CFP last date
20 May 2024
Reseach Article

Forensic Analysis of Dropbox Data Remnants on Windows 10

by Walter Buyu, Elisha Odira Abade
International Journal of Computer Applications
Foundation of Computer Science (FCS), NY, USA
Volume 176 - Number 41
Year of Publication: 2020
Authors: Walter Buyu, Elisha Odira Abade
10.5120/ijca2020920546

Walter Buyu, Elisha Odira Abade . Forensic Analysis of Dropbox Data Remnants on Windows 10. International Journal of Computer Applications. 176, 41 ( Jul 2020), 25-36. DOI=10.5120/ijca2020920546

@article{ 10.5120/ijca2020920546,
author = { Walter Buyu, Elisha Odira Abade },
title = { Forensic Analysis of Dropbox Data Remnants on Windows 10 },
journal = { International Journal of Computer Applications },
issue_date = { Jul 2020 },
volume = { 176 },
number = { 41 },
month = { Jul },
year = { 2020 },
issn = { 0975-8887 },
pages = { 25-36 },
numpages = {9},
url = { https://ijcaonline.org/archives/volume176/number41/31475-2020920546/ },
doi = { 10.5120/ijca2020920546 },
publisher = {Foundation of Computer Science (FCS), NY, USA},
address = {New York, USA}
}
%0 Journal Article
%1 2024-02-07T00:41:02.484571+05:30
%A Walter Buyu
%A Elisha Odira Abade
%T Forensic Analysis of Dropbox Data Remnants on Windows 10
%J International Journal of Computer Applications
%@ 0975-8887
%V 176
%N 41
%P 25-36
%D 2020
%I Foundation of Computer Science (FCS), NY, USA
Abstract

Cloud storage services are popular among businesses and individuals as they offer convenience in storage and sharing of files at an affordable price. However, cloud storage is subject to abuse by cybercriminals, and coupled with the difficulty in getting artefacts of evidential value from cloud storage providers, artefacts from client computer can provide potential evidence on which a case can be based. This paper investigates artefacts left behind by Dropbox, a popular cloud storage application, on Windows 10. Through live and dead forensics, the study determines Dropbox artefacts on Windows 10 for various scenarios including installation, file upload, file deletion, and uninstallation. By identifying these remnants, this work contributes to a better understanding of the artefacts that are likely to remain for digital forensics investigators. Potential information sources identified during the research include the client software installation files, browser, link files, prefetch files, registry, and network traffic.

References
  1. Mell P, Grance T. 2011. The NIST Definition of Cloud Computing. NIST Spec Publ 800-145 :2.
  2. Simou S, Kalloniatis C, Kavakli E, Gritzalis S. 2014. Cloud Forensics: Identifying the Major Issues and Challenges. In: Jarke M, Mylopoulos J, Quix C, Rolland C, Manolopoulos Y, Mouratidis H, Horkoff J (eds) Int. Conf. Adv. Inf. Syst. Eng. Springer International Publishing, Cham, pp 271–284.
  3. Pichan A, Lazarescu M, Soh ST. 2015. Cloud Forensics: Technical Challenges, Solutions and Comparative Analysis. Digit Investig 13:38–57.
  4. Ghafarian A. 2015. Foreniscs Analysis of Cloud Computing Services. In: 2015 Sci. Inf. Conf. pp 1335–1339.
  5. Hu W, Yang T, Matthews JN. 2010. The Good, the Bad and the Ugly of Consumer Cloud Storage. SIGOPS Oper Syst Rev 44(3):110–115.
  6. Caviglione L, Podolski M, Mazurczyk W, Ianigro M. 2017. Covert Channels in Personal Cloud Storage Services: The Case of Dropbox. IEEE Trans Ind Informatics 13(4):1921–1931.
  7. Mehreen S, Aslam B. 2015. Windows 8 Cloud Storage Analysis: Dropbox Forensics. In: 2015 12th Int. Bhurban Conf. Appl. Sci. Technol. pp 312–317.
  8. [Dropbox. 2018. What is Dropbox? Available from: https://www.dropbox.com/features, [21/11/2018].
  9. Dropbox. 2018. How much does Dropbox cost? Available from: https://www.dropbox.com/help/billing/cost, [21/11/2018].
  10. Damshenas M, Dehghantanha A, Mahmoud R, Shamsuddin S bin. 2012. Forensics investigation challenges in cloud computing environments. In: Proc. Title 2012 Int. Conf. Cyber Secur. Cyber Warf. Digit. Forensic. pp 190–194.
  11. Chung H, Park J, Lee S, Kang C. 2012. Digital Forensic Investigation of Cloud Storage Services. Digit Investig 9(2):81–95.
  12. Ahmed AA, Li CX. 2016. Locating and Collecting Cybercrime Evidences on Cloud Storage: Review. In: 2016 Int. Conf. Inf. Sci. Secur. pp 1–5.
  13. Biggs S, Vidalis S. 2009. Cloud Computing: The Impact on Digital Dorensic Investigations. In: 2009 Int. Conf. Internet Technol. Secur. Trans. pp 1–6.
  14. Taylor M, Haggerty J, Gresty D, Lamb D. 2011. Forensic Investigation of Cloud Computing Systems. Netw Secur 2011(3):4–10.
  15. Guo H, Jin B, Shang T. 2012. Forensic Investigations in Cloud Environments. In: 2012 Int. Conf. Comput. Sci. Inf. Process. pp 248–251.
  16. Cisco. 2018. Cisco Global Cloud Index: Forecast and Methodology, 2016–2021. .
  17. NetApplications. 2018. Operating System Market Share. Available from: https://netmarketshare.com/operating-system-market share.aspx?options=%257B%2522filter%2522%253A%257B%2522%2524and%2522%253A%255B%257B%2522deviceType%2522%253A%257B%2522%2524in%2522%253A%255B%2522Desktop%252Flaptop%2522%255D%257D%257D%255D%257D%252C%2522dateLabel%2522%253A%2522Trend%2522%252C%2522attributes%2522%253A%2522share%2522%252, [21/11/2018].
  18. Microsoft. 2018. Windows Lifecycle Fact Sheet. Available from: https://support.microsoft.com/en-gb/help/13853/windows-lifecycle-fact-sheet, [21/11/2018].
  19. Keizer G. 2018. Windows by the numbers: Windows 10 nears ‘crossover’ point with veteran Windows 7. Available from: https://www.itworld.com/article/3199373/windows-pcs/windows-by-the-numbers-windows-10-nears-crossover-point-with-veteran-windows-7.html?page=2#toc-1, [21/11/2018].
  20. Zatyko K, Bay J. 2011. The Digital Forensics Cyber Exchange Principle. 2017:.
  21. McClain F. 2011. Dropbox Forensics. Forensic Focus. Available from: https://www.forensicfocus.com/articles/dropbox-forensics/, [20/04/2020].
  22. Marturana F, Me G, Tacconi S. 2012. A Case Study on Digital Forensics in the Cloud. In: 2012 Int. Conf. Cyber-Enabled Distrib. Comput. Knowl. Discov. pp 111–116.
  23. Quick D, Choo K-KR. 2013. Dropbox Analysis: Data Remnants on User Machines. Digit Investig 10(1):3–18.
  24. Epifani M. 2013. Cloud Storage Forensics. .
  25. Malik R, Shashidhar N, Chen L. 2015. Analysis of Evidence in Cloud Storage Client Applications on the Windows Platform. Proc. Int. Conf. Secur. Manag. .
  26. Amirullah A, Riadi I, Luthfi A. 2016. Forensics Analysis from Cloud Storage Client Application on Proprietary Operating System. Int. J. Comput. Appl. 143:.
  27. Picasso F. 2017. Brush up on Dropbox DBX Decryption. ZENA FORENSICS 2017:.
  28. McKemmish R. 1999. What is Forensic Computing? . Trends Issues Crime Crim Justice 118:1–6.
  29. Microsoft. 2019. How to Find Windows 10 Computer Specifications & Systems Requirements. Available from: https://www.microsoft.com/en-us/windows/windows-10-specifications, [15/01/2020].
  30. Rani DR, Geethakumari G. 2015. An Efficient Approach to Forensic Investigation in Cloud using VM Snapshots. In: 2015 Int. Conf. Pervasive Comput. pp 1–5.
  31. McKemmish R. 2008. When is Digital Evidence Forensically Sound? BT - Advances in Digital Forensics IV. In: Ray I, Shenoi S (eds). Springer US, Boston, MA, pp 3–15.
  32. ACPO. 2012. ACPO Good Practice Guide for Digital Evidence. .
  33. Lyons B. 2016. Disk Image Content Model and Metadata Analysis. .
  34. Warren T. 2015. Cortana for Windows 10 will search Dropbox and Google Drive on Lenovo PCs. Available from:https://www.theverge.com/2015/5/28/8676557/lenovo-cortana-reachit-windows-10, [13/05/2020].
  35. Warren T. 2014. Dropbox and Microsoft form surprise partnership for Office integration. Available from: https://www.theverge.com/2014/11/4/7153975/dropbox-microsoft-partnership-microsoft-office, [13/05/2020].
  36. Quick D, Martini B, Choo K-KR, Quick D, Martini B, Choo K-KR. 2014. Dropbox Analysis: Data Remnants on User Machines. Cloud Storage Forensics :63–93.
  37. Rescorla E. 2000. HTTP Over TLS. Available from: https://tools.ietf.org/html/rfc2818, [13/05/2020].
  38. Hoffman C. 2017. What Is the AppData Folder in Windows? Available from: https://www.howtogeek.com/318177/what-is-the-appdata-folder-in-windows/, [13/05/2020].
  39. Malik R, Shashidhar N, Chen L. 2015. Cloud Storage Client Application Analysis. Int. J. Secur. 9:.
  40. StackExchange. 2012. .dropbox files, can they be deleted? Available from: https://superuser.com/questions/472616/dropbox-files-can-they-be-deleted, [13/05/2020].
  41. Dropbox. Encoding for JSON Arguments. Available from: https://www.dropbox.com/developers/reference/json-encoding, [10/07/2020].
Index Terms

Computer Science
Information Sciences

Keywords

Windows 10 Dropbox Forensics Dropbox Analysis Digital Forensics Computer Forensics Cloud Storage Applications.