• DocumentCode
    2695863
  • Title

    Volatile memory acquisition using backup for forensic investigation

  • Author

    Dezfouli, Farhood Norouzizadeh ; Dehghantanha, Ali ; Mahmoud, Ramlan ; Sani, Nor Fazlida Binti Mohd ; Bin Shamsuddin, Solahuddin

  • Author_Institution
    Fac. of Comput. Sci. & Inf. Technol., Univ. Putra Malaysia, Serdang, Malaysia
  • fYear
    2012
  • fDate
    26-28 June 2012
  • Firstpage
    186
  • Lastpage
    189
  • Abstract
    Nowadays mobile phones are used all over the world for the communication purposes. The capabilities of these devices are improved during the past few years. Due to their capabilities, mobile devices are used broadly in criminal activities especially in cybercrime. The volatile data stored in mobile phones usually contain important evidences regarding the crime. However, collecting these volatile data in a forensically sound manner would not be easy. This paper proposes a new approach for acquiring the volatile data inside a mobile phone in a forensically sound manner that minimizes the chance of evidence modification or lost.
  • Keywords
    computer crime; computer forensics; data acquisition; mobile handsets; backup; criminal activities; cybercrime; forensic investigation; mobile devices; mobile phones; volatile memory acquisition; Computers; Data mining; Forensics; Mobile communication; Mobile computing; Mobile handsets; Random access memory; backup; digital forensics; mobile phone forensics; mobile phone investigation; volatile data;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Cyber Security, Cyber Warfare and Digital Forensic (CyberSec), 2012 International Conference on
  • Conference_Location
    Kuala Lumpur
  • Print_ISBN
    978-1-4673-1425-1
  • Type

    conf

  • DOI
    10.1109/CyberSec.2012.6246108
  • Filename
    6246108