Abstract
Cyber forensics use memory acquisition in advanced forensics and malware analysis. We propose a hypervisor based memory acquisition tool. Our implementation extends the volatility memory forensics framework by reducing the processor's consumption, solves the in-coherency problem in the memory snapshots and mitigates the pressure of the acquisition on the network and the disk. We provide benchmarks and evaluation.
| Original language | English |
|---|---|
| Article number | 301106 |
| Journal | Forensic Science International: Digital Investigation |
| Volume | 37 |
| DOIs | |
| State | Published - Jun 2021 |
| Externally published | Yes |
Keywords
- ARM
- Hypervisor
- Linux
- Real time
- Virtualization
All Science Journal Classification (ASJC) codes
- Computer Science Applications
- Information Systems
- Pathology and Forensic Medicine
- Law
- Medical Laboratory Technology