Investigating the implications of virtual forensics
Harshit Sharma, Nitish Sabharwal · IEEE-International Conference On Advances In Engineering, Science And Management · 2012
Computer Forensic process consists of Preparation, Acquisition, Preservation, Examination and Analysis, and Reporting. With the booming of the virtualization technology and the popularity of virtual machines for end users to deal with daily works, the probability of using virtual machines for malicious purposes keeps increasing. In this paper we propose a methodology by using virtual forensics for malware analysis and network forensics. Traditional forensics is done by using physical data. When company has large storage data and virtual environment, it creates a problem for traditional forensic while acquiring data. This paper proposes challenges, tools to be used, forensic techniques to be used and how to acquire data from cloud.