Visible to the public Research on Digital Forensics Framework for Malicious Behavior in Cloud

TitleResearch on Digital Forensics Framework for Malicious Behavior in Cloud
Publication TypeConference Paper
Year of Publication2019
AuthorsChen, Guangxuan, Wu, Di, Chen, Guangxiao, Qin, Panke, Zhang, Lei, Liu, Qiang
Conference Name2019 IEEE 4th Advanced Information Technology, Electronic and Automation Control Conference (IAEAC)
ISBN Number978-1-7281-1907-6
Keywordscloud computing, cloud-based malicious behavior detection mechanism, composability, Computer crime, cyber crime, cybercrimes, digital forensics, digital forensics framework, emergency services, full-traffic flow detection technology, Human Behavior, human factors, IaaS service based forensics module, infection topology, information forensics, law enforcement, malicious behavior, malicious behavior oriented framework, malicious virtual machine detection, Memory Analysis, Metrics, privacy, privacy leakage, pubcrawl, resilience, Resiliency, SDN, traceability module, virtual machines, Virtual machining, virtualisation, virtualization facility memory evidence extraction, virtualization privacy, volatile data loss problems
Abstract

The difficult of detecting, response, tracing the malicious behavior in cloud has brought great challenges to the law enforcement in combating cybercrimes. This paper presents a malicious behavior oriented framework of detection, emergency response, traceability, and digital forensics in cloud environment. A cloud-based malicious behavior detection mechanism based on SDN is constructed, which implements full-traffic flow detection technology and malicious virtual machine detection based on memory analysis. The emergency response and traceability module can clarify the types of the malicious behavior and the impacts of the events, and locate the source of the event. The key nodes and paths of the infection topology or propagation path of the malicious behavior will be located security measure will be dispatched timely. The proposed IaaS service based forensics module realized the virtualization facility memory evidence extraction and analysis techniques, which can solve volatile data loss problems that often happened in traditional forensic methods.

URLhttps://ieeexplore.ieee.org/document/8997702
DOI10.1109/IAEAC47372.2019.8997702
Citation Keychen_research_2019