Evaluation of a Sector-Hash Based Rapid File Detection Method for Monitoring Infrastructure-as- a-Service Cloud Platforms

Evaluation of a Sector-Hash Based Rapid File Detection Method for Monitoring Infrastructure-as- a-Service Cloud Platforms
复制标题

用于监控基础设施即服务云平台的基于扇区哈希的快速文件检测方法的评估

DOI:
10.1109/ares.2015.15
复制
发表时间:
2015
期刊:
Proc. of the 10th International ConferenceAvailability, Reliability and Security (ARES 2015), The International Workshop on Cloud Security and Forensics
影响因子:
--
通讯作者:
and Koki Yoshida
and Koki Yoshida
中科院分区:
--
文献类型:
--
作者:
Manabu Hirano;Hayate Takase;and Koki Yoshida

文献摘要

相似文献

当前的计算机取证工具在反取证攻击、云计算以及取证目标大小的大幅增加方面存在一些限制。为了解决这些问题,本文提出了一种通过获取所有带有时间戳的数据扇区来保存存储数据的系统。所提出的系统可以在调查员指定的任何日期和时间恢复块设备的先前状态。拟议的系统旨在监控基础设施即服务(IaaS)云平台中的用户行为。本文还提出了一种快速文件检测系统,该系统利用扇区散列和并行分布式处理从获取的大量数据扇区中找到目标文件。该系统使调查人员能够跟踪并找到与云中的事件或犯罪相关的目标文件。首先,本文报告了一种基于扇区散列的文件检测方法在三种主要操作系统上的初步实验,以评估其有效性。利用Xen系统管理程序和MapReduce语言,设计并实现了监控和目标文件检测系统。我们报告其绩效评估结果。最后,我们讨论了改进性能的可能方法和当前提出的机制的局限性。
Current computer forensics tools have some limitations on anti-forensics attacks, cloud computing, and a large increase in the size of forensics targets. To solve these problems, this paper proposes a system that preserves storage data on virtual machines by acquiring all data sectors with time stamps. The proposed system can restore a previous state of a block device at any date and time that is specified by an investigator. The proposed system aims to monitor users' behavior in Infrastructure-as-a-Service (IaaS) cloud platforms. This paper also presents a rapid file detection system that finds a target file from a large collection of the acquired data sectors by using sector-hashes and parallel distributed processing. This system enables investigators to track and to find a target file that is related to incidents or crimes in the cloud. First, this paper reports the preliminary experiments of a sector-hash based file detection method on three major operating systems for evaluating its effectiveness. We present a design and an implementation of the proposed monitoring and target file detection system by using Xen hypervisor and MapReduce. We report results of its performance evaluation. Finally, we discuss possible methods to improve the performance and the limitations of the current proposed mechanism.