Study on the Forensic Methods of Main Memory

碩士 === 華梵大學 === 資訊管理學系碩士班 === 100 === Along with the improvement of information technology and the popularization of IT education, the cybercrime cases are also on the increase. As the Internet enjoys a booming development, the digital evidences are not only stored in the non-volatile storage but al...

Full description

Bibliographic Details
Main Authors: Yeh, Kuang-Chieh, 葉廣傑
Other Authors: Chu, Huei-Chung
Format: Others
Language:zh-TW
Published: 2012
Online Access:http://ndltd.ncl.edu.tw/handle/30836875386116773027
id ndltd-TW-100HCHT0396031
record_format oai_dc
spelling ndltd-TW-100HCHT03960312015-10-13T21:07:17Z http://ndltd.ncl.edu.tw/handle/30836875386116773027 Study on the Forensic Methods of Main Memory 主記憶體鑑識方法之研究 Yeh, Kuang-Chieh 葉廣傑 碩士 華梵大學 資訊管理學系碩士班 100 Along with the improvement of information technology and the popularization of IT education, the cybercrime cases are also on the increase. As the Internet enjoys a booming development, the digital evidences are not only stored in the non-volatile storage but also in the volatile storage ones. Consequently, it becomes an important subject for the forensic personnel to collect the digital evidences from the volatile storage medium especially in the main memory of computers. This study deeply investigates the methods of collection and analysis for digital evidences in the main memory based on the structure of the Windows 7 operating system. It also develops the automate tools for digital evidences collection and analysis in the main memory by integrating all related digital forensic tools. Finally, the feasibility and effectiveness of the proposed tool are testified by case study. It is hoped to make up the functions of single digital forensic tool and reduce the operational procedures during the evidence collection and analysis of the main memory by forensic personnel. Chu, Huei-Chung 朱惠中 2012 學位論文 ; thesis 82 zh-TW
collection NDLTD
language zh-TW
format Others
sources NDLTD
description 碩士 === 華梵大學 === 資訊管理學系碩士班 === 100 === Along with the improvement of information technology and the popularization of IT education, the cybercrime cases are also on the increase. As the Internet enjoys a booming development, the digital evidences are not only stored in the non-volatile storage but also in the volatile storage ones. Consequently, it becomes an important subject for the forensic personnel to collect the digital evidences from the volatile storage medium especially in the main memory of computers. This study deeply investigates the methods of collection and analysis for digital evidences in the main memory based on the structure of the Windows 7 operating system. It also develops the automate tools for digital evidences collection and analysis in the main memory by integrating all related digital forensic tools. Finally, the feasibility and effectiveness of the proposed tool are testified by case study. It is hoped to make up the functions of single digital forensic tool and reduce the operational procedures during the evidence collection and analysis of the main memory by forensic personnel.
author2 Chu, Huei-Chung
author_facet Chu, Huei-Chung
Yeh, Kuang-Chieh
葉廣傑
author Yeh, Kuang-Chieh
葉廣傑
spellingShingle Yeh, Kuang-Chieh
葉廣傑
Study on the Forensic Methods of Main Memory
author_sort Yeh, Kuang-Chieh
title Study on the Forensic Methods of Main Memory
title_short Study on the Forensic Methods of Main Memory
title_full Study on the Forensic Methods of Main Memory
title_fullStr Study on the Forensic Methods of Main Memory
title_full_unstemmed Study on the Forensic Methods of Main Memory
title_sort study on the forensic methods of main memory
publishDate 2012
url http://ndltd.ncl.edu.tw/handle/30836875386116773027
work_keys_str_mv AT yehkuangchieh studyontheforensicmethodsofmainmemory
AT yèguǎngjié studyontheforensicmethodsofmainmemory
AT yehkuangchieh zhǔjìyìtǐjiànshífāngfǎzhīyánjiū
AT yèguǎngjié zhǔjìyìtǐjiànshífāngfǎzhīyánjiū
_version_ 1718055268000989184