2011 Sixth IEEE International Workshop on Systematic Approaches to Digital Forensic Engineering最新文献

筛选
英文 中文
Firmware-assisted Memory Acquisition and Analysis tools for Digital Forensics 用于数字取证的固件辅助记忆获取和分析工具
Jiang Wang, Fengwei Zhang, Kun Sun, A. Stavrou
{"title":"Firmware-assisted Memory Acquisition and Analysis tools for Digital Forensics","authors":"Jiang Wang, Fengwei Zhang, Kun Sun, A. Stavrou","doi":"10.1109/SADFE.2011.7","DOIUrl":"https://doi.org/10.1109/SADFE.2011.7","url":null,"abstract":"Being able to inspect and analyze the operational state of commodity machines is crucial for modern digital forensics. Indeed, volatile system state including memory data and CPU registers contain information that cannot be directly inferred or reconstructed by acquiring the contents of the nonvolatile storage. Unfortunately, it still remains an open problem how to reliably and consistently retrieve the volatile machine state without disrupting its operation. In this paper, we propose to leverage commercial PCI network cards and the current x86 implementation of System Management Mode to reliably replicate the physical memory and critical CPU registers from commodity hardware. Furthermore, we demonstrate how remote state replication can be used for semantic reconstruction, where the analysis of memory structures enables us to interactively perform forensic analysis of the machine's memory content.","PeriodicalId":264200,"journal":{"name":"2011 Sixth IEEE International Workshop on Systematic Approaches to Digital Forensic Engineering","volume":"17 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2011-05-05","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"130662212","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 33
Case Study on South Africa and Namibia: A Model for Electronic Evidence for the SADC Region 南非和纳米比亚案例研究:南部非洲发展共同体区域电子证据模式
A. Phillips
{"title":"Case Study on South Africa and Namibia: A Model for Electronic Evidence for the SADC Region","authors":"A. Phillips","doi":"10.1109/SADFE.2011.4","DOIUrl":"https://doi.org/10.1109/SADFE.2011.4","url":null,"abstract":"The need for standardized laws for electronic evidence is well established. As more countries realize the need for such laws in their day to day affairs, they create ones that work for their country. In today's global economy and interlaced businesses, both civil and criminal cases cross international lines. This case study uses South Africa and Namibia as a model for the SADC region of sub-Saharan Africa in the establishment of digital law and handling of digital evidence.","PeriodicalId":264200,"journal":{"name":"2011 Sixth IEEE International Workshop on Systematic Approaches to Digital Forensic Engineering","volume":"253 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2011-05-05","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"116116250","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 0
Boundary Conditions for the Digital Forensic Use of Electronic Evidence and The Need for Forensic Counter-Analysis 数字法医使用电子证据的边界条件及法医反分析的必要性
M. Losavio, Musa Hindi, Roman V Yampolskiy, D. Keeling
{"title":"Boundary Conditions for the Digital Forensic Use of Electronic Evidence and The Need for Forensic Counter-Analysis","authors":"M. Losavio, Musa Hindi, Roman V Yampolskiy, D. Keeling","doi":"10.1109/SADFE.2011.2","DOIUrl":"https://doi.org/10.1109/SADFE.2011.2","url":null,"abstract":"Network and Digital Forensics provide information about electronic activity in new, sometimes unprecedented forms. These new forms offer new, powerful tactical tools for investigations of electronic malfeasance when incorporated under traditional legal regulation of state power, particular that of Fourth Amendment limitations on police searches and seizures under the U.S. Constitution. These tactical tools raise issues of public policy and privacy that may raise concerns about the proper police oversight of civil society. How those issues are resolved will define personal privacy, autonomy and dignity in the 21st digital century.","PeriodicalId":264200,"journal":{"name":"2011 Sixth IEEE International Workshop on Systematic Approaches to Digital Forensic Engineering","volume":"57 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2011-05-05","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"127886005","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 2
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
相关产品
×
本文献相关产品
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信