API-Based Acquisition of Evidence from Cloud Storage Providers

Cloud computing and cloud storage services, in particular, pose a new challenge to digital forensic investigations. Currently, evidence acquisition for such services still follows the traditional approach of collecting artifacts on a client device. In this work, we show that such an approach not onl...

Full description

Bibliographic Details
Main Author: Barreto, Andres E
Format: Others
Published: ScholarWorks@UNO 2015
Subjects:
Box
Online Access:http://scholarworks.uno.edu/td/2030
http://scholarworks.uno.edu/cgi/viewcontent.cgi?article=3123&context=td
id ndltd-uno.edu-oai-scholarworks.uno.edu-td-3123
record_format oai_dc
spelling ndltd-uno.edu-oai-scholarworks.uno.edu-td-31232016-10-21T17:07:21Z API-Based Acquisition of Evidence from Cloud Storage Providers Barreto, Andres E Cloud computing and cloud storage services, in particular, pose a new challenge to digital forensic investigations. Currently, evidence acquisition for such services still follows the traditional approach of collecting artifacts on a client device. In this work, we show that such an approach not only requires upfront substantial investment in reverse engineering each service, but is also inherently incomplete as it misses prior versions of the artifacts, as well as cloud-only artifacts that do not have standard serialized representations on the client. In this work, we introduce the concept of API-based evidence acquisition for cloud services, which addresses these concerns by utilizing the officially supported API of the service. To demonstrate the utility of this approach, we present a proof-of-concept acquisition tool, kumodd, which can acquire evidence from four major cloud storage providers: Google Drive, Microsoft One, Dropbox, and Box. The implementation provides both command-line and web user interfaces, and can be readily incorporated into established forensic processes. 2015-08-11T07:00:00Z text application/pdf http://scholarworks.uno.edu/td/2030 http://scholarworks.uno.edu/cgi/viewcontent.cgi?article=3123&context=td University of New Orleans Theses and Dissertations ScholarWorks@UNO Cloud forensics cloud storage kumodd API-based evidence acquisition Google Drive Dropbox OneDrive Box Data Storage Systems Information Security
collection NDLTD
format Others
sources NDLTD
topic Cloud forensics
cloud storage
kumodd
API-based evidence acquisition
Google Drive
Dropbox
OneDrive
Box
Data Storage Systems
Information Security
spellingShingle Cloud forensics
cloud storage
kumodd
API-based evidence acquisition
Google Drive
Dropbox
OneDrive
Box
Data Storage Systems
Information Security
Barreto, Andres E
API-Based Acquisition of Evidence from Cloud Storage Providers
description Cloud computing and cloud storage services, in particular, pose a new challenge to digital forensic investigations. Currently, evidence acquisition for such services still follows the traditional approach of collecting artifacts on a client device. In this work, we show that such an approach not only requires upfront substantial investment in reverse engineering each service, but is also inherently incomplete as it misses prior versions of the artifacts, as well as cloud-only artifacts that do not have standard serialized representations on the client. In this work, we introduce the concept of API-based evidence acquisition for cloud services, which addresses these concerns by utilizing the officially supported API of the service. To demonstrate the utility of this approach, we present a proof-of-concept acquisition tool, kumodd, which can acquire evidence from four major cloud storage providers: Google Drive, Microsoft One, Dropbox, and Box. The implementation provides both command-line and web user interfaces, and can be readily incorporated into established forensic processes.
author Barreto, Andres E
author_facet Barreto, Andres E
author_sort Barreto, Andres E
title API-Based Acquisition of Evidence from Cloud Storage Providers
title_short API-Based Acquisition of Evidence from Cloud Storage Providers
title_full API-Based Acquisition of Evidence from Cloud Storage Providers
title_fullStr API-Based Acquisition of Evidence from Cloud Storage Providers
title_full_unstemmed API-Based Acquisition of Evidence from Cloud Storage Providers
title_sort api-based acquisition of evidence from cloud storage providers
publisher ScholarWorks@UNO
publishDate 2015
url http://scholarworks.uno.edu/td/2030
http://scholarworks.uno.edu/cgi/viewcontent.cgi?article=3123&context=td
work_keys_str_mv AT barretoandrese apibasedacquisitionofevidencefromcloudstorageproviders
_version_ 1718388791170826240