KDCFI AI-based knowledge discovery framework for cloud forensic investigation
摘要
Cloud computing offers scalability, flexibility, and cost-effectiveness, but forensic investigation in such environments remains challenging due to complex attack patterns, diverse evidence sources, and delays in root cause analysis. Traditional approaches rely on rule-based log analysis and signature-driven methods, which lack scalability and fail to provide comprehensive, automated solutions. This paper presents KDCFI (Knowledge Discovery Framework for Cloud Forensic Investigation), a novel ontology-driven framework that integrates semantic data models with large language models (LLMs) to enable end-to-end automation of the forensic life cycle. KDCFI systematically acquires and represents heterogeneous cloud forensic evidence—such as memory dumps, carved files, network utilization statistics, and attack events in a unified knowledge graph, enabling inference-driven reasoning and contextual response generation. Experimental results demonstrate that KDCFI effectively identifies attack bursts, such as hydra brute-force attempts across multiple virtual machines, and provides explainable results through ontology alignment. By bridging forensic automation with semantic knowledge representation, the framework addresses key gaps in scalability, explainability, and trustworthiness of cloud forensic investigations, offering a significant advancement over existing solutions.