Research Area:  Digital Forensics
Computer virtualization is not a new technology, it has become increasingly important because of the many advantages it offers to businesses and individuals to reduce costs, while introducing new challenges to the field of digital forensics. As virtualization continues to be adopted by more and more companies every year, malware and hacker attacks are going to have an increasing effect on virtualized systems. Therefore, the increasing growth of virtualization has created the need for a new generation of computer forensic tools and techniques to analyze these compromised systems. Because of the rapid growth of virtualization, new techniques to interact with virtual systems have been developed. Some of these techniques reduce the limitations of traditional forensics tools abilities to analyze the virtual system. Virtual Machine Introspection (VMI) is one of these techniques that have formed the basis for a number of novel approaches in the fields of cyber security and digital forensics. This paper explores how VMI improves traditional digital forensics to overcome its downfalls when used to investigate virtual machines, especially during a live analysis of the machine.
Keywords:  
Author(s) Name:  James Poore ,Juan Carlos Flores, Travis Atkison
Journal name:  
Conferrence name:  ACMSE -13: Proceedings of the 51st ACM Southeast Conference
Publisher name:  ACM
DOI:  10.1145/2498328.2500078
Volume Information:  
Paper Link:   https://dl.acm.org/doi/abs/10.1145/2498328.2500078