Hardware based snapshot/rollback

Discussion in 'backup, imaging & disk mgmt' started by erikloman, May 8, 2010.

Thread Status:
Not open for further replies.
  1. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,032
    Location:
    Hengelo, The Netherlands
    For the purpose of malware analysis I am looking for hardware based snapshot/rollback solution.

    Basically what needs to be done is all sector WRITE actions are diverted to a secondary disk (preferably RAM disk) and of course the changed sectors are to be read from that secondary disk. Upon reboot you can simply wipe the secondary disk, basically reverting to the initial unchanged state.

    Or another solution would be is to record which sectors have been overwritten and these are to be restored on reset/reboot (no need to restore every sector, just the ones that have been altered).

    I don't want to rely on software solutions as most are not resilient against latest MBR rootkit infections. Also virtual environments are undesirable as some malware won't run in virtual environments.

    Does any one know of a hardware based snapshot/rollback product that performs a function similar to what I have described above?
     
  2. erikloman

    erikloman Developer

    Joined:
    Jun 4, 2009
    Posts:
    3,032
    Location:
    Hengelo, The Netherlands
  3. MrBrian

    MrBrian Registered Member

    Joined:
    Feb 24, 2008
    Posts:
    6,032
    Location:
    USA
    Last edited: May 8, 2010
  4. MrBrian

    MrBrian Registered Member

    Joined:
    Feb 24, 2008
    Posts:
    6,032
    Location:
    USA
  5. dlimanov

    dlimanov Registered Member

    Joined:
    Jun 10, 2009
    Posts:
    204
Loading...
Thread Status:
Not open for further replies.