首页> 外文期刊>Journal of Information Security Research >A Lightweight Software Write-blocker for Virtual Machine Forensics
【24h】

A Lightweight Software Write-blocker for Virtual Machine Forensics

机译:用于虚拟机取证的轻量级软件写阻止程序

获取原文
获取原文并翻译 | 示例
           

摘要

The integrity of any original evidence is fundamental to a forensic examination. Preserving the integrity of digital evidence is vitally important as changing just one bit among perhaps gigabits of data, will irrevocably alter that data and cast doubt on any evidence extracted. In traditional digital forensics write-blockers are used to preserve the integrity of that evidence and prevent changes from occurring, but virtual machine forensics presents more difficult challenges to address. Access to the digital storage device will probably not be possible, typically the only accessible storage will be a virtual hard disk drive. This will have the same integrity issues as those of a real device, but with the added complication that it is not possible to use a hardware write-blocker to prevent changes to those data. For this reason it is important to explore how to implement write-blocking mechanisms on a virtual device. In this paper we present an implementation of a software write-blocker and show how we can use it to be compliant with the 2nd ACPO principle on digital evidence.
机译:任何原始证据的完整性都是法医检查的基础。维护数字证据的完整性至关重要,因为仅更改几千兆字节的数据就将不可挽回地更改数据并对任何提取的证据产生疑问。在传统的数字取证中,使用写阻止程序来保留证据的完整性并防止发生更改,但是虚拟机取证提出了更难解决的挑战。可能无法访问数字存储设备,通常唯一可访问的存储将是虚拟硬盘驱动器。这将具有与真实设备相同的完整性问题,但又增加了复杂性,即无法使用硬件写阻止程序来防止更改那些数据。因此,重要的是探索如何在虚拟设备上实现写阻止机制。在本文中,我们介绍了一种软件写阻止程序的实现,并展示了如何使用它来符合数字证据的第二ACPO原则。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号