Abstract

Traditional digital forensic methods become exceedingly feeble in cloud due to the fact that the basic infrastructure turns to virtualized environment. Leveraging properties of virtualization, virtual machine introspection has showed potential for cloud forensic. In this paper, we propose a novel framework, which contains a trustworthy independent agency, to provide memory digital forensic analysis (DFA) for virtual machines (VMs) in cloud. With the assistance of cloud platform, memory dump files can be obtained and transferred to the agency for further DFA, where information of VMs can be extracted using the proper tools. We described the constructional design of the framework. Test results showed the versatility of DFA and ability of malware detection. The framework indicates DFA can be purchased as a service only when there is a need in order to reduce the expenditures on maintaining exclusive facility and furnish standard procedure to multiple cloud platforms.

Full Text
Published version (Free)

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call