Title: Identifying artefact on Microsoft OneDrive client to support Android forensics

Authors: Gandeva Bayu Satrya; A. Ahmad Nasrullah; Soo Young Shin

Addresses: Department of IT Convergence Engineering, Kumoh National Institute of Technology, Gumi, Gyeongbuk 39177, South Korea ' Forensics and Security Laboratory, Telkom University, Bandung, West Java 40257, Indonesia ' Department of IT Convergence Engineering, Kumoh National Institute of Technology, Gumi, Gyeongbuk 39177, South Korea

Abstract: Microsoft software is perhaps the most widely used around the world. As computing technology has evolved they have been at the cutting edge and have developed a number of groundbreaking and useful applications. Microsoft OneDrive is one such application. OneDrive is a cloud storage service offering 7 GB free storage to users. This technology can be misused and through it laws governing the cyber world violated. Current solutions to this are to perform digital forensics when cybercrime has occurred. This research used two different vendors of Android smartphones as experimentation objects. A model has been developed in this research, which provides instructions for digital mobile forensics analysis in finding artefacts related to the client's activities on OneDrive cloud storage application. These artefacts can be used as digital evidence by digital forensics investigators and the research increases the knowledge of cyber law practitioners.

Keywords: artefacts; cybercrime; cloud storage; digital forensics; Android forensics; OneDrive analysis.

DOI: 10.1504/IJESDF.2017.085192

International Journal of Electronic Security and Digital Forensics, 2017 Vol.9 No.3, pp.269 - 291

Received: 15 Apr 2016
Accepted: 20 Jan 2017

Published online: 16 Jul 2017 *

Full-text access for editors Full-text access for subscribers Purchase this article Comment on this article