Skip to main navigation Skip to search Skip to main content

Forensic Investigation Using RAM Analysis on the Hadoop Distributed File System

  • Stuart Laing*
  • , Robert Ludwiniak
  • , Brahim El Boudani
  • , Christos Chrysoulas
  • , George Ubakanma
  • , Nikolaos Pitropakis
  • *Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

The usage of cloud systems is at an all-time high, and with more organizations reaching for Big Data the forensic implications must be analyzed. The Hadoop Distributed File System is widely used both as a cloud service and with organizations implementing it themselves. This paper analyzed the forensic viability of a RAM analysis method for Hadoop based investigations and compared it against targeted process data dumping through the Java heap information. The RAM analysis was done through string searching and the use of the RAM analysis tool Volatility. This work found that RAM analysis can be a valuable tool for discovering artefacts of deleted resources from a Hadoop cluster but was unable to discover further information such as the block to node mapping. The targeted process analysis managed to provide some partial information about deleted resources and produce important metadata on the current state of the file system.
Original languageEnglish
Title of host publication2023 19th International Conference on the Design of Reliable Communication Networks, DRCN 2023
PublisherIEEE
ISBN (Electronic)9781665475983
ISBN (Print)9781665475990
DOIs
Publication statusPublished - 26 Apr 2023
Event19th International Conference on the Design of Reliable Communication Networks 2023 - Vilanova i la Geltru, Spain
Duration: 17 Apr 202320 Apr 2023

Conference

Conference19th International Conference on the Design of Reliable Communication Networks 2023
Abbreviated titleDRCN 2023
Country/TerritorySpain
CityVilanova i la Geltru
Period17/04/2320/04/23

Keywords

  • cloud systems
  • forensic analysis
  • Hadoop
  • HDFS
  • Java Heap Analysis
  • RAM Analysis

ASJC Scopus subject areas

  • Hardware and Architecture
  • Safety, Risk, Reliability and Quality
  • Computer Networks and Communications

Fingerprint

Dive into the research topics of 'Forensic Investigation Using RAM Analysis on the Hadoop Distributed File System'. Together they form a unique fingerprint.

Cite this