Feb 24
cloud based computer forensics pipeline
In a scenario in which there’s a need for flexible computing power for certain companies offering services in the computer forensics arena, cloud computing appears to be a model ready to offer value.
Amazon offers a set of services that may support the needs for flexible computing power a full «ingest/digest» analysis pipeline may need.
They cover computing power with different kinds of instances in different flavors (Windows, SUSE Linux, IBM), storage (EBS, S3) and data transfer or import.
It’s the import/export function the one that makes all this feasible, because data volumes in computer forensics are not easily transferred via network. It takes 82 days to transfer 1TB through a T1… Import service allows you to send media to a datacenter to be imported locally at a reasonable cost.
Of course, data confidentiality is another face of computer forensics: you must send data encrypted. But Amazon does not allow you to manage encrypted containers, so you’ll have to file-encrypt your disk images previous to sending them and decrypt them after import. Same thing applies, reversed, for results, if needed.
This model may have a positive impact in time or in cost (or both).
The gain in cost has to be kept into a balance with time: now you have a fixed time cost to send and import data into Amazon before starting to process the case. In return, you have no fixed cost on infrastructure.
If you already own some infrastructure, you may consider this model when there’s a time gain. It will depend on how powerful is your infrastructure compared to what Amazon can offer.
Summarizing, if you find yourself saying no to cases or you have to delay cases because of lack of computing power, cloud computing may be an option to consider.
Comentarios desactivados en cloud based computer forensics pipeline

