Harvesting digital evidence from an operational cloud environment for digital forensic readiness purposes

Please be advised that the site will be down for maintenance on Sunday, September 1, 2024, from 08:00 to 18:00, and again on Monday, September 2, 2024, from 08:00 to 09:00. We apologize for any inconvenience this may cause.

Show simple item record

dc.contributor.advisor Venter, Hein
dc.contributor.postgraduate Makura, Sheunesu M.
dc.date.accessioned 2020-05-11T08:17:19Z
dc.date.available 2020-05-11T08:17:19Z
dc.date.created 2020-05-06
dc.date.issued 2020-01
dc.description Mini Dissertation (MIT(Computer Science))--University of Pretoria, 2020 en_ZA
dc.description.abstract An increase in organisations’ use of cloud computing technologies has led to cybercriminals targeting cloud environments in order to orchestrate malicious attacks. This led to the need for proactive approaches through the use of digital forensic readiness(DFR). A prototype developed by Kebande et al. (2016) sought to provide a means toattain DFR in a cloud environment without altering the existing cloud functionality. The prototype is presented as a forensic agent that uses modified botnet functionalities in order to amass digital information in a non-malicious operation. The prototype, which was implemented in a simulated environment, is able to harvest digital data like CPU and RAM usage, and keystrokes which are then hashed and stored as information in a database. However, the prototype was never tested on an operational cloud environment, hence this research study, which sought to implement a modified version of the prototype in an operational cloud environment for the purposes of achieving DFR in the cloud. OpenStack is used to provide the operational cloud environment. The prototype is deployed and executed in cloud instances hosted on OpenStack. The experiments performed in this research study show that it is viable to attain DFR in an operational cloud platform through the use of the prototype. Further observations show that the prototype is capable of harvesting digital data from cloud instances and store digital data in a database. The prototype also prepares the operational cloud environment to be forensically prepared for digital forensic investigations to be performed without alternating the functionality of the OpenStack cloud architecture. en_ZA
dc.description.availability Unrestricted en_ZA
dc.description.degree MIT(Computer Science) en_ZA
dc.description.department Computer Science en_ZA
dc.identifier.citation *Makura, SM 2020, Harvesting digital evidence from an operational cloud environment for digital forensic readiness purposes, MIT Mini Dissertation, University of Pretoria en_ZA
dc.identifier.other S2019 en_ZA
dc.identifier.uri http://hdl.handle.net/2263/74523
dc.language.iso en en_ZA
dc.publisher University of Pretoria
dc.rights © 2019 University of Pretoria. All rights reserved. The copyright in this work vests in the University of Pretoria. No part of this work may be reproduced or transmitted in any form or by any means, without the prior written permission of the University of Pretoria.
dc.subject UCTD en_ZA
dc.subject Cloud computing
dc.subject Digital forensic readiness (DFR)
dc.subject Prototype
dc.subject Operational cloud environment
dc.subject OpenStack
dc.title Harvesting digital evidence from an operational cloud environment for digital forensic readiness purposes en_ZA
dc.type Mini Dissertation en_ZA


Files in this item

This item appears in the following Collection(s)

Show simple item record