0% found this document useful (0 votes)
20 views54 pages

Cloud Forensics: Challenges & Concepts

Uploaded by

averylayneoneill
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
20 views54 pages

Cloud Forensics: Challenges & Concepts

Uploaded by

averylayneoneill
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd

Basic Cyber

Forensics
Vinny Lima
Nov 24
Module 11 – Cloud
Forensics and the
Internet of
Anything
The iCloud Celebrity Photo Leak
(2014)

[Link]
An Overview of Cloud
Computing
• Cloud computing offers many benefits to individuals and
organizations

• It has introduced some unique challenges in connection with


digital forensics investigations

• New standards are being developed to improve security practices


and incident responses in cloud environments
History of the Cloud
• The idea of cloud computing came from several people:
• Professor John McCarthy of MIT
• Dr. J.C.R. Licklider, director at the U.S. Department of Defense Advanced Research
Projects Agency (ARPA)
• In 1961, McCarthy proposed selling computing resources (such as data processing)
and software as a service through a public utility, similar to how water, sewer, and
electrical power are made available to the public.

• In 1999, [Link] developed a web service that applied digital marketing research
to business subscribers

• Amazon created Amazon Mechanical Turk in 2002, which provided storage, computations,
and human intelligence, and in 2006, it launched Elastic Compute Cloud (EC2), a web
service aimed at supporting small businesses.
Cloud Service Levels and
Deployment Methods (1 of 2)
• The National Institute of Standards and Technology (NIST)
outlines three basic service levels for cloud computing:
• Software as a service (SaaS) – applications are delivered
via the Internet (E.g.: Google Docs)
Cloud Service Levels and
Deployment Methods (1 of 2)
• The National Institute of Standards and Technology
(NIST) outlines three basic service levels for cloud
computing:
• Software as a service (SaaS) – applications
are delivered via the Internet (E.g.: Google Docs)
• Platform as a service (PaaS) – an OS has
been installed on a cloud server (E.g.: MS Azure)
• Infrastructure as a service (IaaS) –
customers can rent hardware and install
whatever OSs and applications they need
Cloud Service Levels and
Deployment Methods (2 of 2)
• Deployment methods for a cloud include the following:
• Public – accessible to anyone
• Private – can be accessed only by people who have the
necessary credentials
• Community – a way to bring people together for a specific
purpose
• Hybrid – enables a company to keep some information
private and designate other files as public or community
information
Cloud Vendors (1 of 2)
• A cloud service provider (CSP) provides on-demand network
access to a shared pool of resources

• The following are some CSPs and cloud applications:


• Salesforce
• IBM Cloud
• Cisco Cloud Solutions
• Amazon Web Services
• AT&T Synaptic
Cloud Vendors (2 of 2)
• The following are some CSPs and cloud applications (continued):
• Google Cloud Storage
• Hewlett Packard Enterprise (HPE)
• Microsoft Azure
• Citrix Hypervisor
• DigitalOcean
• Rackspace
• Oracle Cloud
Basic Concepts of Cloud Forensics
(1 of 2)
• Cloud forensics can have three dimensions:
• Organizational – addresses the structure of the cloud
• Legal – covers service agreements and other
jurisdictional matters
• Technical – deals with procedures and specialized
applications designed to perform forensics recovery
and analysis in the cloud
Basic Concepts of Cloud Forensics
(2 of 2)
• Forensic tools should have the following capabilities to handle
acquiring data from a cloud:
• Forensic data collection – must be able to identify, label,
record, and acquire data from the cloud
• Elastic, static, and live forensics – must be able to expand and
contract their storage capabilities
• Evidence segregation – different businesses and users share
the same applications and storage space
• Investigations in virtualized environments – should have the
capability to examine virtual systems
Service-Level Agreements (1 of
4)
• A cloud service agreement (CSA) is a contract between a CSP and
the cloud customer that describes what services are being provided
and at what level
• Also called a service-level agreement (SLA)

• CSAs should also specify:


• Support options
• Penalties for services not provided
• Expected system performance and fees
• Provided software or hardware
Service-Level
Agreements (2 of 4)
• CSAs define the scope of services the CSP provides:
• Service hours
• Restrictions applied to the customer by the CSP
• Availability of the cloud to the customer
• Levels of support for the customer
• Response time for data transfers
• Throughput limitations
• Contingency plan for incident response
• Business continuity and disaster recovery plan
Service-Level Agreements (3 of
4)
• Policies, Standards, and Guidelines for CSPs
• Digital forensics investigators should review CSPs policies,
standards, and guidelines for daily operations
• Policies are detailed rules for a CSP’s internal operation
• Standards give guidance to staff for unique operations, hardware,
and software and describe the staff’s obligations regarding security
of the CSP environment
• Guidelines describe best practices for cloud processes and give
staff an example of what they should strive to achieve in their work
Service-Level Agreements (4 of
4)
• CSP processes and procedures are detailed documents that define
workflow and step-by-step instructions for CSP staff
• They often include hardware configuration diagrams, network maps,
and application processing flowcharts
• Digital forensics examiners can use them to understand how data is
stored, manipulated, secured, backed up, restored, and accessed by
CSP staff and customers ([Link] )

• Additional documents of interest are the CSP’s business continuity and


disaster recovery plans
Jurisdiction
Issues
• No law ensures uniform access or
required handling procedures for the
cloud

• Investigators should be concerned about


cases involving data commingled with
other customers’ data

• Often, figuring out what law controls


data stored in the cloud is a challenge

• How privacy rights are defined in


different jurisdictions is a major factor in
problems with the right to access data
Accessing Evidence in the Cloud
(1 of 4)
The location of evidence affects what you can get access to and what laws
regulate your actions

Service level Locations of evidence

SaaS Most likely accessed on a desktop, laptop, tablet, or smartphone; the actual data and software
are stored on the service provider’s infrastructure.
PaaS Most likely found on a desktop or server, although it could also be stored on a company network
or the remote service provider’s infrastructure.
IaaS Usually found on a desktop or server; infrastructure equipment can be owned by the company or
the remote service provider.
Accessing Evidence in the Cloud
(2 of 4)
• The Electronic Communications Privacy Act (ECPA) describes five mechanisms
the government can use to get electronic information from a provider:
• Search warrants
• Subpoenas
• Subpoenas with prior notice to the subscriber or
customer
• Court orders
• Court orders with prior notice to the subscriber or
customer
Accessing Evidence in the Cloud
(3 of 4)
• Search Warrants
• A search warrant can be used only in criminal cases and must be
requested by a law enforcement officer who has evidence of
probable cause that a crime was committed
• The law requires that search warrants contain specific
descriptions of what’s to be seized
• Search warrants must also describe the location of items to seize
• But how in Cloud Forensics?? E.g.: FBI x Liquid Motors
• It must establish how it will be carried out
Accessing Evidence in the Cloud
(4 of 4)
• Subpoenas and Court Orders
• Government agency subpoenas – customer communications
and records can’t be knowingly divulged to any person or entity
• Used to get information when it’s believed there’s a danger
of death or serious physical injury
• Non-government and civil litigation subpoenas – used to
produce information from private parties for litigation
• Court orders – written by judges to compel someone to do or
not do something
Technical Challenges in Cloud
Forensics
• Challenges in conducting cloud forensics include the following:
• Architecture
• Data collection
• Analysis of cloud forensic data
• Anti-forensics
• Incident first responders
• Role management
• Legal issues
• Standards and training
Architecture
• No two CSPs are configured exactly the same way

• Depending on the type of cloud architecture and the SLA,


customer’s data could be commingled

• Most CSPs keep data storage locations confidential for security


reasons

• Differences in recording procedures or log keeping can make it


difficult to determine the data’s origin
• This may complicate an investigation’s chain of evidence
Analysis of Cloud Forensic Data
• Analyzing digital evidence from a cloud requires verifying the
data with other data and log records

• Data may need to be reconstructed to determine what actually


occurred during an incident

• Examining logs can be useful to compare the modified, last


access, and create (MAC) dates and times for files

• Metadata from affected files should be examined to validate file


accesses
Anti-Forensics (1 of 2)
• Destroying ESI that may be potential evidence is called “anti-
forensics”

• Hackers may use specialized malware for defeating evidence


collection

• Additional methods for anti-forensics:


• Inserting malware programs in other files
• Using encryption to obfuscate malware programs activated
through other malware programs
• Using data-hiding utilities that append malware to existing
Anti-Forensics (2 of 2)
• Other techniques affect file metadata by changing the modify
and last access times

• Changing timestamps can make it difficult to develop a timeline


of a hacker’s activities

• Calculating hash values of files and comparing the results with


known good files’ hash values can help identify files that might
have been altered
Incident First Responders
• CSPs have personnel trained to respond to network incidents
• They become first responders when a network intrusion occurs

• When CSPs do not have an internal first responder team, the


forensics examiner should organize CSP staff to handle these
tasks
Role Management
• Role management in the cloud covers:
• Data owners
• Identity protection
• Users
• Access controls

• As an investigator, you need to collect this information so you


can identify additional victims or suspects
Standards and Training
• The Cloud Security Alliance (CSA) has developed resource
documentation for CSPs and their staff
• It provides guidance for privacy agreements, security
measures, questionnaires, and more

• Cloud investigators should have an understanding of cloud


architecture in addition to basic digital and network forensic skills
Acquisitions in the Cloud (1 of
2)
• Methods used to collect evidence in cloud investigations depend on
the nature of the case

• Recovering deleted data from cloud storage might be limited to the


type of file system the CSP uses

• With cloud systems running in a virtual environment, snapshots can


give you valuable information before, during, and after an incident
• Forensic examiners should re-create separate cloud servers from
each snapshot, acquire an image of each server, and calculate a
hash for all files
Acquisitions in the Cloud (2 of
2)
• Many CSPs and third parties offer encryption services for cloud
users as a security measure
• Expect to find encrypted files in cloud investigations

• You need assistance from the data owner or the CSP to decrypt
data with the right encryption key

• Encrypted data in the cloud is in two states:


• Data at rest – data that has been written to disk
• Data in motion – data being transmitted over a network
Conducting a Cloud
Investigation
• When investigating cloud incidents use the same methodical
approach covered throughout this book

• The type of incident determines how to proceed with planning


the investigation

• If the investigation involves searching for and recovering data


from cloud storage or cloud customers
• See modules “Data Acquisition” and “The Investigator’s
Laboratory and Digital Forensics Tools”
Investigating CSPs (1 of 2)
• If a CSP has no team or limited staff, investigators should ask the
following questions to understand how the CSP is set up:
• Does the investigator have the authority to use cloud staff and
resources to conduct an investigation?
• Is detailed knowledge of the cloud’s topology, policies, data
storage methods, and devices available?
• Are there any restrictions on collecting digital evidence from
remote cloud storage?
Investigating CSPs (2 of 2)
• If a CSP has no team or limited staff, investigators should ask the
following questions to understand how the CSP is set up
(continued):
• For e-discovery demands on multitenant cloud systems, is the
data to collect commingled with other cloud customers’
unrelated data? Is there a way to separate the data to prevent
violating privacy rights or confidentiality agreements?
• Is the data of interest to the investigation local or remote? If
it’s in a remote location, can the CSP provide a forensically
sound connection to it?
Investigating Cloud Customers
• If a cloud customer doesn’t have the CSP’s application installed;
• You might find cloud-related evidence in a Web browser’s
cache file

• If the CSP’s application is installed:


• You can find evidence of file transfers in the application’s
folder
• This is usually found under the user’s account folder
Understanding Prefetch Files and
Artifacts
• Prefetch files contain the DLL pathnames and metadata used by an
application

• The OS reads the associated prefetch file and loads its information into
the computer’s memory

• The OS can handle other tasks instead of waiting for an application to


load needed libraries

• Example:
• Metadata in a prefetch file contains an application’s MAC times in
UTC format and a counter of how many times the app has run
Examining Stored Cloud Data on a
PC (1 of 4)
• Dropbox offers third-party applications, such as e-mail, chat,
Cisco WebEx, and other collaboration tools

• Since 2012, Dropbox has used base-64 format to store content


• Reading them requires specialized software that can read and
interpret the Dropbox [Link] file
Examining Stored Cloud Data on a
PC (2 of 4)
• Gmail users have access to Google Drive for cloud data storage
and applications

• Google Drive is installed in: C:\Program Files (x86)\Google\Drive

• Each user has a configuration file stored in C:\Users\username\


AppData\Local\Google\Drive

• If Google Drive has been installed, it creates a folder in the path


C:\Users\username\Google Drive
Examining Stored Cloud Data on a
PC (3 of 4)
• Important Google Drive files include the following:
• sync_config.db - an SQL database file with Google Drive
upgrade number, highest application version number, and
local synchronization root path
• [Link] - contains information about each file accessed,
the URL pathname, the modified and created dates and times
in UNIX timestamp format, and the file’s MD5 value and size
• sync_log.log - has a detailed list of a user’s cloud
transactions
Examining Stored Cloud Data on a
PC (4 of 4)
• OneDrive was created by Microsoft and was originally called
SkyDrive
• Available with Windows 8 and later
• It is similar to Dropbox and Google Drive and offers
subscription services for Microsoft software

• OneDrive stores user profiles in the user’s account path

• Log files and synchronized files are kept in various places under
the user’s account (depending on the Windows version)
Using Cloud Forensics Tools
• The following vendors offer integrated tools that can be applied
to cloud forensics:
• OpenText EnCase Endpoint Security
• Exterro Incident and Relief Management

• Other tools include the following:


• Forensic Open-Stack Tools (FROST)
• F-Response for the Cloud
• Magnet AXIOM Cloud
An Overview of the Internet of Things, the Internet
of Anything, and the Internet of Everything

• The Internet of Things (IoT) refers to the network of devices


connected to the Internet via embedded sensors and software that
allow the devices to send and receive data

• The term Internet of Anything (IoA) encompasses all things that can
be or will be connected to the Internet via communication protocols

• The Internet of Everything (IoE) refers to a large, interconnected


intelligent network
• IoE considers people-to-people (P2P), machine-to-people (M2P),
and machine-to-machine (M2M) connections
Technologies Supporting the
Growth of the Internet of Things
• Radio frequency identification (RFID) uses radio frequency waves
to connect devices

• According to IoT Analytics, connectivity between IoT devices now


falls into the following categories:
• Wi-Fi at 31%
• Bluetooth at 27%
• Cellular at 20%
Categories of the Internet of
Anything
• IoT technology is grouped into the following five categories:
• Consumer Internet of Things (CIoT)
• Commercial Internet of Things
• Industrial Internet of Things (IIoT)
• Infrastructure Internet of Things
• Internet of Military Things (IoMT)
Consumer Internet of Things
• CIoT is made up of applications and devices designed for
personal use
• Focuses on where and how people live, what they wear, and
what they drive

• Some examples include the following:


• Smart appliances
• Electric vehicles
• Wearable devices
Commercial Internet of Things
• Commercial IoT focuses mainly on sectors such as commercial, office
and residential buildings, healthcare, entertainment, hotels, and
travel

• Smart buildings capabilities include:


• Turning building lights on and off as needed
• Monitoring of internal and external temperatures

• Amazon Key for Business allows delivery drivers to gain access to


apartment buildings or gated communities

• The healthcare industry offers a variety of IoT devices to monitor vital


signs
Industrial Internet of Things
• IIoT covers sectors such as agriculture, energy, manufacturing, and
supply-chain logistics

• Operational technology (OT) is the software and hardware used


to identify, monitor, and manage physical devices and processes

• Supervisory control and data acquisition (SCADA) systems are


automated control systems used to monitor processes and machines
• Most SCADA systems use a human-machine interface (HMI)
that allows operators and engineers to monitor and interact with
the system to make necessary updates
Infrastructure Internet of Things
• The Infrastructure IoT includes technologies that manage
infrastructure for rural areas and for smart cities
• Such as traffic control, energy, water and waste management,
and public safety

• An IoT edge device allows the data to be processed as close to


the source as possible
• Edge computing is used to cut down on data transfers

• Vehicle-to-vehicle (V2V) communication allows vehicles to


exchange information about their location, direction, and speed
Internet of Military Things
• IoMT covers the use of IoT technologies, such as military drones
and body cameras, for military applications

• IoMT devices and systems have helped bring increased security


and efficiency to many military processes

• The Internet of Battlefield Things (IoBT) refers to all the IoT-


connected machinery, people, supplies, and weapons used on
the battlefield

• Maritime IoT allows the military chain of command to track


machinery, ships, and submarines
Summary (1 of 2)
Now that the lesson has ended, you should be able to:

• Describe the main concepts of cloud computing


• Summarize the legal challenges in conducting cloud forensics
• Explain the technical challenges associated with cloud forensics
and how to acquire cloud data
• Explain how to conduct a cloud investigation and describe some
of the commonly used tools
Summary (2 of 2)
Now that the lesson has ended, you should be able to (continued):

• Define the Internet of Anything


• Describe the five main categories of the Internet of Anything
• Explain the challenges of forensics in the Internet of Anything
Questions?
[Link]
Guide to
Computer
Forensics and
Investigations,
7e
Module 9: Virtual Machine
Forensics and Live Acquisitions
Forensics

Nelson/Phillips/Steuart/Wilson, Guide to Computer Forensics and Investigations, 7th Edition. ©2025 Cengage Learning, Inc.
All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in 54
part.

You might also like