메뉴 건너뛰기




Volumn 4, Issue 1, 2009, Pages 3-10

Collecting sensitive information from windows physical memory

Author keywords

Live system; Memory forensics; Sensitive information

Indexed keywords

COMPUTER SCIENCE;

EID: 68749122104     PISSN: 1796203X     EISSN: None     Source Type: Journal    
DOI: 10.4304/jcp.4.1.3-10     Document Type: Conference Paper
Times cited : (20)

References (21)
  • 2
    • 3142612259 scopus 로고    scopus 로고
    • Evidence dynamics: Locard's exchange principle and crime reconstruction
    • January
    • W. Chisum and B. Turvey, "Evidence dynamics: Locard's exchange principle and crime reconstruction", Journal of Behavioral Profiling, vol.1, January 2000.
    • (2000) Journal of Behavioral Profiling , vol.1
    • Chisum, W.1    Turvey, B.2
  • 4
    • 3042731401 scopus 로고    scopus 로고
    • A hardware-based memory acquisition procedure for digital investigations
    • February
    • B. D. Carrier and J. Grand. "A hardware-based memory acquisition procedure for digital investigations", Journal of Digital Investigations, vol. 1, pp. 50-60, February 2004.
    • (2004) Journal of Digital Investigations , vol.1 , pp. 50-60
    • Carrier, B.D.1    Grand, J.2
  • 5
    • 78651531987 scopus 로고    scopus 로고
    • http://ntsecurity.nu/onmymind/2006/2006-09-02.html
  • 7
    • 78651540126 scopus 로고    scopus 로고
    • http://www.vmware.com/
  • 8
    • 34447528955 scopus 로고    scopus 로고
    • BodySnatcher: Towards reliable volatile memory acquisition by software
    • September
    • S. Bradley, "BodySnatcher: Towards reliable volatile memory acquisition by software", Journal of Digital Investigations, vol. 4, pp. 126-134, September 2007
    • (2007) Journal of Digital Investigations , vol.4 , pp. 126-134
    • Bradley, S.1
  • 9
    • 78651550960 scopus 로고    scopus 로고
    • http://www.x-ways.net/winhex/index-m.html
  • 12
    • 78651568721 scopus 로고    scopus 로고
    • http://www.microsoft.com/whdc/devtools/debugging/default.mspx
  • 13
    • 78651530182 scopus 로고    scopus 로고
    • http://www.ultraedit.cn/
  • 14
    • 78651579384 scopus 로고    scopus 로고
    • available on computers that have 2 or more gigabytes of RAM
    • "Complete memory dumps are not available on computers that have 2 or more gigabytes of RAM", http://support.microsoft.com/kb/274598/en-us
    • Complete memory dumps are
  • 15
    • 42649130329 scopus 로고    scopus 로고
    • Windows memory forensics
    • May
    • N. Ruff, "Windows memory forensics", Journal of Computer Virology, vol. 4, pp. 83-100, May 2008.
    • (2008) Journal of Computer Virology , vol.4 , pp. 83-100
    • Ruff, N.1
  • 16
  • 17
    • 78651522866 scopus 로고    scopus 로고
    • http://www.runtime.org/
  • 18
    • 78651541713 scopus 로고    scopus 로고
    • http://www.accessdata.com/catalog/partdetail.aspx?partno=11000
  • 19
    • 78651590173 scopus 로고    scopus 로고
    • http://www.x-ways.net/forensics/index-m.html
  • 20
    • 78651557327 scopus 로고    scopus 로고
    • http://www.ilook-forensics.org/


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.