官术网_书友最值得收藏!

Collection

The collection element is where digital forensic examiners begin the process of acquiring the digital evidence. When examining digital evidence, it is important to understand the volatile nature of some of the evidence that an examiner will want to look at. Volatile evidence is evidence that can be lost when a system is powered down. For network equipment this could include active connections or log data that is stored on the device. For laptops and desktops, volatile data includes running memory or the Address Resolution Protocol cache. The Internet Engineering Task Force (IETF) has put together a document titled Guidelines forEvidence Collection and Archiving (RFC 3227) that addresses the order of volatility of digital evidence:

  • Registers, cache
  • Routing Table, ARP Cache, process table, kernel statistics, Memory (RAM)
  • Temporary filesystems
  • Disk
  • Remote logging and monitoring data
  • Physical configuration, network topology
  • Archival media

It is imperative that digital forensic examiners take this volatility into account when starting the process of evidence collection. Methods should be employed where volatile evidence will be collected and moved to a non-volatile medium such as an external hard drive.

主站蜘蛛池模板: 福贡县| 会理县| 华容县| 卢氏县| 德清县| 交口县| 阿克苏市| 咸阳市| 蓝田县| 鸡东县| 怀安县| 德昌县| 彰化县| 张家界市| 翁牛特旗| 永川市| 山阳县| 丹阳市| 双峰县| 东光县| 五寨县| 黄山市| 祥云县| 苗栗市| 秦皇岛市| 横峰县| 泸溪县| 遵义市| 乌鲁木齐市| 兴和县| 巴彦淖尔市| 读书| 宕昌县| 方城县| 宜章县| 铜陵市| 顺平县| 东兰县| 六安市| 子长县| 本溪市|