Implementing an Authentication Mechanism for Machine Deletion on the Cloud
Pooja Dubey, Vineeta Tiwari, Shweta Chawla · 2016
Digital Investigation on the cloud platform is a challenging task. In the Virtual Scenario, Virtual Machines contain evidences. If once VMDK (Virtual Machine Disk file) is destroyed (deleted), it is impossible to recover your VM. At present there does not exist any mechanism that can recover a destroyed VM again which is the flaw in VM itself. All the activities on the VM is logged in VM, whereas activities of CSP (Cloud Service Provider) is logged on the server. So even if someone deleted the VM, all the evidences will be lost. This creates a disaster for the user and acts as a barrier for a forensic investigator to dig out the sensitive data of user that was stored in the Virtual Machine sometime.