Vol: 58(72) No: 2 / June 2013        

Incident Response and Reporting in the Context of Cloud Computing Forensics
Alecsandru Pătrașcu
Department of Computer Science, Military Technical Academy, Bucharest, Romania, e-mail: alecsandru.patrascu@gmail.com
Victor-Valeriu Patriciu
Department of Computer Science, Military Technical Academy, Bucharest, Romania, e-mail: victorpatriciu@yahoo.com

Keywords: cloud computing, secure data forensics, cloud computing incident response, cloud computing forensics, Linux kernel virtualization, KVM, XEN

Digital forensics and cloud computing represents a new research field that combines both the technical and the legal aspects. Combined with the constant need to know where and when a certain piece of data is stored and processed we have the entire picture for a large scale issue existing in today’s datacenters. Furthermore, cloud forensics poses new challenges due to its distributed and virtualized nature. In this paper we will talk about the context in which forensics can help investigators on a regular computer network and in cloud environments. We will present also a new and novel way in which suspect user activity can be monitored using a secure cloud forensic framework together with its detailed architecture.

