Abstract
Cyber forensics use memory acquisition in advanced forensics and malware analysis. We propose a hypervisor based memory acquisition tool. Our implementation extends the volatility memory forensics framework by reducing the processor's consumption, solves the in-coherency problem in the memory snapshots and mitigates the pressure of the acquisition on the network and the disk. We provide benchmarks and evaluation.
Original language | English |
---|---|
Article number | 301106 |
Journal | Forensic Science International: Digital Investigation |
Volume | 37 |
DOIs | |
State | Published - Jun 2021 |
Externally published | Yes |
Keywords
- ARM
- Hypervisor
- Linux
- Real time
- Virtualization