Novel digital forensic readiness technique in the cloud environment

dc.contributor.authorKebande, Victor Rigworo
dc.contributor.authorVenter, H.S. (Hein)
dc.contributor.emailhventer@cs.up.ac.zaen_ZA
dc.date.accessioned2017-04-24T07:24:34Z
dc.date.issued2018
dc.description.abstractThis paper examines the design and implementation of a feasible technique for performing Digital Forensic Readiness (DFR) in cloud computing environments. The approach employs a modified obfuscated Non-Malicious Botnet (NMB) whose functionality operates as a distributed forensic Agent-Based Solution (ABS) in a cloud environment with capabilities of performing forensic logging for DFR purposes. Under basic Service Level Agreements (SLAs), this proactive technique allows any organization to perform DFR in the cloud without interfering with operations and functionalities of the existing cloud architecture or infrastructure and the collected file metadata. Based on the evaluation discussed, the effectiveness of our approach is presented as the easiest way of conducting DFR in the cloud environment as stipulated in the ISO/IEC 27043: 2015 international standard, which is a standard of information technology, security techniques and incident investigation principles and processes. Through this technique, digital forensic analysts are able to maximize the potential use of digital evidence while minimizing the cost of conducting DFR. As a result of this process, the time and cost needed to conduct a Digital Forensic Investigation (DFI) is saved. As a consequence, the technique helps the law enforcement, forensic analysts and Digital Forensic Investigators (DFIs) during post-event response and in a court of law to develop a hypothesis in order to prove or disprove a fact during an investigative process, if there is an occurrence of a security incident. Experimental results of the developed prototype are described which conclude that the technique is effective in improving the planning and preparation of pre-incident detection during digital crime investigations. In spite of that, a comparison with other existing forensic readiness models has been conducted to show the effectiveness of the previously proposed Cloud Forensic Readiness as a Service (CFRaaS) model.en_ZA
dc.description.departmentComputer Scienceen_ZA
dc.description.embargo2018-01-31
dc.description.librarianhb2017en_ZA
dc.description.sponsorshipThe work was supported by National Research Foundation (Grant No. UID85794).en_ZA
dc.description.sponsorshipThe National Research Foundation (Grant No. UID85794)en_ZA
dc.description.urihttp://www.tandfonline.com/loi/tajf20en_ZA
dc.identifier.citationVictor R. Kebande & H. S. Venter (2018) Novel digital forensic readiness technique in the cloud environment, Australian Journal of Forensic Sciences, 50:5, 552-591, DOI: 10.1080/00450618.2016.1267797.en_ZA
dc.identifier.issn0045-0618 (print)
dc.identifier.issn1834-562X (online)
dc.identifier.other10.1080/00450618.2016.1267797
dc.identifier.urihttp://hdl.handle.net/2263/60013
dc.language.isoenen_ZA
dc.publisherTaylor and Francisen_ZA
dc.rights© 2017 Australian Academy of Forensic Sciences. This is an electronic version of an article published in Australian Journal of Forensic Sciences, vol. 50, no. 5, pp. 552-591, 2018. doi : 10.1080/00450618.2016.1267797. Australian Journal of Forensic Sciences is available online at : http://www.tandfonline.com/loi/tajf20.en_ZA
dc.subjectAgent-based solutionen_ZA
dc.subjectDigital evidenceen_ZA
dc.subjectDigital forensics readiness (DFR)en_ZA
dc.subjectCloud computing environmenten_ZA
dc.subjectNon-malicious botnet (NMB)en_ZA
dc.titleNovel digital forensic readiness technique in the cloud environmenten_ZA
dc.typePostprint Articleen_ZA

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Kebande_Novel_2017.pdf
Size:
1006.3 KB
Format:
Adobe Portable Document Format
Description:
Postprint Article

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.75 KB
Format:
Item-specific license agreed upon to submission
Description: