Repository logo
  • Log In
    New user? Click here to register.Have you forgotten your password?
University College Dublin
    Colleges & Schools
    Statistics
    All of DSpace
  • Log In
    New user? Click here to register.Have you forgotten your password?
  1. Home
  2. Institutes and Centres
  3. Insight Centre for Data Analytics
  4. Insight Research Collection
  5. Forensic Analysis of Virtual Hard Drives
 
  • Details
Options

Forensic Analysis of Virtual Hard Drives

Author(s)
Tobin, Patrick  
Le-Khac, Nhien-An  
Kechadi, Tahar  
Uri
http://hdl.handle.net/10197/9653
Date Issued
2017-03-31
Date Available
2019-03-22T08:57:32Z
Abstract
The issue of the volatility of virtual machines is perhaps the most pressing concern in any digital investigation involving a virtual machine. Current digital forensics tools do not fully address the complexities of data recovery that are posed by virtual hard drives. It is necessary, for this reason, to explore ways to capture evidence, other than those using current digital forensic methods. Data recovery should be done in the most efficient and secure manner, as quickly, and in an as non-intrusive way as can be achieved. All data in a virtual machine is disposed of when that virtual machine is destroyed, it may not therefore be possible to extract and preserve evidence such as incriminating images prior to destruction. Recovering that evidence, or finding some way of associating that evidence with the virtual machine before destruction of that virtual machine, is therefore crucial.In this paper we present a method for extracting evidence from a virtual hard disk drive in a quick, secure and verifiable manner, with a minimum impact on the drive thus preserving its integrity for further analysis.
Sponsorship
Science Foundation Ireland
Type of Material
Journal Article
Publisher
The Association of Digital Forensics, Security and Law
Journal
Journal of Digital Forensics, Security and Law
Volume
12
Issue
1
Start Page
46
End Page
58
Subjects

Virtual machine

Digital forensics

Virtual machine foren...

Data recovery

Preserving evidence

Vitual hard drive

DOI
10.15394/jdfsl.2017.1438
Web versions
https://commons.erau.edu/jdfsl/vol12/iss1/10
Language
English
Status of Item
Peer reviewed
This item is made available under a Creative Commons License
https://creativecommons.org/licenses/by-nc-nd/3.0/ie/
File(s)
No Thumbnail Available
Name

insight_publication.pdf

Size

119.6 KB

Format

Adobe PDF

Checksum (MD5)

e794fad87107d704ed2af714fadc91c3

Owning collection
Insight Research Collection

Item descriptive metadata is released under a CC-0 (public domain) license: https://creativecommons.org/public-domain/cc0/.
All other content is subject to copyright.

Built with DSpace-CRIS software - Extension maintained and optimized by 4Science

  • Cookie settings
  • Privacy policy
  • End User Agreement