官术网_书友最值得收藏!

Introduction

Memory analysis is a relatively new, but increasingly relevant field. A memory image can be acquired in the same way as a physical image, but by using different tools, some of which will be discussed in this section.

The image can be stored as one of the many formats, depending on the tool used to acquire the image. Once an investigator has the image, they can then analyse the data within it.

One of the main challenges associated with memory forensics is data preservation. Although your only option in a given investigation may be to power down a system and then image the data therein, in reality this ends up having an impact on other potential data sources that might be important later on. It is vital, therefore, to have a thorough understanding of the scene you are investigating and the specific needs of the case before you decide which method to choose. Any time you interact with a system, you will alter something simply by virtue of having been there. However, memory acquisition can help to minimize the effects of the investigator on the data collected, since a memory image will sample the volatile memory at a specific time, thus creating a sort of snapshot that can then be analysed later.

In cases where an investigator arrives at a scene to find a machine powered on, the memory on the system will be volatile at that time. This means that, if you manage to acquire a memory image then and there, you will be able to see a snapshot of the computer's memory at the moment at which you acquired it. This can be very useful, especially if a suspect has recently fled a scene or has been arrested at the scene.

You will generally need administrative permissions on the computer if you want to acquire volatile memory unless you are using hardware. One such solution is CaptureGUARD Physical Memory Acquisition Hardware. It requires a small CaptureGUARD driver to be installed on the system and creates a memory dump in the standard WinDD format. You can see one of these devices in figure 2.1.

Figure 2.1. ExpressCard

In other words, memory forensics is a complex and temperamental field. You will need to have a thorough understanding of the tool sets you are using, and any potential impacts they could have on volatile memory before you decide which to use it at a scene. However, if you do manage to acquire a memory image, it can provide a wealth of useful information for your case.

主站蜘蛛池模板: 武义县| 襄汾县| 温宿县| 蓝田县| 满洲里市| 和平县| 高淳县| 南召县| 黄大仙区| 乾安县| 溆浦县| 汉寿县| 南郑县| 文山县| 宝坻区| 樟树市| 周宁县| 连城县| 许昌县| 郓城县| 红安县| 莱西市| 永吉县| 濉溪县| 秀山| 贺兰县| 姜堰市| 塔河县| 屏东市| 平舆县| 阿坝| 高唐县| 多伦县| 麻江县| 五大连池市| 鄂托克旗| 金堂县| 文水县| 义马市| 喜德县| 河间市|