Research Article

[Retracted] Digital Forensic Investigation of Healthcare Data in Cloud Computing Environment

Table 1

iCloud forensic approaches.

Research workCloud serviceDevices usedModelData extractionTools used

Lee et al. [3]iCloudWindows system, MacBook system, iPhone, iPodiCloud investigation modelApplication installation history, synced apps, plist, sync locationNo tool is used. Use of encase tool is suggested.
Oestreicher [4]iCloudMacBook Pro Mac OS X 10.9Data acquisition from cloudSynced apps, application path, creation time, modification time, access time, MD5 hash valuesForensic toolkit imager, VisualDiffer v.1.5.7
Canseco et al. [5]Box, iCloudWindows 7 × 64 systemForensic tool-MONOCLERegistry, disk logs, Windows logsVolatility framework
Teing et al. [6]SymformWindows 8.1, Mac OS X 10.9.5, Ubuntu 14.04.1, iOS 7.1.2, Android KitKat 4.4.4Investigation model for cooperative storage cloud serviceDirectory listings, record files, cache database, system log files, synced files, deleted files, thumbnail cache, browser artifacts, memory analysis, event logs, registry files, link files, network logsFTK imager v3.2.0.0, Autopsy 3.1.1, Volatility 2.4, SQLite browser v3.4.0, Wireshark v1.10.1, Browsing History View v1.60, plist explorer v1.0, Windows Event Viewer v1.0
Teing et al. [7]BitTorrent sync v2.xWindows 8.1, Ubuntu 14.04.1, Mac OS X 10.9.5, iOS 7.1.2, Android 4.4.4Forensic process for peer-to-peer (p2p) cloudDirectory listings, plist file, log files, synced data, network data, IP address, URLs, memory analysis, browser dataFTK imager v3.2.0.0, Autopsy 3.1.1, Volatility 2.4, SQLite browser v3.4.0, Wireshark v1.10.1, plist explorer v1.0
Teing et al. [8]CloudMeWindows 8.1 Professional, Ubuntu 14.04.1 LTS, Mac OS X Mavericks 10.9.5Artifact analysis of desktop and mobile devices using cloud servicesCache database, plist files, synced files, registry, log files, user information, timestamp, Web browser artifacts, memory analysis, config filesFTK imager v3.2.0.0, Autopsy 3.1.1, Volatility 2.4, SQLite browser v3.4.0, plist explorer v1.0, Windows File Analyzer 2.6.0.0, Browsing History View v.1.60
Teing et al. [9]Syncany 0.4.6-alphaWindows 8.1 Professional, Ubuntu 14.04.1 LTS, Mac OS X Mavericks 10.9.5Enabled big data storage forensicsProperty list files, event logs, system logs, user profiles, memory analysis, network analysis, synced files, upload and download files, browser artifactsFTK imager v3.2.0.0, Autopsy 3.1.1, Volatility 2.4, SQLite browser v3.4.0, Windows File Analyzer 2.6.0.0, NTFS log tracker
Gomez-Miralles and Arnedo-Moreno [10]iCloudDevices running iOS v7 and 8Security, trust, anti-forensicWi-Fi log, network traffic, preload apps, hardware state, system logs, browser data, iCloud synced data, media filesLockup, jailbreak tools