API-Based Acquisition of Evidence from Cloud Storage Providers
Cloud computing and cloud storage services, in particular, pose a new challenge to digital forensic investigations. Currently, evidence acquisition for such services still follows the traditional approach of collecting artifacts on a client device. In this work, we show that such an approach not onl...
Main Author: | |
---|---|
Format: | Others |
Published: |
ScholarWorks@UNO
2015
|
Subjects: | |
Online Access: | http://scholarworks.uno.edu/td/2030 http://scholarworks.uno.edu/cgi/viewcontent.cgi?article=3123&context=td |
id |
ndltd-uno.edu-oai-scholarworks.uno.edu-td-3123 |
---|---|
record_format |
oai_dc |
spelling |
ndltd-uno.edu-oai-scholarworks.uno.edu-td-31232016-10-21T17:07:21Z API-Based Acquisition of Evidence from Cloud Storage Providers Barreto, Andres E Cloud computing and cloud storage services, in particular, pose a new challenge to digital forensic investigations. Currently, evidence acquisition for such services still follows the traditional approach of collecting artifacts on a client device. In this work, we show that such an approach not only requires upfront substantial investment in reverse engineering each service, but is also inherently incomplete as it misses prior versions of the artifacts, as well as cloud-only artifacts that do not have standard serialized representations on the client. In this work, we introduce the concept of API-based evidence acquisition for cloud services, which addresses these concerns by utilizing the officially supported API of the service. To demonstrate the utility of this approach, we present a proof-of-concept acquisition tool, kumodd, which can acquire evidence from four major cloud storage providers: Google Drive, Microsoft One, Dropbox, and Box. The implementation provides both command-line and web user interfaces, and can be readily incorporated into established forensic processes. 2015-08-11T07:00:00Z text application/pdf http://scholarworks.uno.edu/td/2030 http://scholarworks.uno.edu/cgi/viewcontent.cgi?article=3123&context=td University of New Orleans Theses and Dissertations ScholarWorks@UNO Cloud forensics cloud storage kumodd API-based evidence acquisition Google Drive Dropbox OneDrive Box Data Storage Systems Information Security |
collection |
NDLTD |
format |
Others
|
sources |
NDLTD |
topic |
Cloud forensics cloud storage kumodd API-based evidence acquisition Google Drive Dropbox OneDrive Box Data Storage Systems Information Security |
spellingShingle |
Cloud forensics cloud storage kumodd API-based evidence acquisition Google Drive Dropbox OneDrive Box Data Storage Systems Information Security Barreto, Andres E API-Based Acquisition of Evidence from Cloud Storage Providers |
description |
Cloud computing and cloud storage services, in particular, pose a new challenge to digital forensic investigations. Currently, evidence acquisition for such services still follows the traditional approach of collecting artifacts on a client device. In this work, we show that such an approach not only requires upfront substantial investment in reverse engineering each service, but is also inherently incomplete as it misses prior versions of the artifacts, as well as cloud-only artifacts that do not have standard serialized representations on the client.
In this work, we introduce the concept of API-based evidence acquisition for cloud services, which addresses these concerns by utilizing the officially supported API of the service. To demonstrate the utility of this approach, we present a proof-of-concept acquisition tool, kumodd, which can acquire evidence from four major cloud storage providers: Google Drive, Microsoft One, Dropbox, and Box. The implementation provides both command-line and web user interfaces, and can be readily incorporated into established forensic processes. |
author |
Barreto, Andres E |
author_facet |
Barreto, Andres E |
author_sort |
Barreto, Andres E |
title |
API-Based Acquisition of Evidence from Cloud Storage Providers |
title_short |
API-Based Acquisition of Evidence from Cloud Storage Providers |
title_full |
API-Based Acquisition of Evidence from Cloud Storage Providers |
title_fullStr |
API-Based Acquisition of Evidence from Cloud Storage Providers |
title_full_unstemmed |
API-Based Acquisition of Evidence from Cloud Storage Providers |
title_sort |
api-based acquisition of evidence from cloud storage providers |
publisher |
ScholarWorks@UNO |
publishDate |
2015 |
url |
http://scholarworks.uno.edu/td/2030 http://scholarworks.uno.edu/cgi/viewcontent.cgi?article=3123&context=td |
work_keys_str_mv |
AT barretoandrese apibasedacquisitionofevidencefromcloudstorageproviders |
_version_ |
1718388791170826240 |