Digital Forensic Readiness Architecture for Cloud Computing Systems

dc.contributor.advisorVenter, Hein S.
dc.contributor.emailu23148978@tuks.co.zaen_ZA
dc.contributor.postgraduateRas, Dirk J.
dc.date.accessioned2019-07-09T14:08:19Z
dc.date.available2019-07-09T14:08:19Z
dc.date.created2019
dc.date.issued2019
dc.descriptionDissertation (MSc)--University of Pretoria, 2019.en_ZA
dc.description.abstractCloud computing underpins many of the current emergent and established technologies. As a result, cloud computing has an impact on many components of our daily lives, be it from online shopping and banking to usage of mobile apps. Because of this ubiquity, crime related to cloud systems is an ongoing concern. There are, however, many factors that, while enabling cloud systems to function, also make digital forensic investigations on such systems very challenging. While processes and standards are defined for digital forensics, these processes often do not work when applied to cloud systems. Forensic investigations are, by their nature, very disruptive to the operation of a system. This is often unacceptable in a cloud environment. One way to mitigate the risk of a forensic investigation is to proactively prepare for such an event by achieving forensic readiness. This leads to the research conducted for this dissertation. The central question is whether it possible to achieve forensic readiness in a cloud environment, so that a digital forensic investigation can be conducted with minimal or no disruption to the operation of said cloud environment. This dissertation examines the background information of cloud computing, digital forensics and software architecture in order to get a clear understanding of the various research domains. Five possible models for the acquisition of data in a cloud environment are proposed, using the NIST cloud reference architecture as a baseline. A full, technology neutral, architecture for a cloud forensics system is then generated. This architecture allows for the acquisition of forensic data within a cloud environment. The architecture ensures that the data is kept forensically stable and enables the proactive analysis of the captured data. Using one of the acquisition models, a proof of concept implementation is done of the architecture. Experiments are run to determine whether the system meets the set functional requirements and quality attributes to enable forensic readiness in a cloud system. The architecture and implementation are evaluated against the experimental results and possible improvements are suggested. The research is then concluded and possible future avenues of research in the field of cloud forensics are suggested.en_ZA
dc.description.availabilityUnrestricteden_ZA
dc.description.degreeMScen_ZA
dc.description.departmentComputer Scienceen_ZA
dc.description.sponsorshipNational Research Foundation (NRF)en_ZA
dc.identifier.citationRas, DJ 2019, Digital Forensic Readiness Architecture for Cloud Computing Systems, MSc Dissertation, University of Pretoria, Pretoria, viewed yymmdd <http://hdl.handle.net/2263/70644>en_ZA
dc.identifier.otherA2019en_ZA
dc.identifier.urihttp://hdl.handle.net/2263/70644
dc.language.isoenen_ZA
dc.publisherUniversity of Pretoria
dc.rights© 2019 University of Pretoria. All rights reserved. The copyright in this work vests in the University of Pretoria. No part of this work may be reproduced or transmitted in any form or by any means, without the prior written permission of the University of Pretoria.
dc.subjectUCTDen_ZA
dc.subjectCloud forensicsen_ZA
dc.subjectCloud computingen_ZA
dc.subjectDigital forensicsen_ZA
dc.titleDigital Forensic Readiness Architecture for Cloud Computing Systemsen_ZA
dc.typeDissertationen_ZA

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Ras_Digital_2019.pdf
Size:
8.87 MB
Format:
Adobe Portable Document Format
Description:
Dissertation

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.75 KB
Format:
Item-specific license agreed upon to submission
Description: