메뉴 건너뛰기




Volumn , Issue , 2007, Pages

BodySnatcher: Towards reliable volatile memory acquisition by software

Author keywords

Digital forensics; Memory acquisition; Memory imaging; Volatile memory forensics

Indexed keywords

DIGITAL EVIDENCE; DIGITAL FORENSIC; FULL CONTROL; PHYSICAL MEMORY; PROOF OF CONCEPT; ROOTKITS; VOLATILE MEMORY; WINDOWS 2000;

EID: 84868380591     PISSN: None     EISSN: None     Source Type: Conference Proceeding    
DOI: 10.1016/j.diin.2007.06.009     Document Type: Conference Paper
Times cited : (18)

References (22)
  • 1
    • 49149100153 scopus 로고    scopus 로고
    • Cooperative linux
    • Ottawa, CA
    • Aloni D. Cooperative Linux. In: Linux symposium, Ottawa, CA, 2004.
    • (2004) Linux Symposium
    • Aloni, D.1
  • 6
    • 3042731401 scopus 로고    scopus 로고
    • A hardware-based memory acquisition procedure for digital investigations
    • Carrier BD, Grand J. A hardware-based memory acquisition procedure for digital investigations. J Digit Investig 2004;1(1).
    • (2004) J Digit Investig , vol.1 , Issue.1
    • Carrier, B.D.1    Grand, J.2
  • 7
    • 3042727237 scopus 로고    scopus 로고
    • Practical approaches to recovering encrypted digital evidence
    • Casey E. Practical approaches to recovering encrypted digital evidence. Int J Digit Evid 2002;1(3).
    • (2002) Int J Digit Evid , vol.1 , Issue.3
    • Casey, E.1
  • 8
    • 34447551547 scopus 로고    scopus 로고
    • [cited April 2007]
    • Carvey H. lsproc released [cited April 2007]. Available from: 〈http://windowsir.blogspot.com/2006/04/lsproc-released.html〉; 2006.
    • (2006) Lsproc Released
    • Carvey, H.1
  • 9
    • 84868383441 scopus 로고    scopus 로고
    • [citedApril 2007]
    • DFRWS.Memory analysis challenge [citedApril 2007].Available from: 〈http://www.dfrws.org/2005/challenge/index.html〉; 2005.
    • (2005) Memory Analysis Challenge
  • 16
    • 33751342034 scopus 로고    scopus 로고
    • FATKit: A framework for the extraction and analysis of digital forensic data from volatile system memory
    • Petroni NL, et al. FATKit: a framework for the extraction and analysis of digital forensic data from volatile system memory. Digit Investig 2006;3(4).
    • (2006) Digit Investig , vol.3 , Issue.4
    • Petroni, N.L.1
  • 19
    • 50849097989 scopus 로고    scopus 로고
    • Searching for processes and threads in Microsoft Windows memory dumps
    • Schuster A. Searching for processes and threads in Microsoft Windows memory dumps. In: Digital forensics workshop (DFRWS), 2006.
    • (2006) Digital Forensics Workshop (DFRWS)
    • Schuster, A.1


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.