Volatile Memory Collection and Analysis for Windows Mission-Critical Computer Systems

被引:2
|
作者
Savoldi, Antonio [1 ]
Gubian, Paolo [1 ]
机构
[1] Univ Brescia, Brescia, Italy
关键词
Blurriness; Live Forensic Analysis; Page File Collection; Ram Collection; Volatile Memory Analysis; Volatile Memory Integrity;
D O I
10.4018/jdcf.2009070103
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Most enterprises rely on the continuity of service guaranteed by means of a computer system infrastructure, which can often be based on the Windows operating system family. For such a category of systems, which might be referred to as mission-critical for the relevance of the service supplied, it is indeed fundamental to be able to define which approach could be better to apply when a digital investigation needs to be performed. This is the very goal of this paper: the definition of a forensically sound methodology which can be used to collect the full state of the machine being investigated by avoiding service interruptions. It will be pointed out why the entire volatile memory dump, with the necessary extension which is nowadays missing, is required with the purpose of being able to gather much more evidential data, by illustrating also, at the same time, the limitation and disadvantages of current state of-the-art approaches in performing the collection phase.
引用
收藏
页码:42 / 61
页数:20
相关论文
共 50 条
  • [41] Assuring Autonomy of UAVs in Mission-critical Scenarios by Performability Modeling and Analysis
    Andrade, Ermeson
    Machida, Fumio
    ACM TRANSACTIONS ON CYBER-PHYSICAL SYSTEMS, 2024, 8 (03)
  • [42] Coping With the Obsolescence of Safety- or Mission-Critical Embedded Systems Using FPGAs
    Guzman-Miranda, Hipolito
    Sterpone, Luca
    Violante, Massimo
    Aguirre, Miguel A.
    Gutierrez-Rizo, Manuel
    IEEE TRANSACTIONS ON INDUSTRIAL ELECTRONICS, 2011, 58 (03) : 814 - 821
  • [43] Methodology for cost-effective software fault tolerance for mission-critical systems
    Kreutzfeld, Robert J.
    Neese, Richard E.
    AIAA/IEEE Digital Avionics Systems Conference - Proceedings, 1996, : 19 - 24
  • [44] A methodology for cost-effective software fault tolerance for mission-critical systems
    Kreutzfeld, RJ
    Neese, RE
    15TH DASC - AIAA/IEEE DIGITAL AVIONICS SYSTEMS CONFERENCE, 1996, : 19 - 24
  • [45] Monitoring, capturing and analysis of mission-critical traffic in experimental communication networks
    Wietgrefe, Hermann
    Ajenjo, Alberto Domingo
    Rogula, Tomasz
    2006 2ND INTERNATIONAL CONFERENCE ON TESTBEDS AND RESEARCH INFRASTRUCTURES FOR THE DEVELOPMENT OF NETWORKS & COMMUNITIES, 2006, : 331 - 339
  • [46] Methodology for cost-effective software fault tolerance for mission-critical systems
    Kreutzfeld, RJ
    Neese, RE
    IEEE AEROSPACE AND ELECTRONIC SYSTEMS MAGAZINE, 1997, 12 (09) : 25 - 30
  • [47] Architecture Analysis of Service-Oriented Mission-Critical Network System
    Liang, Ying
    Tian, Xiu-Wei
    INTERNATIONAL CONFERENCE ON COMPUTER NETWORKS AND INFORMATION SECURITY (CNIS 2015), 2015, : 142 - 148
  • [48] Toward a simulation benchmark for distributed mission-critical real-time systems
    Cavanaugh, CD
    2005 IEEE Networking, Sensing and Control Proceedings, 2005, : 1037 - 1042
  • [49] Ensuring Safety, Security, and Sustainability of Mission-Critical Cyber-Physical Systems
    Banerjee, Ayan
    Venkatasubramanian, Krishna K.
    Mukherjee, Tridib
    Gupta, Sandeep Kumar S.
    PROCEEDINGS OF THE IEEE, 2012, 100 (01) : 283 - 299
  • [50] Methodology for cost-effective software fault tolerance for mission-critical systems
    TASC, Fairborne, United States
    IEEE Aerosp Electron Syst Mag, 1600, 9 (25-30):