Abstract
When something erroneous happens happens in digital environment, a Digital Forensic Investigations (DFIs) can be used to gather information about the event. When conducting a DFI, Digital Forensic Procedures (DFPs) are followed. DFPs provide steps to follow to ensure the successful completion of the DFI. One of the steps in a DFP is to isolate possible evidence in order to protect the evidence from contamination and tampering. The introduction of Cloud computing complicated the isolation process because there is a shared layer between users. This means that the methods used to isolate evidence must be adapted and reworked to work in the Cloud environment. In some cases new procedures need to be introduced to address the isolation problem.
In this article we introduce the idea of Cloud separation to isolate a part of the Cloud. We argue that the separation process consists of methods to move instances, as well as methods to divide the Cloud. The paper also introduces methods to accomplish the movement of instances and the division of the Cloud. The paper reports on the finding of testing the dividing methods on different Cloud operating systems in experimental conditions. The experimental outcome was that some of the methods are not applicable to Cloud separation and the methods to be used will depend on the circumstances of the DFI. Out of the experiment some lessons were learnt which should be considered when conducting Cloud separation.
Access this chapter
Tax calculation will be finalised at checkout
Purchases are for personal use only
Preview
Unable to display preview. Download preview PDF.
Similar content being viewed by others
References
Vouk, M.A.: Cloud computing - issues, research and implementations. In: 30th International Conference on Information Technology Interfaces, ITI 2008, pp. 31–40 (June 2008)
Barrett, D., King, T.: Computer networking illuminated. Jones and Bartlett illuminated series. Jones and Bartlett (2005)
Biggs, S., Vidalis, S.: Cloud computing: The impact on digital forensic investigations. In: International Conference for Internet Technology and Secured Transactions, ICITST 2009, pp. 1–6 (November 2009)
Foster, I., Zhao, Y., Raicu, I., Lu, S.: Cloud computing and grid computing 360-degree compared. In: Grid Computing Environments Workshop, GCE 2008, pp. 1–10 (November 2008)
Mell, P., Grance, T.: The NIST Definition of Cloud Computing, Recommendations of the National Institute of Standards and Technolog. Technical report, National Institute of Standards and Technology (2011)
Ashcroft, J.: Electronic Crime Scene Investigation: A Guide for First Responders. Technical Working Group for Electronic Crime Scene Investigation (July 2001)
Cohen, F.: Digital Forensic Evidence Examination, 2nd edn. Fed Cohen & Associates, Livermore (2010)
Delport, W., Olivier, M.S.: Isolation, stuck inside the cloud. In: Eighth Annual IFIP WG 11.9 International Conference on Digital Forensics (in Press, 2012)
Binnig, C., Kossmann, D., Kraska, T., Loesing, S.: How is the weather tomorrow?: towards a benchmark for the cloud. In: Proceedings of the Second International Workshop on Testing Database Systems, DBTest 2009, pp. 1–9. ACM, New York (2009)
Lu, R., Lin, X., Liangand, X., Shen, X.: Secure provenance: the essential of bread and butter of data forensics in cloud computing. In: Proceedings of the 5th ACM Symposium on Information, Computer and Communications Security, ASIACCS 2010, pp. 282–292. ACM, New York (2010)
Nitu, I.: Configurability in SaaS (software as a service) applications. In: Proceedings of the 2nd India software engineering conference, ISEC 2009, pp. 19–26. ACM, New York (2009)
Ruan, K., Carthy, J., Kechadi, T., Crosbie, M.: Cloud forensics: An overview. In: IFIP International Conference on Digital Forensics, p. 7 (2011)
Lim, N., Khoo, A.: Forensics of computers and handheld devices: identical or fraternal twins? Commun. ACM 52, 132–135 (2009)
Lyle, J.R.: A strategy for testing hardware write block devices. Digital Investigation 3(suppl.), 3–9 (2006); The Proceedings of the 6th Annual Digital Forensic Research Workshop (DFRWS 2006)
Delport, W., Olivier, M.S., Köhn, M.: Isolating a cloud instance for a digital forensic investigation. In: 2011 Information Security for South Africa (ISSA 2011) Conference (2011)
Vmware inc. Computer Program. vSphere 5.0 (2011), http://www.vmware.com (accessed May 26, 2012)
Author information
Authors and Affiliations
Editor information
Editors and Affiliations
Rights and permissions
Copyright information
© 2012 Springer-Verlag Berlin Heidelberg
About this paper
Cite this paper
Delport, W., Olivier, M.S. (2012). Cloud Separation: Stuck Inside the Cloud. In: Fischer-Hübner, S., Katsikas, S., Quirchmayr, G. (eds) Trust, Privacy and Security in Digital Business. TrustBus 2012. Lecture Notes in Computer Science, vol 7449. Springer, Berlin, Heidelberg. https://doi.org/10.1007/978-3-642-32287-7_4
Download citation
DOI: https://doi.org/10.1007/978-3-642-32287-7_4
Publisher Name: Springer, Berlin, Heidelberg
Print ISBN: 978-3-642-32286-0
Online ISBN: 978-3-642-32287-7
eBook Packages: Computer ScienceComputer Science (R0)