首页> 外文会议>IEEE International Conference on Mobile Adhoc and Sensor Systems >Automated Forensic Data Acquisition in the Cloud
【24h】

Automated Forensic Data Acquisition in the Cloud

机译:云端自动取证数据采集

获取原文

摘要

Movement of businesses and individuals to the cloud has posed many new complications for digital forensic investigators. This is due to a multi-tenant environment on cloud servers, chain of custody problems, globalization of data, and the inability of the Cloud Service Provider (CSP) to keep logs of everything within their network. This paper proposes a practical solution that can be implemented to mitigate the challenges with minimal to no CSP upkeep. Our model builds upon and adds to existing models and solutions including network monitoring for Infrastructure as a Service and snapshot capabilities to provide forensic evidence. We propose to utilize the automation of snapshots and an open-source tool, Google Rapid Response (GRR), set off by a hypervisor-based intrusion detection system in order to collect forensic evidence. Finally, we discuss the ideal implementation of our model and the future research direction.
机译:企业和个人向云计算的迁移给数字取证调查人员带来了许多新的复杂性。这是由于云服务器上的多租户环境,监管链问题,数据全球化以及云服务提供商(CSP)无法将其网络中所有内容的日志保留而造成的。本文提出了一种切实可行的解决方案,该解决方案可以在不进行CSP维护的情况下进行,以最小程度地缓解维护难题。我们的模型建立在现有模型和解决方案的基础之上,并增加了这些模型和解决方案,包括对基础架构即服务的网络监视和快照功能以提供法证证据。我们建议利用快照的自动化和开源工具Google快速响应(GRR),该工具由基于虚拟机管理程序的入侵检测系统引起,以收集法医证据。最后,我们讨论了模型的理想实现和未来的研究方向。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号