Cloud-Forensik

Cloud Forensics

Cloud-Forensik

Cloud forensics is the forensic investigation of incidents in cloud environments — from software services to infrastructure at external providers. It is particularly demanding because the data is distributed, physical access is lacking and one depends on the provider's logs and interfaces. Here forensics shifts from the data carrier to the data trace.

History & facts. In the cloud there is no device to seize: evidence consists above all of logs — sign-in, access and configuration events — and is often available only to a limited extent and for a limited time. The shared responsibility between customer and provider, changing locations (also across jurisdictions) and the transience of virtual resources complicate preservation. Those who do not enable and export relevant logs in advance often have nothing to hand in an emergency. Outlook & recommendation. Cloud forensics begins before the incident: enable logging, ensure retention, secure logs centrally and independently of the provider account. This makes it possible to reconstruct later what happened, even if the provider has long since rotated the data. A central collection of cloud telemetry in one's own detection closes the gap between scattered provider logs and an end-to-end investigation.
Cloud-Forensik — Cloud Forensics