STorage as a Service (STaaS) cloud services has been adopted by both individuals and businesses as a dominant technology worldwide. Similar to other technologies, this widely accepted service can be misused by criminals. Investigating cloud platforms is becoming a standard component of contemporary digital investigation cases. Hence, digital forensic investigators need to have a working knowledge of the potential evidence that might be stored on cloud services. In this chapter, we conducted a number of experiments to locate data remnants of users' activities when utilizing the Ubuntu One cloud service. We undertook experiments based on common activities performed by users on cloud platforms including downloading, uploading, viewing, and deleting files. We then examined the resulting digital artifacts on a range of client devices, namely, Windows 8.1, Apple Mac OS X, and Apple iOS. Our examination extracted a variety of potentially evidential items ranging from Ubuntu One databases and log files on persistent storage to remnants of user activities in device memory and network traffic.
翻译:与其它技术一样,这种被广泛接受的服务可能被犯罪分子滥用。调查云平台正在成为当代数字调查案件的一个标准组成部分。因此,数字法医调查员需要掌握关于云服务可能储存的潜在证据的工作知识。在本章中,我们在利用Ubuntu One云服务时进行了一些实验,以寻找用户活动的数据残余。我们根据用户在云平台上开展的共同活动进行了实验,这些活动包括下载、上传、查看和删除文件。然后,我们审查了一系列客户设备,即Windows 8.1、苹果MacOS X和苹果iOS上产生的数字文物。我们的检查从Ubuntu One数据库和关于持续储存的日志档案到装置记忆和网络交通中的用户活动残余等各种潜在证据。