메뉴 건너뛰기




Volumn 42, Issue 3, 2008, Pages 74-82

Forensics examination of volatile system data using virtual introspection

Author keywords

Digital forensics; Virtual introspection; Virtual machine monitor; VIX

Indexed keywords

ALTERNATIVE APPROACH; DIGITAL FORENSIC; HARD DISKS; OBSERVATION TECHNIQUES; OFFLINE; RESEARCH AGENDA; RESEARCH AREAS; SYSTEM PROPERTY; TARGET SYSTEMS; VIRTUAL MACHINE MONITORS; VIRTUAL MACHINES; VIRTUALIZATIONS; VOLATILE DATA; VOLATILE MEMORY;

EID: 54049127315     PISSN: 01635980     EISSN: None     Source Type: Conference Proceeding    
DOI: 10.1145/1368506.1368517     Document Type: Conference Paper
Times cited : (104)

References (35)
  • 1
    • 77952283995 scopus 로고    scopus 로고
    • Retrieved August 10, 2007 from
    • Access Data. Retrieved August 10, 2007 from http://www.accessdata.com
  • 6
    • 77952263951 scopus 로고    scopus 로고
    • Retrieved November 15, 2007 from
    • Data Center Management Research Report September 2007. Retrieved November 15, 2007 from http://www.novell.com/products/zenworks/orchestrator/data-center- research-report-sep2007.pdf
    • Data Center Management Research Report September 2007
  • 8
    • 77952270236 scopus 로고    scopus 로고
    • Retrieved November 15, 2007 from
    • Grand Ideas Studio: Tribble. Retrieved November 15, 2007 from http://www.grandideastudio.com/src/portfolio.php?cat=&prod=14
    • Grand Ideas Studio: Tribble
  • 9
    • 77952274396 scopus 로고    scopus 로고
    • Retrieved August 10, 2007 from
    • Guidance Software, Inc. EnCase. Retrieved August 10, 2007 from http://www.guidancesoftware.com/
    • EnCase
  • 11
    • 34547941727 scopus 로고    scopus 로고
    • Retrieved November 15, 2007 from
    • Introducing Blue Pill. Retrieved November 15, 2007 from http://theinvisiblethings.blogspot.com/2006/06/introducing-blue-pill.html
    • Introducing Blue Pill
  • 13
    • 77949635694 scopus 로고    scopus 로고
    • Retrieved November 18, 2007 from
    • Kernel based Virtual Machine. Retrieved November 18, 2007 from http://kvm.qumranet.com/kvmwiki.
    • Kernel Based Virtual Machine
  • 14
    • 32044466453 scopus 로고    scopus 로고
    • HyperSpector: Virtual distributed monitoring environments for secure intrusion detection
    • DOI 10.1145/1064979.1065006, Proceedings of the First ACM/USENIX International Conference on Virual Execution Environments, VEE 05
    • Kourai, K. and Chiba, S. 2005. HyperSpector: virtual distributed monitoring environments for secure intrusion detection. In Proceedings of the 1st ACM/USENIX international Conference on Virtual Execution Environments (Chicago, IL, USA, June 11 - 12, 2005). VEE '05. ACM, New York, NY, 197-207. DOI=http://doi.acm.org/10.1145/1064979.1065006 (Pubitemid 43195515)
    • (2005) Proceedings of the First ACM/USENIX International Conference on Virual Execution Environments, VEE 05 , pp. 197-207
    • Kourai, K.1    Chiba, S.2
  • 16
    • 77952256051 scopus 로고    scopus 로고
    • Retrieved July 15, 2007 from
    • Microsoft Virtual PC Server. Retrieved July 15, 2007 from http://www.microsoft.com/windows/products/wi
  • 17
    • 77952269387 scopus 로고    scopus 로고
    • Retrieved November 15, 2007 from
    • National Security Agency Central Security Service - Technology Profile Fact Sheet. Retrieved November 15, 2007 from http://www.nsa.gov/techtrans/ techt00011.cfm
  • 18
    • 77952261275 scopus 로고    scopus 로고
    • Retrieved July 25, 2007 from
    • Parallels. Retrieved July 25, 2007 from http://www.parallels.com/
  • 19
    • 77952278195 scopus 로고    scopus 로고
    • Retrieved November 15, 2007 from
    • ParavirtBenefits. Retrieved November 15, 2007 from http://virt. kernelnewbies.org/ParavirtBenefits
  • 20
    • 38349041413 scopus 로고    scopus 로고
    • A layered approach to simplified access control in virtualized systems
    • (Jul. 2007), DOI= http://doi.acm.org/10.1145/1278901.1278905
    • Payne, B. D., Sailer, R., Cáceres, R., Perez, R., and Lee, W. 2007. A layered approach to simplified access control in virtualized systems. SIGOPS Oper. Syst. Rev. 41, 4 (Jul. 2007), 12-19. DOI= http://doi.acm.org/10. 1145/1278901.1278905
    • (2007) SIGOPS Oper. Syst. Rev. , vol.41 , Issue.4 , pp. 12-19
    • Payne, B.D.1    Sailer, R.2    Cáceres, R.3    Perez, R.4    Lee, W.5
  • 23
    • 77952273938 scopus 로고    scopus 로고
    • Retrieved on November 18, 2007 from
    • QEMU. Open Source Process Emulator. Retrieved on November 18, 2007 from http://fabrice.bellard.free.fr/qemu/.
    • Open Source Process Emulator
  • 24
    • 35248835511 scopus 로고    scopus 로고
    • Towards a tamper-resistant kernel rootkit detector
    • DOI 10.1145/1244002.1244070, Proceedings of the 2007 ACM Symposium on Applied Computing
    • Quynh, N. A. and Takefuji, Y. 2007. Towards a tamperresistant kernel rootkit detector. In Proceedings of the 2007 ACM Symposium on Applied Computing (Seoul, Korea, March 11 - 15, 2007). SAC '07. ACM, New York, NY, 276-283. DOI= http://doi.acm.org/10.1145/1244002.1244070 (Pubitemid 47568299)
    • (2007) Proceedings of the ACM Symposium on Applied Computing , pp. 276-283
    • Quynh, N.A.1    Takefuji, Y.2
  • 25
    • 77952271863 scopus 로고    scopus 로고
    • Retrieved November 15
    • Red Hat Enterprise Linux 5 - Virtualization. Retrieved November 15, 2007 from http://www.redhat.com/rhel/virtualization/
    • (2007)
  • 26
    • 85024276949 scopus 로고    scopus 로고
    • The Reincarnation of Virtual Machines
    • (Jul. 2004)
    • Rosenblum, M. 2004. The Reincarnation of Virtual Machines. Queue 2, 5 (Jul. 2004), 34-40.
    • (2004) Queue , vol.2 , Issue.5 , pp. 34-40
    • Rosenblum, M.1
  • 28
    • 77952253567 scopus 로고    scopus 로고
    • Retrieved November 15, 2007 from
    • SLES 10 - Novell Virtualization Technology. Retrieved November 15, 2007 from http://www.novell.com/documentation/vmserver/pdfdoc/virtualization-basic/ virtualization-basics.pdf
  • 29
    • 77952283097 scopus 로고    scopus 로고
    • Retrieved November 15, 2007 from
    • UNIX man pages: ps. Retrieved November 15, 2007 from http://unixhelp.ed. ac.uk/CGI/man-cgi?ps
  • 30
    • 77952267270 scopus 로고    scopus 로고
    • Retrieved November 18, 2007 from
    • VMware. Retrieved November 18, 2007 from http://www.vmware.com.
  • 31
    • 77952285366 scopus 로고    scopus 로고
    • Retrieved November 15, 2007 from
    • VMware White Paper: Understanding Full Virtualization, Paravirtualization, and Hardware Assist. Retrieved November 15, 2007 from http://www.vmware.com/files/pdf/VMware-paravirtualization.pdf
  • 32
    • 77952281492 scopus 로고    scopus 로고
    • Retrieved November 15, 2007 from
    • XenAccess Documentation. Retrieved November 15, 2007 from http://xenaccess.sourceforge.net/doc/index.html
  • 33
    • 77952259401 scopus 로고    scopus 로고
    • Retrieved July 27, 2007 from
    • Xensource. Retrieved July 27, 2007 from http://www.xensource.com/xen/xen/ nfamily/virtualpc/default.mspx
  • 34
    • 77952263742 scopus 로고    scopus 로고
    • Retrieved November 15, 2007 from
    • Xen: Mailing Lists. Retrieved November 15, 2007 from http://lists. xensource.com/


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.