AFTID: Anti-Forensic Threat Identification and Detection Mechanism for Cloud Logs

Shaik Khaja Mohiddin, Mohammed Ali Hussain, Divya Midhun Chakkaravarthy · 2025

The integrity of cloud logs is vital for forensic investigation as they provide evidence of system activities, security incidents, cyber threats, etc. Forensic analysis methods such as correlation and trajectory analysis can be impeded by anti-forensic techniques including log obfuscation, log timestamp alteration, and log deletion. To address this, a Hybrid Machine learning based Anti-forensic Threat Detection Mechanism, with the acronym, AFTID (Anti-forensic Threat Identification and Detection), is proposed to safeguard the integrity of cloud logs. AFTID uses multiple machine learning models like Isolation Forests and Autoencoders for anomaly detection and Random Forests for classification, etc. to detect and announce anti-forensic tampering activities. Leveraging unsupervised models to discover unknown anomalies and supervised models for known tampering patterns to reinforce anti-forensic defence, improve detection rates and help differentiate between processes which generated benign events versus tampering attempts. AFTID works via the use of cryptographic hash verification (Merkle trees or hashing mechanisms backed on either a decentralized or private blockchain) to ensure that logs are immutable. This approach secures the integrity of logs and allows forensic validation that cannot be tampered with. When anti-forensic activities are detected, AFTID alerts and takes regular backups to prevent loss of untarnished log data. The assessment of four metrics, including the accuracy of detection of anti-forensic activities by hybrid models, a response time to measure speed at which AFTID takes over detection and appears to trigger notifications for tampered logs, the reliability of integrity verification to evaluate the hash-based protection against adjustments for the logs, and a false-positive rate to avoid fluff alerts. Based on the evaluation of these parameters, this study approves the efficacy of AFTID for satisfying the log integrity and reinforcing forensic investigations, while also securing cloud environments against future sophisticated anti-forensics.

Read the paper · More papers on PaperTik