A Method of Extracting Picture in Memory

Article Preview

Abstract:

Memory forensics can provide crucial evidence or further investigation clues, it also has a direct connection with field investigation. Image is a common and intuitive way to express information, and has direct effect as evidence. This article analyzes the characteristics of common image formats (BMP, PNG, JPEG, GIF) data stored in the memory and summarizes some rules of extracting the picture data. On this basis, the article proposed a method of extracting picture data from the memory image. The experimental results show that picture data can be accurately recovered from the image.

You might also be interested in these eBooks

Info:

Periodical:

Pages:

5186-5189

Citation:

Online since:

May 2014

Authors:

Export:

Price:

Permissions CCC:

Permissions PLS:

Сopyright:

© 2014 Trans Tech Publications Ltd. All Rights Reserved

Share:

Citation:

* - Corresponding Author

[1] Schuster Andreas. Digital Forensic Research Workshop (Lafayette, Indiana, August 14-16, 2006). pp.6-10.

Google Scholar

[2] Zhang Ruichao, Wang Lianhai, Zhang Shuhui, 2009 Fifth international conference on information assurance and security (. Xi'an, August 18-20, 2009) Vol. 2, pp.677-680.

Google Scholar

[3] T Xiang, M. L Gou . Computer Engineering and Applications . Vol. 49(2013) No. 19 p: 67-71.

Google Scholar

[4] L.H. Wang, L. J Xu, S. H Zhang. China Communications. Vol. 7(2010), No. 6. pp.44-51.

Google Scholar

[5] J Okolica, G Peterson. Digital Forensic Research Workshop (Portland, Oregon, August 2-4, 2010). pp.48-56.

Google Scholar

[6] F. A Olajide: A study of application level information from the volatile memory of Windows computer systems (PhD., University of Portsmouth, England 2011) p.27.

Google Scholar

[7] A . Castiglione, G. Cattaneo, A. D Santis. 2011 Third International Conference on Intelligent Networking and Collaborative Systems (Japan , Nov. 30 – Dec. 2 , 2011) pp.679-684.

DOI: 10.1109/incos.2011.17

Google Scholar

[8] L Chen, K Jing, Q. Y Tian. Journal of Chongqing University of Posts and Telecommunications (Natural Science Edition). Vol. 1 (2013) No. 25, p.122.

Google Scholar

[9] S Vomel , F C. Freiling . Digital Investigation . Vol. 8 (2011) No. 1. p: 3-22.

Google Scholar