...
首页> 外文期刊>Computers & Security >SNAPS: Towards building snapshot based provenance system for virtual machines in the cloud environment
【24h】

SNAPS: Towards building snapshot based provenance system for virtual machines in the cloud environment

机译:SNAPS:致力于为云环境中的虚拟机构建基于快照的出处系统

获取原文
获取原文并翻译 | 示例

摘要

Recent threats in cloud show the necessity to perform forensics in the cloud environment. But performing forensic investigation in the cloud is different from traditional digital forensics. Cloud characteristics like multi-tenancy, rapid elasticity, diversity, and complexity raise additional challenges for cloud forensics. For each cloud Virtual Machine (VM), there will be several evidences like vdisk, vRAM, Snapshots, Volumes, Service logs, and VM logs. The forensic challenges differ from one evidence to the other. In this paper, we look at the challenges of snapshot acquisition and analysis. In reality, snapshots for a VM may not always exist. To increase their availability, we suggest the use of Cloud Forensic Readiness (CFR) models in which the snapshots are collected before the actual incident. The captured snapshots have to be transferred to the investigators environment via network. Since the cloud VM snapshots will be generally of huge size, transferring them elsewhere for processing may lead to the problem of data gravity. We resolve this problem by designing a framework named SNAPS (Snapshots based Provenance Aware System) which is derived from the existing spatio-temporal models and then customized to suit cloud forensic investigation. The motivation behind proposing SNAPS is to generate provenance for each object in the target virtual machine using its multiple snapshots. Moreover, SNAPS can be used to address various forensic challenges starting from simple to complex ones. Few of those were illustrated with the VM snapshots acquired from the Openstack Cloud Environment. (C) 2019 Elsevier Ltd. All rights reserved.
机译:云中最近出现的威胁表明有必要在云环境中执行取证。但是,在云中执行取证调查不同于传统的数字取证。云特征(如多租户,快速弹性,多样性和复杂性)给云取证带来了更多挑战。对于每个云虚拟机(VM),将有多个证据,例如vdisk,vRAM,快照,卷,服务日志和VM日志。司法鉴定挑战从一个证据到另一个证据都不同。在本文中,我们着眼于快照获取和分析的挑战。实际上,VM的快照可能并不总是存在。为了提高其可用性,我们建议使用Cloud Forensic Readiness(CFR)模型,其中在实际事件之前收集快照。捕获的快照必须通过网络传输到调查人员环境。由于云VM快照通常会很大,因此将它们转移到其他地方进行处理可能会导致数据严重性问题。我们通过设计一个名为SNAPS(基于快照的Provenance Aware System)的框架来解决此问题,该框架是从现有的时空模型派生而来的,然后进行了定制以适合云取证调查。提出SNAPS的动机是使用目标虚拟机的多个快照为目标虚拟机中的每个对象生成源。此外,SNAPS可用于解决从简单到复杂的各种法证挑战。从Openstack Cloud Environment获取的VM快照说明了其中很少的内容。 (C)2019 Elsevier Ltd.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号