You are here

Following the Breadcrumbs

Title: Following the Breadcrumbs: Timestamp Pattern Identification for Cloud Forensics.
13 views
0 downloads
Name(s): Ho, Shuyuan Mary, author
Kao, Dayu, author
Wu, Wen-Ying, author
Type of Resource: text
Genre: Text
Journal Article
Date Issued: 2018-01-31
Physical Form: computer
online resource
Extent: 1 online resource
Language(s): English
Abstract/Description: This study explores the challenges of digital forensics investigation in file access, transfer and operations, and identifies file operational and behavioral patterns based on timestamps—in both the standalone as well as interactions between Windows NTFS and Ubuntu Ext4 filesystems. File-based metadata is observed, and timestamps across different cloud access behavioral patterns are compared and validated. As critical metadata information cannot be easily observed, a rigorous iterative approach was implemented to extract hidden, critical file attributes and timestamps. Direct observation and cross-sectional analysis were adopted to analyze timestamps, and to differentiate between patterns based on different types of cloud access operations. Fundamental observation rules and characteristics of file interaction in the cloud environment are derived as behavioral patterns for cloud operations.10.1016 This study contributes to cloud forensics investigation of data breach incidents where the crime clues, characteristics and evidence of the incidents are collected, identified and analyzed. The results demonstrate the effectiveness of pattern identification for digital forensics across various types of cloud access operations.
Identifier: FSU_libsubv1_scholarship_submission_1521647723_b62ba381 (IID), 10.1016/j.diin.2017.12.001 (DOI)
Keywords: Timestamp, Cloud forensics, Behavioral analysis, Pattern identification, File metadata
Publication Note: This article was accepted for publication in Digital Investigation. The publisher's version of record is available at https://doi.org/10.1016/j.diin.2017.12.001.
Grant Number: MOST 103-2221-E-015-003; MOST106-2221-E-015-002
Persistent Link to This Record: http://purl.flvc.org/fsu/fd/FSU_libsubv1_scholarship_submission_1521647723_b62ba381
Owner Institution: FSU
Is Part Of: Digital Investigation.
Issue: vol. 24

Choose the citation style.
Ho, S. M., Kao, D., & Wu, W. -Y. (2018). Following the Breadcrumbs: Timestamp Pattern Identification for Cloud Forensics. Digital Investigation. Retrieved from http://purl.flvc.org/fsu/fd/FSU_libsubv1_scholarship_submission_1521647723_b62ba381