Visible to the public Towards a Generic Approach for Memory Forensics

TitleTowards a Generic Approach for Memory Forensics
Publication TypeConference Paper
Year of Publication2019
AuthorsQawasmeh, Ethar, Al-Saleh, Mohammed I., Al-Sharif, Ziad A.
Conference Name2019 Sixth HCT Information Technology Trends (ITT)
Date Publishednov
ISBN Number978-1-7281-5061-1
KeywordsApplication's data, data mining, data structures, Debugging, Debugging information, digital evidence, Forensics, Human Behavior, human factors, information forensics, Kernel, memory forensics, Metrics, Microsoft Windows, PDB file, pubcrawl, Random access memory, resilience, Resiliency, Scalability
Abstract

The era of information technology has, unfortunately, contributed to the tremendous rise in the number of criminal activities. However, digital artifacts can be utilized in convicting cybercriminal and exposing their activities. The digital forensics science concerns about all aspects related to cybercrimes. It seeks digital evidence by following standard methodologies to be admitted in court rooms. This paper concerns about memory forensics for the unique artifacts it holds. Memory contains information about the current state of systems and applications. Moreover, an application's data explains how a criminal has been interacting the application just before the memory is acquired. Memory forensics at the application level is currently random and cumbersome. Targeting specific applications is what forensic researchers and practitioner are currently striving to provide. This paper suggests a general solution to investigate any application. Our solution aims to utilize an application's data structures and variables' information in the investigation process. This is because an application's data has to be stored and retrieved in the means of variables. Data structures and variables' information can be generated by compilers for debugging purposes. We show that an application's information is a valuable resource to the investigator.

URLhttps://ieeexplore.ieee.org/document/9075122
DOI10.1109/ITT48889.2019.9075122
Citation Keyqawasmeh_towards_2019