• DocumentCode
    1924759
  • Title

    Enhancement of Forensic Computing Investigations through Memory Forensic Techniques

  • Author

    Simon, Matthew ; Slay, Jill

  • Author_Institution
    Defence & Syst. Inst. (DASI), Univ. of South Australia, Adelaide, SA
  • fYear
    2009
  • fDate
    16-19 March 2009
  • Firstpage
    995
  • Lastpage
    1000
  • Abstract
    The use of memory forensic techniques has the potential to enhance computer forensic investigations. The analysis of digital evidence is facing several key challenges; an increase in electronic devices, network connections and bandwidth, the use of anti-forensic technologies and the development of network centric applications and technologies has lead to less potential evidence stored on static media and increased amounts of data stored off-system. Memory forensic techniques have the potential to overcome these issues in forensic analysis. While much of the current research in memory forensics has been focussed on low-level data, there is a need for research to extract high-level data from physical memory as a means of providing forensic investigators with greater insight into a target system. This paper outlines the need for further research into memory forensic techniques. In particular it stresses the need for methods and techniques for understanding context on a system and also as a means of augmenting other data sources to provide a more complete and efficient searching of investigations.
  • Keywords
    security of data; data stored off-system; digital evidence; electronic devices; forensic computing investigations; memory forensic techniques; network centric applications; network connections; Application software; Australia; Availability; Cryptography; Electronic mail; Forensics; Image storage; Physics computing; Random access memory; Security; Computer forensics; Digital evidence; Digital investigation; Electronic evidence; RAM forensics; Volatile memory forensics.;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Availability, Reliability and Security, 2009. ARES '09. International Conference on
  • Conference_Location
    Fukuoka
  • Print_ISBN
    978-1-4244-3572-2
  • Electronic_ISBN
    978-0-7695-3564-7
  • Type

    conf

  • DOI
    10.1109/ARES.2009.119
  • Filename
    5066600