Data Acquisition from Cloud Network Storage
Raymond Lutui, Brian O. Cusack · 2021
forensic actions are taken to determine causes of system failure and to diagnose network security breaches. The challenge and problem for network investigators is that many of the data repositories are now virtualized and Cloud distributed. The requirement is to devise effective and systematic methods for data acquisition that are robust in the new networking contexts and sufficiently comprehensive for fault determination. This paper reports the extraction of evidence from virtualized RAM in the Cloud context on a virtual machine. Such evidence informs network system fault correction, and attack diagnosis. The contribution of this research is to promote an awareness of valuable evidence held in Cloud virtual machines, where it is located, and the extraction tools. The new data collection scope for network investigators is thus demonstrated in the Cloud network context.