首页> 外文期刊>The Australian journal of forensic sciences >Electronic crime investigations in a virtualised environment: a forensic process and prototype for evidence collection and analysis
【24h】

Electronic crime investigations in a virtualised environment: a forensic process and prototype for evidence collection and analysis

机译:虚拟化环境中的电子犯罪调查:证据收集和分析的法医程序和原型

获取原文
获取原文并翻译 | 示例
           

摘要

The constant evolution of virtualisation technologies and the availability of anti-forensic techniques and tools complicate efforts by forensic investigators to investigate a crime or a cyber security incident. Forensic collection can be complicated and requires significant efforts to investigate incidents involving contemporary technologies (e.g. crime launched from a virtual machine and there had been attempts to erase evidence after the incident). This paper presents a forensic process to collect and analyse traces of a virtual machine and its corresponding manager, recorded across multiple sources including the file system, Windows registry, history, and log files from a forensic viewpoint. To demonstrate utility of the forensic mechanism, the Virtual Machine Forensic Artefact Collector (VMFAC) prototype is developed and presented in this paper.
机译:虚拟化技术的持续演变和反务技术的可用性和工具的可用性使法医调查人员调查犯罪或网络安全事件的努力使努力复杂化。 法医收藏可能是复杂的,需要大量努力调查涉及当代技术的事件(例如,从虚拟机启动的犯罪,并且已经试图在事件后删除证据)。 本文介绍了法医过程,用于收集和分析虚拟机及其相应管理器的痕迹,跨多个来源记录,包括来自法证视点的文件系统,Windows注册表,历史记录和日志文件。 为了证明法医机制的效用,本文开发并介绍了虚拟机法医器材收集器(VMFAC)原型。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号