DocumentCode
690443
Title
A Method on Extracting Registry Information from Windows CE Memory Images
Author
Shumian Yang ; Lianhai Wang ; Shuhui Zhang ; Jian Liu
Author_Institution
Shandong Comput. Sci. Center, Shandong Provincial Key Lab. of Comput. Network, Jinan, China
fYear
2013
fDate
14-15 Dec. 2013
Firstpage
728
Lastpage
732
Abstract
The Windows CE registry plays a very important role from physical memory and contains lots of important information that are of potential evidential value in forensic analysis. Memory acquisition and analysis is the most important in Windows CE devices forensic. The paper introduces physical memory acquisition and analysis methods in Windows environment and the procedure of memory analysis on the different kernels of windows CE device. The algorithm for extracting the registry information from the physics memory is presented and mainly composed of the following steps: judging the version of operating system, locating the ROMHDR structure, File structure and Module structure, lpszFileName traversal until to find the file name whose Suffix is. Rgu and. hv, locating the ulLoadOffset and nFileSize to find the entry address and the size of registry file. The method is proved to be effective and reliable in extracting registry file from physical memory on Windows mobile6.5 operating system.
Keywords
database management systems; digital forensics; information retrieval; operating system kernels; ROMHDR structure location; Windows CE device; Windows CE memory images; Windows CE registry; Windows mobile 6.5 operating system; file structure location; forensic analysis; kernels; lpszFileName traversal; module structure location; nFileSize location; operating system version; physical memory acquisition; physical memory analysis; registry information extraction; ulLoadOffset location; Computers; Data mining; Forensics; Kernel; Mobile communication; Mobile handsets; forensic analysis; physical memory; registry information extraction; windows CE forensics; windows CE kernel; windows CE registry; windows mobile device forensics;
fLanguage
English
Publisher
ieee
Conference_Titel
Computer Sciences and Applications (CSA), 2013 International Conference on
Conference_Location
Wuhan
Type
conf
DOI
10.1109/CSA.2013.175
Filename
6835701
Link To Document