Study of Memory Forensics Technology Oriented to Windows Operating System

QIAN Qin,DONG Bu-yun,TANG Zhe,FU Xiao,MAO Bing
DOI: https://doi.org/10.3969/j.issn.1000-3428.2014.08.058
2014-01-01
Abstract:Traditional methods of memory acquisition focus on the persistent data of disk or hard disk in the attacked computers. However,as the growing use of encryption routines or rapidly increasing storage capabilities of hard drives,it is very difficult to get data in time with the original method that is meant for persistent data. So in the field of computer forensics,people start to change the data source and focus on the volatile information in RAM. This paper specifically describes the prevailing methods of memory acquisition and analysis and the process of memory forensics. It explains the characteristics of each method and gives the advantage and disadvantage of them. In the end,it concludes all these methods and gives some suggestions of the future of computer forensics.
What problem does this paper attempt to address?