Näytä suppeat kuvailutiedot

dc.contributor.authorKiperberg, Michael
dc.contributor.authorLeon, Roee
dc.contributor.authorResh, Amit
dc.contributor.authorAlgawi, Asaf
dc.contributor.authorZaidenberg, Nezer
dc.contributor.editorMori, Paolo
dc.contributor.editorFurnell, Steven
dc.contributor.editorCamp, Olivier
dc.date.accessioned2019-07-25T05:09:06Z
dc.date.available2019-07-25T05:09:06Z
dc.date.issued2019
dc.identifier.citationKiperberg, M., Leon, R., Resh, A., Algawi, A., & Zaidenberg, N. (2019). Hypervisor-assisted Atomic Memory Acquisition in Modern Systems. In P. Mori, S. Furnell, & O. Camp (Eds.), <i>ICISSP 2019 : Proceedings of the 5th International Conference on Information Systems Security and Privacy, Volume 1</i> (pp. 155-162). SCITEPRESS Science And Technology Publications. <a href="https://doi.org/10.5220/0007566101550162" target="_blank">https://doi.org/10.5220/0007566101550162</a>
dc.identifier.otherCONVID_30725172
dc.identifier.urihttps://jyx.jyu.fi/handle/123456789/65108
dc.description.abstractReliable memory acquisition is essential to forensic analysis of a cyber-crime. Various methods of memory acquisition have been proposed, ranging from tools based on a dedicated hardware to software only solutions. Recently, a hypervisor-based method for memory acquisition was proposed (Qi et al., 2017; Martignoni et al., 2010). This method obtains a reliable (atomic) memory image of a running system. The method achieves this by making all memory pages non-writable until they are copied to the memory image, thus preventing uncontrolled modification of these pages. Unfortunately, the proposed method has two deficiencies: (1) the method does not support multiprocessing and (2) the method does not support modern operating systems featuring address space layout randomization (ASLR). We describe a hypervisor-based memory acquisition method that solves the two aforementioned deficiencies. We analyze the memory usage and performance of the proposed method.fi
dc.format.extent738
dc.format.mimetypeapplication/pdf
dc.language.isoeng
dc.publisherSCITEPRESS Science And Technology Publications
dc.relation.ispartofICISSP 2019 : Proceedings of the 5th International Conference on Information Systems Security and Privacy, Volume 1
dc.rightsIn Copyright
dc.subject.otherlive forensics
dc.subject.othermemory forensics
dc.subject.othermemory acquisition
dc.subject.othervirtualization
dc.subject.otherreliability
dc.subject.otheratomicity
dc.subject.otherintegrity of a memory snapshot
dc.subject.otherforensic soundness
dc.titleHypervisor-assisted Atomic Memory Acquisition in Modern Systems
dc.typeconference paper
dc.identifier.urnURN:NBN:fi:jyu-201907243671
dc.contributor.laitosInformaatioteknologian tiedekuntafi
dc.contributor.laitosFaculty of Information Technologyen
dc.contributor.oppiaineTietotekniikkafi
dc.contributor.oppiaineMathematical Information Technologyen
dc.type.urihttp://purl.org/eprint/type/ConferencePaper
dc.date.updated2019-07-24T12:15:08Z
dc.relation.isbn978-989-758-359-9
dc.type.coarhttp://purl.org/coar/resource_type/c_5794
dc.description.reviewstatuspeerReviewed
dc.format.pagerange155-162
dc.type.versionacceptedVersion
dc.rights.copyright© 5th International Conference on Information Systems Security and Privacy by SCITEPRESS
dc.rights.accesslevelopenAccessfi
dc.type.publicationconferenceObject
dc.relation.conferenceInternational Conference on Information Systems Security and Privacy
dc.subject.ysotietoturva
dc.subject.ysomuistit (tietotekniikka)
dc.subject.ysovirtualisointi
dc.format.contentfulltext
jyx.subject.urihttp://www.yso.fi/onto/yso/p5479
jyx.subject.urihttp://www.yso.fi/onto/yso/p12658
jyx.subject.urihttp://www.yso.fi/onto/yso/p22009
dc.rights.urlhttp://rightsstatements.org/page/InC/1.0/?language=en
dc.relation.doi10.5220/0007566101550162
dc.type.okmA4


Aineistoon kuuluvat tiedostot

Thumbnail

Aineisto kuuluu seuraaviin kokoelmiin

Näytä suppeat kuvailutiedot

In Copyright
Ellei muuten mainita, aineiston lisenssi on In Copyright