【24h】

RAM data significance in digital forensics

机译:数字取证中的RAM数据意义

获取原文

摘要

In present modern times when operating systems require larger amounts of RAM or Random Access Memory, we usually come across computers with 4 GB RAM, but given the price drops, it is quite usual to come across computers with 64 GB of RAM as well. By imaging this part of computer memory and by performing forensics analysis of the data located in RAM, it can be easily concluded that performing RAM imagining and analysis should be one of the essential steps in any forensic investigation. This paper will give a short introduction to digital forensics and the role of live data forensics. Furthermore, the mail goal will be to show and explain the importance of forensics of live machines and artefacts which can be found as well as methods and tools which are used for extracting and analyzing data from RAM. In addition, it will be shown that sometimes in forensic investigations, data contained in RAM can contain enough evidence to solve the whole case and actually be everything a digital forensics investigator really need.
机译:在当前的现代时代,当操作系统需要更大数量的RAM或随机存取存储器时,我们通常会遇到具有4 GB RAM的计算机,但是鉴于价格下降,通常也会遇到具有64 GB RAM的计算机。通过对计算机内存的这一部分进行成像并通过对位于RAM中的数据进行取证分析,可以很容易地得出结论,对RAM进行成像和分析应该是任何取证研究中必不可少的步骤之一。本文将简要介绍数字取证和实时数据取证的作用。此外,邮件的目标将是显示和解释可以发现的实时机器和人工制品取证的重要性,以及用于从RAM中提取和分析数据的方法和工具。此外,将显示出有时在法医调查中,RAM中包含的数据可以包含足够的证据来解决整个案件,并且实际上是数字法证研究人员真正需要的一切。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号