Related Experiment Videos
Analyzing Data Remnant Remains on User Devices to Determine Probative Artifacts in Cloud Environment
Abdulghani Ali Ahmed1, Chua Xue Li1
1Faculty of Computer Systems & Software Engineering, Universiti Malaysia Pahang, 26300, Kuantan, Pahang, Malaysia.
Journal of Forensic Sciences
|April 12, 2017
Summary
Cloud storage presents digital forensic challenges. This study introduces an investigation scheme using pCloud, collecting data remnants from end-user devices to identify cybercrime artifacts.
Area of Science:
- Digital Forensics
- Cybersecurity
- Cloud Computing
Background:
- Cloud storage enables remote data access, management, and backup.
- Cloud environments pose significant challenges for digital forensic investigations.
- Collecting, identifying, acquiring, and preserving digital evidence in the cloud is complex.
Purpose of the Study:
- To propose a novel investigation scheme for analyzing data remnants in cloud storage.
- To identify probative artifacts within cloud data remnants on end-user devices.
- To address the challenges faced by digital forensic practitioners in cloud environments.
Main Methods:
- Utilized pCloud as a case study for cloud storage analysis.
- Collected data remnants from end-user devices after data storage, upload, and access.
- Gathered evidence from diverse sources: client software, directory listings, prefetch, registry, network PCAP, browser history, and memory/link files.
Main Results:
- Demonstrated the value of collected data remnants in digital forensic investigations.
- Successfully identified numerous probative artifacts related to cybercrime activities.
- Confirmed the feasibility of the proposed investigation scheme in a real-world cloud scenario.
Conclusions:
- The proposed investigation scheme effectively aids in uncovering digital evidence in cloud storage.
- Data remnants on end-user devices are crucial for reconstructing cybercrime events.
- This research provides a practical framework for digital forensics in cloud computing environments.