Hypervisor-Level Memory Dump Dataset for Cloud VM Attack Simulation using Libvirt
收藏资源简介:
This dataset contains raw memory dump images acquired at the hypervisor level from virtual machines deployed in a private cloud environment. Additionally it also has cloud telemetry data collected in the cloud orchestration. Which makes it unique dataset having correlation of the cloud telemetry and memory dumps acquired during attack and benign scenarios. The experiment scenarios used to generate the dataset simulated real-world cyber attacks on cloud-hosted virtual machines (VMs) , including attacker VM and victim VM interactions. Memory acquisition was performed using a hypervisor-agnostic approach via the libvirt API, ensuring minimal guest OS interference and preserving forensic soundness. The dataset includes analysis-ready raw memory dumps of both victim and attacker virtual machines, enabling reproducible research in cloud forensics, memory forensics, malware analysis, and incident response. These dumps are suitable for analysis using tools such as Volatility and similar memory forensics frameworks, and are intended to support research on evidence detection, attack reconstruction, and forensic triage in virtualized cloud environments.
本数据集包含从私有云环境中部署的虚拟机的hypervisor(虚拟机监控程序)层面获取的原始内存转储镜像。此外,本数据集还涵盖了在云编排(cloud orchestration)流程中收集的云遥测数据,这使得本数据集具备独特性,包含了攻击场景与良性场景下采集的云遥测数据与内存转储镜像之间的关联信息。 用于生成本数据集的实验场景模拟了针对云托管虚拟机(VMs)的真实网络攻击,包含攻击方虚拟机与受害方虚拟机的交互过程。内存采集采用了与hypervisor无关的方法,通过libvirt API完成,确保对guest OS(客户机操作系统)的干扰降至最低,同时保障了取证严谨性。 本数据集包含受害方与攻击方虚拟机的可直接用于分析的原始内存转储镜像,可支持云取证(cloud forensics)、内存取证(memory forensics)、恶意软件分析以及事件响应领域的可复现研究。 此类转储镜像适用于Volatility及同类内存取证框架等工具开展分析,旨在支持虚拟化云环境中证据检测、攻击重构以及取证分诊相关研究。



