Skip to main content
Top

WaybackVisor: Hypervisor-Based Scalable Live Forensic Architecture for Timeline Analysis

  • 2017
  • OriginalPaper
  • Chapter
Published in:

Activate our intelligent search to find suitable subject content or patents.

search-config
loading …

Abstract

Current forensic investigations have to process a large amount of collected data in a limited time. Moreover, we need to ensure collected data are not compromised before seizing suspects’ computers. For protecting evidences on important computers, this paper proposes a lightweight hypervisor that supports proactive collection and preservation of I/O logs. The proposed WaybackVisor automatically transfers all I/O logs of ATA drives to a Hadoop cluster. Our experiment showed the prototype implementation of WaybackVisor achieves write throughput of 79.7 MB/s. This paper also demonstrates timeline analysis functions for the I/O logs on the Hadoop cluster. Finally, we compared the proposed WaybackVisor with similar lightweight hypervisors that support live forensics.

Not a customer yet? Then find out more about our access models now:

Individual Access

Start your personal individual access now. Get instant access to more than 164,000 books and 540 journals – including PDF downloads and new releases.

Starting from 54,00 € per month!    

Get access

Access for Businesses

Utilise Springer Professional in your company and provide your employees with sound specialist knowledge. Request information about corporate access now.

Find out how Springer Professional can uplift your work!

Contact us now
Title
WaybackVisor: Hypervisor-Based Scalable Live Forensic Architecture for Timeline Analysis
Authors
Manabu Hirano
Takuma Tsuzuki
Seishiro Ikeda
Naoga Taka
Kenji Fujiwara
Ryotaro Kobayashi
Copyright Year
2017
DOI
https://doi.org/10.1007/978-3-319-72395-2_21
This content is only visible if you are logged in and have the appropriate permissions.

Premium Partner

    Image Credits
    Neuer Inhalt/© ITandMEDIA, Nagarro GmbH/© Nagarro GmbH, AvePoint Deutschland GmbH/© AvePoint Deutschland GmbH, AFB Gemeinnützige GmbH/© AFB Gemeinnützige GmbH, USU GmbH/© USU GmbH, Ferrari electronic AG/© Ferrari electronic AG