2010
DOI: 10.1007/978-3-642-15506-2_13
|View full text |Cite
|
Sign up to set email alerts
|

Identifying Volatile Data from Multiple Memory Dumps in Live Forensics

Abstract: International audienceOne of the core components of live forensics is to collect and analyze volatile memory data. Since the dynamic analysis of memory is not possible, most live forensic approaches focus on analyzing a single snapshot of a memory dump. Analyzing a single memory dump raises questions about evidence reliability; consequently, a natural extension is to study data from multiple memory dumps. Also important is the need to differentiate static data from dynamic data in the memory dumps; this enable… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1

Citation Types

0
1
0

Year Published

2011
2011
2023
2023

Publication Types

Select...
2
1
1

Relationship

0
4

Authors

Journals

citations
Cited by 4 publications
(1 citation statement)
references
References 9 publications
0
1
0
Order By: Relevance
“…Recent work attempts to leverage multiple memory dumps using a tool called "CMAT". CMAT parses a memory dump to find active, inactive and hidden processes as well as system registry information [20] Complementing the existing semantic approaches, our work focuses on the process of acquiring the system state and thus, it is an enabling technology that enhances the value of existing memory analysis mechanisms.…”
Section: Related Workmentioning
confidence: 99%
“…Recent work attempts to leverage multiple memory dumps using a tool called "CMAT". CMAT parses a memory dump to find active, inactive and hidden processes as well as system registry information [20] Complementing the existing semantic approaches, our work focuses on the process of acquiring the system state and thus, it is an enabling technology that enhances the value of existing memory analysis mechanisms.…”
Section: Related Workmentioning
confidence: 99%