TY - GEN
T1 - Digital evidence collection process in integrity and memory information gathering
AU - Lee, Seokhee
AU - Kim, Hyunsang
AU - Lee, Sangjin
AU - Lim, Jongin
PY - 2005
Y1 - 2005
N2 - In this paper, we inspect general digital evidence collection process which is according to RFC3227 document[1], and establish specific steps for guaranteeing integrity of digital evidence and memory information collection, EnCase™[4] which was used globally has a weakness that MDC value of digital evidence can be modified, hence we propose MDC public system, MAC system and Public authentication system with PKI as a countermeasure. And we explain detail of each system. Besides, we include memory dump process to existing digital evidence collection process, and examine privacy information through dumping real user's memory and collecting pagefile which is part of virtual memory system.
AB - In this paper, we inspect general digital evidence collection process which is according to RFC3227 document[1], and establish specific steps for guaranteeing integrity of digital evidence and memory information collection, EnCase™[4] which was used globally has a weakness that MDC value of digital evidence can be modified, hence we propose MDC public system, MAC system and Public authentication system with PKI as a countermeasure. And we explain detail of each system. Besides, we include memory dump process to existing digital evidence collection process, and examine privacy information through dumping real user's memory and collecting pagefile which is part of virtual memory system.
UR - http://www.scopus.com/inward/record.url?scp=33847209935&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=33847209935&partnerID=8YFLogxK
U2 - 10.1109/SADFE.2005.9
DO - 10.1109/SADFE.2005.9
M3 - Conference contribution
AN - SCOPUS:33847209935
SN - 0769524788
SN - 9780769524788
T3 - Proceedings - First International Workshop on Systematic Approaches to Digital Forensic Engineering
SP - 236
EP - 247
BT - Proceedings - First International Workshop on Systematic Approaches to Digital Forensic Engineering
T2 - Proceedings - First International Workshop on Systematic Approaches to Digital Forensic Engineering
Y2 - 7 November 2005 through 9 November 2005
ER -