官术网_书友最值得收藏!

Collection

The collection element is where digital forensic examiners begin the process of acquiring the digital evidence. When examining digital evidence, it is important to understand the volatile nature of some of the evidence that an examiner will want to look at. Volatile evidence is evidence that can be lost when a system is powered down. For network equipment this could include active connections or log data that is stored on the device. For laptops and desktops, volatile data includes running memory or the Address Resolution Protocol cache. The Internet Engineering Task Force (IETF) has put together a document titled Guidelines forEvidence Collection and Archiving (RFC 3227) that addresses the order of volatility of digital evidence:

  • Registers, cache
  • Routing Table, ARP Cache, process table, kernel statistics, Memory (RAM)
  • Temporary filesystems
  • Disk
  • Remote logging and monitoring data
  • Physical configuration, network topology
  • Archival media

It is imperative that digital forensic examiners take this volatility into account when starting the process of evidence collection. Methods should be employed where volatile evidence will be collected and moved to a non-volatile medium such as an external hard drive.

主站蜘蛛池模板: 香河县| 苗栗县| 涞水县| 深泽县| 当涂县| 沐川县| 师宗县| 林芝县| 廊坊市| 乡宁县| 浦江县| 贵溪市| 威远县| 隆安县| 四川省| 苏尼特左旗| 沙洋县| 湘阴县| 鹤岗市| 棋牌| 甘德县| 兴山县| 湖州市| 梨树县| 敦煌市| 全南县| 满城县| 雷州市| 东海县| 庆阳市| 共和县| 吉安县| 合阳县| 双辽市| 中江县| 海城市| 新化县| 凉山| 上林县| 高陵县| 稷山县|