Vis: Virtualization Enhanced Live Forensics Acquisition for Native System

ثبت نشده
چکیده

Live forensic is becoming one significant part in modern digital investigation. It is effective in obtaining criminal evidence which only exists in memory. Unfortunately, current efforts either fail to provide accurate acquisition of native system state at the given time point or require suspending the machine and altering the execution environment drastically. To address this issue, we propose Vis, a light-weight virtualization approach to provide accurate retrieving of native system state while preserving the execution of target system. Vis is built on two key technologies. The first one Virtual-Snapshot ensures the accuracy of the dumped system state without suspending the target system. The second one Late-Virtualization builds the required virtualization environment by encapsulating the native system into a single virtual machine after the OS finishes booting without environment impact upon the target system execution. Our experimental results indicate that Vis is capable of reliably retrieving an accurate system image. Besides, Vis accomplishes live acquisition within 97.09∼105.86 seconds, which proves Vis is practical when comparing with hours needed by previous remote live acquisition tools and even days needed in static acquisition. In average, Vis introduces only 9.62% performance overhead to the target system.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Vis: Virtualization enhanced live forensics acquisition for native system

Focusing on obtaining in-memory evidence, current live acquisition efforts either fail to provide accurate native system physical memory acquisition at the given time point or require suspending the machine and altering the execution environment drastically. To address this issue, we propose Vis, a light-weight virtualization approach to provide accurate retrieving of physical memory content wh...

متن کامل

How Virtualized Environments Affect Computer Forensics

Virtualized environments can make forensics investigation more difficult. Technological advances in virtualization tools essentially make removable media a PC that can be carried around in a pocket or around a neck. Running operating systems and applications this way leaves very little trace on the host system. This paper will explore all the newest methods for virtualized environments and the ...

متن کامل

A Platform for the Evaluation of Live Digital Forensics

Live digital forensics presents unique challenges with respect to maintaining forensic soundness, but also offers the ability to examine information that is unavailable to quiescent analysis. Any perturbation of a live operating system by a forensic examiner will have far-reaching effects on the state of the system being analysed. Numerous approaches to live digital forensic evidence acquisitio...

متن کامل

Trends in Virtualized User Environments

Virtualized environments can make forensics investigation more difficult. Technological advances in virtualization tools essentially make removable media a PC that can be carried around in a pocket or around a neck. Running operating systems and applications this way leaves very little trace on the host system. This paper will explore all the newest methods for virtualized environments and the ...

متن کامل

Pypette: A Platform for the Evaluation of Live Digital Forensics

Live digital forensics presents unique challenges with respect to maintaining forensic soundness, but also offers the ability to examine information that is unavailable to quiescent analysis. Any perturbation of a live operating system by a forensic examiner will have far-reaching effects on the state of the system being analysed. Numerous approaches to live digital forensic evidence acquisitio...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2011