2007
DOI: 10.1016/j.diin.2008.02.001
|View full text |Cite
|
Sign up to set email alerts
|

Persistent systems techniques in forensic acquisition of memory

Abstract: In this paper we discuss how operating system design and implementation influences the methodology for computer forensics investigations, with the focus on forensic acquisition of memory. In theory the operating system could support such investigations both in terms of tools for analysis of data and by making the system data readily accessible for analysis. Conventional operating systems such as Windows and UNIX derivatives offer some memory-related tools that are geared towards the analysis of system crashes,… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

0
13
0

Year Published

2008
2008
2023
2023

Publication Types

Select...
3
2
1

Relationship

0
6

Authors

Journals

citations
Cited by 13 publications
(13 citation statements)
references
References 12 publications
0
13
0
Order By: Relevance
“…Substantial research has focused on tools that can acquire memory images without altering memory content [7,10,11,15]. However, the dynamic nature of memory means that obtaining a complete and consistent perspective of memory is impossible without taking multiple memory snapshots.…”
Section: Related Workmentioning
confidence: 99%
“…Substantial research has focused on tools that can acquire memory images without altering memory content [7,10,11,15]. However, the dynamic nature of memory means that obtaining a complete and consistent perspective of memory is impossible without taking multiple memory snapshots.…”
Section: Related Workmentioning
confidence: 99%
“…Forensic processes on live and volatile sources of digital evidence, evidentiary disturbance caused by memory acquisition and live forensic analysis, and evidentiary integrity processes and standards (see, e.g., [23,24,28,35,62,63,68,73]). …”
Section: Other Important Research Topicsmentioning
confidence: 99%
“…More specifically, it is the acquisition and analysis of physical memory [3,4,5,6,7]. Memory forensics is more challenging than disk-based forensics for several reasons: it is volatile in nature and therefore difficult to collect.…”
Section: Introductionmentioning
confidence: 99%
“…It is also difficult to analyse, as memory does not use a set structure. Acquisition and analysis of the data represent separate distinct research areas and are the focus of much research within the discipline [4]. Although the concept of memory forensics has existed for some time, the catalyst for the current explosion in interested started as a result of the 2005 Digital Forensic Research Workshop (DFRWS) [5,6].…”
Section: Introductionmentioning
confidence: 99%
See 1 more Smart Citation