官术网_书友最值得收藏!

Collection

The collection element is where digital forensic examiners begin the process of acquiring the digital evidence. When examining digital evidence, it is important to understand the volatile nature of some of the evidence that an examiner will want to look at. Volatile evidence is evidence that can be lost when a system is powered down. For network equipment this could include active connections or log data that is stored on the device. For laptops and desktops, volatile data includes running memory or the Address Resolution Protocol cache. The Internet Engineering Task Force (IETF) has put together a document titled Guidelines forEvidence Collection and Archiving (RFC 3227) that addresses the order of volatility of digital evidence:

  • Registers, cache
  • Routing Table, ARP Cache, process table, kernel statistics, Memory (RAM)
  • Temporary filesystems
  • Disk
  • Remote logging and monitoring data
  • Physical configuration, network topology
  • Archival media

It is imperative that digital forensic examiners take this volatility into account when starting the process of evidence collection. Methods should be employed where volatile evidence will be collected and moved to a non-volatile medium such as an external hard drive.

主站蜘蛛池模板: 阳泉市| 积石山| 仁怀市| 中卫市| 长寿区| 慈溪市| 大城县| 清镇市| 额尔古纳市| 大英县| 河津市| 沐川县| 榆林市| 壶关县| 金溪县| 大厂| 响水县| 子洲县| 米脂县| 赞皇县| 余姚市| 灵石县| 沧州市| 宁武县| 周至县| 罗平县| 天气| 科尔| 万宁市| 拉萨市| 黔西| 金昌市| 永丰县| 无锡市| 喀喇沁旗| 定兴县| 甘谷县| 临武县| 建平县| 安平县| 张家界市|