dumps, console logs and network captures. In this paper, we have come up with a remote evidence collection and pre-processing framework using Struts and Hadoop distributed file system. Collection of VM disk images, logs etc., are initiated through a pull model when triggered by the investigator, whereas cloud node periodically pushes network captures to HDFS. Pre-processing steps such as clustering and correlation of logs and VM disk images are carried out through Mahout and Weka to implement cross drive analysis.
Keywords
cloud computing; data handling; digital forensics; parallel processing; pattern classification; virtualisation; Hadoop distributed file system; Mahout; Struts; VM disk images; Weka; cloud component logs; cloud computing systems; cloud forensics; commercial business applications; console logs; cross drive analysis; cyber attacks; digital forensic mechanism; log clustering; log correlation; network captures; preliminary analysis; remote evidence collection; resource virtualization; virtual machine disk images; volatile memory dumps; Cloud computing; Clustering algorithms; Correlation; Digital forensics; Random access memory; Security; Cloud forensics; Digital forensics; OpenStack cloud;
fLanguage
English
Publisher
ieee
Conference_Titel
Advance Computing Conference (IACC), 2015 IEEE International
Conference_Location
Banglore
Print_ISBN
978-1-4799-8046-8
Type
conf
DOI
10.1109/IADCC.2015.7154751
Filename
7154751
Link To Document