首页> 外文会议>Advances in Digital Forensics IV >FORENSIC ANALYSIS OF VOLATILE INSTANT MESSAGING
【24h】

FORENSIC ANALYSIS OF VOLATILE INSTANT MESSAGING

机译:即时消息传递的法医学分析

获取原文
获取原文并翻译 | 示例

摘要

Older instant messaging programs typically require some form of installation on the client machine, enabling forensic investigators to find a wealth of evidentiary artifacts. However, this paradigm is shifting as web-based instant messaging becomes more popular. Many traditional messaging clients (e.g., AOL Messenger, Yahoo! and MSN), can now be accessed using only a web browser. This presents new challenges for forensic examiners due to the volatile nature of the data and artifacts created by web-based instant messaging programs. These web-based programs do not write to registry keys or leave configuration files on the client machine. Investigators are, therefore, required to look for remnants of whole or partial conversations that may be dumped to page files and unallocated space on the hard disk. This paper examines the artifacts that can be recovered from web-based instant messaging programs and the challenges faced by forensic examiners during evidence recovery. An investigative framework for dealing with volatile instant messaging is also presented.
机译:较旧的即时消息传递程序通常需要在客户端计算机上进行某种形式的安装,从而使法医研究人员能够找到大量的证据制品。但是,随着基于Web的即时消息越来越流行,这种范例正在发生转变。现在,仅使用网络浏览器即可访问许多传统的邮件客户端(例如AOL Messenger,Yahoo!和MSN)。由于基于Web的即时消息传递程序创建的数据和工件的易变性,这给法医检查人员提出了新的挑战。这些基于Web的程序不会写入注册表项,也不会在客户端计算机上保留配置文件。因此,要求调查人员查找可能会转储到页面文件和硬盘上未分配空间的全部或部分对话的剩余内容。本文研究了可以从基于Web的即时消息传递程序中恢复的工件,以及取证过程中法医检查人员所面临的挑战。还提出了一种用于处理易失性即时消息传递的调查框架。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号