文件格式、大小和存储介质对内存取证的影响

IF 2 4区 医学 Q3 COMPUTER SCIENCE, INFORMATION SYSTEMS
Ziad A. Al-Sharif , Reema Al-Senjalawi , Omar A. Alzoubi
{"title":"文件格式、大小和存储介质对内存取证的影响","authors":"Ziad A. Al-Sharif ,&nbsp;Reema Al-Senjalawi ,&nbsp;Omar A. Alzoubi","doi":"10.1016/j.fsidi.2024.301692","DOIUrl":null,"url":null,"abstract":"<div><p>Main memory or RAM contains volatile but critical data about the system's state and its recent activities. Often, RAM based artifacts are hard to be found elsewhere. Digital investigators can find in this volatile data an essential information about the recent usage of a system including the used documents. Nowadays, documents are often fetched from a variety of storage media, most of which are internet based. This can complicate the digital investigation process due to the remote nature of these storage media; most of these remote files cannot be traced on the local hard disk drive (HDD) of the captured machine. However, whenever the document's contents are successfully recovered from RAM images, it can ensure the actual usage of the document. This paper studies the effects of various storage media (<em>local and remote</em>) on the amount of volatile artifacts of different types of documents. Experiments are designed to evaluate the effects of local hard drives, removable media, and a set of cloud based platforms such as Dropbox, Google Drive, and OneDrive on the RAM based artifacts of a used document. Results show that the recovered contents are significantly affected by the used storage media. Moreover, the document's type has an effect too. Frequently, a good ratio of the document's contents are recovered from RAM even when the document is living on the cloud, the document is closed, and the connection is terminated.</p></div>","PeriodicalId":48481,"journal":{"name":"Forensic Science International-Digital Investigation","volume":null,"pages":null},"PeriodicalIF":2.0000,"publicationDate":"2024-01-19","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://www.sciencedirect.com/science/article/pii/S2666281724000015/pdfft?md5=47f894a33d4dcb10c0cee7b8447cd252&pid=1-s2.0-S2666281724000015-main.pdf","citationCount":"0","resultStr":"{\"title\":\"The effects of document's format, size, and storage media on memory forensics\",\"authors\":\"Ziad A. Al-Sharif ,&nbsp;Reema Al-Senjalawi ,&nbsp;Omar A. Alzoubi\",\"doi\":\"10.1016/j.fsidi.2024.301692\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"<div><p>Main memory or RAM contains volatile but critical data about the system's state and its recent activities. Often, RAM based artifacts are hard to be found elsewhere. Digital investigators can find in this volatile data an essential information about the recent usage of a system including the used documents. Nowadays, documents are often fetched from a variety of storage media, most of which are internet based. This can complicate the digital investigation process due to the remote nature of these storage media; most of these remote files cannot be traced on the local hard disk drive (HDD) of the captured machine. However, whenever the document's contents are successfully recovered from RAM images, it can ensure the actual usage of the document. This paper studies the effects of various storage media (<em>local and remote</em>) on the amount of volatile artifacts of different types of documents. Experiments are designed to evaluate the effects of local hard drives, removable media, and a set of cloud based platforms such as Dropbox, Google Drive, and OneDrive on the RAM based artifacts of a used document. Results show that the recovered contents are significantly affected by the used storage media. Moreover, the document's type has an effect too. Frequently, a good ratio of the document's contents are recovered from RAM even when the document is living on the cloud, the document is closed, and the connection is terminated.</p></div>\",\"PeriodicalId\":48481,\"journal\":{\"name\":\"Forensic Science International-Digital Investigation\",\"volume\":null,\"pages\":null},\"PeriodicalIF\":2.0000,\"publicationDate\":\"2024-01-19\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"https://www.sciencedirect.com/science/article/pii/S2666281724000015/pdfft?md5=47f894a33d4dcb10c0cee7b8447cd252&pid=1-s2.0-S2666281724000015-main.pdf\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Forensic Science International-Digital Investigation\",\"FirstCategoryId\":\"3\",\"ListUrlMain\":\"https://www.sciencedirect.com/science/article/pii/S2666281724000015\",\"RegionNum\":4,\"RegionCategory\":\"医学\",\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q3\",\"JCRName\":\"COMPUTER SCIENCE, INFORMATION SYSTEMS\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Forensic Science International-Digital Investigation","FirstCategoryId":"3","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S2666281724000015","RegionNum":4,"RegionCategory":"医学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q3","JCRName":"COMPUTER SCIENCE, INFORMATION SYSTEMS","Score":null,"Total":0}
引用次数: 0

摘要

主存储器或 RAM 包含有关系统状态和近期活动的易失性重要数据。通常,基于 RAM 的人工制品很难在其他地方找到。数字调查人员可以从这些易失性数据中找到有关系统近期使用情况的重要信息,包括使用过的文档。如今,文件通常是从各种存储介质中获取的,其中大部分都基于互联网。由于这些存储介质的远程性质,这可能会使数字调查过程复杂化;这些远程文件大多无法在捕获机器的本地硬盘驱动器(HDD)上进行追踪。不过,只要能从 RAM 映像中成功恢复文件内容,就能确保文件的实际使用情况。本文研究了各种存储介质(本地和远程)对不同类型文档的易失性人工痕迹数量的影响。实验旨在评估本地硬盘、可移动媒体和一组基于云的平台(如 Dropbox、Google Drive 和 OneDrive)对已使用文档的基于 RAM 的人工痕迹的影响。结果表明,恢复的内容受所用存储介质的影响很大。此外,文档类型也有影响。通常情况下,即使文档存活在云中、文档已关闭、连接已终止,也能从 RAM 中恢复相当比例的文档内容。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
The effects of document's format, size, and storage media on memory forensics

Main memory or RAM contains volatile but critical data about the system's state and its recent activities. Often, RAM based artifacts are hard to be found elsewhere. Digital investigators can find in this volatile data an essential information about the recent usage of a system including the used documents. Nowadays, documents are often fetched from a variety of storage media, most of which are internet based. This can complicate the digital investigation process due to the remote nature of these storage media; most of these remote files cannot be traced on the local hard disk drive (HDD) of the captured machine. However, whenever the document's contents are successfully recovered from RAM images, it can ensure the actual usage of the document. This paper studies the effects of various storage media (local and remote) on the amount of volatile artifacts of different types of documents. Experiments are designed to evaluate the effects of local hard drives, removable media, and a set of cloud based platforms such as Dropbox, Google Drive, and OneDrive on the RAM based artifacts of a used document. Results show that the recovered contents are significantly affected by the used storage media. Moreover, the document's type has an effect too. Frequently, a good ratio of the document's contents are recovered from RAM even when the document is living on the cloud, the document is closed, and the connection is terminated.

求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
CiteScore
5.90
自引率
15.00%
发文量
87
审稿时长
76 days
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信