• DocumentCode
    1801953
  • Title

    Volatile Memory Acquisition via Warm Boot Memory Survivability

  • Author

    Vidas, Timothy

  • Author_Institution
    Carnegie Mellon Univ., Pittsburgh, PA, USA
  • fYear
    2010
  • fDate
    5-8 Jan. 2010
  • Firstpage
    1
  • Lastpage
    6
  • Abstract
    As with other areas of digital forensics the validity and in some cases the sheer possibility of media analysis depends upon successfully acquisition of data from the media. The analysis of acquired Random Access Memory has been an active area of recent research. This paper demonstrates a USB based method of memory acquisition invoked via a system reboot. The method does not depend upon the operating system type or version.
  • Keywords
    computer forensics; data acquisition; random-access storage; data acquisition; digital forensics; memory acquisition; operating system; random access memory; system reboot; volatile memory acquisition; warm boot memory survivability; Command and control systems; Cryptography; Data structures; Digital forensics; Image analysis; Nonvolatile memory; Operating systems; Random access memory; Routing; Universal Serial Bus;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    System Sciences (HICSS), 2010 43rd Hawaii International Conference on
  • Conference_Location
    Honolulu, HI
  • ISSN
    1530-1605
  • Print_ISBN
    978-1-4244-5509-6
  • Electronic_ISBN
    1530-1605
  • Type

    conf

  • DOI
    10.1109/HICSS.2010.439
  • Filename
    5428490