ENGLISH

Cloud Storage Forensics

Book information

Publisher
Syngress
Year
2013
ISBN
0124199704, 9780124199705
Language
english
Format
PDF
Filesize
5 MB (5498703 bytes)
Pages
208\208
Time added
2021-03-21 13:48:35

Description

To reduce the risk of digital forensic evidence being called into question in judicial proceedings, it is important to have a rigorous methodology and set of procedures for conducting digital forensic investigations and examinations. Digital forensic investigation in the cloud computing environment, however, is in infancy due to the comparatively recent prevalence of cloud computing. Cloud Storage Forensics presents the first evidence-based cloud forensic framework. Using three popular cloud storage services and one private cloud storage service as case studies, the authors show you how their framework can be used to undertake research into the data remnants on both cloud storage servers and client devices when a user undertakes a variety of methods to store, upload, and access data in the cloud. By determining the data remnants on client devices, you gain a better understanding of the types of terrestrial artifacts that are likely to remain at the Identification stage of an investigation. Once it is determined that a cloud storage service account has potential evidence of relevance to an investigation, you can communicate this to legal liaison points within service providers to enable them to respond and secure evidence in a timely manner. Front Cover Cloud Storage Forensics Copyright Page Contents Acknowledgments About the Authors Forewords 1 Introduction Introduction Cybercrime and the cloud Challenges faced by law enforcement and government agencies Summary Structure of book and contributions to knowledge References 2 Cloud Storage Forensic Framework Introduction Cloud (storage) forensic framework Commence (Scope) Preparation Evidence source identification and preservation Collection Examination and analysis Presentation Complete Framework summary References 3 Microsoft SkyDrive Cloud Storage Forensic Analysis Introduction SkyDrive forensics: Windows 7 PC Commence (Scope) Preparation Evidence source identification and preservation Collection Examination and analysis Control—Base-VMs SkyDrive client software SkyDrive account when accessed via a browser Keyword search terms Directory listings Prefetch files Link files Thumbcache files Event log files Registry files $Recycle.Bin Data carve Browser analysis Metadata Network analysis System Volume Information Memory (RAM) analysis Eraser, CCleaner, and DBAN Presentation Analysis findings Complete SkyDrive forensics: Apple iPhone 3G Commence (Scope) Preparation Evidence source identification and preservation Collection Examination and analysis Control—Base-XRY SkyDrive accessed via the iOS Safari browser SkyDrive application used to access the research account Presentation Analysis findings Complete Case study Step 1—Commence (Scope) Step 2—Preparation Step 3—Evidence source identification and preservation Step 4—Collection Step 5—Examination and analysis Step 6—Presentation Step 7—Complete Conclusion References 4 Dropbox Analysis: Data Remnants on User Machines Introduction Dropbox forensics: Windows 7 PC Commence (Scope) Preparation Evidence source identification and preservation Collection Examination and analysis Web browser Dropbox account information Control—Base-VMs Dropbox client software Uninstallation of Dropbox client software Keyword search terms Directory listings Prefetch files Link files Registry Thumbcache Event logs Browser analysis Network traffic (PCAP) analysis Memory analysis Results of applying anti-forensic techniques (Eraser, CCleaner) Presentation Artifacts from windows client Volatile data capture Artifacts from browser Complete Dropbox forensics: Apple iPhone 3G Commence (Scope) Preparation Evidence source identification and preservation Collection Examination and analysis Control—Base-XRY Dropbox accessed via the iOS Safari browser Dropbox application used to access the research account Presentation Artifacts from iOS browser Artifacts from Dropbox iOS client software Complete Case study Step 1—Commence (Scope) Step 2—Preparation Step 3—Evidence source identification and preservation Step 4—Collection Step 5—Examination and analysis Step 6—Presentation Step 7—Complete Conclusion References 5 Google Drive: Forensic Analysis of Cloud Storage Data Remnants Introduction Google drive forensics: Windows 7 PC Commence (Scope) Preparation Evidence source identification and preservation Collection Examination and analysis Control—Base-VMs Google drive client software Google drive account when accessed via a browser Keyword search terms Directory listings Prefetch files Link files Thumbcache files Event log files Registry files $Recycle.Bin Data carve Browser analysis Metadata Network analysis System volume information Memory (RAM) analysis Eraser, CCleaner, and DBAN Presentation Analysis findings Complete Google drive forensics: Apple iPhone 3G Commence (Scope) Preparation Evidence source identification and preservation Collection Examination and analysis Control—Base-XRY Google drive accessed via the iOS Safari browser Presentation Analysis findings Complete Google drive case study Step 1—Commence (Scope) Step 2—Preparation Step 3—Evidence source identification and preservation Preservation (PC on scene) Analysis (PC on scene) Collection (iPhone on scene) Analysis (iPhone on scene) Preservation (laptop on scene) Analysis (laptop on scene) Transportation to lab Step 4—Collection Step 5—Examination and analysis Step 6—Presentation Step 7—Complete Conclusion Summary of Microsoft SkyDrive, Dropbox, and Google Drive findings References Appendix A 6 Open Source Cloud Storage Forensics: ownCloud as a Case Study Introduction Cloud forensics framework Outline Experiment setup ownCloud overview Environment configuration Findings Client forensics Evidence source identification and preservation, and collection Examination and analysis of client devices Reporting and presentation Server forensics Evidence source identification and preservation Collection Server examination and analysis Summary of findings Conclusion References 7 Forensic Collection of Cloud Storage Data: Does the Act of Collection Result in Changes to the Data or its Metadata? Introduction Cloud storage providers Dropbox Google Drive Microsoft SkyDrive Data collection via Internet access to a user account Dropbox Collection Analysis Browser dates and times Client software dates and times Client software log files Google Drive Collection Analysis Browser dates and times Client software dates and times Client software log files Microsoft SkyDrive Collection Analysis Browser dates and times Client software dates and times Client software log files Research findings: discussion File contents Dates and times Client software dates and times Browser dates and times Verification of findings Summary Conclusion References 8 Conclusion and Future Work Research summary Future work Glossary Index

Similar books