Hypervisor Event Logs as a Source of Consistent Virtual Machine Evidence for Forensic Cloud Investigations.
Sean S. E. ThorpeIndrajit RayTyrone GrandisonAbbie BarbirRobert B. FrancePublished in: DBSec (2013)
Keyphrases
- virtual machine
- event logs
- process mining
- digital forensics
- operating system
- data center
- process model
- crime investigation
- cloud computing environment
- computing resources
- business process
- virtual memory
- cloud computing
- log files
- multi tasking
- law enforcement
- business processes
- formal concept analysis
- control flow
- computer systems
- web search
- database systems
- information systems
- databases
- database