On the Identification of Information Extracted from Windows Physical Memory
نویسندگان
چکیده
Forensic investigation of the physical memory of computer systems is gaining the attention of experts in the digital forensics community. Forensic investigators find it helpful to seize and capture data from the physical memory and perform post-incident analysis when identifying potential evidence. However, there have been few investigations which have identified the quantity and quality of information that can be recovered from only the computer system memory (RAM) while the application is still running. In this paper, we present the results of investigations carried out to identify relevant information that has been extracted from the physical memory of computer systems running Windows XP. We found fragments of partial evidence from allocated memory segments. This evidence was dispersed in the physical memory that had been allocated to the application. The identification of this information is useful to forensic investigators as this approach can uncover what a user is doing on the application which can be used as evidence
منابع مشابه
Extraction of Forensically Sensitive Information from Windows Physical Memory
Forensic analysis of physical memory is gaining good attention from experts in the community especially after recent development of valuable tools and techniques. Investigators find it very helpful to seize physical memory contents and perform post-incident analysis of this potential evidence. Most of the research carried out focus on enumerating processes and threads by accessing memory reside...
متن کاملCollective Memory as a Measure to Evaluate the Infill Architecture Innovations in Historic Contexts (Case Study: Historic Context of Imamzadeh Yahya in Tehran)
Historic contexts remind us of an era when cities were built based on the needs, goals, and preferences of their inhabitants. In other words, the mental world of both the builders and the inhabitants was closely interrelated. But by ignoring citizens' memories and interests and their mental needs, today's interventions with rapid developments within historic contexts have led to amnesia and the...
متن کاملCaffeine attenuates paradoxical sleep deprivation induced- memory impairment during paradoxical sleep windows in rats
There is considerable evidence to support the hypothesis of relationship between paradoxical sleep (PS) and learning–memory processing. It has been suggested that PS is important in memory retention at the specific time course called PS windows (PSW). The time of PSWs occurrence and duration of these PSWs following the training sessions and, the neurochemical nature of PSWs has not been well kn...
متن کاملCaffeine attenuates paradoxical sleep deprivation induced- memory impairment during paradoxical sleep windows in rats
There is considerable evidence to support the hypothesis of relationship between paradoxical sleep (PS) and learning–memory processing. It has been suggested that PS is important in memory retention at the specific time course called PS windows (PSW). The time of PSWs occurrence and duration of these PSWs following the training sessions and, the neurochemical nature of PSWs has not been well kn...
متن کاملAcquisition of Network Connection Status Information from Physical Memory on Windows Vista Operating System
A method to extract information of network connection status information from physical memory on Windows Vista operating system is proposed. Using this method, a forensic examiner can extract accurately the information of current TCP/IP network connection information, including IDs of processes which established connections, establishing time, local address, local port, remote address, remote p...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2012