首页> 外文会议>International Conference on Availability, Reliability, and Security >Investigating the Implications of Virtual Machine Introspection for Digital Forensics
【24h】

Investigating the Implications of Virtual Machine Introspection for Digital Forensics

机译:调查虚拟机内省对数字取证的影响

获取原文

摘要

Researchers and practitioners in computer forensics currently must base their analysis on information that is either incomplete or produced by tools that may themselves be compromised as a result of the intrusion. Complicating these issues are the techniques employed by the investigators themselves. If the system is quiescent when examined, most of the information in memory has been lost. If the system is active, the kernel and programs used by the forensic investigators are likely to influence the results and as such are themselves suspect. Using virtual machines and a technique called virtual machine introspection can help overcome these limits, but it introduces its own research challenges. Recent developments in virtual machine introspection have led to the identification of four initial priority research areas in virtual machine introspection including virtual machine introspection tool development, applications of virtual machine introspection to non-quiescent virtual machines, virtual machine introspection covert operations, and virtual machine introspection detection.
机译:计算机取证的研究人员和从业者目前必须将他们的分析基于不完整或由工具产生的信息,这些信息本身可能因入侵而受到损害。使这些问题复杂化是调查人员自己所雇用的技术。如果系统在检查时静态,则内存中的大多数信息都已丢失。如果系统是活动的,则法医调查员使用的内核和程序可能会影响结果,因此本身就是怀疑。使用虚拟机和一种称为虚拟机内省的技术可以帮助克服这些限制,但它介绍了自己的研究挑战。虚拟机内省的最新进展导致了识别虚拟机进入的四个初始优先级研究领域,包括虚拟机内省的工具开发,虚拟机的应用到非静态虚拟机,虚拟机内省封面操作,以及虚拟机的内省检测。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号