首页> 外文期刊>The Australian journal of forensic sciences >Novel digital forensic readiness technique in the cloud environment
【24h】

Novel digital forensic readiness technique in the cloud environment

机译:云环境中的新型数字法医准备技术

获取原文
获取原文并翻译 | 示例
           

摘要

This paper examines the design and implementation of a feasible technique for performing Digital Forensic Readiness (DFR) in cloud computing environments. The approach employs a modified obfuscated Non-Malicious Botnet (NMB) whose functionality operates as a distributed forensic Agent-Based Solution (ABS) in a cloud environment with capabilities of performing forensic logging for DFR purposes. Under basic Service Level Agreements (SLAs), this proactive technique allows any organization to perform DFR in the cloud without interfering with operations and functionalities of the existing cloud architecture or infrastructure and the collected file metadata. Based on the evaluation discussed, the effectiveness of our approach is presented as the easiest way of conducting DFR in the cloud environment as stipulated in the ISO/IEC 27043: 2015 international standard, which is a standard of information technology, security techniques and incident investigation principles and processes. Through this technique, digital forensic analysts are able to maximize the potential use of digital evidence while minimizing the cost of conducting DFR. As a result of this process, the time and cost needed to conduct a Digital Forensic Investigation (DFI) is saved. As a consequence, the technique helps the law enforcement, forensic analysts and Digital Forensic Investigators (DFIs) during post-event response and in a court of law to develop a hypothesis in order to prove or disprove a fact during an investigative process, if there is an occurrence of a security incident. Experimental results of the developed prototype are described which conclude that the technique is effective in improving the planning and preparation of pre-incident detection during digital crime investigations. In spite of that, a comparison with other existing forensic readiness models has been conducted to show the effectiveness of the previously proposed Cloud Forensic Readiness as a Service (CFRaaS) model.
机译:本文介绍了在云计算环境中执行数字法医准备(DFR)的可行技术的设计与实现。该方法采用修改后的混淆非恶意僵尸网络(NMB),其功能作为云环境中的基于分布式取证代理的解决方案(ABS),其具有对DFR目的进行法医日志记录的能力。根据基本服务级别协议(SLA),此主动技术允许任何组织在云中执行DFR,而不会干扰现有云架构或基础架构和收集的文件元数据的操作和功能。基于评估所讨论的,我们的方法的有效性是在ISO / IEC 27043:2015国际标准中规定的云环境中进行DFR的最简单方法,这是一种信息技术,安全技术和事件调查的标准原则和流程。通过这种技术,数字法医分析师能够最大限度地利用数字证据,同时最小化进行DFR的成本。由于这个过程,进行了数字法医调查(DFI)所需的时间和成本。因此,该技术有助于在事件后响应和法庭中的法院执法,法医分析师和数字法医调查员(DFIS)制定假设,以便在调查过程中证明或反驳事实是一个安全事件的发生。描述了开发原型的实验结果,这结论是,该技术在改善数字犯罪调查期间改善预先发生检测的规划和制备有效。尽管如此,已经进行了与其他现有的法医准备模型的比较,以显示以前提出的云法证准备作为服务(CFRAAS)模型的有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号