File Download
There are no files associated with this item.
Links for fulltext
(May Require Subscription)
- Publisher Website: 10.1109/FGCN.2007.93
- Scopus: eid_2-s2.0-52249105372
- Find via
Supplementary
-
Citations:
- Scopus: 0
- Appears in Collections:
Conference Paper: Consistency Issue on Live Systems Forensics
Title | Consistency Issue on Live Systems Forensics |
---|---|
Authors | |
Issue Date | 2007 |
Citation | Proceedings Of Future Generation Communication And Networking, Fgcn 2007, 2007, v. 2, p. 136-140 How to Cite? |
Abstract | Volatile data, being vital to digital investigation, have become part of the standard items targeted in the course of live response to a computer system. In traditional computer forensics where investigation is carried out on a dead system (e.g. hard disk), data integrity is the first and foremost issue for digital evidence validity in court. In the context of live system forensics, volatile data are acquired from a running system. Due to the ever-changing and volatile nature, it is impossible to verify the integrity of volatile data. Let alone the integrity issue, a more critical problem - data consistency, is present at the data collected on a live system. In this paper, we address and study the consistency issue on live systems forensics. By examining the memory data on a Unix system, we outline a model to distinguish integral data from inconsistent data in a memory dump. |
Persistent Identifier | http://hdl.handle.net/10722/151926 |
ISBN | |
ISSN | |
References |
DC Field | Value | Language |
---|---|---|
dc.contributor.author | Law, FYW | en_US |
dc.contributor.author | Chow, KP | en_US |
dc.contributor.author | Kwan, MYK | en_US |
dc.contributor.author | Lai, PKY | en_US |
dc.date.accessioned | 2012-06-26T06:30:56Z | - |
dc.date.available | 2012-06-26T06:30:56Z | - |
dc.date.issued | 2007 | en_US |
dc.identifier.citation | Proceedings Of Future Generation Communication And Networking, Fgcn 2007, 2007, v. 2, p. 136-140 | en_US |
dc.identifier.isbn | 0-7695-3048-6 | - |
dc.identifier.issn | 2153-1447 | - |
dc.identifier.uri | http://hdl.handle.net/10722/151926 | - |
dc.description.abstract | Volatile data, being vital to digital investigation, have become part of the standard items targeted in the course of live response to a computer system. In traditional computer forensics where investigation is carried out on a dead system (e.g. hard disk), data integrity is the first and foremost issue for digital evidence validity in court. In the context of live system forensics, volatile data are acquired from a running system. Due to the ever-changing and volatile nature, it is impossible to verify the integrity of volatile data. Let alone the integrity issue, a more critical problem - data consistency, is present at the data collected on a live system. In this paper, we address and study the consistency issue on live systems forensics. By examining the memory data on a Unix system, we outline a model to distinguish integral data from inconsistent data in a memory dump. | en_US |
dc.language | eng | en_US |
dc.relation.ispartof | Proceedings of Future Generation Communication and Networking, FGCN 2007 | en_US |
dc.title | Consistency Issue on Live Systems Forensics | en_US |
dc.type | Conference_Paper | en_US |
dc.identifier.email | Chow, KP:chow@cs.hku.hk | en_US |
dc.identifier.authority | Chow, KP=rp00111 | en_US |
dc.description.nature | link_to_subscribed_fulltext | en_US |
dc.identifier.doi | 10.1109/FGCN.2007.93 | - |
dc.identifier.scopus | eid_2-s2.0-52249105372 | en_US |
dc.identifier.hkuros | 152348 | - |
dc.relation.references | http://www.scopus.com/mlt/select.url?eid=2-s2.0-52249105372&selection=ref&src=s&origin=recordpage | en_US |
dc.identifier.volume | 2 | en_US |
dc.identifier.spage | 136 | en_US |
dc.identifier.epage | 140 | en_US |
dc.identifier.scopusauthorid | Law, FYW=19640490000 | en_US |
dc.identifier.scopusauthorid | Chow, KP=7202180751 | en_US |
dc.identifier.scopusauthorid | Kwan, MYK=19640239200 | en_US |
dc.identifier.scopusauthorid | Lai, PKY=19640260600 | en_US |
dc.identifier.issnl | 2153-1447 | - |