Tobin, Patrick, Le-Khac, Nhien-An and Kechadi, Tahar (2017) Forensic Analysis of Virtual Hard Drives. Journal of Digital Forensics, Security and Law, 12 (10). pp. 47-58. doi:10.15394/jdfsl.2017.1438
|
Text (Final published version)
10472 Tobin, P. (2017) Forensic-Analysis-of-Virtual-Hard-Drives.pdf - Published Version Available under License Creative Commons Attribution Non-commercial 4.0. Download (146kB) | Preview |
Abstract
The issue of the volatility of virtual machines is perhaps the most pressing concern in any digital investigation. Current digital forensics tools do not fully address the complexities of data recovery that are posed by virtual hard drives. It is necessary, for this reason, to explore ways to capture evidence other than those using current digital forensic methods. This should be done in the most efficient and secure manner, as quickly, and in a non-intrusive way as can be achieved. All data in a virtual machine is disposed of when that virtual machine is destroyed, it may not therefore be possible to extract and preserve evidence such as incriminating images prior to destruction. Recovering that evidence, or finding some way of associating that evidence with the virtual machine before its destruction, is therefore crucial. In this paper, we present a method of extracting evidence from a virtual hard disk drive in a quick, secure and verifiable manner, with a minimum impact on the drive thus preserving its integrity for further analysis.
Item Type: | Article |
---|---|
Article Type: | Article |
Uncontrolled Keywords: | Virtual machine; Digital forensics; Virtual machine forensics; Virtual hard drive |
Subjects: | Q Science > QA Mathematics > QA75 Electronic computers. Computer science Q Science > QA Mathematics > QA76 Computer software |
Divisions: | Schools and Research Institutes > School of Business, Computing and Social Sciences |
Research Priority Areas: | Applied Business & Technology |
Depositing User: | Kate Greenaway |
Date Deposited: | 17 Dec 2021 13:31 |
Last Modified: | 31 Aug 2023 08:01 |
URI: | https://eprints.glos.ac.uk/id/eprint/10472 |
University Staff: Request a correction | Repository Editors: Update this record