Data acquisition from volatile memory a memory acquisition tool for Microsoft Windows Vista

The focus of this research is on extracting data from the volatile random access memory (RAM) on a personal computer running Microsoft's Windows Vista operating system, while minimally affecting the existing data. The projected work includes the development of a kernel-mode device driver with...

Full description

Bibliographic Details
Main Author: Cheong, Choong Wee Vincent
Other Authors: Vidas, Timothy M.
Published: Monterey, California. Naval Postgraduate School 2012
Online Access:http://hdl.handle.net/10945/3795
id ndltd-nps.edu-oai-calhoun.nps.edu-10945-3795
record_format oai_dc
spelling ndltd-nps.edu-oai-calhoun.nps.edu-10945-37952014-11-27T16:04:51Z Data acquisition from volatile memory a memory acquisition tool for Microsoft Windows Vista Cheong, Choong Wee Vincent Vidas, Timothy M. Dinolt, George W. Naval Postgraduate School (U.S.) The focus of this research is on extracting data from the volatile random access memory (RAM) on a personal computer running Microsoft's Windows Vista operating system, while minimally affecting the existing data. The projected work includes the development of a kernel-mode device driver with the capabilities on one or more versions of Microsoft Windows Vista, a user-mode application that interacts with the driver, usage documentation and outcome of the research. The main objectives of the research is to show the possibility of extracting information from the random access memory using a user mode application (with a suitable driver already installed) and to document the process of Window Vista driver development, so that future works in this area can benefit by putting more effort into specific research rather than configuring a development environment. 2012-03-14T17:39:25Z 2012-03-14T17:39:25Z 2008-12 Thesis http://hdl.handle.net/10945/3795 301564693 Approved for public release, distribution unlimited Monterey, California. Naval Postgraduate School
collection NDLTD
sources NDLTD
description The focus of this research is on extracting data from the volatile random access memory (RAM) on a personal computer running Microsoft's Windows Vista operating system, while minimally affecting the existing data. The projected work includes the development of a kernel-mode device driver with the capabilities on one or more versions of Microsoft Windows Vista, a user-mode application that interacts with the driver, usage documentation and outcome of the research. The main objectives of the research is to show the possibility of extracting information from the random access memory using a user mode application (with a suitable driver already installed) and to document the process of Window Vista driver development, so that future works in this area can benefit by putting more effort into specific research rather than configuring a development environment.
author2 Vidas, Timothy M.
author_facet Vidas, Timothy M.
Cheong, Choong Wee Vincent
author Cheong, Choong Wee Vincent
spellingShingle Cheong, Choong Wee Vincent
Data acquisition from volatile memory a memory acquisition tool for Microsoft Windows Vista
author_sort Cheong, Choong Wee Vincent
title Data acquisition from volatile memory a memory acquisition tool for Microsoft Windows Vista
title_short Data acquisition from volatile memory a memory acquisition tool for Microsoft Windows Vista
title_full Data acquisition from volatile memory a memory acquisition tool for Microsoft Windows Vista
title_fullStr Data acquisition from volatile memory a memory acquisition tool for Microsoft Windows Vista
title_full_unstemmed Data acquisition from volatile memory a memory acquisition tool for Microsoft Windows Vista
title_sort data acquisition from volatile memory a memory acquisition tool for microsoft windows vista
publisher Monterey, California. Naval Postgraduate School
publishDate 2012
url http://hdl.handle.net/10945/3795
work_keys_str_mv AT cheongchoongweevincent dataacquisitionfromvolatilememoryamemoryacquisitiontoolformicrosoftwindowsvista
_version_ 1716720855062413312