Загрузка страницы

A New Perspective on Resource-Level Cloud Forensics

AWS classifies cloud incidents across three domains: Service, Infrastructure, and Application. There has been much previous discussion across the Service and Application domains, see for example the excellent SANS DFIR 2022 Keynote. This talk will focus on the unique challenges and opportunities of responding to incidents in the Infrastructure domain. Cloud Service Providers, such as AWS, GCP and Azure, often introduce artifacts of forensic value when developing features for the automation and monitoring of resources. Typically, these artifacts are undocumented and exist purely for the provider's own troubleshooting, but they also provide valuable insight to an investigator analyzing malicious activity on a system. Frequently, this insight surpasses that of “provider-supported” forensic data sources. Most of the discourse around performing forensics in the cloud focuses on provider-level logging. While this is undoubtedly useful, practitioners understand that resource-level forensic analysis is crucial when responding to incidents affecting cloud infrastructure. And much of this knowledge remains opaque and undocumented. In this presentation, Chris Doman, CTO of Cado Security will present novel research on undocumented forensic artifacts from cloud service provider-specific operating systems and tools. He will provide the audience with an overview of forensic techniques across cloud computing and serverless environments. He will also discuss native operating system artifacts, contrast them with their cloud equivalents, and consider their usefulness in the context of the cloud. Attendees can expect to gain a unique perspective on resource-level cloud forensics and should leave the talk with a host of new data sources and knowledge for performing forensic analysis of cloud resources.

SANS DFIR Summit 2023

Speaker: Chris Doman, Co-founder, Cado Security

View upcoming Summits: http://www.sans.org/u/DuS

Видео A New Perspective on Resource-Level Cloud Forensics канала SANS Digital Forensics and Incident Response
Показать
Комментарии отсутствуют
Введите заголовок:

Введите адрес ссылки:

Введите адрес видео с YouTube:

Зарегистрируйтесь или войдите с
Информация о видео
19 сентября 2023 г. 18:08:32
00:28:11
Яндекс.Метрика