【24h】

A TAXONOMY OF HYPERVISOR FORENSIC TOOLS

机译:管理程序法医工具的分类

获取原文

摘要

Cloud computing models are deployed on a compute server whose hardware resources are virtualized to enable multiple virtual machines to run on a single physical system. Several types of virtualization such as bare metal and hosted virtualization are available along with virtualization modes such as full, paravirtualized, hardware-assisted and paravirtualized-hardware-assisted virtualization. Virtual machines are inaccessible from each other when the physical server hardware is abstracted in the full virtualization mode. Physical information such as hard disk drives and server memory are made available in a virtualized environment as a virtual hard disk, vCPU and guest operating system state. Hypervisor operations generate copious amounts of data that are of value in forensic investigations of virtualized cloud environments. This chapter presents a taxonomy of hypervisor forensic tools, which provides a searchable catalog for forensic practitioners to identify specific tools that fulfill their technical requirements. A case study involving a KVM hypervisor demonstrates the evidence that can be found in a virtual machine at the virtual machine manager and host system layers.
机译:云计算模型部署在计算硬件资源的计算服务器上,虚拟化以启用多个虚拟机以在单个物理系统上运行。诸如裸机和托管虚拟化等几种类型的虚拟化以及虚拟化模式,如完整,半虚拟化,硬件辅助和半虚拟化 - 硬件辅助虚拟化。当在完整的虚拟化模式下抽象物理服务器硬件时,虚拟机彼此无法访问。虚拟化环境中可用的物理信息(如硬盘驱动器和服务器内存)作为虚拟硬盘,VCPU和客户机操作系统状态。虚拟机管理程序操作生成大量数据,这些数据具有虚拟化云环境的法医调查中的价值。本章介绍了管理程序法医工具的分类,为法医从业者提供了一个可搜索的目录,以确定满足其技术要求的特定工具。涉及KVM虚拟机管理程序的案例研究展示了可以在虚拟机管理器和主机系统层的虚拟机中找到的证据。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号