Evidence Detection in Cloud Forensics
收藏资源简介:
Cloud forensics is different than digital forensics because of the architectural implementation of the cloud. In an Infrastructure as a Service (IaaS) cloud model. Virtual Machines (VM) deployed over the cloud can be used by adversaries to carry out a cyber-attack using the cloud as an environment. Investigation of such a crime requires sufficient evidence data to prove the attack in the court of law. Electronic evidence (EE) is any data that produce information relevant to the investigation. Identifying evidence from the data generated in a cloud environment is a tedious and manual process. Adhering to RFC 27037 the evidence collection can be carried out once the evidence data is detected with appropriate triage.Cyber attack originating from a VM leaves its trails on the resource that it utilizes. These patterns of attacks on the resource and its properties can be used to detect and acquire evidence data generated in a cloud.We have generated a dataset using the following settings:To generate the dataset a private cloud was set up. The system configuration included Intel® CoreTM i5-4590 Processor with 12 GB of RAM with 1TB of HDD. The private cloud setup was done using a KVM type-1 hypervisor along with OpenNebula (version 5.12) as a cloud management platform. To simulate the real-time cloud environment a script generating synthetic workload was deployed on the virtual machines of the cloud. An attack was carried out. The dataset is manually tagged with the known state of attack or normal to respective VM.
云取证与数字取证存在差异,其根源在于云架构的实现方式。在基础设施即服务(Infrastructure as a Service, IaaS)云模式下,部署于云端的虚拟机(Virtual Machine, VM)可被攻击者利用,将云环境作为载体发起网络攻击。对此类案件开展调查时,需获取充分的证据数据,以便在法庭上证实攻击行为。电子证据(Electronic Evidence, EE)指所有可提供与调查相关信息的数据。从云环境生成的数据中甄别证据,是一项繁琐且需人工完成的工作。遵循RFC 27037标准,在通过恰当的初步分流筛查检测到证据数据后,即可开展证据收集工作。由虚拟机发起的网络攻击会在其占用的云资源上留下痕迹,针对资源及其属性的攻击模式,可用于检测并获取云环境中生成的证据数据。本数据集基于以下配置生成:为生成该数据集,我们搭建了私有云环境。系统配置为:英特尔® 酷睿™ i5-4590处理器,搭配12GB内存与1TB机械硬盘。该私有云采用KVM Type-1型虚拟机监控器搭建,并以OpenNebula(5.12版本)作为云管理平台。为模拟真实云环境,我们在云平台的虚拟机上部署了生成合成工作负载的脚本,随后发起模拟攻击。本数据集已针对各虚拟机的对应状态,人工标注为"攻击发生"或"正常运行"两类标签。



