Abstract

The increasing usage of mobile cloud computing leads the cloud to become a hotbed of crime. Cloud storage is different from previous data storage in digital forensics. In this paper, we concentrate on gathering evidence from mobile iOS devices and the types of data remnants that can be found on iOS devices for different user scenarios and device states. We develop several steps for experimenting on Google Drive, OneDrive and Dropbox. We found that the evidence collection of power-off state is not the major problem in digital forensics. Different applications of cloud storage show the different statuses of data remnants. The study also shows that thumbnails and cache files are the key of evidence recovery. We present how the digital investigators to collect evidence by examining the data remnants files as well.

Full Text
Published version (Free)

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call