Memory forensics: The path forward

Memory forensics: The path forward
复制标题

DOI:
10.1016/j.diin.2016.12.004
复制
发表时间:
2017-03-01
影响因子:
--
通讯作者:
Richard, Golden G., III
Richard, Golden G., III
中科院分区:
工程技术4区
文献类型:
--
作者:
Case, Andrew;Richard, Golden G., III

文献摘要

被引文献

相似文献

传统上,数字取证专注于位于计算机系统,手机,数码相机和其他电子设备的存储设备上的工件。然而,在过去的十年中,研究人员创建了许多强大的内存取证工具,这些工具扩大了数字取证的范围,以包括对挥发性内存的检查。尽管内存法医技术已经从简单的字符串搜索演变为对许多平台和操作系统的应用程序和内核数据结构的深入,结构化分析,但仍有许多研究要做。本文调查记忆取证中的最新作品,对当前生成技术进行批判性分析,描述影响记忆取证的操作系统设计中的重要变化,并为进一步的研究绘制重要领域。 (c)2017 Elsevier Ltd.保留所有权利。
Traditionally, digital forensics focused on artifacts located on the storage devices of computer systems, mobile phones, digital cameras, and other electronic devices. In the past decade, however, researchers have created a number of powerful memory forensics tools that expand the scope of digital forensics to include the examination of volatile memory as well. While memory forensic techniques have evolved from simple string searches to deep, structured analysis of application and kernel data structures for a number of platforms and operating systems, much research remains to be done. This paper surveys the state-of-the-art in memory forensics, provide critical analysis of current-generation techniques, describe important changes in operating systems design that impact memory forensics, and sketches important areas for further research. (C) 2017 Elsevier Ltd. All rights reserved.