摘要:In this paper we discuss the potential role of virtual environments in the analysis
phase of computer forensics investigations. General concepts of virtual
environments and software tools are presented and discussed. Further we identify
the limitations of virtual environments leading to the conclusion that this method can
not be considered to be a replacement for conventional techniques of computer
evidence collection and analysis. We propose a new approach where two
environments, conventional and virtual, are used independently. Further we
demonstrate that this approach can considerably shorten the time of the computer
forensics investigation analysis phase and it also allows for better utilisation of less
qualified personnel.