首页> 外文期刊>International journal of parallel programming >A Virtualization Based Monitoring System for Mini-intrusive Live Forensics
【24h】

A Virtualization Based Monitoring System for Mini-intrusive Live Forensics

机译:基于虚拟化的微型侵入式现场取证监控系统

获取原文
获取原文并翻译 | 示例
           

摘要

Digital evidences hold great significance for governing cybercrime. Unfortunately, previous acquisition tools were troubled by either the shortage of suspending the target system's running or the security of the acquisition tools themselves, thus the correctness and accuracy of their obtained evidences cannot be guaranteed. In this paper, we propose VAIL, a novel virtualization based monitoring system for mini-intrusive live forensics, which employs hardware assisted virtualization technique to gather integrated information from the native computer system. Meanwhile, the execution of the target system will not be interrupted and VAIL keeps immune to attacks from the target system. We have implemented a proof-of-concept prototype that has been validated with a Windows guest system. The experimental results show that VAIL can obtain comprehensive digital evidences from the target system as designed, including the CPU state, the physical memory content, and the I/O activities. And on average, VAIL only introduces 4.21 % performance overhead to the target system, which proves that VAIL is practical in real commercial environments.
机译:数字证据对于治理网络犯罪具有重要意义。不幸的是,先前的采集工具由于缺乏暂停目标系统的运行或采集工具本身的安全性而受到困扰,因此无法保证其获得的证据的正确性和准确性。在本文中,我们提出了VAIL,这是一种用于小型侵入式现场取证的新型基于虚拟化的监视系统,该系统采用硬件辅助虚拟化技术从本地计算机系统收集集成信息。同时,目标系统的执行不会被中断,并且VAIL可以不受目标系统的攻击。我们已经实现了概念验证原型,该原型已通过Windows来宾系统验证。实验结果表明,VAIL可以从设计的目标系统中获得全面的数字证据,包括CPU状态,物理内存内容和I / O活动。平均而言,VAIL仅向目标系统引入4.21%的性能开销,这证明VAIL在实际的商业环境中是可行的。

著录项

  • 来源
    《International journal of parallel programming》 |2015年第3期|455-471|共17页
  • 作者单位

    Shanghai Key Laboratory of Scalable Computing and Systems, School of Software, Shanghai Jiao Tong University, Shanghai, China;

    Shanghai Key Laboratory of Scalable Computing and Systems, School of Software, Shanghai Jiao Tong University, Shanghai, China;

    Carnegie Mellon University, Pittsburgh, PA, USA;

    Shanghai Key Laboratory of Scalable Computing and Systems, School of Software, Shanghai Jiao Tong University, Shanghai, China;

    Shanghai Key Laboratory of Scalable Computing and Systems, School of Software, Shanghai Jiao Tong University, Shanghai, China;

  • 收录信息 美国《科学引文索引》(SCI);美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Virtualization; Monitoring system; Mini-intrusive; Live forensics;

    机译:虚拟化;监视系统;迷你型现场取证;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号