首页> 外文会议>Availability, Reliability and Security, 2009. ARES '09 >Investigating the Implications of Virtual Machine Introspection for Digital Forensics
【24h】

Investigating the Implications of Virtual Machine Introspection for Digital Forensics

机译:调查虚拟机自省对数字取证的影响

获取原文

摘要

Researchers and practitioners in computer forensics currently must base their analysis on information that is either incomplete or produced by tools that may themselves be compromised as a result of the intrusion. Complicating these issues are the techniques employed by the investigators themselves. If the system is quiescent when examined, most of the information in memory has been lost. If the system is active, the kernel and programs used by the forensic investigators are likely to influence the results and as such are themselves suspect. Using virtual machines and a technique called virtual machine introspection can help overcome these limits, but it introduces its own research challenges. Recent developments in virtual machine introspection have led to the identification of four initial priority research areas in virtual machine introspection including virtual machine introspection tool development, applications of virtual machine introspection to non-quiescent virtual machines, virtual machine introspection covert operations, and virtual machine introspection detection.
机译:目前,计算机取证的研究人员和从业人员必须基于不完整的信息或由可能由于入侵而自身受到损害的工具产生的信息来进行分析。研究人员自己使用的技术使这些问题复杂化。如果系统在检查时处于静止状态,则内存中的大多数信息都将丢失。如果系统处于活动状态,则法医研究人员使用的内核和程序可能会影响结果,因此,它们本身就是可疑的。使用虚拟机和称为虚拟机自省的技术可以帮助克服这些限制,但它带来了自己的研究挑战。虚拟机自检的最新发展已导致确定了虚拟机自检中的四个初始优先研究领域,包括虚拟机自检工具开发,虚拟机自检在非静态虚拟机中的应用,虚拟机自检隐蔽操作以及虚拟机自检检测。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号