Cloud Memory Forensics via Virtual Image Generation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current memory forensics methods involve manual processes that can overwrite evidence in volatile memory, compromising forensic integrity and requiring changes to the target machine, making it difficult to create accurate memory profiles without altering the system's state.
Innovation Solution
A system and method for creating a memory map of a target machine by extracting operating system and kernel details, generating a memory image, and creating a memory map that includes a list of applications running at a specific time, allowing for analysis without modifying the target machine, using a cloud-based system with modules for OS extraction, kernel identification, memory image creation, and map analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual memory profile generation is performed by connecting to the target machine and running profile generation tools, then the memory profile can be created, but evidence in volatile memory may be overwritten and forensic integrity is compromised
Solution Approach 1:
The patent creates a virtual copy (virtual machine) of the target machine's memory state instead of directly accessing the physical memory. This virtual memory image can be analyzed without affecting the original volatile memory, thus preserving forensic integrity while still enabling accurate memory profiling through the virtualized environment
Solution Approach 2:
The patent introduces a virtualization layer as an intermediary between the analyst and the target machine's memory. The virtual machine acts as a mediator that replicates the memory state, allowing profile generation tools to run on the virtual copy without directly impacting the original memory evidence
2Ease of operation
If manual processes are used to create memory profiles, then analysis can be performed, but the target machine's state is altered and evidence may be lost
Solution Approach 1:
The system creates a virtual copy of the target machine's memory state in a virtualized environment. This copy can be freely analyzed, manipulated, and examined without risking loss of the original volatile memory evidence, thus enabling easy operation while preventing information loss
Solution Approach 2:
The patent performs preliminary action by creating a virtual memory image before any analysis takes place. This pre-created copy serves as a safe working replica that can undergo extensive analysis without affecting the original evidence, allowing thorough examination while preserving the source material
3Manufacturing precision
If profile generation tools are run on the target machine, then memory mapping is achieved, but the manual process is time-consuming and may overwrite critical data
Solution Approach 1:
By working with a virtual copy of the memory rather than the original, the system enables parallel processing and multiple analysis attempts without time constraints that would otherwise exist from the need to preserve original evidence. This virtual environment allows faster, more flexible profile generation while maintaining accuracy
Solution Approach 2:
The patent replaces the manual mechanical process of connecting to and analyzing the live target machine with an automated virtualized system. The virtual machine environment allows for automated profile generation tools to run without human intervention, reducing both time and the risk of manual errors that could overwrite data
Data Source
AI summary
A method for creating a memory map of a memory present in a target machine is disclosed for electronically protecting computer systems. In one step, extracting operating system details and kernel details from the target machine. A memory image is generated from the operating system and the kernel details extracted from the target machine. The memory image comprises similar configuration as that of the target machine. A memory map is created from the memory image. The memory map includes a list of applications running in the memory of the target machine at a particular instance of time. The memory map is analyzed for security issues to identify the applications running at the particular instance of time.


