Analisis Memory Forensics Windows Subsystem for Linux 2 (WSL2) Berbasis Hyper-V pada Windows 11 Berdasarkan Nist 800-86

Bagas Kurnadi,Fachrul Ali Nurfadillah,Muhammad Tegar Sabila
DOI: https://doi.org/10.54066/jpsi.v2i1.1594
2024-02-02
Abstract:In the context of the growing blend of Windows and Linux operating systems through Windows Subsystem for Linux (WSL), this study explores forensic memory analysis on Hyper-V-based Windows Subsystem for Linux 2 (WSL2) in a Windows 11 environment using the NIST SP 800-86 method. WSL2, as the latest development of WSL, provides new opportunities in security and digital forensics, but also raises challenges related to security incidents. The study builds on the findings of previous research, focusing on forensic memory applications that have never been applied to WSL2 in Windows 11 before. By choosing Ubuntu 20.04 as the object of research and implementing the NIST SP 800-86 standard. The experimental results were obtained in scenario 1 where without deleting WSL2 all experimental artifacts were obtained or it can be said that artifacts were found by 100%, while in scenario 2 by deleting WSL2 only 2 experimental artifacts were found or by 16.7%. This research aims to provide in-depth insights into forensic analysis on WSL2, provide practical guidance for digital forensics experts in addressing security challenges that continue to evolve as technology evolves, and complement our understanding of security incidents involving a mix of Windows and Linux operating systems in the WSL2 era.
What problem does this paper attempt to address?