{"title":"Forensic acquisition and analysis of VMware virtual machine artifacts","authors":"V. Meera, M. Isaac, C. Balan","doi":"10.1109/IMAC4S.2013.6526418","DOIUrl":null,"url":null,"abstract":"Virtual Forensics is a new trend in the area of computer forensics. Virtualization technology paved the way for the growth of virtual forensics. VMware virtual environment provides a completely virtualized set of hardware to the guest operating system. The features of Virtual Machine make it an interesting platform to commit cyber crimes. The combination of innovative criminal techniques and advanced technologies makes the traditional techniques out-dated for detecting such crimes. This paper discusses how live acquisition can be performed to acquire virtual machine related files from the host operating system. The paper also describes how to analyze these acquired files to obtain raw data stored in various grains. The study is supported by methods that assist forensic examiners by providing valuable information from the raw data which is retrieved from various grains pointed by grain table entries.","PeriodicalId":403064,"journal":{"name":"2013 International Mutli-Conference on Automation, Computing, Communication, Control and Compressed Sensing (iMac4s)","volume":"111 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2013-03-22","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"11","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2013 International Mutli-Conference on Automation, Computing, Communication, Control and Compressed Sensing (iMac4s)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/IMAC4S.2013.6526418","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 11
Abstract
Virtual Forensics is a new trend in the area of computer forensics. Virtualization technology paved the way for the growth of virtual forensics. VMware virtual environment provides a completely virtualized set of hardware to the guest operating system. The features of Virtual Machine make it an interesting platform to commit cyber crimes. The combination of innovative criminal techniques and advanced technologies makes the traditional techniques out-dated for detecting such crimes. This paper discusses how live acquisition can be performed to acquire virtual machine related files from the host operating system. The paper also describes how to analyze these acquired files to obtain raw data stored in various grains. The study is supported by methods that assist forensic examiners by providing valuable information from the raw data which is retrieved from various grains pointed by grain table entries.