What are the challenges associated with cloud computing and digital forensic investigation?

The inaccessibility of data, potential lack of information and unknown provenance of evidence are major concerns for digital forensics in the cloud and can result in a situation where evidence may not be available or where the integrity of the evi- dence cannot be verified on the systems used for cloud computing (Casey …

The challenges can be listed as the evidence identification, legal, data acquisition and the suitability of traditional digital forensic tools to acquire data within Cloud based environments.

Evidence identification is the major task in cloud forensics because it is comprised of different kind of services and deployment models. Data is spread all over the world so there is no chance to seize any physical device to get evidence.

In a cloud forensic investigation, the service provider controls the amount of data released to the investigator; the amount of data released affects incident reconstruction. In addition, the physical disparity of the data can make it difficult to put the data in the correct context and temporal order.

    Modern network forensic techniques face several challenges that must be resolved to improve the forensic methods. Some of the key challenges include high storage speed, the requirement of ample storage space, data integrity, data privacy, access to IP address, and location of data extraction.

    Cloud forensics is an application of scientific principles, practices, and methods to reorganize the events through identification, collection, preservation, examination, and reporting of digital evidence [5].

    Loss of location Whilst the use of encryption, cryptocurrencies and other technologies such as the dark web or cloud storage may result in the loss of data, they also present significant challenges for law enforcement in establishing the physical location of perpetrators, criminal infrastructure or electronic evidence.

    These challenges include: the need to track down sophisticated users who commit unlawful acts on the Internet while hiding their identities; the need for close coordination among law enforcement agencies; and the need for trained and well-equipped personnel to gather evidence, investigate, and prosecute these cases.

    Cloud forensics refers to investigations that are focused on crimes that occur primarily involving the cloud. This could include data breaches or identity thefts. With cloud forensics implemented, the owner has protection and can better preserve evidence.

    The Three Dimensions of Cloud Forensics This includes forensic data collection, elastic/static/live forensics, evidence segregation, investigations in virtualized environments, and pro-active preparations.

    Some common challenges are lack of availability of proper guidelines for collection acquisition and presentation of electronic evidence, rapid change in technology, big data, use of anti-forensic techniques by criminals, use of free online tools for investigation, etc.

    Potentially the biggest threat to plan for in the future of digital forensics is potential security breaches. As more data is stored in cloud-based services, there is an increasing threat of security breaches and cyber-attacks.

    What is NIST cloud computing forensic science challenges 8006?

    NIST announces the final publication of NISTIR 8006, NIST Cloud Computing Forensic Science Challenges, which defines and discusses a set of challenges related to achieving effective cloud computing forensics.

    The cloud exacerbates many technological, organizational, and legal challenges already faced by digital forensic examiners. Several of these challenges—such as those associated with data replication, location transparency, and multi-tenancy—are somewhat unique to cloud computing forensics [4], [72].

    What are the first responder challenges in Cloud forensics?

    Incident first responder challenges in cloud forensics include: o Confidence, competence, and trustworthiness of the cloud s to act as first Provider responders and perform data collection o Difficulty in performing initial triage o Processing a large volume of collected forensic artifacts •

    Is it possible to collect additional forensic data in the cloud?

    Additional collection is often infeasible in the cloud Relevant forensic information is often located in places not immediately evident from the original crime scene.