Digital evidence needs to be made persistent so that it can be used later. For citizen forensics, sometimes intelligence cannot or should not be made persistent forever. In this position paper, we propose a form of snap forensics by defining an elastic duration of evidence/intelligence validity. Explicitly declaring such a duration could unify the treatment of both ephemeral intelligence and persistent evidence towards more flexible storage to satisfy privacy requirements. CCS CONCEPTS • Security and privacy → Privacy protections; KEYWORDS digital forensics, privacy requirements ACM Reference format:
Business organizations are migrating from capital expenditure models to the pay per use model of Cloud computing and avoiding infrastructural costs. Cloud systems being prone to attacks, there is a need of cyber forensic mechanisms. Traditional digital forensics models and solutions cannot be applied directly in cloud platform due to its distinct features such as multi tenancy, virtualization, rapid elasticity and the segregation of duties among cloud actors. Several technical challenges under variability of architecture, data collection, analysis and anti-forensics exist in cloud forensics. In this paper, firstly a cloud forensic clustering model is proposed across multiple virtual machine instances. Every virtual machine constitutes a virtual machine disk and its corresponding RAM image. This forensic clustering solution reduces the search space, enables multi drive correlation and forms a social network of virtual machine instances. Secondly addressing variability of cloud architectures, open source cloud platforms OpenNebula and OpenStack are compared with respect to location of evidence artifacts. An acquisition approach with the pre-processing engine to handle different architectures is designed and implemented.
scite is a Brooklyn-based organization that helps researchers better discover and understand research articles through Smart Citations–citations that display the context of the citation and describe whether the article provides supporting or contrasting evidence. scite is used by students and researchers from around the world and is funded in part by the National Science Foundation and the National Institute on Drug Abuse of the National Institutes of Health.