Options
Virtual Machine Forensics by means of Introspection and Kernel Code Injection
Author(s)
Date Issued
2014-03-24
Date Available
2015-04-14T09:50:21Z
Abstract
Virtual Machine Introspection offers the ability to access a virtual machine remotely and extract informationfrom it. Virtual machine introspection allows all processes, local data, and network traffic to be tracked andmade available to the investigation process. These properties offer the possibility to monitor a suspect virtualmachine (VM). Moreover, the access to a VM data is far from being trivial; there are various complex tasks tobe dealt with. For instance the returned data is in a raw format, and it is necessary to remap into a userfriendly representation (canonical representation). In this paper we propose a method of bridging thissemantic gap, and provide a graphical reconstruction of events. This proposal is essentially, the recreation ofa virtual machine at a remote location and the subsequent recreation of all processes, data, network traffic ina virtual machine as they occur in the original. This should be achieved in real-time, which will give anopportunity to quickly make decisions based on the evidence as we collect them in real-time. Our approachinvolves recreating a virtual machine and injecting into it all code and data within the original virtual machine,presenting an identical copy for examination. The approach proposed also has another advantage byallowing all data to be saved for further analysis and verification.
Sponsorship
Science Foundation Ireland
Type of Material
Conference Publication
Copyright (Published Version)
2014 the Author
Language
English
Status of Item
Peer reviewed
Conference Details
9th International Conference on Cyber Warfare and Security, Purdue University, West Lafayette, Indiana, United States, 24-25 March 2014
This item is made available under a Creative Commons License
File(s)
Owning collection
Views
1497
Acquisition Date
Apr 17, 2024
Apr 17, 2024
Downloads
550
Last Month
3
3
Acquisition Date
Apr 17, 2024
Apr 17, 2024