Skip to main content
QUICK REVIEW

[논문 리뷰] Evaluation of Digital Forensic Process Models with Respect to Digital Forensics as a Service

Xiaoyu Du, Nhien‐An Le‐Khac|arXiv (Cornell University)|2017. 08. 05.
Digital and Cyber Forensics참고 문헌 17인용 수 54
한 줄 요약

이 논문은 기존 디지털 포렌식 프로세스 모델을 평가하여 클라우드 기반의 Digital Forensics as a Service(DFaaS) 패러다임 및 클라우드 증거 처리에의 적용 가능성을 평가합니다.

ABSTRACT

Digital forensic science is very much still in its infancy, but is becoming increasingly invaluable to investigators. A popular area for research is seeking a standard methodology to make the digital forensic process accurate, robust, and efficient. The first digital forensic process model proposed contains four steps: Acquisition, Identification, Evaluation and Admission. Since then, numerous process models have been proposed to explain the steps of identifying, acquiring, analysing, storage, and reporting on the evidence obtained from various digital devices. In recent years, an increasing number of more sophisticated process models have been proposed. These models attempt to speed up the entire investigative process or solve various of problems commonly encountered in the forensic investigation. In the last decade, cloud computing has emerged as a disruptive technological concept, and most leading enterprises such as IBM, Amazon, Google, and Microsoft have set up their own cloud-based services. In the field of digital forensic investigation, moving to a cloud-based evidence processing model would be extremely beneficial and preliminary attempts have been made in its implementation. Moving towards a Digital Forensics as a Service model would not only expedite the investigative process, but can also result in significant cost savings - freeing up digital forensic experts and law enforcement personnel to progress their caseload. This paper aims to evaluate the applicability of existing digital forensic process models and analyse how each of these might apply to a cloud-based evidence processing paradigm.

연구 동기 및 목표

  • 디지털 포렌식 프로세스 모델의 현황과 이를 클라우드 기반 DFaaS 패러다임 지원 능력을 평가한다.
  • 전통적 프로세스가 클라우드 기반 증거 처리 및 서비스 지향 워크플로우에 어떻게 매핑되는지 분석한다.
  • 조사 워크플로우에서 DFaaS 도입의 잠재적 이점과 도전을 식별한다.

제안 방법

  • DFaaS 요건에 관한 기존 디지털 포렌식 프로세스 모델의 검토와 비판.
  • 증거 처리, 처리 및 서비스 제공에 미치는 클라우드 컴퓨팅의 영향 분석.
  • 프로세스 단계(획득, 식별, 분석, 저장, 보고)가 클라우드 기반 처리와 어떻게 정합하는지에 대한 개념적 평가.

실험 결과

연구 질문

  • RQ1기존 디지털 포렌식 프로세스 모델이 DFaaS 접근 방식에 얼마나 잘 정합하는가?
  • RQ2디지털 포렌식 워크플로우를 클라우드 기반 서비스 모델로 옮기는 잠재적 이점과 한계는 무엇인가?
  • RQ3클라우드 기반 증거 처리에 가장 영향을 받는 프로세스 모델 단계는 무엇인가?
  • RQ4실제로 클라우드 기반 DFaaS를 구현하기 위해 어떤 고려사항이 필요한가?

주요 결과

  • 기존 프로세스 모델은 기본 구조를 제공하지만 클라우드 기반 처리에 대한 적응이 필요하다.
  • DFaaS는 연구를 가속하고 클라우드 기반 증거 처리를 통해 비용 절감을 제공할 수 있다.
  • 클라우드 기반 DFaaS의 채택은 포렌식 워크플로우의 효율성, 보안, 거버넌스에 대한 고려를 수반한다.

더 나은 연구,지금 바로 시작하세요

논문 읽기부터 검토까지, 연구 시간을 획기적으로 줄여보세요.

카드 등록 없음 · 무료 플랜 제공

이 리뷰는 AI가 만들고, 인간 에디터가 검토했습니다.