Skip to main content
QUICK REVIEW

[Paper Review] Digital Forensic Investigation of Cloud Storage Services

Hyunji Chung, Jungheum Park|arXiv (Cornell University)|Aug 22, 2017
Digital and Cyber Forensics1 references4 citations
TL;DR

This paper proposes a comprehensive digital forensic investigation framework for cloud storage services, covering artifacts across Windows, Mac, iPhone, and Android devices. It outlines a multi-platform procedure to collect, analyze, and correlate forensic evidence from client-side artifacts and cloud service logs, enhancing incident response and digital investigation in cloud environments.

ABSTRACT

The demand for cloud computing is increasing because of the popularity of digital devices and the wide use of the Internet. Among cloud computing services, most consumers use cloud storage services that provide mass storage. This is because these services give them various additional functions as well as storage. It is easy to access cloud storage services using smartphones. With increasing utilization, it is possible for malicious users to abuse cloud storage services. Therefore, a study on digital forensic investigation of cloud storage services is necessary. This paper proposes new procedure for investigating and analyzing the artifacts of all accessible devices, such as Windows, Mac, iPhone, and Android smartphone.

Motivation & Objective

  • Address the growing challenge of digital forensics in cloud storage environments due to increasing misuse and data breaches.
  • Identify and analyze client-side artifacts across diverse devices (Windows, Mac, iPhone, Android) used to access cloud storage services.
  • Develop a standardized, repeatable procedure for digital forensic investigations targeting cloud storage platforms.
  • Improve the effectiveness of incident response and forensic analysis by integrating evidence from both local devices and cloud service logs.
  • Support law enforcement and digital investigators in tracking malicious activities in cloud storage ecosystems.

Proposed method

  • Propose a multi-phase forensic investigation procedure tailored for cloud storage services.
  • Collect and analyze client-side artifacts such as cache files, configuration files, and synchronization logs from Windows, Mac, iPhone, and Android devices.
  • Correlate local device artifacts with cloud service logs to reconstruct user activities and detect anomalies.
  • Utilize reverse engineering and static/dynamic analysis techniques to extract forensic-relevant data from cloud storage applications.
  • Standardize evidence collection workflows to ensure forensically sound and platform-agnostic procedures.
  • Integrate findings from device-level artifacts with cloud provider metadata to establish a complete digital timeline.

Experimental results

Research questions

  • RQ1How can forensic artifacts from diverse client devices (Windows, Mac, iOS, Android) be systematically collected and analyzed in cloud storage investigations?
  • RQ2What are the key digital artifacts present on client devices that can reveal user activity in cloud storage services?
  • RQ3How can evidence from client-side artifacts be correlated with cloud service logs to reconstruct a complete timeline of events?
  • RQ4What challenges exist in maintaining chain-of-custody and forensic soundness when investigating cloud storage services?
  • RQ5To what extent can a standardized forensic procedure be applied across different cloud storage platforms and device types?

Key findings

  • The proposed framework successfully identifies and collects forensic artifacts from all major operating systems and devices used to access cloud storage services.
  • Client-side artifacts such as cache files, configuration files, and synchronization logs contain critical evidence for reconstructing user activities.
  • Correlation between local device artifacts and cloud service logs enables the reconstruction of a detailed digital timeline of user interactions.
  • The method enhances the reliability and completeness of digital forensic investigations in cloud environments by integrating evidence from multiple sources.
  • The procedure is adaptable to various cloud storage platforms and supports forensic soundness across heterogeneous device ecosystems.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.