A lightweight software write-blocker for virtual machine forensics | IEEE Conference Publication | IEEE Xplore

A lightweight software write-blocker for virtual machine forensics


Abstract:

The integrity of any original evidence is fundamental to a forensic examination. Preserving the integrity of digital evidence is vitally important as changing just one bi...Show More

Abstract:

The integrity of any original evidence is fundamental to a forensic examination. Preserving the integrity of digital evidence is vitally important as changing just one bit among perhaps gigabits of data, will irrevocably alter that data and cast doubt on any evidence extracted. In traditional digital forensics write-blockers are used to preserve the integrity of that evidence and prevent changes from occurring, but virtual machine forensics presents more difficult challenges to address. Access to the digital storage device will probably not be possible, typically the only accessible storage will be a virtual hard disk drive. This will have the same integrity issues as those of a real device, but with the added complication that it is not possible to use a hardware write-blocker to prevent changes to those data. For this reason it is important to explore how to implement write-blocking mechanisms on a virtual device. In this paper we present an implementation of a software write-blocker and show how we can use it to be compliant with the 2nd ACPO principle on digital evidence.
Date of Conference: 24-26 August 2016
Date Added to IEEE Xplore: 09 February 2017
ISBN Information:
Conference Location: Dublin, Ireland

Contact IEEE to Subscribe

References

References is not available for this document.