Vis: Virtualization Enhanced Live Forensics Acquisition for Native System
ثبت نشده
چکیده
Live forensic is becoming one significant part in modern digital investigation. It is effective in obtaining criminal evidence which only exists in memory. Unfortunately, current efforts either fail to provide accurate acquisition of native system state at the given time point or require suspending the machine and altering the execution environment drastically. To address this issue, we propose Vis, a light-weight virtualization approach to provide accurate retrieving of native system state while preserving the execution of target system. Vis is built on two key technologies. The first one Virtual-Snapshot ensures the accuracy of the dumped system state without suspending the target system. The second one Late-Virtualization builds the required virtualization environment by encapsulating the native system into a single virtual machine after the OS finishes booting without environment impact upon the target system execution. Our experimental results indicate that Vis is capable of reliably retrieving an accurate system image. Besides, Vis accomplishes live acquisition within 97.09∼105.86 seconds, which proves Vis is practical when comparing with hours needed by previous remote live acquisition tools and even days needed in static acquisition. In average, Vis introduces only 9.62% performance overhead to the target system.
منابع مشابه
Vis: Virtualization enhanced live forensics acquisition for native system
Focusing on obtaining in-memory evidence, current live acquisition efforts either fail to provide accurate native system physical memory acquisition at the given time point or require suspending the machine and altering the execution environment drastically. To address this issue, we propose Vis, a light-weight virtualization approach to provide accurate retrieving of physical memory content wh...
متن کاملHow Virtualized Environments Affect Computer Forensics
Virtualized environments can make forensics investigation more difficult. Technological advances in virtualization tools essentially make removable media a PC that can be carried around in a pocket or around a neck. Running operating systems and applications this way leaves very little trace on the host system. This paper will explore all the newest methods for virtualized environments and the ...
متن کاملA Platform for the Evaluation of Live Digital Forensics
Live digital forensics presents unique challenges with respect to maintaining forensic soundness, but also offers the ability to examine information that is unavailable to quiescent analysis. Any perturbation of a live operating system by a forensic examiner will have far-reaching effects on the state of the system being analysed. Numerous approaches to live digital forensic evidence acquisitio...
متن کاملTrends in Virtualized User Environments
Virtualized environments can make forensics investigation more difficult. Technological advances in virtualization tools essentially make removable media a PC that can be carried around in a pocket or around a neck. Running operating systems and applications this way leaves very little trace on the host system. This paper will explore all the newest methods for virtualized environments and the ...
متن کاملPypette: A Platform for the Evaluation of Live Digital Forensics
Live digital forensics presents unique challenges with respect to maintaining forensic soundness, but also offers the ability to examine information that is unavailable to quiescent analysis. Any perturbation of a live operating system by a forensic examiner will have far-reaching effects on the state of the system being analysed. Numerous approaches to live digital forensic evidence acquisitio...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2011