Live and Trustworthy Forensic Analysis of Commodity Production Systems

Martignoni, Lorenzo, Fattori, Aristide, Paleari, Roberto and Cavallaro, Lorenzo

(2010)

Martignoni, Lorenzo, Fattori, Aristide, Paleari, Roberto and Cavallaro, Lorenzo (2010) Live and Trustworthy Forensic Analysis of Commodity Production Systems
In: Recent Advances in Intrusion Detection: 13th International Symposium, RAID 2010, Ottawa, Ontario, Canada, September 15-17, 2010: Proceedings. Springer.

Our Full Text Deposits

Full text access: Open

Full text file - 701.46 KB

Links to Copies of this Item Held Elsewhere



Abstract

We present HyperSleuth, a framework that leverages the virtualization extensions provided by commodity hardware to securely perform live forensic analysis of potentially compromised production systems. HyperSleuth provides a trusted execution environment that guarantees four fundamental properties. First, an attacker controlling the system cannot interfere with the analysis and cannot tamper the results. Second, the framework can be installed as the system runs, without a reboot and without loosing any volatile data. Third, the analysis performed is completely transparent to the OS and to an attacker. Finally, the analysis can be periodically and safely interrupted to resume normal execution of the system. On top of HyperSleuth we implemented three forensic analysis applications: a lazy physical memory dumper, a lie detector, and a system call tracer. The experimental evaluation we conducted demonstrated that even time consuming analysis, such as the dump of the content of the physical memory, can be securely performed without interrupting the services oered by the system.

Information about this Version

This is a Approved version
This version's date is: 15/9/2010
This item is not peer reviewed

Link to this Version

https://repository.royalholloway.ac.uk/items/5540a938-9dd6-f739-8272-4be107949058/13/

Item TypeBook Item
TitleLive and Trustworthy Forensic Analysis of Commodity Production Systems
AuthorsMartignoni, Lorenzo
Fattori, Aristide
Paleari, Roberto
Cavallaro, Lorenzo
Departments

Identifiers

doihttp://dx.doi.org/10.1007/978-3-642-15512-3_16

Deposited by Research Information System (atira) on 18-Nov-2014 in Royal Holloway Research Online.Last modified on 18-Nov-2014


Details