Proactive Forensics: Keystroke Logging from the Cloud as Potential Digital Evidence for Forensic Readiness Purposes


연구 분야: Analysis



학회: 2020 IEEE International Conference on Informatics, IoT, and Enabling Technologies (ICIoT)


초록

The relationship between negative and positive connotations with regard to malware in the cloud is rarely investigated according to the prevailing literature. However, there is a significant relationship between the use of positive and negative connotations. A clear distinction between the two emanates when we use the originally considered malicious code, for positive connotation like in the case of capturing keystrokes in a proactive forensic purpose. This is done during the collection of digital evidence for Digital Forensic Readiness (DFR) purposes, in preparation of a Digital Forensic Investigation (DFI) process. The paper explores the problem of having to use the keystrokes for positive reasons as a piece of potential evidence through extraction and digitally preserving it as highlighted in ISO/IEC 27037: 2012 (security approaches) and ISO/IEC 27043: 2015 (legal connotations). In this paper, therefore, the authors present a technique of how DFR can be achieved through the collection of digital information from the originally considered malicious code. This is achieved without modifying the cloud operations or the infrastructure thereof, while preserving the integrity of digital information and possibly maintain the chain of custody at the same time. The paper proposes that the threshold of malicious code intrusion in the cloud can be transformed to an efficacious process of DFR through logical acquisition and digitally preserving keystrokes. The experiment-tested keystrokes have shown a significant approach that could achieve proactive forensics.


Author Profile
Sheunesu M. Makura

Department of Computer Science Faculty of EBIT University of Pretoria Pretoria South Africa

South Africa
Author Profile
H. S. Venter

Department of Computer Science Faculty of EBIT University of Pretoria Pretoria South Africa

South Africa
Author Profile
Richard Adeyemi Ikuesan

Cybersecurity and Networking Department School of Information Technology Community College of Qatar Doha Qatar

Andorra

📄 논문 정보

발행 연도 2020년
인용수 13
출판 국가 South Africa, Australia, Andorra, Malta
사이트 IEEE
좋아요 수 0

연관 논문 목록 (198건)