2018
DOI: 10.17654/ec018050695
|View full text |Cite
|
Sign up to set email alerts
|

Carving and Clustering Files in Ram for Memory Forensics

Abstract: Memory contains vital information about the current state of a system such as processes, network connections and opened files. The contents of a file can be reconstructed from memory either by following the Operating System's data structures (which might not be always available) or by carving data based on the file's internal structure. Unfortunately, the problem gets more complicated when carving several files with the same internal structure that happen to coexist in memory. This paper carves chunks of a cer… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1

Citation Types

0
1
0

Year Published

2019
2019
2024
2024

Publication Types

Select...
4
2

Relationship

0
6

Authors

Journals

citations
Cited by 6 publications
(1 citation statement)
references
References 28 publications
0
1
0
Order By: Relevance
“…They achieved in somehow good clustering labels. In [29], the authors used a hierarchical clustering algorithm to distribute the chunks of a certain file type from memory into their corresponding files. This method does not need any information about the number of clusters.…”
Section: E Benchmarking Different Clustering Algorithmsmentioning
confidence: 99%
“…They achieved in somehow good clustering labels. In [29], the authors used a hierarchical clustering algorithm to distribute the chunks of a certain file type from memory into their corresponding files. This method does not need any information about the number of clusters.…”
Section: E Benchmarking Different Clustering Algorithmsmentioning
confidence: 99%