Publication:
Comprehensive Forensic Data Extraction and Representation System for Windows Registry

dc.contributor.authorW. De Alwis, C
dc.contributor.authorRupasinghe, L
dc.date.accessioned2022-03-23T07:00:11Z
dc.date.available2022-03-23T07:00:11Z
dc.date.issued2019-12-05
dc.description.abstractComputer forensics is the process of methodically examining computer media (hard disks, diskettes, tapes, etc.) for evidence. When considering computer forensics, registry forensics plays a vital role because it helps identifying system configurations, application details, user configurations and helps in finding registry malware. Therefore, it is significant to extract this registry information to simplify the investigations for forensic professionals. At present, tools are limited to few commonly used registry information and there is a much border area to cover. Investigators have to manually search for the registries for required artifacts. But the nature and complexity of the registry file structure limits most of the investigators using these registries. Limiting this registry analysis only to the physical registry files and not considering the ability of extraction of registry information from Volatile Memory is another significant issue in registry forensics. Because these tools are only rely on the physical registry files and cannot extract registry artifacts from Volatile Memory. In order to cater to this problem, this research provide a comprehensive solution to registry analysis. This system is capable of extracting registry information from both physical registry files and Volatile Memory.en_US
dc.identifier.citationW. D. A. Chirath and L. Rupasinghe, "Comprehensive Forensic Data Extraction and Representation System for Windows Registry," 2019 International Conference on Advancements in Computing (ICAC), 2019, pp. 346-350, doi: 10.1109/ICAC49085.2019.9103417.en_US
dc.identifier.doi10.1109/ICAC49085.2019.9103417en_US
dc.identifier.isbn978-1-7281-4170-1
dc.identifier.urihttps://rda.sliit.lk/handle/123456789/1761
dc.language.isoenen_US
dc.publisherIEEEen_US
dc.relation.ispartofseries2019 International Conference on Advancements in Computing (ICAC);Pages 346-350
dc.subjectComprehensiveen_US
dc.subjectForensic Data Extractionen_US
dc.subjectRepresentation Systemen_US
dc.subjectWindows Registryen_US
dc.titleComprehensive Forensic Data Extraction and Representation System for Windows Registryen_US
dc.typeArticleen_US
dspace.entity.typePublication

Files

Original bundle

Now showing 1 - 1 of 1
No Thumbnail Available
Name:
Comprehensive_Forensic_Data_Extraction_and_Representation_System_for_Windows_Registry.pdf
Size:
284.64 KB
Format:
Adobe Portable Document Format
Description:

License bundle

Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed upon to submission
Description: