1
1

00:00:00,270  -->  00:00:02,220
<v Instructor>Cloud Forensics.</v>
2

2

00:00:02,220  -->  00:00:03,660
In this lesson, we're going to talk
3

3

00:00:03,660  -->  00:00:06,180
about some of the challenges with Cloud Forensics.
4

4

00:00:06,180  -->  00:00:08,130
Now, we covered a lot of Digital Forensics
5

5

00:00:08,130  -->  00:00:09,480
back earlier in this course,
6

6

00:00:09,480  -->  00:00:11,940
when we covered the entire Digital Forensics Section,
7

7

00:00:11,940  -->  00:00:14,010
but there are some unique things that we have to think
8

8

00:00:14,010  -->  00:00:15,810
about when we deal with the Cloud.
9

9

00:00:15,810  -->  00:00:17,370
For instance, when you start dealing
10

10

00:00:17,370  -->  00:00:18,900
with Digital Forensics in the Cloud,
11

11

00:00:18,900  -->  00:00:21,240
it becomes much more challenging.
12

12

00:00:21,240  -->  00:00:24,000
This is because all of the resources you're talking about,
13

13

00:00:24,000  -->  00:00:27,120
the servers, the networks and the disc storage,
14

14

00:00:27,120  -->  00:00:30,540
is all technically virtual stuff, it's not physical.
15

15

00:00:30,540  -->  00:00:33,030
This means that you may not have access to it.
16

16

00:00:33,030  -->  00:00:36,420
So because it's virtual, you can logically access it,
17

17

00:00:36,420  -->  00:00:39,390
but you can't do a physical disc image of that disc,
18

18

00:00:39,390  -->  00:00:42,150
because that disc could be located anywhere in the world.
19

19

00:00:42,150  -->  00:00:44,640
It might be located in multiple regions of the world.
20

20

00:00:44,640  -->  00:00:46,050
And it might have data that's spread
21

21

00:00:46,050  -->  00:00:48,990
out across multiple data centers all at the same time.
22

22

00:00:48,990  -->  00:00:51,120
Now, this makes it so much harder for you
23

23

00:00:51,120  -->  00:00:52,890
to be able to get that data.
24

24

00:00:52,890  -->  00:00:54,360
Now, on the other side of things,
25

25

00:00:54,360  -->  00:00:57,240
the Cloud makes it a lot easier for attackers as well.
26

26

00:00:57,240  -->  00:00:59,490
Attackers can use any of a number of Clouds
27

27

00:00:59,490  -->  00:01:00,810
to perform their attack.
28

28

00:01:00,810  -->  00:01:02,610
And many attackers will actually create
29

29

00:01:02,610  -->  00:01:04,500
a multicloud service for them
30

30

00:01:04,500  -->  00:01:06,870
to be able to create their own attack platform.
31

31

00:01:06,870  -->  00:01:08,550
And so when you're trying to investigate
32

32

00:01:08,550  -->  00:01:11,010
the source of an attack and you look at the IP,
33

33

00:01:11,010  -->  00:01:13,710
you may find that it's coming from Amazon Web Services
34

34

00:01:13,710  -->  00:01:17,130
or Microsoft Azure or the Google Cloud Platform.
35

35

00:01:17,130  -->  00:01:19,170
All of these could be the source of your attack,
36

36

00:01:19,170  -->  00:01:22,140
but it's not likely that Amazon or Microsoft or Google,
37

37

00:01:22,140  -->  00:01:23,700
are the ones performing it.
38

38

00:01:23,700  -->  00:01:25,410
Instead, it's an attacker who leased
39

39

00:01:25,410  -->  00:01:26,580
some kind of an instance,
40

40

00:01:26,580  -->  00:01:28,620
and then they're using that to perform their attack.
41

41

00:01:28,620  -->  00:01:30,090
Now, throughout the rest of this lesson,
42

42

00:01:30,090  -->  00:01:33,210
I want to focus on three main points that you need to consider
43

43

00:01:33,210  -->  00:01:35,880
in terms of the difficulty with Cloud Forensics.
44

44

00:01:35,880  -->  00:01:38,310
First, when you talk about performing forensics
45

45

00:01:38,310  -->  00:01:41,070
in a Public Cloud, this is going to be complicated,
46

46

00:01:41,070  -->  00:01:43,410
especially because the access you're allowed to have
47

47

00:01:43,410  -->  00:01:45,660
and the access you're permitted is going to be based
48

48

00:01:45,660  -->  00:01:49,050
on the Cloud provider's SLA, their Service Level Agreement.
49

49

00:01:49,050  -->  00:01:52,380
For example, the SLA I have with my Cloud Service Provider,
50

50

00:01:52,380  -->  00:01:54,330
doesn't allow me to jump in my car,
51

51

00:01:54,330  -->  00:01:57,090
drive to their server farm, plug in my device,
52

52

00:01:57,090  -->  00:01:59,670
and start doing a bit-by-bit copy of that server.
53

53

00:01:59,670  -->  00:02:00,870
It's not allowed.
54

54

00:02:00,870  -->  00:02:03,180
So if I want to get data or forensics performed
55

55

00:02:03,180  -->  00:02:04,710
on my Cloud Instance,
56

56

00:02:04,710  -->  00:02:05,850
I would have to ask them,
57

57

00:02:05,850  -->  00:02:07,350
and they would have to do it for me.
58

58

00:02:07,350  -->  00:02:09,570
And that's only if it's based on the SLA
59

59

00:02:09,570  -->  00:02:11,070
and what I agree to pay them,
60

60

00:02:11,070  -->  00:02:13,710
in terms of that SLA to do that work for me.
61

61

00:02:13,710  -->  00:02:16,200
The second major concern is that instances
62

62

00:02:16,200  -->  00:02:18,630
are created and destroyed very quickly,
63

63

00:02:18,630  -->  00:02:20,100
due to the elasticity.
64

64

00:02:20,100  -->  00:02:22,590
Now, this is a great thing in terms of our operations,
65

65

00:02:22,590  -->  00:02:24,570
but from a forensic standpoint,
66

66

00:02:24,570  -->  00:02:27,180
it makes recovery much more difficult.
67

67

00:02:27,180  -->  00:02:28,920
As these instances are created,
68

68

00:02:28,920  -->  00:02:30,840
they start taking up more disc space.
69

69

00:02:30,840  -->  00:02:32,310
When they're done, they're deleted,
70

70

00:02:32,310  -->  00:02:34,320
and that disc space becomes available again.
71

71

00:02:34,320  -->  00:02:36,630
Then another customer might create a new instance,
72

72

00:02:36,630  -->  00:02:39,510
and it writes over your data that was recently deleted,
73

73

00:02:39,510  -->  00:02:41,850
making recovery much more difficult.
74

74

00:02:41,850  -->  00:02:43,320
This is a big issue.
75

75

00:02:43,320  -->  00:02:45,000
Now, a lot of Cloud Service Providers
76

76

00:02:45,000  -->  00:02:46,530
realize this is an issue,
77

77

00:02:46,530  -->  00:02:48,030
and so they start doing more extensive
78

78

00:02:48,030  -->  00:02:50,730
logging and monitoring options to try to overcome this,
79

79

00:02:50,730  -->  00:02:52,230
or take snapshots and keep them
80

80

00:02:52,230  -->  00:02:54,990
for a certain amount of time to go back for data recovery.
81

81

00:02:54,990  -->  00:02:56,700
But again, this is one of those things
82

82

00:02:56,700  -->  00:02:58,260
that this is a benefit of the Cloud,
83

83

00:02:58,260  -->  00:02:59,970
but it's also a drawback.
84

84

00:02:59,970  -->  00:03:01,440
The benefit is the elasticity.
85

85

00:03:01,440  -->  00:03:04,290
The drawback is it's harder to do forensic recovery.
86

86

00:03:04,290  -->  00:03:06,180
The third issue we want to talk about here,
87

87

00:03:06,180  -->  00:03:08,430
is that there are issues with chain of custody.
88

88

00:03:08,430  -->  00:03:10,410
Now, this happens because the investigator
89

89

00:03:10,410  -->  00:03:12,810
can't just go in and do the image themself.
90

90

00:03:12,810  -->  00:03:14,790
Instead, they're relying on the cloud service provider
91

91

00:03:14,790  -->  00:03:16,140
to provide them the data.
92

92

00:03:16,140  -->  00:03:18,300
So if I want an image of my server,
93

93

00:03:18,300  -->  00:03:21,060
I'm going to ask my service provider to do that for me.
94

94

00:03:21,060  -->  00:03:22,620
Now, they're going to have to hopefully,
95

95

00:03:22,620  -->  00:03:25,320
document and record that as closely as possible,
96

96

00:03:25,320  -->  00:03:27,390
but again, they're not law enforcement,
97

97

00:03:27,390  -->  00:03:28,770
and so it would be an issue
98

98

00:03:28,770  -->  00:03:32,610
if we need a actual legal binding evidence collection here,
99

99

00:03:32,610  -->  00:03:33,960
based on our jurisdiction,
100

100

00:03:33,960  -->  00:03:35,910
because we wouldn't be able to get it.
101

101

00:03:35,910  -->  00:03:36,743
The other issue here,
102

102

00:03:36,743  -->  00:03:37,890
when you start talking about chain of custody,
103

103

00:03:37,890  -->  00:03:40,680
is again, that data can be anywhere in the world.
104

104

00:03:40,680  -->  00:03:43,440
So if my data's in a server farm in Thailand,
105

105

00:03:43,440  -->  00:03:45,870
that means in Thailand, there's data sovereignty there.
106

106

00:03:45,870  -->  00:03:48,480
But I'm a US company, I don't have data sovereignty
107

107

00:03:48,480  -->  00:03:49,980
with my data being in Thailand.
108

108

00:03:49,980  -->  00:03:51,210
Now, my data's not in Thailand,
109

109

00:03:51,210  -->  00:03:52,710
but it's just giving you an example.
110

110

00:03:52,710  -->  00:03:54,330
These are things you have to consider
111

111

00:03:54,330  -->  00:03:55,770
when you start moving to the Cloud,
112

112

00:03:55,770  -->  00:03:58,270
and they can make forensics much more challenging.
