云鉴证分流框架(CFTF)[2021]24页 “英文电子版”

ID:27844

阅读量:0

大小:3.97 MB

页数:24页

时间:2023-01-01

金币:20

上传者:战必胜
© 2021 The SANS Institute, Author Retains Full Rights

21
 
Cloud Forensics Triage Framework (CFTF)
GIAC (GCFA) Gold Certification
Author: Michael Beck, mbeck.eagle@gmail.com
Advisor: Clay Risenhoover
Accepted: 23-June-2021
Abstract
Digital media forensic investigations come in multiple forms and span single assets -
from thumb drives, laptops, mobile phones, or a single email server to large-scale
corporate incident response actions. Corporate network investigations are when analysts
can become overwhelmed with the volume of internal hosts of interest, which must be
forensically triaged and analyzed. The pressure to produce evidence to support or refute
a case is still the same. Analysts need to deliver the evidence as quickly as possible and
maintain proper evidence handling procedures. Endpoint Detection and Response (EDR)
tools perform a great job identifying these systems and providing a platform to collect
data. The next step of preparation and analysis of these hosts must be done and is time-
consuming. This circumstance is where a Cloud Forensics Triage Framework (CFTF) can
leverage cloud resources to set up a scalable and automated forensic triage framework
and benefit the digital media forensic investigators. The research will explore the
possibilities of using a mixture of traditional forensic media collection processes and
modern cloud technologies to determine if reducing the time it takes to deliver processed
media benefits the overall mean time to deliver results.
Will this reduce the time required to find the needle in the stack of needles?
资源描述:

当前文档最多预览五页,下载文档查看全文

此文档下载收益归作者所有

当前文档最多预览五页,下载文档查看全文
温馨提示:
1. 部分包含数学公式或PPT动画的文件,查看预览时可能会显示错乱或异常,文件下载后无此问题,请放心下载。
2. 本文档由用户上传,版权归属用户,天天文库负责整理代发布。如果您对本文档版权有争议请及时联系客服。
3. 下载前请仔细阅读文档内容,确认文档内容符合您的需求后进行下载,若出现内容与标题不符可向本站投诉处理。
4. 下载文档时可能由于网络波动等原因无法下载或下载错误,付费完成后未能成功下载的用户请联系客服处理。
关闭