The Study of Text Evidence in Memory

Article Preview

Abstract:

The text message which has been viewed and edited is stored in physical memory. In this paper, we take the notepad process as sample, designs a recovery scheme for user’s viewing-data and judge whether the document was edited, First this scheme extracts the data of all notepad’s process in memory with the member information of the process’s EPROCESS structure, and then, matches the data with the target string, thus, it can recovery the viewing-data of a different order. Experiments show that this scheme can recovery the text message when the user browsing in the last minutes and analyze the behavior of the user.

You might also be interested in these eBooks

Info:

Periodical:

Pages:

6266-6269

Citation:

Online since:

May 2014

Export:

Price:

Permissions CCC:

Permissions PLS:

Сopyright:

© 2014 Trans Tech Publications Ltd. All Rights Reserved

Share:

Citation:

* - Corresponding Author

[1] Dolan Gavitt: Digital Forensic Research Workshop (Baltimore, MD, August 11-13, 2008), pp.26-32.

Google Scholar

[2] Okolica J, Peterson G: Digital Forensic Research Workshop (Portland, Oregon, August 2-4, 2010), pp.48-56.

Google Scholar

[3] L. Chen, L. Zhang and Q. Y. Tian: Journal of Chongqing Universities of Posts and Telecommunications, Vol. 25 (2013) No. 6, p.854.

Google Scholar

[4] M. Richard, Stevens and Eoghan Casey: Digital Investigation Journal, Vol. 7 (2010) No. 6, p.57.

Google Scholar

[5] Y. H. Gao, T. J. Cao: Journal of Computers, Vol. 5 (2010) No. 4, p.541.

Google Scholar

[6] J. Okolica, G. Peterson: Digital Investigations Journal, Vol. 9 (2011) No. 7, p.118.

Google Scholar

[7] Funminiyi, Akanfe and Olajide:  A study of application level information from the volatile memory of Windows computer systems (Ph.D., University of Portsmouth, England 2011), p.27.

Google Scholar

[8] Information on http: /secmeeting. ihep. ac. cn/paper/Paper_Chen_Long_ICDFI2012. pdf.

Google Scholar

[9] L. Chen, K. Jing: Journal of Chongqing Universities of Posts and Telecommunications, Vol. 1 (2013) No. 25, p.122.

Google Scholar