Forensic Isolation of Cloud Storage Resources
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current forensic investigation techniques are hindered in cloud environments due to ongoing modifications by authorized users after unauthorized access, making it difficult to perform a comprehensive analysis.
Innovation Solution
A system and method for forensically isolating a production cloud computing and storage environment by detecting unauthorized access, deploying a forensic isolation application to freeze resources, duplicating them, and storing the duplicates outside the environment for analysis while rerouting authorized requests to the isolated resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If authorized users continue to access and modify cloud resources after unauthorized access is detected, then normal operations can be maintained, but forensic investigation capability is compromised
Solution Approach 1:
The system segments cloud resources into two distinct copies: a frozen forensic copy for investigation and an operational copy for continued business operations. This segmentation allows forensic analysis to proceed without interference from ongoing modifications while maintaining service continuity.
Solution Approach 2:
The system creates a duplicate copy of the compromised cloud resources. The original resources remain operational while the copied resources are frozen for forensic analysis, allowing both investigative integrity and operational continuity to coexist.
2Reliability
If cloud resources are frozen for forensic analysis, then forensic investigation integrity is improved, but operational availability deteriorates
Solution Approach 1:
Instead of freezing the original operational resources, the system creates a separate duplicate copy for forensic analysis. This copying approach preserves the integrity of forensic investigation while leaving the original resources available for continued operations.
Solution Approach 2:
The system introduces a forensic isolation environment as an intermediary layer between the operational resources and the forensic analysis process. This intermediary allows investigators to analyze a replicated environment without affecting the availability of production resources.
3Measurement precision
If traditional forensic isolation techniques are applied to individual hard drives or computers, then forensic analysis can be performed, but cloud environment complexity prevents implementation
Solution Approach 1:
The system provides a universal forensic isolation solution that works across diverse cloud resource types (storage buckets, databases, compute instances, etc.) through a unified approach of resource duplication and freezing, rather than requiring resource-specific forensic techniques.
Solution Approach 2:
The system applies a consistent copying mechanism across all cloud resource types, creating frozen duplicates that can be analyzed forensically. This universal copying approach simplifies the complexity of implementing different forensic techniques for different resource types.
Data Source
AI summary
Embodiments disclosed are directed to a computing system that performs steps to forensically isolate a compromised storage resource (e.g., bucket) of a production cloud computing and storage environment. In response to detecting an unauthorized access to resources (e.g., objects) stored in storage resource of the production cloud computing and storage environment, the computing system deploys a forensic isolation application that freezes the compromised storage resource so that a forensic analysis can be performed, duplicates the compromised storage resource's resources, and stores the duplicate resources as forensically isolated resources in a storage device outside of the production cloud computing and storage environment. The forensic isolation application then stores the duplicate resources as operational resources. Subsequently, the forensic isolation application reroutes authorized requests for the frozen resource to the operational copy of the frozen resource.


