The Experts below are selected from a list of 228 Experts worldwide ranked by ideXlab platform

Leventhal Paul - One of the best experts on this subject based on the ideXlab platform.

Paul Leventhal - One of the best experts on this subject based on the ideXlab platform.

K. L. Thomas - One of the best experts on this subject based on the ideXlab platform.

  • SNDS - Towards Retrieving Live Forensic Artifacts in Offline Forensics
    Communications in Computer and Information Science, 2012
    Co-Authors: S Dija, T. R. Deepthi, C. Balan, K. L. Thomas
    Abstract:

    Live Forensics is the process of collecting forensically sound evidence from the suspect’s computer system when it is in running state. But, this process is not widely accepted as a cyber forensic procedure in most of the countries. Instead of starting with a live forensic procedure, usually a traditional offline forensics is adopted according to the accepted cyber forensic procedure. This involves pulling the power plug of the suspect’s system and imaging the storage media. The crucial evidence available in the running system is lost forever when turning off the system. The most important information that can be collected in live forensics is the evidence available in the Random Access Memory of a system. Since a Windows operating system adds footprints of each of its current activity in RAM, analyzing its content is indispensable in a cyber forensic analysis. And, this may provide information that can be crucial in carrying out further investigation. Since RAM content is highly volatile, its complete content is lost when turning off the system. In this paper a methodology to retrieve memory forensic artifacts while adopting a traditional offline forensics is explained. This is done by analyzing the hibernation file available in windows Directory Partition inside the hard disk of the suspect’s system.

S Dija - One of the best experts on this subject based on the ideXlab platform.

  • SNDS - Towards Retrieving Live Forensic Artifacts in Offline Forensics
    Communications in Computer and Information Science, 2012
    Co-Authors: S Dija, T. R. Deepthi, C. Balan, K. L. Thomas
    Abstract:

    Live Forensics is the process of collecting forensically sound evidence from the suspect’s computer system when it is in running state. But, this process is not widely accepted as a cyber forensic procedure in most of the countries. Instead of starting with a live forensic procedure, usually a traditional offline forensics is adopted according to the accepted cyber forensic procedure. This involves pulling the power plug of the suspect’s system and imaging the storage media. The crucial evidence available in the running system is lost forever when turning off the system. The most important information that can be collected in live forensics is the evidence available in the Random Access Memory of a system. Since a Windows operating system adds footprints of each of its current activity in RAM, analyzing its content is indispensable in a cyber forensic analysis. And, this may provide information that can be crucial in carrying out further investigation. Since RAM content is highly volatile, its complete content is lost when turning off the system. In this paper a methodology to retrieve memory forensic artifacts while adopting a traditional offline forensics is explained. This is done by analyzing the hibernation file available in windows Directory Partition inside the hard disk of the suspect’s system.

T. R. Deepthi - One of the best experts on this subject based on the ideXlab platform.

  • SNDS - Towards Retrieving Live Forensic Artifacts in Offline Forensics
    Communications in Computer and Information Science, 2012
    Co-Authors: S Dija, T. R. Deepthi, C. Balan, K. L. Thomas
    Abstract:

    Live Forensics is the process of collecting forensically sound evidence from the suspect’s computer system when it is in running state. But, this process is not widely accepted as a cyber forensic procedure in most of the countries. Instead of starting with a live forensic procedure, usually a traditional offline forensics is adopted according to the accepted cyber forensic procedure. This involves pulling the power plug of the suspect’s system and imaging the storage media. The crucial evidence available in the running system is lost forever when turning off the system. The most important information that can be collected in live forensics is the evidence available in the Random Access Memory of a system. Since a Windows operating system adds footprints of each of its current activity in RAM, analyzing its content is indispensable in a cyber forensic analysis. And, this may provide information that can be crucial in carrying out further investigation. Since RAM content is highly volatile, its complete content is lost when turning off the system. In this paper a methodology to retrieve memory forensic artifacts while adopting a traditional offline forensics is explained. This is done by analyzing the hibernation file available in windows Directory Partition inside the hard disk of the suspect’s system.