Please use this identifier to cite or link to this item: https://rda.sliit.lk/handle/123456789/2776
Title: Forensic Investigation Tool for Volatility Framework
Authors: Rupasinghe, R
Fernando, D. N
Keywords: Volatility Framework
Forensic Investigation
Issue Date: Mar-2022
Publisher: www.ijisrt.com
Series/Report no.: International Journal of Innovative Science and Research Technology;Volume 7, Issue 3
Abstract: According to many research findings, the volatile memory has become a more vital space used by attackers and malicious users to store data that needs to be covert from others and avoid reverse-engineering. Since most incident response teams seldom study the volatile memory and lack the knowledge and equipment needed to extract information from it, there is plenty of data to back this up. Furthermore, the recent development of malicious codes can remain in the memory without affecting the physical disk. Therefore security analysts must prioritize and investigate the volatile memory as an important component rather than being following traditional logic thinking that the malicious users will only look into hard disk storage. The Volatility Framework is an open-source and free set of tools to analyze computer memory. This framework provides many options for data analysis in different aspects as a command-line interface. This makes complications for forensic analysts to memorize and use the tools and plugins. This research offers a GUI and extensions for the Volatility Framework, which simplifies the usage and provides a time-saving approach as the investigators do not want to memorize long command sequences.
URI: http://rda.sliit.lk/handle/123456789/2776
ISSN: 2456-2165
Appears in Collections:Research Papers - Dept of Computer Systems Engineering
Research Papers - Open Access Research
Research Papers - SLIIT Staff Publications

Files in This Item:
File Description SizeFormat 
IJISRT22MAR657_(1).pdf476.77 kBAdobe PDFView/Open


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.