{"title":"Approaches to Selective Imaging of Live Systems via Memory Forensics","authors":"Sarishma Dangi, K. Ghanshala, Sachin Sharma","doi":"10.1109/CONIT59222.2023.10205824","DOIUrl":null,"url":null,"abstract":"Modern day forensic investigations rely on forensically sound digital evidence which is acceptable in a court of law. The increase cybersecurity attacks have enormously increased the need of forensic investigations leading to a huge corpus of data. Mostly, the memory image dump is so huge for individual cases out of which the critical evidence is present in a comparatively smaller amount of memory. Selective imaging provides a way to partially image the memory of target device without necessarily copying the rest of the image that may be of little or no use to the investigation. Selective imaging allows the investigator to forensically acquire memory in a strategic manner depending upon the nature of the case at hand. In this work, we explore the realm of selective imaging and present a consolidated literature review along with the various approaches available for considering selective memory imaging for live systems to conduct forensic investigations via live memory forensics. The work concludes by pointing the research directions around selective imaging for enhancing the effectiveness of live memory forensics.","PeriodicalId":377623,"journal":{"name":"2023 3rd International Conference on Intelligent Technologies (CONIT)","volume":"120 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-06-23","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2023 3rd International Conference on Intelligent Technologies (CONIT)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/CONIT59222.2023.10205824","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2
Abstract
Modern day forensic investigations rely on forensically sound digital evidence which is acceptable in a court of law. The increase cybersecurity attacks have enormously increased the need of forensic investigations leading to a huge corpus of data. Mostly, the memory image dump is so huge for individual cases out of which the critical evidence is present in a comparatively smaller amount of memory. Selective imaging provides a way to partially image the memory of target device without necessarily copying the rest of the image that may be of little or no use to the investigation. Selective imaging allows the investigator to forensically acquire memory in a strategic manner depending upon the nature of the case at hand. In this work, we explore the realm of selective imaging and present a consolidated literature review along with the various approaches available for considering selective memory imaging for live systems to conduct forensic investigations via live memory forensics. The work concludes by pointing the research directions around selective imaging for enhancing the effectiveness of live memory forensics.