【24h】

Windows registry analysis for forensic investigation

机译:法医调查的Windows注册表分析

获取原文
获取外文期刊封面目录资料

摘要

Cyber attack comes in various approach and forms, either internally or externally. Remote access and spyware are forms of cyber attack leaving an organization to be susceptible to vulnerability. This paper investigates illegal activities and potential evidence of cyber attack through studying the registry on the Windows 7 Home Premium (32 bit) Operating System in using the application Virtual Network Computing (VNC) and keylogger application. The aim is to trace the registry artifacts left by the attacker which connected using Virtual Network Computing (VNC) protocol within Windows 7 Operating System (OS). The analysis of the registry focused on detecting unwanted applications or unauthorized access to the machine with regard to the user activity via the VNC connection for the potential evidence of illegal activities by investigating the Registration Entries file and image file using the Forensic Toolkit (FTK) Imager. The outcome of this study is the findings on the artifacts which correlate to the user activity.
机译:网络攻击处于各种方法和形式,在内部或外部。远程访问和间谍软件是网络攻击的形式,使组织易受脆弱性。本文通过使用应用程序虚拟网络计算(VNC)和Keylogger应用程序来研究Windows 7家庭溢价(32位)操作系统的注册表来研究网络攻击的非法活动和潜在的证据。目的是跟踪由Windows 7操作系统(OS)内使用虚拟网络计算(VNC)协议的攻击者留下的注册表项。注册表的分析专注于通过VNC连接检测不需要的应用程序或未授权访问机器,以通过使用法医工具包(FTK)成像器来调查登记条目文件和图像文件的非法活动的潜在证据。本研究的结果是与用户活动相关的伪影的发现。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号