Show simple item record

dc.contributor.authorKiperberg, Michael
dc.contributor.authorLeon, Roee
dc.contributor.authorResh, Amit
dc.contributor.authorAlgawi, Asaf
dc.contributor.authorZaidenberg, Nezer
dc.contributor.editorMori, Paolo
dc.contributor.editorFurnell, Steven
dc.contributor.editorCamp, Olivier
dc.date.accessioned2019-07-25T05:09:06Z
dc.date.available2019-07-25T05:09:06Z
dc.date.issued2019
dc.identifier.citationKiperberg, M., Leon, R., Resh, A., Algawi, A., & Zaidenberg, N. (2019). Hypervisor-assisted Atomic Memory Acquisition in Modern Systems. In P. Mori, S. Furnell, & O. Camp (Eds.), <i>ICISSP 2019 : Proceedings of the 5th International Conference on Information Systems Security and Privacy, Volume 1</i> (pp. 155-162). SCITEPRESS Science And Technology Publications. <a href="https://doi.org/10.5220/0007566101550162" target="_blank">https://doi.org/10.5220/0007566101550162</a>
dc.identifier.otherCONVID_30725172
dc.identifier.otherTUTKAID_81483
dc.identifier.urihttps://jyx.jyu.fi/handle/123456789/65108
dc.description.abstractReliable memory acquisition is essential to forensic analysis of a cyber-crime. Various methods of memory acquisition have been proposed, ranging from tools based on a dedicated hardware to software only solutions. Recently, a hypervisor-based method for memory acquisition was proposed (Qi et al., 2017; Martignoni et al., 2010). This method obtains a reliable (atomic) memory image of a running system. The method achieves this by making all memory pages non-writable until they are copied to the memory image, thus preventing uncontrolled modification of these pages. Unfortunately, the proposed method has two deficiencies: (1) the method does not support multiprocessing and (2) the method does not support modern operating systems featuring address space layout randomization (ASLR). We describe a hypervisor-based memory acquisition method that solves the two aforementioned deficiencies. We analyze the memory usage and performance of the proposed method.fi
dc.format.extent738
dc.format.mimetypeapplication/pdf
dc.language.isoeng
dc.publisherSCITEPRESS Science And Technology Publications
dc.relation.ispartofICISSP 2019 : Proceedings of the 5th International Conference on Information Systems Security and Privacy, Volume 1
dc.rightsIn Copyright
dc.subject.otherlive forensics
dc.subject.othermemory forensics
dc.subject.othermemory acquisition
dc.subject.othervirtualization
dc.subject.otherreliability
dc.subject.otheratomicity
dc.subject.otherintegrity of a memory snapshot
dc.subject.otherforensic soundness
dc.titleHypervisor-assisted Atomic Memory Acquisition in Modern Systems
dc.typeconferenceObject
dc.identifier.urnURN:NBN:fi:jyu-201907243671
dc.contributor.laitosInformaatioteknologian tiedekuntafi
dc.contributor.laitosFaculty of Information Technologyen
dc.contributor.oppiaineTietotekniikkafi
dc.contributor.oppiaineMathematical Information Technologyen
dc.type.urihttp://purl.org/eprint/type/ConferencePaper
dc.date.updated2019-07-24T12:15:08Z
dc.relation.isbn978-989-758-359-9
dc.type.coarhttp://purl.org/coar/resource_type/c_5794
dc.description.reviewstatuspeerReviewed
dc.format.pagerange155-162
dc.type.versionacceptedVersion
dc.rights.copyright© 5th International Conference on Information Systems Security and Privacy by SCITEPRESS
dc.rights.accesslevelopenAccessfi
dc.relation.conferenceInternational Conference on Information Systems Security and Privacy
dc.subject.ysotietoturva
dc.subject.ysomuistit (tietotekniikka)
dc.subject.ysovirtualisointi
dc.format.contentfulltext
jyx.subject.urihttp://www.yso.fi/onto/yso/p5479
jyx.subject.urihttp://www.yso.fi/onto/yso/p12658
jyx.subject.urihttp://www.yso.fi/onto/yso/p22009
dc.rights.urlhttp://rightsstatements.org/page/InC/1.0/?language=en
dc.relation.doi10.5220/0007566101550162
dc.type.okmA4


Files in this item

Thumbnail

This item appears in the following Collection(s)

Show simple item record

In Copyright
Except where otherwise noted, this item's license is described as In Copyright