DocumentCode :
1924759
Title :
Enhancement of Forensic Computing Investigations through Memory Forensic Techniques
Author :
Simon, Matthew ; Slay, Jill
Author_Institution :
Defence & Syst. Inst. (DASI), Univ. of South Australia, Adelaide, SA
fYear :
2009
fDate :
16-19 March 2009
Firstpage :
995
Lastpage :
1000
Abstract :
The use of memory forensic techniques has the potential to enhance computer forensic investigations. The analysis of digital evidence is facing several key challenges; an increase in electronic devices, network connections and bandwidth, the use of anti-forensic technologies and the development of network centric applications and technologies has lead to less potential evidence stored on static media and increased amounts of data stored off-system. Memory forensic techniques have the potential to overcome these issues in forensic analysis. While much of the current research in memory forensics has been focussed on low-level data, there is a need for research to extract high-level data from physical memory as a means of providing forensic investigators with greater insight into a target system. This paper outlines the need for further research into memory forensic techniques. In particular it stresses the need for methods and techniques for understanding context on a system and also as a means of augmenting other data sources to provide a more complete and efficient searching of investigations.
Keywords :
security of data; data stored off-system; digital evidence; electronic devices; forensic computing investigations; memory forensic techniques; network centric applications; network connections; Application software; Australia; Availability; Cryptography; Electronic mail; Forensics; Image storage; Physics computing; Random access memory; Security; Computer forensics; Digital evidence; Digital investigation; Electronic evidence; RAM forensics; Volatile memory forensics.;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Availability, Reliability and Security, 2009. ARES '09. International Conference on
Conference_Location :
Fukuoka
Print_ISBN :
978-1-4244-3572-2
Electronic_ISBN :
978-0-7695-3564-7
Type :
conf
DOI :
10.1109/ARES.2009.119
Filename :
5066600
Link To Document :
بازگشت