Electronic crime investigations in a virtualised environment: a forensic process and prototype for evidence collection and analysis

1Citations
Citations of this article
36Readers
Mendeley users who have this article in their library.
Get full text

Abstract

The constant evolution of virtualisation technologies and the availability of anti-forensic techniques and tools complicate efforts by forensic investigators to investigate a crime or a cyber security incident. Forensic collection can be complicated and requires significant efforts to investigate incidents involving contemporary technologies (e.g. crime launched from a virtual machine and there had been attempts to erase evidence after the incident). This paper presents a forensic process to collect and analyse traces of a virtual machine and its corresponding manager, recorded across multiple sources including the file system, Windows registry, history, and log files from a forensic viewpoint. To demonstrate utility of the forensic mechanism, the Virtual Machine Forensic Artefact Collector (VMFAC) prototype is developed and presented in this paper.

Cite

CITATION STYLE

APA

Ahmad, I., Abbas, H., Raza, A., Choo, K. K. R., Sajid, A., Pasha, M., & Khan, F. A. (2018). Electronic crime investigations in a virtualised environment: a forensic process and prototype for evidence collection and analysis. Australian Journal of Forensic Sciences, 50(2), 183–208. https://doi.org/10.1080/00450618.2016.1229814

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free