首页> 外文期刊>Journal of forensic sciences. >In-Depth Analysis of Computer Memory Acquisition Software for Forensic Purposes
【24h】

In-Depth Analysis of Computer Memory Acquisition Software for Forensic Purposes

机译:用于法医目的的计算机内存获取软件的深入分析

获取原文
获取原文并翻译 | 示例
获取外文期刊封面目录资料

摘要

The comparison studies on random access memory (RAM) acquisition tools are either limited in metrics or the selected tools were designed to be executed in older operating systems. Therefore, this study evaluates widely used seven shareware or freeware/open source RAM acquisition forensic tools that are compatible to work with the latest 64-bit Windows operating systems. These tools' user interface capabilities, platform limitations, reporting capabilities, total execution time, shared and proprietary DLLs, modified registry keys, and invoked files during processing were compared. We observed that Windows Memory Reader and Belkasoft's Live Ram Capturer leaves the least fingerprints in memory when loaded. On the other hand, ProDiscover and FTK Imager perform poor in memory usage, processing time, DLL usage, and not-wanted artifacts introduced to the system. While Belkasoft's Live Ram Capturer is the fastest to obtain an image of the memory, Pro Discover takes the longest time to do the same job.
机译:对随机存取存储器(RAM)采集工具的比较研究要么在指标上受限制,要么所选工具旨在在较旧的操作系统中执行。因此,本研究评估了广泛使用的七个共享软件或免费软件/开源RAM获取取证工具,这些工具可与最新的64位Windows操作系统兼容。比较了这些工具的用户界面功能,平台限制,报告功能,总执行时间,共享和专有DLL,修改的注册表项以及在处理过程中调用的文件。我们观察到Windows Memory Reader和Belkasoft的Live Ram Capturer在加载时在内存中留下的指纹最少。另一方面,ProDiscover和FTK Imager在内存使用,处理时间,DLL使用以及引入系统的不需要的工件方面表现不佳。 Belkasoft的Live Ram Capturer是获取内存映像最快的工具,而Pro Discover需要花费最长的时间来完成相同的工作。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号