A survey of main memory acquisition and analysis techniques for the windows operating system

Digital Investigation(2011)

引用 58|浏览0
暂无评分
摘要
Traditional, persistent data-oriented approaches in computer forensics face some limitations regarding a number of technological developments, e.g., rapidly increasing storage capabilities of hard drives, memory-resident malicious software applications, or the growing use of encryption routines, that make an in-time investigation more and more difficult. In order to cope with these issues, security professionals have started to examine alternative data sources and emphasize the value of volatile system information in RAM more recently. In this paper, we give an overview of the prevailing techniques and methods to collect and analyze a computer's memory. We describe the characteristics, benefits, and drawbacks of the individual solutions and outline opportunities for future research in this evolving field of IT security.
更多
查看译文
关键词
individual solution,main memory acquisition,security professional,memory-resident malicious software application,it security,memory forensics,microsoft windows,live forensics,analysis technique,computer forensics,alternative data source,hard drive,in-time investigation,memory acquisition,memory analysis,encryption routine,operating system
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要