DocumentCode :
691660
Title :
Extraction of HTTP messages for retrieval of live evidence
Author :
Mohanty, Ipsita ; Velusamy, R. Leela
Author_Institution :
Dept. of Comput. Sci. & Eng., Nat. Inst. of Technol., Tiruchirappalli, India
fYear :
2013
fDate :
25-27 July 2013
Firstpage :
40
Lastpage :
45
Abstract :
There has been a surge towards physical memory forensics with recent development of valuable tools and techniques in acquisition and analysis. However, most of the research is skewed towards the Operating System architecture with primary focus on processes, threads, kernel modules etc. There has been little research towards retrieval of application level data. Moreover, the research is majorly application specific and keyword search oriented, involving text string search tools which use match and/or indexing algorithms to search digital evidence. Our paper aims to unearth application level data through a generic approach and provide some degree of automation to reduce the string search dependency. The paper revolves around the web browser and the HTTP protocol which are the basic elements of the interface between a user and the internet. Programs have been developed for the extraction of HTTP message headers from the acquired RAM image and a detailed analysis of how the information in these headers is crucial, follows.
Keywords :
Internet; digital forensics; hypermedia; indexing; information retrieval; online front-ends; operating system kernels; transport protocols; HTTP message extraction; HTTP message headers; HTTP protocol; RAM image; Web browser; application level data; application specific search; indexing algorithms; kernel modules; keyword search; live evidence retrieval; operating system architecture; physical memory forensics; text string search tools; valuable tools; Browsers; Data mining; Facebook; Internet; Market research; Protocols; Random access memory; Application level Data; Digital Forensic; HTTP message; Live Evidence;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Recent Trends in Information Technology (ICRTIT), 2013 International Conference on
Conference_Location :
Chennai
Type :
conf
DOI :
10.1109/ICRTIT.2013.6844177
Filename :
6844177
Link To Document :
بازگشت