LogDrive: a proactive data collection and analysis framework for time-traveling forensic investigation in IaaS cloud environments

LogDrive: a proactive data collection and analysis framework for time-traveling forensic investigation in IaaS cloud environments
复制标题

DOI:
10.1186/s13677-018-0119-2
复制
发表时间:
2018-10-03
影响因子:
4
通讯作者:
Kobayashi, Ryotaro
Kobayashi, Ryotaro
中科院分区:
计算机科学3区
文献类型:
--
作者:
Hirano, Manabu;Tsuzuki, Natsuki;Kobayashi, Ryotaro

文献摘要

被引文献

相似文献

本文介绍了LogDrive框架,用于缓解云结构即服务(IaaS)云环境中存储取证的以下问题:易变性、取证数据量增加以及隐藏虚拟机中事件痕迹的反取证攻击。虚拟块设备的主动数据收集功能可以缓解云环境中的波动性问题,并使时间旅行调查能够揭示被覆盖或删除的证据文件。我们采用了一种基于扇区哈希的文件检测方法,随机采样,以搜索虚拟存储的写日志记录中的证据文件。问题的制定,调查的背景下,并与五个算法的设计。我们通过详细的评估来探索LogDrive的性能。最后,基于STRIDE(Spoofing,Tampering,Repubdiation,Information Disclosure,Denial of Service,and Elevation of Privilege,欺骗、篡改、否认、信息泄露、拒绝服务和特权提升)威胁模型和相关工作,对LogDrive进行了安全分析。我们在GitHub上发布了LogDrive的源代码。
This paper presents the LogDrive framework for mitigating the following problems of storage forensics in Infrastructure-as-a-Service (IaaS) cloud environments: volatility, increasing volume of forensic data, and anti-forensic attacks that hide traces of incidents in virtual machines. The proposed proactive data collection function of virtual block devices mitigates the problem of volatility within the cloud environments and enables a time-traveling investigation to reveal overwritten or deleted evidence files. We employ a sector-hash-based file detection method with random sampling to search for an evidence file in the record of the write logs of the virtual storage. The problem formulation, the investigation context, and the design with five algorithms are presented. We explore the performance of LogDrive through a detailed evaluation. Finally, security analysis of LogDrive is presented based on the STRIDE (Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, and Elevation of privilege) threats model and related work. We posted the source code of LogDrive on GitHub.