Core Paper IV covers fundamental computer hardware architecture, storage subsystems, operating system file structures, virtualization layers, and cloud deployment models essential for conducting rigorous cyber forensics investigations and maintaining digital evidence integrity.
Unit 1: Computer Hardware Architecture and Motherboard Components
A thorough understanding of physical hardware components forms the foundation of forensic data recovery and live system analysis. The motherboard acts as the central printed circuit board that connects the central processor, system memory, input and output subsystems, and peripheral storage interfaces.
- Motherboard Architecture: Houses chipset buses, PCI Express expansion slots, and peripheral controller chips that coordinate high-speed communication between system components.
- BIOS and UEFI Firmware: Basic Input/Output System (BIOS) and Unified Extensible Firmware Interface (UEFI) initialize hardware components during the power-on self-test (POST) sequence and hand over control to the operating system bootloader.
- CMOS Memory: A dedicated battery-backed complementary metal-oxide-semiconductor RAM chip preserves system configuration parameters, hardware profiles, and the real-time system clock. In forensic investigations, verifying CMOS time against network time server logs is crucial for establishing chronological event timelines.
- Central Processing Unit (CPU): Executes binary instruction sets through the fetch, decode, execute, and writeback cycle. Multi-core processors and hardware-assisted virtualization extensions dictate how guest virtual machines interact with underlying physical silicon.
- System Memory (RAM): Volatile random access memory stores executing processes, active kernel modules, decrypted cryptographic keys, and open network connections. Capturing volatile RAM before system shutdown is a mandatory priority during live forensic triage.
Storage Subsystems, File Systems, and RAID Configurations
Digital storage media hold persistent evidence that forensic examiners must image and interpret without modifying underlying sector data.
- Magnetic Hard Disk Drives (HDD): Store data on rotating magnetic platters divided into tracks, cylinders, and sectors. Residual slack space and unallocated sectors frequently contain recoverable remnants of deleted files.
- Solid State Drives (SSD): Utilize non-volatile NAND flash memory chips. SSD controller algorithms, such as wear-leveling and background TRIM commands, actively sanitize unallocated blocks, presenting unique challenges for carving deleted digital artifacts.
- File System Architectures: FAT32, NTFS, and ext4 organize data on storage volumes. Forensic analysis of the NTFS Master File Table ($MFT) and volume log files ($LogFile) provides granular records of file creation, modification, access, and deletion timestamps.
- Redundant Array of Independent Disks (RAID): RAID configurations (RAID 0 striping, RAID 1 mirroring, RAID 5 distributed parity, and RAID 10 nested arrays) combine multiple physical disks into logical storage units. Reconstructing RAID volumes requires identifying stripe block sizes, parity distribution schemes, and disk order.
- Removable Media and Backup Systems: USB flash drives, external optical discs, and magnetic tape archives require write-blocking hardware during image acquisition to prevent metadata alteration.
Input, Output, Display Systems, and Peripheral Forensics
Peripheral hardware interfaces generate identifiable registry entries and hardware event logs across operating systems.
- System Ports and Communication Buses: Universal Serial Bus (USB), Thunderbolt, Serial RS-232, and parallel ports maintain device connection artifacts. USBSTOR registry keys on Windows systems record the vendor name, product model, serial number, and drive letter of connected storage devices.
- Input Devices: Keyboards, pointing devices, and biometric scanners interface through human interface device (HID) drivers, leaving event records in system event logs.
- Display Arrays and Graphics Adapters: Video Graphics Array (VGA), Digital Visual Interface (DVI), and High-Definition Multimedia Interface (HDMI) controllers communicate with dedicated Graphics Processing Units (GPU), which may hold cached frame buffers and computational artifacts.
Virtualization Technologies and Hypervisor Architecture
Virtualization decouples operating systems and application workloads from physical hardware, enabling scalable multi-tenant environments.
- Type-1 Bare-Metal Hypervisors: Run directly on host physical hardware (e.g., VMware ESXi, Microsoft Hyper-V, KVM), managing guest virtual machine resource allocations with minimal latency.
- Type-2 Hosted Hypervisors: Run as software applications atop an existing host operating system (e.g., Oracle VirtualBox, VMware Workstation).
- Forensic Value of Virtual Artifacts: Virtual hard disk files (VMDK, VHDX, QCOW2) can be mounted read-only for dead-box analysis. Virtual machine snapshots and suspended state memory files (.vmem) capture complete volatile memory states without requiring live host software agents. Applying standardized digital forensics investigation techniques ensures virtual disk images remain forensically sound and admissible in court.
Cloud Computing Service Models and Forensic Challenges
Cloud computing delivers shared computing resources over networks based on on-demand self-service, broad network access, resource pooling, rapid elasticity, and measured service metrics.
- Infrastructure as a Service (IaaS): Cloud service providers supply virtualized compute, storage, and networking hardware. Consumers maintain control over operating systems, deployed applications, and security configurations, giving forensic investigators access to system-level virtual disk images and guest OS logs.
- Platform as a Service (PaaS): Providers manage the underlying infrastructure and runtime environments, while consumers deploy custom applications. Forensic access is restricted to application logs, API gateway logs, and database transaction ledgers.
- Software as a Service (SaaS): Providers deliver fully managed software applications (e.g., webmail, collaboration suites, CRM platforms). Forensic examinations rely exclusively on provider-exported audit logs, tenant activity records, and client-side web browser artifacts.
Cloud Investigation Methodology and Evidence Preservation
Investigating security incidents in multi-tenant cloud architectures requires adapting traditional chain of custody protocols to distributed environments. Physical hardware seizure is rarely feasible because cloud servers host workloads for thousands of unrelated tenants simultaneously.
Examiners must utilize cloud provider API snapshots, object storage bucket versioning, centralized security information and event management (SIEM) telemetry, and cryptographically verified digital evidence containers. Compliance with Indian cyber laws and digital evidence guidelines under Section 65B of the Indian Evidence Act (and corresponding provisions under the Bharatiya Sakshya Adhiniyam) is mandatory to ensure electronic records and hash verifications satisfy judicial admissibility thresholds.
| Cloud Service Model | Customer Control Level | Forensic Acquisition Scope | Primary Evidence Artifacts |
|---|---|---|---|
| IaaS (Infrastructure) | OS, storage, deployed software, network rules | Virtual disk snapshots, RAM dumps, system logs | VHD/VMDK files, MFT, kernel event traces |
| PaaS (Platform) | Application code, local database schemas | Application logs, API metrics, database tables | HTTP access logs, SQL query logs, error dumps |
| SaaS (Software) | Application user settings, user data | Exported tenant audit logs, client browser caches | Login history, session tokens, web history |
