2015
DOI: 10.1111/1556-4029.12979
|View full text |Cite
|
Sign up to set email alerts
|

In‐Depth Analysis of Computer Memory Acquisition Software for Forensic Purposes

Abstract: The comparison studies on random access memory (RAM) acquisition tools are either limited in metrics or the selected tools were designed to be executed in older operating systems. Therefore, this study evaluates widely used seven shareware or freeware/open source RAM acquisition forensic tools that are compatible to work with the latest 64-bit Windows operating systems. These tools' user interface capabilities, platform limitations, reporting capabilities, total execution time, shared and proprietary DLLs, mod… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
2

Citation Types

0
11
0

Year Published

2018
2018
2023
2023

Publication Types

Select...
5
2
1

Relationship

0
8

Authors

Journals

citations
Cited by 14 publications
(11 citation statements)
references
References 10 publications
0
11
0
Order By: Relevance
“…Moreover, it also shows that sometimes the forensic investigation, the data contained in RAM can contain sufficient evidence to settle the whole case. Mcdown, et al in [7] Acquisition software selection greatly affects the quality of the data when copying. The results of research analyzing the memory depth at seven acquisition software that runs on Windows 7 that FTK Imager, Belkasoft RAM Capturer, ProDiscover, Windows Memory Reader, WinEn, DumpIt and Memoryze.…”
Section: Related Workmentioning
confidence: 99%
See 2 more Smart Citations
“…Moreover, it also shows that sometimes the forensic investigation, the data contained in RAM can contain sufficient evidence to settle the whole case. Mcdown, et al in [7] Acquisition software selection greatly affects the quality of the data when copying. The results of research analyzing the memory depth at seven acquisition software that runs on Windows 7 that FTK Imager, Belkasoft RAM Capturer, ProDiscover, Windows Memory Reader, WinEn, DumpIt and Memoryze.…”
Section: Related Workmentioning
confidence: 99%
“…The success of the investigation depends on the quality of data collected. The quality of the copied data contains completeness of information such as information access, time and users, data quality is also affected by artefacts (Registry Key, DLL) left by the use of software acquisition [7]. Processing time, DLL, Registry Key and Memory Usage will impact to potential evidence.…”
Section: Introductionmentioning
confidence: 99%
See 1 more Smart Citation
“…Since then, researchers are benefiting from the vital information that can be available in RAM [2]. Some researchers are focused on the memory acquisition techniques [27] while others are focused on the emerging platforms and computing domains. For example, researchers in [28] proposed a hardware virtualization to facilitate a lightweight live memory forensic approach, in which they proposed on the fly virtualization environment that allows the migration of virtual machines without modification or termination.…”
Section: Related Workmentioning
confidence: 99%
“…Following refinement and rigorous testing, many methods/technologies have been adopted by forensic laboratories, including polymerase chain reaction (PCR) [1,2], capillary electrophoretic instrumentation (Genetic Analyzers) [3,4], automated liquid handling (Microfluidic devices) [5][6][7], and expert software systems [8][9][10][11]. Introduction of robust validation processes has a long term impact to test evidentiary samples to be presented to the court of law.…”
Section: Introductionmentioning
confidence: 99%