...
首页> 外文期刊>Digital investigation >Vis: Virtualization enhanced live forensics acquisition for native system
【24h】

Vis: Virtualization enhanced live forensics acquisition for native system

机译:Vis:虚拟化增强了本机系统的实时取证

获取原文
获取原文并翻译 | 示例
           

摘要

Current live acquisition systems can obtain memory content of a running system, but they either fail to provide accurate native system physical memory acquisition at the given time point or require suspending the machine and altering the execution environment drastically. To address this issue, we propose Vis, a lightweight virtualization approach to provide accurate retrieval of physical memory content without disturbing the execution of the target native system. Our experimental results indicate that Vis is capable of reliably retrieving an accurate system image. Moreover, Vis accomplishes live acquisition in around 100 s, where previous remote live acquisition tools take hours and static acquisition takes days. On average, the performance reduction for the target system is 9.62%.
机译:当前的实时采集系统可以获取正在运行的系统的内存内容,但是它们要么无法在给定的时间点提供准确的本机系统物理内存采集,要么需要暂停机器并彻底改变执行环境。为解决此问题,我们提出了Vis,这是一种轻量级的虚拟化方法,可提供对物理内存内容的准确检索,而不会影响目标本机系统的执行。我们的实验结果表明,Vis能够可靠地检索准确的系统映像。此外,Vis可以在大约100 s内完成实时采集,而以前的远程实时采集工具需要数小时,而静态采集则需要数天。平均而言,目标系统的性能降低为9.62%。

著录项

  • 来源
    《Digital investigation》 |2012年第1期|p.22-33|共12页
  • 作者单位

    Shanghai Key Laboratory of Scalable Computing and Systems, Shanghai Jiao long University, China,Shanghai Jiao Tong University, Shanghai Key Laboratory of Scalable Computing and Systems, 800 Dongchuan Road, Room 1207, Shanghai 200240, China;

    Shanghai Key Laboratory of Scalable Computing and Systems, Shanghai Jiao long University, China;

    Shanghai Key Laboratory of Scalable Computing and Systems, Shanghai Jiao long University, China;

    Shanghai Key Laboratory of Scalable Computing and Systems, Shanghai Jiao long University, China;

    Shanghai Key Laboratory of Scalable Computing and Systems, Shanghai Jiao long University, China;

    Shanghai Key Laboratory of Scalable Computing and Systems, Shanghai Jiao long University, China;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    vis; live acquisition; accuracy; virtualization; late-virtualization; virtual-snapshot;

    机译:可见实时获取;准确性;虚拟化;后期虚拟化;虚拟快照;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号