Skip to main content

2012 | OriginalPaper | Buchkapitel

Cloud Digital Investigations Based on a Virtual Machine Computer History Model

verfasst von : Sean Thorpe, Indrajit Ray, Tyrone Grandison, Abbie Barbir

Erschienen in: Future Information Technology, Application, and Service

Verlag: Springer Netherlands

Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.

search-config
loading …

Abstract

In several traditional digital investigations, several forensic frameworks have been proposed. The selection of a suitable forensic framework for the cloud computing virtual environments further challenges the existing digital forensics space, as no conclusive generic framework exist that inclusively supports or can work for any cloud computing digital investigations. To solve this problem for the data cloud logical domains, this paper describes a model of using the computer’s virtual machine history based on finite state machine (FSM) automata theory. The model can be used to define the theory of a virtual machine (VM) cloud computing digital investigation allowing one to set the stage for prescribed applications operating within these abstract domains. The paper summarizes the theoretical concept used by the virtual machine hypervisor kernel logs that map the ideal and inferred VM history to the set of corresponding low level primitive states and events of the VM hosted computer environment.

Sie haben noch keine Lizenz? Dann Informieren Sie sich jetzt über unsere Produkte:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Literatur
1.
Zurück zum Zitat Gary, P (2001) A road map for digital forensic research. Technical report DTR-T001–01, DFRWS; November 2001. Report from the first digital forensic research workshop Gary, P (2001) A road map for digital forensic research. Technical report DTR-T001–01, DFRWS; November 2001. Report from the first digital forensic research workshop
2.
Zurück zum Zitat Beebe NL, Clark JG (2004) A hierarchical, objectives based framework for the digital investigation process. In: Proceedings of the 2004 digital forensic research workshop (DFRWS), 2004 Beebe NL, Clark JG (2004) A hierarchical, objectives based framework for the digital investigation process. In: Proceedings of the 2004 digital forensic research workshop (DFRWS), 2004
3.
Zurück zum Zitat Carrier BD, Spafford EH (2004) An event-based digital forensic investigation framework. In: Proceedings of the 2004 digital forensic research workshop (DFRWS), 2004 Carrier BD, Spafford EH (2004) An event-based digital forensic investigation framework. In: Proceedings of the 2004 digital forensic research workshop (DFRWS), 2004
5.
Zurück zum Zitat Thorpe, S, Indrajit, R, Grandison, T (2011) Towards a formal temporal log model for the virtual machine kernel synchronized environment. Proc J Inf Assur Sec (JIAS) 6 Thorpe, S, Indrajit, R, Grandison, T (2011) Towards a formal temporal log model for the virtual machine kernel synchronized environment. Proc J Inf Assur Sec (JIAS) 6
6.
Zurück zum Zitat Grandison, T, Maximillen, M, Thorpe, S, Alba, A (2010) Towards a formal definition of cloud computing. Proceedings of IEEE services, July 2010 Grandison, T, Maximillen, M, Thorpe, S, Alba, A (2010) Towards a formal definition of cloud computing. Proceedings of IEEE services, July 2010
7.
Zurück zum Zitat Thorpe, S, Ray, I (2012) File timestamps in a cloud digital investigation. J Inf Assur Secur (JIAS) 7 Thorpe, S, Ray, I (2012) File timestamps in a cloud digital investigation. J Inf Assur Secur (JIAS) 7
8.
Zurück zum Zitat Thorpe, S, Ray, I (2012) Detecting temporal inconsistency in virtual machine activity timelines. J Inf Assur Sec (JIAS) 7 Thorpe, S, Ray, I (2012) Detecting temporal inconsistency in virtual machine activity timelines. J Inf Assur Sec (JIAS) 7
9.
Zurück zum Zitat Baryamureeba, V, Tushabe, F (2004) The enhanced digital investigation process model. In: Proceedings of the 2004 digital forensic research workshop (DFRWS), 2004 Baryamureeba, V, Tushabe, F (2004) The enhanced digital investigation process model. In: Proceedings of the 2004 digital forensic research workshop (DFRWS), 2004
10.
Zurück zum Zitat Carrier B (2003) Defining digital forensic examination and analysis tools using abstraction layers. Int J Digit Evid (IJDE) 1(4) (winter) Carrier B (2003) Defining digital forensic examination and analysis tools using abstraction layers. Int J Digit Evid (IJDE) 1(4) (winter)
Metadaten
Titel
Cloud Digital Investigations Based on a Virtual Machine Computer History Model
verfasst von
Sean Thorpe
Indrajit Ray
Tyrone Grandison
Abbie Barbir
Copyright-Jahr
2012
Verlag
Springer Netherlands
DOI
https://doi.org/10.1007/978-94-007-4516-2_78

Neuer Inhalt