p.1767
p.1771
p.1779
p.1783
p.1787
p.1791
p.1795
p.1799
p.1804
Analysis of User Activity Based on Registry in RAM
Abstract:
As important evidences and clue sources in computer crime investigation, the information of user activity plays an important role in the aspect of revealing detail of offender’s operation. The specific keys of registry in RAM are related to specific user activity. The structures of registry in RAM are different from in disk, especially in the aspect of cell index translation. Based on analysis of data structure for registry in RAM, this paper introduces the technology of cell index translation in detail. Also summarizes the keys closely related to user activity, and illustrates the method of analysis of user activity based on registry in RAM with real case. The method is proved to be accurate and efficient in real work of digital investigation.
Info:
Periodical:
Pages:
1787-1790
Citation:
Online since:
January 2013
Authors:
Keywords:
Price:
Сopyright:
© 2013 Trans Tech Publications Ltd. All Rights Reserved
Share:
Citation: