کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
456425 695713 2016 19 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
Adaptive evidence collection in the cloud using attack scenarios
ترجمه فارسی عنوان
جمع آوری شواهد سازنده در ابر با استفاده از سناریوهای حمله
کلمات کلیدی
آمادگی قضایی، پردازش ابری، نرم افزار سازگار، برنامه ریزی حمله تحقیقات دیجیتال
موضوعات مرتبط
مهندسی و علوم پایه مهندسی کامپیوتر شبکه های کامپیوتری و ارتباطات
چکیده انگلیسی

The increase in crimes targeting the cloud is increasing the amount of data that must be analysed during a digital forensic investigation, exacerbating the problem of processing such data in a timely manner. Since collecting all possible evidence proactively could be cumbersome to analyse, evidence collection should mainly focus on gathering the data necessary to investigate potential security breaches that can exploit vulnerabilities present in a particular cloud configuration. Cloud elasticity can also change the attack surface available to an adversary and, consequently, the way potential security breaches can arise. Therefore, evidence collection should be adapted depending on changes in the cloud configuration, such as those determined by allocation/deallocation of virtual machines. In this paper, we propose to use attack scenarios to configure more effective evidence collection for cloud services. In particular, evidence collection activities are targeted to detect potential attack scenarios that can violate existing security policies. These activities also adapt when new/different attack scenarios can take place due to changes in the cloud configuration. We illustrate our approach by using examples of insider and outsider attacks. Our results demonstrate that using attack scenarios allows us to target evidence collection activities towards those security breaches that are likely, while saving space and time necessary to store and process such data.

ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: Computers & Security - Volume 59, June 2016, Pages 236–254
نویسندگان
, , , ,