官术网_书友最值得收藏!

Chapter 3. Volatile Data Collection

This chapter is dedicated to some issues that are related to the acquisition of data, which has changed very fast. Due to its nature, it reflects the state of the system at a certain time because the collection of data takes place on a live system.

The Request for Comments RFC 3227 document provides a list of digital evidence and the order in which it should be collected. The main principle that should guide this is that the most rapidly changing data should be collected first.

The list of evidence from RFC comprises the following:

  • Registers and cache CPU
  • Routing table, ARP cache, process table, kernel statistics, and memory
  • Temporary filesystems
  • Disk
  • Remote logging and monitoring data that is relevant to the system's media
  • Physical configuration and network topology
  • Archival media

According to this list, the volatile data which should be collected first are memory and network related data.

主站蜘蛛池模板: 惠来县| 建德市| 阿瓦提县| 南安市| 万荣县| 石泉县| 南阳市| 乌兰浩特市| 青河县| 安吉县| 桑植县| 余江县| 丁青县| 兰溪市| 嘉峪关市| 长治市| 正蓝旗| 周口市| 太白县| 包头市| 绥棱县| 巫溪县| 军事| 津市市| 和龙市| 宣城市| 成安县| 龙游县| 海宁市| 磴口县| 广平县| 邵阳县| 洞头县| 五华县| 商洛市| 泗水县| 镇巴县| 静乐县| 广宁县| 玉环县| 邹平县|