DocumentCode :
2627737
Title :
Windows registry analysis for forensic investigation
Author :
Saidi, Raihana Md ; Ahmad, Siti A. ; Noor, Norliza Mohd ; Yunos, Rozita
Author_Institution :
Fac. of Comput. & Math. Sci., Univ. Teknol. MARA, Shah Alam, Malaysia
fYear :
2013
fDate :
9-11 May 2013
Firstpage :
132
Lastpage :
136
Abstract :
Cyber attack comes in various approach and forms, either internally or externally. Remote access and spyware are forms of cyber attack leaving an organization to be susceptible to vulnerability. This paper investigates illegal activities and potential evidence of cyber attack through studying the registry on the Windows 7 Home Premium (32 bit) Operating System in using the application Virtual Network Computing (VNC) and keylogger application. The aim is to trace the registry artifacts left by the attacker which connected using Virtual Network Computing (VNC) protocol within Windows 7 Operating System (OS). The analysis of the registry focused on detecting unwanted applications or unauthorized access to the machine with regard to the user activity via the VNC connection for the potential evidence of illegal activities by investigating the Registration Entries file and image file using the Forensic Toolkit (FTK) Imager. The outcome of this study is the findings on the artifacts which correlate to the user activity.
Keywords :
authorisation; computer crime; digital forensics; operating systems (computers); FTK imager; Forensic Toolkit imager; VNC protocol; Virtual Network Computing; Windows 7 Home Premium operating system; Windows Registry analysis; Windows-7 OS; cyber attack; illegal activities; image file; keylogger application; registration entry file; remote access; spyware; unauthorized access detection; unwanted application detection; Computers; Mirrors; Security; Servers; Virtual Network Computing (VNC); computer artifacts; digital forensics; registry;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Technological Advances in Electrical, Electronics and Computer Engineering (TAEECE), 2013 International Conference on
Conference_Location :
Konya
Print_ISBN :
978-1-4673-5612-1
Type :
conf
DOI :
10.1109/TAEECE.2013.6557209
Filename :
6557209
Link To Document :
بازگشت