Article ID | Journal | Published Year | Pages | File Type |
---|---|---|---|---|
10342385 | Digital Investigation | 2014 | 10 Pages |
Abstract
To further access to these techniques for the investigator/researcher we have developed a new VMI monitoring language. This language is based on a review of the most commonly used VMI-techniques to date, and it enables the user to monitor the virtual machine's memory, events and data streams. A prototype implementation of our monitoring system was implemented in KVM, though implementation on any hypervisor that uses the common x86 virtualization hardware assistance support should be straightforward. Our prototype outperforms the proprietary VMWare VProbes in many cases, with a maximum performance loss of 18% for a realistic test case, which we consider acceptable. Our implementation is freely available under a liberal software distribution license.
Related Topics
Physical Sciences and Engineering
Computer Science
Computer Networks and Communications
Authors
Florian Westphal, Stefan Axelsson, Christian Neuhaus, Andreas Polze,