首页 | 官方网站   微博 | 高级检索  
     


In‐Depth Analysis of Computer Memory Acquisition Software for Forensic Purposes
Authors:Robert J McDown BSc  Cihan Varol PhD  Leonardo Carvajal MSc  Lei Chen PhD
Affiliation:Department of Computer Science, Sam Houston State University, Huntsville, TX
Abstract:The comparison studies on random access memory (RAM) acquisition tools are either limited in metrics or the selected tools were designed to be executed in older operating systems. Therefore, this study evaluates widely used seven shareware or freeware/open source RAM acquisition forensic tools that are compatible to work with the latest 64‐bit Windows operating systems. These tools' user interface capabilities, platform limitations, reporting capabilities, total execution time, shared and proprietary DLLs, modified registry keys, and invoked files during processing were compared. We observed that Windows Memory Reader and Belkasoft's Live Ram Capturer leaves the least fingerprints in memory when loaded. On the other hand, ProDiscover and FTK Imager perform poor in memory usage, processing time, DLL usage, and not‐wanted artifacts introduced to the system. While Belkasoft's Live Ram Capturer is the fastest to obtain an image of the memory, Pro Discover takes the longest time to do the same job.
Keywords:forensic science  computer forensics  forensic tools  live forensics  memory acquisition  volatile data
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司    京ICP备09084417号-23

京公网安备 11010802026262号