Title :
Cloud forensics: Evidence collection and preliminary analysis
Author :
Saibharath, S. ; Geethakumari, G.
Author_Institution :
Dept. of Comput. Sci. & Inf. Syst., BITS-Pilani, Hyderabad, India
Abstract :
Cloud computing systems host most of today´s commercial business applications yielding it high revenue which makes it a target of cyber attacks. This emphasizes the need for a digital forensic mechanism for the cloud environment. Conventional digital forensics cannot be directly presented as a cloud forensic solution due to the multi tenancy and virtualization of resources prevalent in cloud. While we do cloud forensics, the data to be inspected are cloud component logs, virtual machine disk images, volatile memory dumps, console logs and network captures. In this paper, we have come up with a remote evidence collection and pre-processing framework using Struts and Hadoop distributed file system. Collection of VM disk images, logs etc., are initiated through a pull model when triggered by the investigator, whereas cloud node periodically pushes network captures to HDFS. Pre-processing steps such as clustering and correlation of logs and VM disk images are carried out through Mahout and Weka to implement cross drive analysis.
Keywords :
cloud computing; data handling; digital forensics; parallel processing; pattern classification; virtualisation; Hadoop distributed file system; Mahout; Struts; VM disk images; Weka; cloud component logs; cloud computing systems; cloud forensics; commercial business applications; console logs; cross drive analysis; cyber attacks; digital forensic mechanism; log clustering; log correlation; network captures; preliminary analysis; remote evidence collection; resource virtualization; virtual machine disk images; volatile memory dumps; Cloud computing; Clustering algorithms; Correlation; Digital forensics; Random access memory; Security; Cloud forensics; Digital forensics; OpenStack cloud;
Conference_Titel :
Advance Computing Conference (IACC), 2015 IEEE International
Conference_Location :
Banglore
Print_ISBN :
978-1-4799-8046-8
DOI :
10.1109/IADCC.2015.7154751