Crime scene is any given place where it committed a criminal offense, in which the investigation should be done to find the causes and mechanisms of occurrence and on these to be investigated, for tracking and apprehe...Crime scene is any given place where it committed a criminal offense, in which the investigation should be done to find the causes and mechanisms of occurrence and on these to be investigated, for tracking and apprehension of perpetrators. Preservation of the scene is a very important action regarding the investigation and prosecution of the event that has happened, where law enforcement agencies or units that conduct surveillance of the scene make it. To preserve a scene means: to preserve the land in that state who has left the presidency. Preservation of the scene of that condition that has left the perpetrator is of particular importance to the inspection teams for tracks and material evidence found there are untouched and proceeding or their expertise will help prosecute perpetrators respectively capture of that work. Tracks and material evidence found in the scene should be retained together with all the space where the event happened because a possible carelessness during the examination as well as during the process of storage and security will bring us to a situation in which we will have our doubts concerning the tracks and material evidence found in that place. Also, preservation of the crime scene needs to be done because of the all action who have to take the searching unit, they need to be sure and security from everything that comes from outside.展开更多
Recently,virtualization technologies have been widely used in industry.In order to monitor the security of target systems in virtualization environments,conventional methods usually put the security monitoring mechani...Recently,virtualization technologies have been widely used in industry.In order to monitor the security of target systems in virtualization environments,conventional methods usually put the security monitoring mechanism into the normal functionality of the target systems.However,these methods are either prone to be tempered by attackers or introduce considerable performance overhead for target systems.To address these problems,in this paper,we present a concurrent security monitoring method which decouples traditional serial mechanisms,including security event collector and analyzer,into two concurrent components.On one hand,we utilize the SIM framework to deploy the event collector into the target virtual machine.On the other hand,we combine the virtualization technology and multi-core technology to put the event analyzer into a trusted execution environment.To address the synchronization problem between these two concurrent components,we make use of Lamport's ring buffer algorithm.Based on the Xen hypervisor,we have implemented a prototype system named COMO.The experimental results show that COMO can monitor the security of the target virtual machine concurrently within a little performance overhead.展开更多
文摘Crime scene is any given place where it committed a criminal offense, in which the investigation should be done to find the causes and mechanisms of occurrence and on these to be investigated, for tracking and apprehension of perpetrators. Preservation of the scene is a very important action regarding the investigation and prosecution of the event that has happened, where law enforcement agencies or units that conduct surveillance of the scene make it. To preserve a scene means: to preserve the land in that state who has left the presidency. Preservation of the scene of that condition that has left the perpetrator is of particular importance to the inspection teams for tracks and material evidence found there are untouched and proceeding or their expertise will help prosecute perpetrators respectively capture of that work. Tracks and material evidence found in the scene should be retained together with all the space where the event happened because a possible carelessness during the examination as well as during the process of storage and security will bring us to a situation in which we will have our doubts concerning the tracks and material evidence found in that place. Also, preservation of the crime scene needs to be done because of the all action who have to take the searching unit, they need to be sure and security from everything that comes from outside.
基金supported in part by National Natural Science Foundation of China(NSFC)under Grant No.61100228 and 61202479the National High-tech R&D Program of China under Grant No.2012AA013101+1 种基金the Strategic Priority Research Program of the Chinese Academy of Sciences under Grant No.XDA06030601 and XDA06010701Open Found of Key Laboratory of IOT Application Technology of Universities in Yunnan Province Grant No.2015IOT03
文摘Recently,virtualization technologies have been widely used in industry.In order to monitor the security of target systems in virtualization environments,conventional methods usually put the security monitoring mechanism into the normal functionality of the target systems.However,these methods are either prone to be tempered by attackers or introduce considerable performance overhead for target systems.To address these problems,in this paper,we present a concurrent security monitoring method which decouples traditional serial mechanisms,including security event collector and analyzer,into two concurrent components.On one hand,we utilize the SIM framework to deploy the event collector into the target virtual machine.On the other hand,we combine the virtualization technology and multi-core technology to put the event analyzer into a trusted execution environment.To address the synchronization problem between these two concurrent components,we make use of Lamport's ring buffer algorithm.Based on the Xen hypervisor,we have implemented a prototype system named COMO.The experimental results show that COMO can monitor the security of the target virtual machine concurrently within a little performance overhead.