• DocumentCode
    3749199
  • Title

    Cloud forensic investigation: A sneak-peek into acquisition

  • Author

    BKSP Kumar Raju; Meera G;G Geethakumari

  • Author_Institution
    BITS Pilani Hyderabad Campus, 500078, India
  • fYear
    2015
  • Firstpage
    348
  • Lastpage
    352
  • Abstract
    The popularity and usage of the cloud for both commercial and non-commercial purposes has grown exceptionally. This triggered researchers around the world to focus on performing forensic investigation in cloud environment. Recently, the National Institute of Standards and Technology had collected, categorized and listed various architectural, acquisition, analysis and legal issues in cloud forensics. In this paper, we focus on the challenges involved in acquisition phase. We developed a tool to acquire virtual machine evidences from the cloud. An investigator who is using our tool can acquire at least one of the three major evidences (virtual memory, virtual disk and service logs) by preserving corresponding evidence integrity. Basically, the tool can be used either by the cloud provider or by the investigator (external/internal). The results shown in this paper are specific to openstack cloud but the methodology used can be extended to other cloud platforms as well.
  • Keywords
    "Cloud computing","Forensics","Virtual machining","Standards","Electronic mail"
  • Publisher
    ieee
  • Conference_Titel
    Computing and Network Communications (CoCoNet), 2015 International Conference on
  • Type

    conf

  • DOI
    10.1109/CoCoNet.2015.7411209
  • Filename
    7411209