Hypervisor event logs as a source of consistent virtual machine evidence for forensic cloud investigations

9Citations
Citations of this article
25Readers
Mendeley users who have this article in their library.

This article is free to access.

Abstract

Cloud Computing is an emerging model of computing where users can leverage the computing infrastructure as a service stack or commodity. The security and privacy concerns of this infrastructure arising from the large co-location of tenants are, however, significant and pose considerable challenges in its widespread deployment. The current work addresses one aspect of the security problem by facilitating forensic investigations to determine if these virtual tenant spaces were maliciously violated by other tenants. It presents the design, application and limitations of a software prototype called the Virtual Machine (VM) Log Auditor that helps in detecting inconsistencies within the activity timelines for a VM history. A discussion on modeling a consistent approach is also provided. © 2013 IFIP International Federation for Information Processing.

Cite

CITATION STYLE

APA

Thorpe, S., Ray, I., Grandison, T., Barbir, A., & France, R. (2013). Hypervisor event logs as a source of consistent virtual machine evidence for forensic cloud investigations. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 7964 LNCS, pp. 97–112). https://doi.org/10.1007/978-3-642-39256-6_7

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free