Cloud-based digital forensics evaluation test (D-FET) platform.

作者: Elias Ekonomou , Robert Ludwiniak , Jamie Graves , Flavien Flandrin , Richard Macfarlane

DOI:

关键词:

摘要: This paper outlines the specification of Cloud-based DFET platform which is used to evaluate performance digital forensics tools, aim detect presence trails evidence, such as for illicit images and determination user accounts from a host. Along with measuring key quality metrics, truepositives, false-positives, it also measures operational performance, speed success, CPU utilization memory usage. determine basic footprint package-under-test. The presents proof-of-concept system using VMware vSphere Hypervisor (ESXi) within vCenter Cloud management infrastructure, provides cluster environment, supports creation instantiation well-defined virtual test operation system. infrastructure has been teaching environment two semesters, shown cope well in terms administration. Two evaluation points related whether cloudbased will provide improvement on existing stand-alone workstation-based virtualisation are energy consumption each machine. Thus results show some metrics consumptions created instances, can be justify improvements consumption, opposed scalability infrastructure.

参考文章(21)
Jesse D. Kornblum, The Linux Kernel and the Forensic Acquisition of Hard Discs with an Odd Number of Sectors. International Journal of Digital Evidence. ,vol. 3, ,(2004)
Matthew Meyers, Marc Rogers, Computer Forensics: The Need for Standardization and Certification. International Journal of Digital Evidence. ,vol. 3, ,(2004)
Brian Carrier, File system forensic analysis ,(2005)
Nicole Beebe, DIGITAL FORENSIC RESEARCH: THE GOOD, THE BAD AND THE UNADDRESSED international conference on digital forensics. ,vol. 306, pp. 17- 36 ,(2009) , 10.1007/978-3-642-04155-6_2
Robert Ludwiniak, Jamie Graves, Brian Davison, Richard Macfarlane, William J Buchanan, Niladri Bose, Performance and student perception evaluation of cloud-based virtualised security and digital forensics labs. ,(2011)
Greg Dorn, Chris Marberry, Scott Conrad, Philip Craiger, Analyzing the Impact of a Virtual Machine on a Host Machine international conference on digital forensics. ,vol. 306, pp. 69- 81 ,(2009) , 10.1007/978-3-642-04155-6_5
Stephen Brueckner, David Guaspari, Frank Adelstein, Joseph Weeks, Automated computer forensics training in a virtualized environment Digital Investigation. ,vol. 5, ,(2008) , 10.1016/J.DIIN.2008.05.009
Michael Cohen, Bradley Schatz, Hash based disk imaging using AFF4 Digital Investigation. ,vol. 7, ,(2010) , 10.1016/J.DIIN.2010.05.015
M.I. Cohen, PyFlag - An advanced network forensic framework Digital Investigation. ,vol. 5, ,(2008) , 10.1016/J.DIIN.2008.05.016