Journal article
Forensic analysis of container snapshot chains for post-event reconstruction
- Abstract:
- Container orchestration platforms have become a crucial part of the cloud-native infrastructure for deploying modern applications. The highly dynamic and ephemeral nature of these environments, however, introduces new challenges for digital forensics: malicious code often runs entirely in memory and vanishes when the container terminates, leaving no traces. The absence of forensic data can be just as dangerous as the malicious activity itself, preventing post-incident investigation and adequate response. In this paper, we propose Forensic Snapshot Chains (FSC) – a framework that transparently captures and preserves the state, configurations, and metadata of running containers. These snapshot artifacts allow investigators to accurately reconstruct and analyze the events during a security incident without impacting the running cluster. To achieve this, FSC leverages memory-tracking mechanisms inspired by live-migration optimization techniques that enable high-frequency snapshot capture when a security alert is triggered, while minimizing performance and storage overhead. Our evaluation with real-world cloud-native workloads demonstrates that FSC, with minimal performance overhead, enables accurate temporal reconstruction of memory-resident malicious activity derived from container snapshot chains under both stealthy execution and active attack scenarios.
- Publication status:
- Accepted
- Peer review status:
- Peer reviewed
Actions
Authors
+ European Union
More from this funder
- Funder identifier:
- https://ror.org/019w4f821
- Grant:
- 101189689
- Programme:
- Horizon Europe research and innovation programme
+ Fundação para a Ciência e Tecnologia
More from this funder
- Funder identifier:
- https://ror.org/00snfqn58
- Grant:
- LISBOA2030-FEDER-00748300
- UID/PRR/50021/2025
- UID/50021/2025
+ Engineering and Physical Sciences Research Council
More from this funder
- Funder identifier:
- https://ror.org/0439y7842
- Grant:
- 2595601
- Publisher:
- Elsevier
- Journal:
- Journal of Forensic Science International: Digital Investigation More from this journal
- Acceptance date:
- 2026-04-03
- EISSN:
-
2666-2825
- ISSN:
-
2666-2817
- Language:
-
English
- Keywords:
- Pubs id:
-
2407775
- Local pid:
-
pubs:2407775
- Deposit date:
-
2026-04-17
- ARK identifier:
If you are the owner of this record, you can report an update to it here: Report update to this record