Managing forensic recovery in the cloud

Weir, George R. S. and Aßmuth, Andreas and Jäger, Nicholas (2018) Managing forensic recovery in the cloud. In: Cloud Computing 2018, 2018-02-18 - 2018-02-22. (In Press)

[thumbnail of Weir-etal-Cloud-Computing-2018-Managing-forensic-recovery-in-the-cloud]
Preview
Text. Filename: Weir_etal_Cloud_Computing_2018_Managing_forensic_recovery_in_the_cloud.pdf
Accepted Author Manuscript

Download (285kB)| Preview

Abstract

As organisations move away from locally hosted computer services toward Cloud platforms, there is a corresponding need to ensure the forensic integrity of such instances. The primary reasons for concern are (i) the locus of responsibility, and (ii) the associated risk of legal sanction and financial penalty. Building upon previously proposed techniques for intrusion monitoring, we highlight the multi-level interpretation problem, propose enhanced monitoring of Cloud-based systems at diverse operational and data storage level as a basis for review of historical change across the hosted system and afford scope to identify any data impact from hostile action or 'friendly fire'.