...
首页> 外文期刊>International journal of electronic security and digital forensics >Vol Net: a framework for analysing network-based artefacts from volatile memory
【24h】

Vol Net: a framework for analysing network-based artefacts from volatile memory

机译:VOL NET:一个框架,用于分析基于网络的艺术品从挥发性记忆

获取原文
获取原文并翻译 | 示例
           

摘要

Volatile memory contains an affluence of information regarding the current state of the running system. Memory forensics techniques inspect RAM to extract information such as credentials, encryption keys, network activity and logs, malware, MFT records and the set of processes, open file descriptors currently executed by the operating system, etc. To achieve retrievability of potential artefacts, a memory dump should be taken prior to shutting down the system. It is the most vital aspect for carving information residing into the volatile memory. Volatile memory dump is used for offline investigation of volatile data. The analysis provides information regarding the activities being performed over the running system. This research focuses on our developed framework called as VolNet through which investigator can extract and analyse the artefacts related to network communication, social chats, cloud-based artefacts, private browsing and anonymous surfing and other potential artefacts that can be obtained from RAM dumps of live systems.
机译:易失性存储器包含关于运行系统当前状态的信息的富裕。内存取证技术检查RAM以提取凭据,加密密钥,网络活动和日志,恶意软件,MFT记录和流程集的信息,打开当前由操作系统执行的文件描述符等,以实现潜在人工制品的可检索性,a在关闭系统之前应采取内存转储。它是驻留在挥发性存储器中的信息中最重要的方面。易失性存储器转储用于挥发性数据的离线调查。该分析提供了关于正在运行系统执行的活动的信息。本研究侧重于我们发达的框架,称为volnet,调查员可以通过哪些调查员提取和分析与网络通信,社会聊天,基于云的人工制品,私人浏览和匿名冲浪以及可以从现场垃圾划分场所获得的其他潜在人工制品的人工制品系统。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号