Title :
Combining static and live digital forensic analysis in virtual environment
Author :
Mrdovic, Sasa ; Huseinovic, Alvin ; Zajko, Ernedin
Author_Institution :
Fac. of Electr. Eng., Univ. of Sarajevo Sarajevo, Sarajevo, Bosnia-Herzegovina
Abstract :
Traditional digital forensics is performed through static analysis of data preserved on permanent storage media. Not all data needed to understand the state of examined system exists in nonvolatile memory. Live analysis uses running system to obtain volatile data for deeper understanding of events going on. Sampling running system might irreversibly change its state making collected evidence invalid. This paper proposes combination of static and live analysis. Virtualization is used to bring static data to life. Volatile memory dump is used to enable offline analysis of live data. Using data from memory dump, virtual machine created from static data can be adjusted to provide better picture of the live system at the time when the dump was made. Investigator can have interactive session with virtual machine without violating evidence integrity. Tests with sample system confirm viability of proposed approach.
Keywords :
data analysis; interactive systems; program diagnostics; security of data; virtual machines; interactive session; live data offline analysis; live digital forensic analysis; permanent storage media; sampling running system; static analysis; virtual environment; virtual machine; volatile memory dump; Authentication; Digital forensics; Information security; Performance analysis; Privacy; Product codes; Radio frequency; Radiofrequency identification; Scalability; Virtual environment; forensics; hard disk image; hibernation; virtual machine; volatile memory dump;
Conference_Titel :
Information, Communication and Automation Technologies, 2009. ICAT 2009. XXII International Symposium on
Conference_Location :
Bosnia
Print_ISBN :
978-1-4244-4220-1
Electronic_ISBN :
978-1-4244-4221-8
DOI :
10.1109/ICAT.2009.5348415