2022
DOI: 10.14569/ijacsa.2022.0131163
|View full text |Cite
|
Sign up to set email alerts
|

The Influence of Virtual Secure Mode (VSM) on Memory Acquisition

Abstract: Recently, acquiring the Random Access Memory (RAM) full memory and access data is gaining significant interest in digital forensics. However, a security feature on the Windows operating system -Virtual Secure Mode (VSM) -presents challenges to the acquisition process by causing a system crash known as a Blue Screen of Death (BSoD). The crash is likely to occur when memory acquisition tools are being used. Subsequently, it disrupts the goal of memory acquisition since the system must be restarted, and the RAM c… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1
1

Citation Types

0
3
1

Year Published

2023
2023
2024
2024

Publication Types

Select...
1
1

Relationship

0
2

Authors

Journals

citations
Cited by 2 publications
(4 citation statements)
references
References 14 publications
0
3
1
Order By: Relevance
“…These figs implies that the FTK Imager application is running smoothly without any problem found in the operating system. Different between this study, the latest research by Niken [6], it shows that this application cannot run properly in Windows 10 while VSM environment being turned on.…”
Section: System Analysiscontrasting
confidence: 85%
See 3 more Smart Citations
“…These figs implies that the FTK Imager application is running smoothly without any problem found in the operating system. Different between this study, the latest research by Niken [6], it shows that this application cannot run properly in Windows 10 while VSM environment being turned on.…”
Section: System Analysiscontrasting
confidence: 85%
“…Other than Autopsy, the experiment on FTK Imager shows that the tools running smoothly for both versions. It leads to comparing this experiment with research by Niken [6], because the result on FTK Imager is different with this study. System analysis method is being applied on FTK Imager and shows that the difference between the edition of Windows 10 can cause different occurrence in the safe mode.…”
Section: Discussionmentioning
confidence: 65%
See 2 more Smart Citations