| By Jon Shende | Article Rating: |
|
| September 27, 2010 11:12 AM EDT | Reads: |
8,432 |
Within the realms of digital forensics analysts traditionally performed analysis on static data, either from a core dump, bit to bit imaging etc. Recently we have seen an increased focus directed at the live forensics environment. As users rely more on mobile and other remote devices to access data on demand; data possibly held in some manner of cloud environment, investigators will have to adapt their mode of investigations to suit.
I recall reading a marketing pitch a while aback where some vendor claimed that an advantage of Cloud Computing is, an ability to conduct live forensics without disrupting mission critical systems. How effective this claim may be, is subject to examination.
According to Brian Carrier - "The only difference between a live and a dead analysis is the reliability of the results; a live analysis techniques use software that existed on the system during the time-frame being investigated; dead analysis techniques, use no software that existed on the system during that time-frame." - Bear in mind though that there are different aspects and levels to these statements.

A few of the experts in this field with whom I was able to interact whilst conducting graduate research a while aback, did state that when conducting a live analysis, the system under investigation will inevitably be altered in some manner or another.This in essence can define a live analysis as not being a pure forensic form.
However the potential for gaining valuable data is looked on as the lesser of two worse case scenarios in this instance.
As we know the concept of cloud computing is an amalgamation of already existing sundry computing concepts viz. distributed, grid and utility computing.
The Cloud Computing environment is as we know susceptible to classical attacks (Cross Site Scripting,DDoS,etc ) as is any regular system. A concern for any security consultant can be the potential for exploitation of a system under live analysis.
Thus the health of any one cloud ecosystem lies within the domains which ensure that confidentiality and privacy concerns within cloud computing are effectively monitored, managed and mitigated. This will include the area of digital forensics and its place within the e-discovery process.
In regular systems one instance of exploitation can be with rootkits. Rootkits as we know can be divided into database rootkits and BIOS rootkits. The potential for exploiting both and remain undetected is high e.g.by manipulating the ACPI (Advanced Configuration Power Interface) in BIOS via its ASL programming language to modify hardware features or memory.
Hypothetically speaking one may be able to insert a rootkit which reacts to a forensic probe and then output pre-programmed results to suit an attacker; remember that a snapshot of a running system can be only reproduced up to its specific instance and cannot be reproduced at a later time-frame. As a result with a live system, data from a probe up to one instance will be different from data from another probe say 15 minutes into the live system.
In another scenario a rootkit may be programmed to respond to a probe by purging and shutting down the system - According to R.C. Vernon "A "hard" reboot includes a power cycle, which ensures that sensitive information in volatile memory is purged".
One can then question; what happens if an attack is able to compromise a host's cloud system and insert a rootkit which remains undetected as described above? Can multiple tenants of any one cloud ecosystem be compromised and if so how far can any such exploitation propagate without detection?
Within the cloud users expect their identity and data to remain private via anonymous authentication; if per chance a system is compromised, an attacker then take advantage of this factor of anonymous authentication and possibly spoof any tenant within the cloud as the attacker while data is compromised. How can an investigator identify and track such an issue?
Continued in Part 2
Published September 27, 2010 Reads 8,432
Copyright © 2010 SYS-CON Media, Inc. — All Rights Reserved.
Syndicated stories and blog feeds, all rights reserved by the author.
More Stories By Jon Shende
Jon RG Shende is an executive with over 18 years of industry experience. He commenced his career, in the medical arena, then moved into the Oil and Gas environment where he was introduced to SCADA and network technologies,also becoming certified in Industrial Pump and Valve repairs. Jon gained global experience over his career working within several verticals to include pharma, medical sales and marketing services as well as within the technology services environment, eventually becoming the youngest VP of an international enterprise. He is a graduate of the University of Oxford, holds a Masters certificate in Business Administration, as well as an MSc in IT Security, specializing in Computer Crime and Forensics with a thesis on security in the Cloud. Jon, well versed with the technology startup and mid sized venture ecosystems, has contributed at the C and Senior Director level for former clients. As an IT Security Executive, Jon has experience with Virtualization,Strategy, Governance,Risk Management, Continuity and Compliance. He was an early adopter of web-services, web-based tools and successfully beta tested a remote assistance and support software for a major telecom. Within the realm of sales, marketing and business development, Jon earned commendations for turnaround strategies within the services and pharma industry. For one pharma contract he was responsibe for bringing low performing districts up to number 1 rankings for consecutive quarters; as well as outperforming quotas from 125% up to 314%. Part of this was achieved by working closely with sales and marketing teams to ensure message and product placement were on point. Professionally he is a Fellow of the BCS Chartered Institute for IT, an HITRUST Certified CSF Practitioner and holds the CITP and CRISC certifications.Jon Shende currently works as a Senior Director for a CSP. A recognised thought Leader, Jon has been invited to speak for the SANs Institute, has spoken at Cloud Expo in New York as well as sat on a panel at Cloud Expo Santa Clara, and has been an Ernst and Young CPE conference speaker. His personal blog is located at http://jonshende.blogspot.com/view/magazine "We are what we repeatedly do. Excellence, therefore, is not an act, but a habit."
- Cloud People: A Who's Who of Cloud Computing
- New Relic Q1 2013 Blazes Past Growth Targets and Reaches 40,000 Active Customer Accounts
- Learn How To Use Google Apps Script
- Cloud Expo New York: Rethink IT and Reinvent Business with IBM SmartCloud
- Cloud Expo New York: API Security, Does My Business Need an OAuth Server?
- Session Topics: 12th Cloud Expo / Cloud Expo New York
- Cloud Expo NY: Best Practices for Delivering Oracle Database as a Service
- Measuring the Business Value of Cloud Computing
- Cloud Expo New York: Build Modern Business Applications
- Cloud Expo New York: Using APIs for Better Business Partnerships
- Five Big Data Features in SQL Server
- Cloud Expo New York: Evolving Cloud Computing Models
- Cloud People: A Who's Who of Cloud Computing
- New Relic Q1 2013 Blazes Past Growth Targets and Reaches 40,000 Active Customer Accounts
- Cloud Expo New York: Delivering Digital Marketing on the Cloud
- Learn How To Use Google Apps Script
- Cloud Expo New York: Rethink IT and Reinvent Business with IBM SmartCloud
- Cloud Expo New York: API Security, Does My Business Need an OAuth Server?
- Cloudant to Exhibit at Cloud Expo & Big Data Expo New York
- Session Topics: 12th Cloud Expo / Cloud Expo New York
- Cloud Expo New York: Basics of SSD Technology and Its Use in Cloud
- The Accessibility of the Cloud
- Cloud Expo NY: Best Practices for Delivering Oracle Database as a Service
- What CIOs Need to Know About Enterprise Virtualization
- A Cup of AJAX? Nay, Just Regular Java Please
- Java Developer's Journal Exclusive: 2006 "JDJ Editors' Choice" Awards
- JavaServer Faces (JSF) vs Struts
- The i-Technology Right Stuff
- Rich Internet Applications with Adobe Flex 2 and Java
- Java vs C++ "Shootout" Revisited
- Bean-Managed Persistence Using a Proxy List
- Reporting Made Easy with JasperReports and Hibernate
- Creating a Pet Store Application with JavaServer Faces, Spring, and Hibernate
- Why Do 'Cool Kids' Choose Ruby or PHP to Build Websites Instead of Java?
- What's New in Eclipse?
- Where Are RIA Technologies Headed in 2008?





















