• DocumentCode
    599387
  • Title

    Forensic memory evidence of windows application

  • Author

    Olajide, F. ; Savage, Neil ; Akmayeva, G. ; Trafford, R.

  • Author_Institution
    Sch. of Eng., Univ. of Portsmouth, Portsmouth, UK
  • fYear
    2012
  • fDate
    10-12 Dec. 2012
  • Firstpage
    715
  • Lastpage
    718
  • Abstract
    In modern digital investigations, forensic sensitive information can be gathered from the physical memory of computer systems. Digital forensic community feels the urge towards accurate data collection, preservation, examination, validation, data analysis and presentation. This investigative process has become an essential part of digital investigation. The extraction of forensically relevant evidence from the physical memory can reveals users´ actions. This research will report the amount of evidence that can be extracted and how the evidence changes with the length of time that the system is switched on and the application is still opened. In this experiment, the quantitative assessment of user input on the most commonly used applications will be presented.
  • Keywords
    digital forensics; operating systems (computers); user interfaces; Windows application; data analysis; data collection; data examination; data presentation; data preservation; data validation; digital forensics; digital investigation; forensic memory evidence; forensic sensitive information; user action; user input quantitative assessment; Analytical models; Computational modeling; Educational institutions; Image reconstruction; Kernel; Lead; Application; Windows; memory; time;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Internet Technology And Secured Transactions, 2012 International Conference for
  • Conference_Location
    London
  • Print_ISBN
    978-1-4673-5325-0
  • Type

    conf

  • Filename
    6470910