{"title":"Real time monitoring of security events for forensic purposes in Cloud environments using SIEM","authors":"Imane Bachane, Youness Idrissi Khamlichi Adsi, Habiba Chaoui Adsi","doi":"10.1109/SYSCO.2016.7831327","DOIUrl":null,"url":null,"abstract":"The use of Cloud computing keeps increasing day after day due to the unique combination of characteristics that the cloud introduce, including: on-demand self-service, broad network access, resource pooling, rapid elasticity and measured service. Though, from forensics experts' point of view, many challenges are faced when responding to incidents that have occurred in a cloud computing ecosystem. This paper examines some of the challenges in cloud forensics identified in the current research literature. Furthermore, it discusses an approach offered by researchers aiming to resolve forensics need in cloud computing. Finally, it presents a new approach for forensics investigation in the cloud based on SIEM by providing real time monitoring of security events and storing this events in order to use it as evidences in investigations.","PeriodicalId":328833,"journal":{"name":"2016 Third International Conference on Systems of Collaboration (SysCo)","volume":"36 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2016-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"10","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2016 Third International Conference on Systems of Collaboration (SysCo)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/SYSCO.2016.7831327","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 10
Abstract
The use of Cloud computing keeps increasing day after day due to the unique combination of characteristics that the cloud introduce, including: on-demand self-service, broad network access, resource pooling, rapid elasticity and measured service. Though, from forensics experts' point of view, many challenges are faced when responding to incidents that have occurred in a cloud computing ecosystem. This paper examines some of the challenges in cloud forensics identified in the current research literature. Furthermore, it discusses an approach offered by researchers aiming to resolve forensics need in cloud computing. Finally, it presents a new approach for forensics investigation in the cloud based on SIEM by providing real time monitoring of security events and storing this events in order to use it as evidences in investigations.