Study on the Forensic Methods of Main Memory
碩士 === 華梵大學 === 資訊管理學系碩士班 === 100 === Along with the improvement of information technology and the popularization of IT education, the cybercrime cases are also on the increase. As the Internet enjoys a booming development, the digital evidences are not only stored in the non-volatile storage but al...
Main Authors: | , |
---|---|
Other Authors: | |
Format: | Others |
Language: | zh-TW |
Published: |
2012
|
Online Access: | http://ndltd.ncl.edu.tw/handle/30836875386116773027 |
id |
ndltd-TW-100HCHT0396031 |
---|---|
record_format |
oai_dc |
spelling |
ndltd-TW-100HCHT03960312015-10-13T21:07:17Z http://ndltd.ncl.edu.tw/handle/30836875386116773027 Study on the Forensic Methods of Main Memory 主記憶體鑑識方法之研究 Yeh, Kuang-Chieh 葉廣傑 碩士 華梵大學 資訊管理學系碩士班 100 Along with the improvement of information technology and the popularization of IT education, the cybercrime cases are also on the increase. As the Internet enjoys a booming development, the digital evidences are not only stored in the non-volatile storage but also in the volatile storage ones. Consequently, it becomes an important subject for the forensic personnel to collect the digital evidences from the volatile storage medium especially in the main memory of computers. This study deeply investigates the methods of collection and analysis for digital evidences in the main memory based on the structure of the Windows 7 operating system. It also develops the automate tools for digital evidences collection and analysis in the main memory by integrating all related digital forensic tools. Finally, the feasibility and effectiveness of the proposed tool are testified by case study. It is hoped to make up the functions of single digital forensic tool and reduce the operational procedures during the evidence collection and analysis of the main memory by forensic personnel. Chu, Huei-Chung 朱惠中 2012 學位論文 ; thesis 82 zh-TW |
collection |
NDLTD |
language |
zh-TW |
format |
Others
|
sources |
NDLTD |
description |
碩士 === 華梵大學 === 資訊管理學系碩士班 === 100 === Along with the improvement of information technology and the popularization of IT education, the cybercrime cases are also on the increase. As the Internet enjoys a booming development, the digital evidences are not only stored in the non-volatile storage but also in the volatile storage ones. Consequently, it becomes an important subject for the forensic personnel to collect the digital evidences from the volatile storage medium especially in the main memory of computers.
This study deeply investigates the methods of collection and analysis for digital evidences in the main memory based on the structure of the Windows 7 operating system. It also develops the automate tools for digital evidences collection and analysis in the main memory by integrating all related digital forensic tools. Finally, the feasibility and effectiveness of the proposed tool are testified by case study. It is hoped to make up the functions of single digital forensic tool and reduce the operational procedures during the evidence collection and analysis of the main memory by forensic personnel.
|
author2 |
Chu, Huei-Chung |
author_facet |
Chu, Huei-Chung Yeh, Kuang-Chieh 葉廣傑 |
author |
Yeh, Kuang-Chieh 葉廣傑 |
spellingShingle |
Yeh, Kuang-Chieh 葉廣傑 Study on the Forensic Methods of Main Memory |
author_sort |
Yeh, Kuang-Chieh |
title |
Study on the Forensic Methods of Main Memory |
title_short |
Study on the Forensic Methods of Main Memory |
title_full |
Study on the Forensic Methods of Main Memory |
title_fullStr |
Study on the Forensic Methods of Main Memory |
title_full_unstemmed |
Study on the Forensic Methods of Main Memory |
title_sort |
study on the forensic methods of main memory |
publishDate |
2012 |
url |
http://ndltd.ncl.edu.tw/handle/30836875386116773027 |
work_keys_str_mv |
AT yehkuangchieh studyontheforensicmethodsofmainmemory AT yèguǎngjié studyontheforensicmethodsofmainmemory AT yehkuangchieh zhǔjìyìtǐjiànshífāngfǎzhīyánjiū AT yèguǎngjié zhǔjìyìtǐjiànshífāngfǎzhīyánjiū |
_version_ |
1718055268000989184 |