LiveCloudInspector: Towards Integrated IaaS Forensics in the Cloud - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Communication Dans Un Congrès Année : 2015

LiveCloudInspector: Towards Integrated IaaS Forensics in the Cloud

Julian Zach
  • Fonction : Auteur
  • PersonId : 1031368
Hans P. Reiser
  • Fonction : Auteur
  • PersonId : 1031369

Résumé

Cloud-based systems are becoming an increasingly attractive target for malicious attacks. In IaaS environments, malicious attacks on a cloud customer’s virtual machine may affect the customer, who cannot use all diagnostic means that are available in dedicated in-house infrastructures, as well as the cloud provider, due to possible subsequent attacks against the cloud infrastructure and other co-hosted customers. This paper presents an integrated approach towards forensics and incident analysis in IaaS cloud environments. The proposed architecture enables the cloud provider to securely offer forensics services to its customers on a self-service platform. The architecture combines three important analysis techniques and provides significantly better investigation capabilities than existing systems: First, it supports host-based forensics based on virtual machine introspection. Second, it offers live remote capture of network traffic. Third, and most importantly, it provides hybrid combinations of the first two techniques, which enables enhanced analysis capabilities such as support for monitoring encrypted communication.
Fichier principal
Vignette du fichier
978-3-319-19129-4_17_Chapter.pdf (378.58 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-01775040 , version 1 (24-04-2018)

Licence

Paternité

Identifiants

Citer

Julian Zach, Hans P. Reiser. LiveCloudInspector: Towards Integrated IaaS Forensics in the Cloud. 15th IFIP International Conference on Distributed Applications and Interoperable Systems (DAIS), Jun 2015, Grenoble, France. pp.207-220, ⟨10.1007/978-3-319-19129-4_17⟩. ⟨hal-01775040⟩
101 Consultations
160 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More