2009 XXII International Symposium on Information, Communication and Automation Technologies 2009
DOI: 10.1109/icat.2009.5348415
|View full text |Cite
|
Sign up to set email alerts
|

Combining static and live digital forensic analysis in virtual environment

Abstract: Traditional digital forensics is performed through static analysis of data preserved on permanent storage media. Not all data needed to understand the state of examined system exists in nonvolatile memory. Live analysis uses running system to obtain volatile data for deeper understanding of events going on. Sampling running system might irreversibly change its state making collected evidence invalid. This paper proposes combination of static and live analysis. Virtualization is used to bring static data to lif… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

0
17
0
2

Year Published

2011
2011
2020
2020

Publication Types

Select...
5
4

Relationship

0
9

Authors

Journals

citations
Cited by 29 publications
(19 citation statements)
references
References 13 publications
0
17
0
2
Order By: Relevance
“…Any scientific procedure adopted during investigation should make no changes to the evidence in order to ensure its admissibility in the court. In case of any alteration due to forensic procedures, a proper explanation must be provided [4].…”
Section: Introductionmentioning
confidence: 99%
“…Any scientific procedure adopted during investigation should make no changes to the evidence in order to ensure its admissibility in the court. In case of any alteration due to forensic procedures, a proper explanation must be provided [4].…”
Section: Introductionmentioning
confidence: 99%
“…Then comes the likelihood of inappropriate application of tools and procedures; propelled by inadequate understanding of architectural layout and operations of a target system [11]. Integrity takes all the blows, and belated response to these could yield undesirable phenomena characterised by wrong or unjust acquittals, or false prosecutions [25].…”
Section: International Journal Of Computer Applications (0975 -8887) mentioning
confidence: 99%
“…One adoptable technique towards guaranteeing integrity with relation to volatile evidence in the Windows platform included the utilization of the in-built memory dump utility (Microsoft Windows Hibernation), the creation of a bit image, and subsequent analysis of such acquired bit-image using CERT's LiveView image analysis utility in a virtual machine [25]. This process of image mounting and booting allowed for the efficient acquisition of an interactive user-level access and perspective of the operating environment with modifications to the underlying image or contents therein.…”
Section: Im(proving) Integrity: Related Workmentioning
confidence: 99%
“…Investigators need to detect malfunction and analyze malware in virtual environments. Currently digital forensics covers a very vast field where there are abundant developments of novel approaches for investigating digital crimes [4].…”
Section: Introductionmentioning
confidence: 99%