【24h】

Windows registry analysis for forensic investigation

机译:Windows注册表分析用于法医调查

获取原文

摘要

Cyber attack comes in various approach and forms, either internally or externally. Remote access and spyware are forms of cyber attack leaving an organization to be susceptible to vulnerability. This paper investigates illegal activities and potential evidence of cyber attack through studying the registry on the Windows 7 Home Premium (32 bit) Operating System in using the application Virtual Network Computing (VNC) and keylogger application. The aim is to trace the registry artifacts left by the attacker which connected using Virtual Network Computing (VNC) protocol within Windows 7 Operating System (OS). The analysis of the registry focused on detecting unwanted applications or unauthorized access to the machine with regard to the user activity via the VNC connection for the potential evidence of illegal activities by investigating the Registration Entries file and image file using the Forensic Toolkit (FTK) Imager. The outcome of this study is the findings on the artifacts which correlate to the user activity.
机译:网络攻击以内部或外部的各种方式和形式出现。远程访问和间谍软件是网络攻击的一种形式,使组织容易受到漏洞的攻击。本文通过使用应用程序虚拟网络计算(VNC)和键盘记录程序应用程序研究Windows 7 Home Premium(32位)操作系统上的注册表,调查了非法活动和潜在的网络攻击证据。目的是跟踪攻击者留下的注册表工件,该攻击者使用Windows 7操作系统(OS)中的虚拟网络计算(VNC)协议进行连接。注册表分析的重点在于,通过使用取证工具包(FTK)成像器调查注册条目文件和图像文件,通过VNC连接检测与用户活动有关的有害应用程序或对计算机的未授权访问,以查找非法活动的潜在证据。 。这项研究的结果是在与用户活动相关的人工制品上的发现。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号