DocumentCode :
2607252
Title :
Combining static and live digital forensic analysis in virtual environment
Author :
Mrdovic, Sasa ; Huseinovic, Alvin ; Zajko, Ernedin
Author_Institution :
Fac. of Electr. Eng., Univ. of Sarajevo Sarajevo, Sarajevo, Bosnia-Herzegovina
fYear :
2009
fDate :
29-31 Oct. 2009
Firstpage :
1
Lastpage :
6
Abstract :
Traditional digital forensics is performed through static analysis of data preserved on permanent storage media. Not all data needed to understand the state of examined system exists in nonvolatile memory. Live analysis uses running system to obtain volatile data for deeper understanding of events going on. Sampling running system might irreversibly change its state making collected evidence invalid. This paper proposes combination of static and live analysis. Virtualization is used to bring static data to life. Volatile memory dump is used to enable offline analysis of live data. Using data from memory dump, virtual machine created from static data can be adjusted to provide better picture of the live system at the time when the dump was made. Investigator can have interactive session with virtual machine without violating evidence integrity. Tests with sample system confirm viability of proposed approach.
Keywords :
data analysis; interactive systems; program diagnostics; security of data; virtual machines; interactive session; live data offline analysis; live digital forensic analysis; permanent storage media; sampling running system; static analysis; virtual environment; virtual machine; volatile memory dump; Authentication; Digital forensics; Information security; Performance analysis; Privacy; Product codes; Radio frequency; Radiofrequency identification; Scalability; Virtual environment; forensics; hard disk image; hibernation; virtual machine; volatile memory dump;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Information, Communication and Automation Technologies, 2009. ICAT 2009. XXII International Symposium on
Conference_Location :
Bosnia
Print_ISBN :
978-1-4244-4220-1
Electronic_ISBN :
978-1-4244-4221-8
Type :
conf
DOI :
10.1109/ICAT.2009.5348415
Filename :
5348415
Link To Document :
بازگشت