【24h】

Forensic memory evidence of windows application

机译:Windows应用程序的法医内存证据

获取原文

摘要

In modern digital investigations, forensic sensitive information can be gathered from the physical memory of computer systems. Digital forensic community feels the urge towards accurate data collection, preservation, examination, validation, data analysis and presentation. This investigative process has become an essential part of digital investigation. The extraction of forensically relevant evidence from the physical memory can reveals users' actions. This research will report the amount of evidence that can be extracted and how the evidence changes with the length of time that the system is switched on and the application is still opened. In this experiment, the quantitative assessment of user input on the most commonly used applications will be presented.
机译:在现代数字调查中,可以从计算机系统的物理内存收集法医敏感信息。 数字法医社区感受到准确数据收集,保存,检查,验证,数据分析和演示的促使。 该调查过程已成为数字调查的重要组成部分。 从物理内存中提取取证相关证据可以揭示用户的行为。 本研究将报告可以提取的证据量以及如何通过系统打开的时间长度以及应用程序仍然打开的时间来改变。 在该实验中,将介绍对最常用应用的用户输入的定量评估。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号