How Can Cloud Forensics Work at Large Scale?

852 views
β€’
April 27, 2012
by
RSAC Cybersecurity
YouTube video player
How Can Cloud Forensics Work at Large Scale?

TL;DR

Large-scale cloud forensics should acquire narrowly targeted evidence without disrupting innocent tenants or crossing legal boundaries unnecessarily. Investigators can improve precision by examining the richer evidence available beneath virtual disks, reconstructing how workloads touched compute and storage resources, and accounting for privacy laws across every jurisdiction where relevant data resides.

Transcript

This is Jean Friedman, Content Manager for RSA Conference. Welcome to the webcast Large-Scale Cloud Forensics. I am pleased to introduce Sam Curry and Edward Haletky, who are updating their popular session from RSA Conference two thousand and twelve. Sam Curry is Chief Technology Officer for the Identity and Data Protection Business Unit at RSA. He... Read More

Key Insights

  • Cloud forensics is complicated by virtualization because physical hardware is separated from computing workloads. Traditional investigations based on seizing equipment may therefore collect data belonging to many unrelated tenants while still overlooking evidence distributed across virtual infrastructure components.
  • Forensic investigations are designed to answer specific questions about whether a person performed particular actions. The resulting evidence must withstand scrutiny and potentially support a conviction, so investigators need a reliable reconstruction rather than an indiscriminate collection of every available system.
  • Underlying file systems contain a richer set of forensic data than virtual disks alone. Investigators can examine the storage layer beneath virtual disks, including hypervisor and host file systems, to recover evidence that conventional virtual-disk analysis may miss.
  • Virtualized infrastructure leaves a crumb trail as workloads move through compute, disk, and storage resources. Reconstructing those traces can reveal where systems touched the environment and may allow investigators to recover evidence about activity that occurred before the suspected crime became known.
  • Broad hardware seizure can severely disrupt innocent cloud tenants. In the described case, a raid affecting roughly thirty tenants shut down unrelated organizations, and some smaller operators did not survive the interruption even though about half the equipment was returned roughly a week later.
  • Large-scale acquisition can reduce investigative effectiveness because law enforcement must search enormous quantities of data while determining which assets belong to the target. The collection process may also cross tenant boundaries that investigators did not know existed when the equipment was removed.
  • Cloud investigations can cross national and legal jurisdictions even when the physical raid occurs in one country. Investigators may need to address foreign laws, treaties, tenant privacy, and communications with organizations located elsewhere before examining or using affected data.
  • A disciplined forensic approach must protect business continuity while narrowing collection to relevant evidence. Treating complete infrastructure seizure as the default resembles using a sledgehammer for a precise task and creates technical, commercial, privacy, and civil-liability risks.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How should large-scale cloud forensic evidence be acquired?

Large-scale cloud evidence should be acquired through a disciplined, targeted process that identifies the relevant tenant, systems, and infrastructure traces before equipment is removed. Investigators should consider evidence from virtual disks, underlying file systems, compute resources, and storage layers. Narrow collection reduces unnecessary business interruption, limits exposure of unrelated tenant data, and makes the resulting evidence easier to interpret.

Q: Why are traditional forensic seizures risky in cloud environments?

Traditional seizures are risky because many tenants can share the same physical cloud infrastructure. Removing equipment associated with one target may take unrelated customers offline, expose their data, and threaten their businesses. The described raid affected roughly twenty to thirty smaller players, and some did not survive the interruption. Broad collection can also make the actual evidence harder to find.

Q: What evidence can underlying virtual infrastructure provide?

Underlying virtual infrastructure can provide evidence that is unavailable when investigators examine only a virtual disk. Host and hypervisor file systems may preserve traces showing how a workload interacted with storage and computing resources. This richer evidence can help reconstruct a crumb trail across the environment and clarify what occurred before investigators knew that a suspected crime had taken place.

Q: How does virtualization complicate forensic reconstruction?

Virtualization separates physical equipment from the computing workloads investigators need to examine. Workloads and their data can move across compute, disk, and storage resources, so the physical server alone may not represent the complete scene. Investigators must reconstruct where relevant systems moved, what they touched, and which traces belong to the target rather than to unrelated tenants.

Q: How can cloud forensic investigations affect innocent tenants?

Cloud forensic investigations can interrupt innocent tenants when investigators seize shared physical equipment instead of isolating the target's assets. In the case discussed, a raid connected with arrests in Latvia affected infrastructure in Virginia and disrupted a Swiss company along with other smaller players. Some businesses could not survive the outage, despite having no stated connection to the suspected activity.

Q: Why do jurisdictional boundaries matter in cloud forensics?

Jurisdictional boundaries matter because cloud data, tenants, physical infrastructure, and law-enforcement actions may be located in different countries. An investigation that begins with the FBI in the United States can still affect organizations in Switzerland and activity in Latvia. Investigators must consider local privacy laws, international treaties, tenant boundaries, and the legal basis for communicating with or examining foreign organizations.

Q: Why is examining virtual disks alone insufficient?

Examining virtual disks alone is insufficient because it treats each disk as the primary unit of evidence and ignores other parts of the virtual environment. Investigators may spend time deciding which disk belongs to the target while missing traces stored beneath those disks. Hypervisor, host file-system, compute, and storage evidence can provide a more complete reconstruction of relevant activity.

Q: What should a cloud forensic architecture prioritize?

A cloud forensic architecture should prioritize precise acquisition, reliable interpretation, business continuity, tenant separation, and compliance with privacy laws in every relevant jurisdiction. It should help investigators identify the evidence needed to answer a specific question, use traces across virtual infrastructure, and avoid removing complete shared environments when a narrower collection can preserve relevant material without harming innocent customers.

Summary & Key Takeaways

  • Virtualization separates physical hardware from computing workloads, complicating traditional forensic methods that collect physical equipment after an incident. Investigators must reconstruct a reliable trail across compute, disks, storage, and underlying file systems, then determine whether the evidence answers a specific question strongly enough to withstand scrutiny in legal proceedings.

  • A reported cloud raid demonstrated the risks of indiscriminate acquisition. Investigators seeking one tenant's environment removed equipment supporting many tenants, interrupted unrelated businesses, and caused some smaller organizations to fail. Although about half the equipment was returned and services resumed roughly a week later, innocent customers still suffered serious consequences.

  • Effective cloud investigations must balance evidence acquisition, interpretation, business continuity, tenant privacy, and legal obligations. Large environments may contain thousands of tenants and data across several jurisdictions. A disciplined architecture should identify relevant evidence precisely, respect tenant and national boundaries, and use information beyond virtual disks to reconstruct activity without collecting entire environments.


Read in Other Languages (beta)

Share This Summary πŸ“š

Explore More Summaries from RSAC Cybersecurity πŸ“š