DocumentCode
599387
Title
Forensic memory evidence of windows application
Author
Olajide, F. ; Savage, Neil ; Akmayeva, G. ; Trafford, R.
Author_Institution
Sch. of Eng., Univ. of Portsmouth, Portsmouth, UK
fYear
2012
fDate
10-12 Dec. 2012
Firstpage
715
Lastpage
718
Abstract
In modern digital investigations, forensic sensitive information can be gathered from the physical memory of computer systems. Digital forensic community feels the urge towards accurate data collection, preservation, examination, validation, data analysis and presentation. This investigative process has become an essential part of digital investigation. The extraction of forensically relevant evidence from the physical memory can reveals users´ actions. This research will report the amount of evidence that can be extracted and how the evidence changes with the length of time that the system is switched on and the application is still opened. In this experiment, the quantitative assessment of user input on the most commonly used applications will be presented.
Keywords
digital forensics; operating systems (computers); user interfaces; Windows application; data analysis; data collection; data examination; data presentation; data preservation; data validation; digital forensics; digital investigation; forensic memory evidence; forensic sensitive information; user action; user input quantitative assessment; Analytical models; Computational modeling; Educational institutions; Image reconstruction; Kernel; Lead; Application; Windows; memory; time;
fLanguage
English
Publisher
ieee
Conference_Titel
Internet Technology And Secured Transactions, 2012 International Conference for
Conference_Location
London
Print_ISBN
978-1-4673-5325-0
Type
conf
Filename
6470910
Link To Document