Virtual Machine Memory Forensics Method for XenServer Platform
Shuhui Zhang, Lianhai Wang, Lijuan Xu, Shujiang Xu, Xiaohui Han, Shumian Yang · 2019
Memory forensics technology is valuable for not only analyzing malicious code and system vulnerability but also generating evidence used in court. Hereby, this technology has been extensively used in many fields. However, few research is carried out on Virtual machine (VM) for the XenServer platform. In this paper, we focus on an effective VM memory analysis framework for the XenServer platform using a virtual machine. By employing a hardware-based method on the host machine, its entire physical memory can be achieved and saved as an image file. This method of acquisition has no influence on the VMs and ensures the integrity of evidence. Through deep analysis of memory content, VMs running inside the host machine can be detected and their high-level semantic information can be also extracted. Hereby, using our solution, the comprehensive status information of target VMs can be automatically reconstructed without any prior knowledge. Experiments indicate that our method can handle the host machine and VMs of the mainstream operating system (OS) versions and is reliably resistant to attacks.