Automatic Forensic Imaging of a Virtual USB Device with Emulated User Interaction

M. Alji, Khalid Chougdali
{"title":"Automatic Forensic Imaging of a Virtual USB Device with Emulated User Interaction","authors":"M. Alji, Khalid Chougdali","doi":"10.1109/ISDFS55398.2022.9800838","DOIUrl":null,"url":null,"abstract":"The bird’s-eye view of the digital forensic process is the acquisition and preservation of the evidence, the analysis of the acquired data, and the presentation of the findings. Forensic practitioners need a hands-on approach to investigate with high-quality standards. Among the ways to produce labs and demonstrations, there is forensic imaging of USB devices where the forensic expert has planted, for instance, suspicious files. Such a process is time-consuming. We intend to programmatically write a scenario of user actions rather than manually perform them. It would be much easier if we get rid of the USB device and use a virtual USB-like disk image file. The current study describes how we have automatically generated user digital artifacts on a USB-like disk image file. A host OS script would control a pre-configured VM and a guest agent. That agent would take care of the emulation of a user’s scenario.","PeriodicalId":114335,"journal":{"name":"2022 10th International Symposium on Digital Forensics and Security (ISDFS)","volume":"46 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-06-06","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2022 10th International Symposium on Digital Forensics and Security (ISDFS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ISDFS55398.2022.9800838","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

The bird’s-eye view of the digital forensic process is the acquisition and preservation of the evidence, the analysis of the acquired data, and the presentation of the findings. Forensic practitioners need a hands-on approach to investigate with high-quality standards. Among the ways to produce labs and demonstrations, there is forensic imaging of USB devices where the forensic expert has planted, for instance, suspicious files. Such a process is time-consuming. We intend to programmatically write a scenario of user actions rather than manually perform them. It would be much easier if we get rid of the USB device and use a virtual USB-like disk image file. The current study describes how we have automatically generated user digital artifacts on a USB-like disk image file. A host OS script would control a pre-configured VM and a guest agent. That agent would take care of the emulation of a user’s scenario.
具有模拟用户交互的虚拟USB设备的自动取证成像
数字取证过程的鸟瞰图是证据的获取和保存、获取数据的分析以及结果的呈现。法医从业者需要亲自动手,以高质量的标准进行调查。在制造实验室和演示的方法中,有对USB设备进行法医成像的方法,比如法医专家在其中植入了可疑文件。这个过程很耗时。我们打算以编程方式编写用户操作的场景,而不是手动执行它们。如果我们去掉USB设备,使用一个类似USB的虚拟磁盘映像文件,那就容易多了。当前的研究描述了我们如何在类似usb的磁盘映像文件上自动生成用户数字工件。主机操作系统脚本将控制预配置的VM和客户机代理。该代理将负责用户场景的模拟。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信