Source-linked AI summary
Calm Before the Storm: The Challenges of Cloud Computing in Digital Forensics
George Grispos, Tim Storer, William Bradley Glisson
TL;DR
Cloud computing challenges digital forensics because evidence can be ephemeral, remotely controlled, distributed, and difficult to acquire or preserve under conventional procedures. The paper analyzes established forensic models against cloud environments and identifies invalid assumptions alongside research needs for acquisition, evaluation, storage, and legal handling.
Problem
Existing digital-forensic principles, frameworks, practices, and tools assume investigator control of storage media, while cloud evidence may be ephemeral and beyond immediate control.
Method
The paper summarizes cloud-computing characteristics and analyzes their effects on established digital-forensic models, while identifying related research challenges and possible acquisition approaches.
Results
Many assumptions in existing forensic-investigation models are not valid in cloud environments.
Takeaways & Limitations
Cloud forensics requires guidance on forensically sound evidence retrieval, service-specific acquisition methods, large-scale evidence management, and reconsideration of data-retention and privacy issues.
Takeaways & Limitations
Empirical evaluation is constrained by the lack of standard evaluation methods and datasets for cloud-forensic methods.
Abstract
from arXiv · showhide
Cloud computing is a rapidly evolving information technology (IT) phenomenon. Rather than procure, deploy and manage a physical IT infrastructure to host their software applications, organizations are increasingly deploying their infrastructure into remote, virtualized environments, often hosted and managed by third parties. This development has significant implications for digital forensic investigators, equipment vendors, law enforcement, as well as corporate compliance and audit departments (among others). Much of digital forensic practice assumes careful control and management of IT assets (particularly data storage) during the conduct of an investigation. This paper summarises the key aspects of cloud computing and analyses how established digital forensic procedures will be invalidated in this new environment. Several new research challenges addressing this changing context are also identified and discussed.
INTRODUCTION
Cloud computing replaces much traditional IT infrastructure with remotely hosted, virtualized services, offering scalable and potentially more efficient provision while creating major forensic and legal challenges. Different service and deployment models affect what evidence exists, how volatile it is, and which legal frameworks govern its collection.
- Cloud computing replaces much traditional data-centre hardware with virtualized, remote, on-demand services configured to organizational needs.
- Cloud services were forecast to grow rapidly, including worldwide revenue increasing from $58.6 billion in 2009 to $68.3 billion in 2010.The same forecast projected $148.8 billion in 2014.
- Cloud computing can increase flexibility and efficiency by rapidly scaling or reconfiguring services without acquiring redundant hardware.It can also reduce IT-service costs by eliminating redundant infrastructure.
- Security of confidential corporate and private data remains a major concern as cloud use exposes organizations to security breaches and cybercrime risks.
- Existing digital-forensic approaches assume investigator control of storage media, whereas cloud evidence may be ephemeral and stored beyond immediate control.
- SaaS stores application-generated data in the cloud, while PaaS provides application-development platforms and IaaS leases virtualized processing, memory, and storage resources.
- Cloud deployment options can distribute data geographically, making the applicable legal framework and evidence-gathering procedures difficult to determine.
CURRENT DIGITAL FORENSIC PROCESS MODELS
Established digital-forensic process models and ACPO guidelines were developed for investigations in which investigators physically control the target system and storage media. That central assumption is likely invalid in cloud environments.
- ACPO guidelines and related forensic models organize investigations around preparation, discovery, acquisition and analysis, and review.
- ACPO principles require preserving original data, competent access when necessary, and an audit trail of forensic processes.
- The models include the DFRW Investigative Process, Abstract Digital Forensics, Integrated Digital Investigation, and Enhanced Digital Investigation models.
- These guidelines largely assume investigators have physical access and control over the target system and its storage media.
- The physical-control assumption underlying established models is likely invalidated when investigating activity in a cloud environment.
DIGITAL FORENSICS IN CLOUD ENVIRONMENTS
The paper examines cloud-forensic challenges against established investigation models and finds that many of their assumptions do not hold in cloud environments. It identifies acquisition, storage, evaluation, and legal issues requiring further research and guidance.
- The analysis uses the DFRW Investigative Process Model and ACPO principles to assess cloud computing’s effects on digital-forensic investigation stages.
- Many assumptions incorporated into existing forensic-investigation models are not valid in the context of cloud computing.
Identification
Cloud environments complicate forensic identification and preservation because data is distributed, virtualized, elastic, and often controlled by providers across jurisdictions. Existing investigation practices therefore face challenges in storage, access, imaging, timing, chain of custody, and privacy.
- Storage Capacity: Cloud investigations may require gathering extremely large amounts of data because storage can scale elastically with user requirements.This can increase storage and analysis burdens for investigators.
- Media Imaging: Traditional forensic imaging assumes investigator-controlled storage media, whereas cloud environments may require partial imaging or interfaces to virtual storage.Partial imaging may face legal challenges, while physical imaging of all cloud media is impractical.
- Data Acquisition: Live acquisition may recover more information from a connected cloud client, but client-side encryption can prevent providers from decrypting stored data.In zero-knowledge systems, only the data owner retains the decryption key.
- Data Acquisition: Cloud elasticity and provider deletion policies can make deleted-data recovery difficult or impossible.Google’s described policy deletes data from active and replication servers and removes pointers to remnants.
- Chain of Custody: Cloud providers could employ trained forensic personnel to begin a chain of custody before transferring evidence to investigators.The paper notes uncertainty about who would pay for this service and whether legislation might mandate it.
- Time and Legal Context: Cloud evidence may span jurisdictions and time zones, complicating legal authority, timeline reconstruction, and cross-jurisdictional procedures.Distributed storage and user-specific service time zones can affect interpretation of event times.
Examination and Analysis
Cloud investigations rely on examination tools and evidence sources similar to conventional forensics, but cloud logging, provider-controlled integrity checks, and distributed storage complicate access and validation.
- Forensic tool suites support pattern matching, filtering, and recovery of deleted data after evidence has been preserved and collected.
- Cloud investigations can use ordinary documents, emails, and images alongside provider-generated records of user activity.
- Message Log Search can identify email dates, account IDs, recipients, and sending or receiving mail-transfer-agent IP addresses when investigators access the administrator account.
- Amazon S3 logging records bucket requests, including request type, resource, and request time and date.
- Accessing cloud logs generally requires administrative credentials, while provider involvement introduces chain-of-custody concerns.
- Cloud-provider checksums can help demonstrate evidence integrity, but investigators have fewer opportunities to independently test the single provider implementation.
Presentation
Presenting cloud-derived evidence requires explaining cloud systems to courts and demonstrating that investigative methods satisfy scientific reliability standards. The field lacks standardized methods and evaluation resources, while rapidly changing technology complicates empirical testing.
- Cloud forensic methods may be judged under Daubert principles requiring consideration of testing, peer review, error rates, operational standards, and acceptance.
- Cloud investigations in the United States and United Kingdom will presumably face the same reliability tests when their evidence is offered in court.
- Empirical testing is difficult because cloud technology evolves rapidly and standard datasets for evaluating cloud forensic methods remain unclear.
- Cloud evidence may require expert witnesses to explain cloud computing to juries unfamiliar with how cloud systems work.
- Cloud forensics currently lacks a standard method or tool set for conducting investigations or evaluating and certifying proposed tools.
- Courts may therefore face problems assessing the presentation and admissibility of evidence derived from cloud services.
RELATED WORK
Related work identifies cloud forensics as an emerging area with technical, legal, operational, and conceptual challenges. Proposed benefits include centralized evidence and elastic forensic resources, but practitioners and researchers lack consensus and mature tools or evaluation models.
- Some authors propose that centralized cloud data could make incident investigations more efficient.
- Prior studies identify challenges including loss of registry entries, temporary files, metadata, and tools for investigations involving cloud data centers.
- Defining cloud forensics solely as network forensics omits the potentially significant forensic effects of virtualization.
- Practitioner surveys report considerable diversity of opinion about cloud computing’s future impact on digital forensic investigations.
- Legal analyses emphasize that cloud evidence collection remains subject to local laws and legislation.
- Cloud environments may provide ready virtual instances, storage for forensic images, and computing resources for password and encryption-key cracking.
FUTURE WORK
The paper proposes an immediate research agenda to address unresolved cloud-forensics problems across procedures, tools, methodologies, and specific environments.
- Future research should examine cloud service usage, acquisition-method effectiveness, commercial cloud environments, forensic management, and impacts on mobile devices.
Analysis of Cloud Service Usage
The research first needs to establish how widely organizations use cloud environments and what support private-sector users currently receive from police. It also considers whether existing support should be improved or withdrawn where inefficient.
- The initial survey stage should determine how many organizations use cloud storage and related environments.
- A second survey stage should assess private-sector demand for police support and document existing collaboration at local, regional, and national levels.
- The survey should also identify improvements to existing police support and consider removing support judged inefficient or unnecessary.
Acquisition Methods for Cloud Environments
Cloud evidence acquisition requires evaluating whether current forensic tools can capture data from clients and providers, with distinct methodologies likely needed for different cloud service models. Distributed storage and encryption create additional acquisition barriers.
- Current methods must be evaluated for capturing evidence from both cloud clients and service providers.
- SaaS, PaaS, and IaaS environments are expected to require unique acquisition methodologies and present distinct forensic challenges.
- IaaS acquisition must support forensic imaging of virtual machines running within the cloud environment.
- Distributed file systems may require alternative tools to locate and collect evidence across multiple physical locations, while encryption can prevent acquired data from functioning as a forensic image.
- Identifying useful client- and provider-side data would let investigators target requests at known artefacts and could support a revised cloud investigation model.
Commercial Cloud Providers
Research on commercial cloud providers must examine recoverable artefacts, preserve forensic integrity, and address the security, custody, legal, and scale problems of using cloud-hosted evidence and forensic infrastructure.
- Commercial cloud providers: Experiments should compare cloud storage services using controlled file manipulations to identify residual artefacts and establish typical cloud activity.
- Commercial cloud providers: Provider-specific investigations should test recovery of email content and headers, logs, viewed documents, and evidence-preserving forensic procedures.
- Commercial cloud providers: A cloud-hosted forensic server raises chain-of-custody concerns when evidence is transferred into cloud storage and security-breach concerns when providers are compromised.
- Commercial cloud providers: Large cloud evidence sets require effective processing and secure storage strategies beyond those currently used for smaller investigations.
- Commercial cloud providers: Cloud investigations must address preserving evidence during transfer and storage, complying with local data-protection laws, and preventing unauthorized access or modification.
- Commercial cloud providers: Sensitive evidence stored in the cloud introduces additional handling concerns, while cloud computing may also support data-intensive investigations and password cracking.
- Commercial cloud providers: Encryption could protect cloud-hosted evidence, but large evidence volumes may make it cumbersome, motivating research into efficient security solutions.
Mobile Cloud Device Environments
As smartphones become increasingly integrated with cloud services, mobile-cloud forensics will need usage surveys, controlled test data, performance benchmarks, and analysis of changing residual artefacts and encryption-key storage. The paper concludes that conventional forensic methods may be insufficient for cloud environments and calls for new guidance, legal review, and empirical evaluation mechanisms.
- Mobile Cloud Device Environments: Mobile-cloud research should examine corporate and private-sector use while developing test datasets for residual-artefact analysis and commercial performance benchmarks.
- Mobile Cloud Device Environments: Residual information may change with each operating-system release, complicating comparisons across mobile cloud environments.
- Mobile Cloud Device Environments: Research should examine how encryption keys secure cloud access and where those keys are stored on the device or with a third party.
- Conclusion: Conventional digital-forensic methods and guidelines could be insufficient in cloud environments, where evidence retrieval lacks adequate guidance and software tools.
- Conclusion: The paper calls for reexamining cloud data-retention and privacy laws and establishing empirical mechanisms to evaluate forensic frameworks, procedures, and software tools.