메뉴 건너뛰기




Volumn 4, Issue SUPPL., 2007, Pages 126-134

BodySnatcher: Towards reliable volatile memory acquisition by software

Author keywords

Digital forensics; Memory acquisition; Memory imaging; Volatile memory forensics

Indexed keywords

COMPUTER OPERATING SYSTEMS; IMAGING SYSTEMS; RELIABILITY THEORY; SECURITY OF DATA;

EID: 34447528955     PISSN: 17422876     EISSN: None     Source Type: Journal    
DOI: 10.1016/j.diin.2007.06.009     Document Type: Article
Times cited : (53)

References (22)
  • 1
    • 34447512079 scopus 로고    scopus 로고
    • Aloni D. Cooperative Linux. In: Linux symposium, Ottawa, CA, 2004.
  • 5
    • 21644433634 scopus 로고    scopus 로고
    • Barham P, Dragovic B, Fraser K, Hand, S, Harris T, et al. Xen and the art of virtualization. In: ACM symposium on operating systems principles, Bolton Landing, NY; 2003.
  • 6
    • 3042731401 scopus 로고    scopus 로고
    • A hardware-based memory acquisition procedure for digital investigations
    • Carrier B.D., and Grand J. A hardware-based memory acquisition procedure for digital investigations. J Digit Investig 1 1 (2004)
    • (2004) J Digit Investig , vol.1 , Issue.1
    • Carrier, B.D.1    Grand, J.2
  • 7
    • 3042727237 scopus 로고    scopus 로고
    • Practical approaches to recovering encrypted digital evidence
    • Casey E. Practical approaches to recovering encrypted digital evidence. Int J Digit Evid 1 3 (2002)
    • (2002) Int J Digit Evid , vol.1 , Issue.3
    • Casey, E.1
  • 13
    • 34447518454 scopus 로고    scopus 로고
    • Goyal V, Biederman EW, Nellitheertha H. Kdump, a kexec-based kernel crash dumping mechanism. In: Linux symposium, Ottowa, CA, 2005.
  • 16
    • 33751342034 scopus 로고    scopus 로고
    • FATKit: a framework for the extraction and analysis of digital forensic data from volatile system memory
    • Petroni N.L., et al. FATKit: a framework for the extraction and analysis of digital forensic data from volatile system memory. Digit Investig 3 4 (2006)
    • (2006) Digit Investig , vol.3 , Issue.4
    • Petroni, N.L.1
  • 18
    • 35048889034 scopus 로고    scopus 로고
    • Volatile memory computer forensics to detect kernel level compromise
    • p. 158-70
    • Ring S., and Cole E. Volatile memory computer forensics to detect kernel level compromise. Lecture notes in Computer Science (2004) p. 158-70
    • (2004) Lecture notes in Computer Science
    • Ring, S.1    Cole, E.2
  • 19
    • 50849097989 scopus 로고    scopus 로고
    • Schuster A. Searching for processes and threads in Microsoft Windows memory dumps. In: Digital forensics workshop (DFRWS), 2006.


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.