Memory forensic: detecting unusual intrusion activity in dump of RAM memory using FTK imager


연구 분야: Analysis



학회: International Journal of Information Technology


초록

Memory forensics helps the forensic investigator to detect any unusual activity. In this paper, we have discussed memory forensics and how to dump the content of primary memory RAM (Random Access Memory) using the FTK (Forensic Tool Kit) Imager tool. This memory dump helps to detect unusual activity in the systems, and we have also demonstrated the detection of hacker activities (find the traces of ping commands initiated by a hacker, get the traces of credentials used by the hacker) in the memory dump. Our proposed memory forensics methodology is based on the Identification, Prevention, Analysis, Documentation, and Presentation methodology. Our proposed technique will help law enforcement agencies, government organisations, and cyber forensic investigators to solve high-level cybercrimes.


Author Profile
Bishwajeet Pandey

GL Bajaj Institute of Technology and Management Greater Noida India

Andorra
Author Profile
Amit Kumar

Gyancity Research Consultancy Greater Noida India

India
Author Profile
Deepak Bhaskar Acharya

The University of Alabama in Huntsville Huntsville AL USA

Albania

📄 논문 정보

발행 연도 2025년
인용수 0
출판 국가 Andorra, India, Albania
사이트 Springer
좋아요 수 0

연관 논문 목록 (186건)