On the analysis of information found on Windows application memory

Olajide, F. ORCID: 0000-0003-1627-6637, Savage, N., Akmayeva, G. and Shoniregun, C.A., 2013. On the analysis of information found on Windows application memory. International Journal of Intelligent Computing Research, 4 (2), pp. 328-333.

[img]
Preview
Text
1597883_Olajide.pdf - Published version

Download (584kB) | Preview

Abstract

Digital forensic community feels the urge for the development of tools and techniques in volatile memory analysis. The extraction of user input from physical memory of Windows applications may reveal useful information that could be used as evidence in crime cases; the information that may not be found on traditional hard disk forensic investigations. However, there have been few digital investigations into the amount of user input recovered from Windows application memory. This paper presents on the analysis of user input stored on an application, and the forensically relevant information recovered from the memory of some commonly used Windows applications. Quantitative results of the experiments carried out on these applications will be presented.

Item Type: Journal article
Publication Title: International Journal of Intelligent Computing Research
Creators: Olajide, F., Savage, N., Akmayeva, G. and Shoniregun, C.A.
Publisher: Infonomics Society
Date: June 2013
Volume: 4
Number: 2
Identifiers:
NumberType
10.20533/ijicr.2042.4655.2013.0042DOI
1597883Other
Rights: Copyright © 2013, Infonomics Society. This work is licensed under a Creative Commons Attribution 4.0 International License.
Divisions: Schools > School of Science and Technology
Record created by: Linda Sullivan
Date Added: 21 Sep 2022 10:49
Last Modified: 21 Sep 2022 10:49
URI: https://irep.ntu.ac.uk/id/eprint/47060

Actions (login required)

Edit View Edit View

Views

Views per month over past year

Downloads

Downloads per month over past year