Virtual machines: the ultimate tool for computer forensics

Subscribers:
344,000
Published on ● Video Link: https://www.youtube.com/watch?v=e6ps55VIP_k



Duration: 1:01:39
530 views
2


The field of computer forensics seeks to help investigators reconstruct what happened during a computer intrusion. Did an attacker break in, and if so, how? What havoc did the attacker wreak after breaking in? Tools that help investigators answer these types of questions are still quite primitive and are often hindered by incomplete or incorrect information. Virtual machines can enable more-powerful forensic analysis through techniques such as replaying a computer's instruction stream and introspecting on the state of a virtual machine. This talk describes how to provide and use virtual machine replay and introspection to enable arbitrary forensic analysis, enable reverse debugging of intrusions and bugs, and detect intrusions in the past and present through vulnerability-specific predicates.




Other Videos By Microsoft Research


2016-09-05Social Mobile Applications, Location, Privacy and the Capital of Nevada [1/16]
2016-09-05Search Engines Considered Harmful: In Search of an Unbiased Web Ranking
2016-09-05Science Friction: Where the Known Meets the Unknown
2016-09-05Concave utility functions on finite sets
2016-09-05Exploring Mars by 4-Wheel Drive
2016-09-05Computing with Selfish Agents [1/2]
2016-09-05Opportunities and Challenges in End-to-End Verification of Software Systems
2016-09-05Tools and Techniques for Prototyping Future Interactions [1/2]
2016-09-05Mathematical Sketching: A New Approach for Creating and Exploring Dynamic Illustrations
2016-09-05A learning-based approach to summarization
2016-09-05Virtual machines: the ultimate tool for computer forensics
2016-09-05Headwinds and Tailwinds:  Where is the U.S. economy going?
2016-09-05Paradigms of Worm Defense & Thoughts from an Ivory Tower
2016-09-05Machine Learning Methods for Discovery of Regulatory Elements in Bacteria
2016-09-05Eyes on Multimodal Interaction
2016-09-05From Promoter to Expression ΓÇô A Probabilistic Framework for Inferring Regulatory Mechanisms
2016-09-05Automated Reconstruction of 3D City Models from Laser Scans and Camera Images
2016-09-05Bergman complexes, Coxeter arrangements, and graph associahedra
2016-09-05Biomal Human Emotion Recognition and Peer Steaming Projects at  Ryerson Multimedia Research Lab
2016-09-05Interfaces for Staying in the Flow         [1/3]
2016-09-05Place Lab: Device Positioning Using Radio Beacons in the Wild



Tags:
microsoft research