| | SLO | ENG | Cookies and privacy

Bigger font | Smaller font

Show document Help

Title:DIGITALNA PREISKAVA NEOBSTOJNIH PODATKOV OPERACIJSKIH SISTEMOV WINDOWS
Authors:ID Garantini, Slavko (Author)
ID Kežmah, Boštjan (Mentor) More about this mentor... New window
Files:.pdf VS_Garantini_Slavko_2012.pdf (5,25 MB)
MD5: B6763416DE612975AD0B18B3F96E7F0A
PID: 20.500.12556/dkum/fef55710-83d2-45fc-944c-058d7bb2c30b
 
Language:Slovenian
Work type:Undergraduate thesis
Typology:2.11 - Undergraduate Thesis
Organization:FERI - Faculty of Electrical Engineering and Computer Science
Abstract:Tematika diplomske naloge obsega digitalno preiskavo neobstojnih podatkov operacijskih sistemov Windows. Vzroki in dejanja, ki privedejo do uvedbe preiskave so različni. Neodvisno od uporabljenega orodja in verzije preiskovanega operacijskega sistema potrebujemo metodologijo, ki zagotavlja dosledno zajetje ter analizo neobstojnih podatkov. Preiskavo zato vedno vodimo v štirih fazah, pri čemer zajete podatke preoblikujemo v dokaze. Pomemben vir neobstojnih podatkov predstavlja fizični pomnilnik. Predstavili bomo nekatere teoretične osnove delovanja pomnilnika, načine za ohranitev njegovega stanja ter opravili analizo izdelane slike.
Keywords:digitalna preiskava, neobstojni podatki, fizični pomnilnik, volatility okvir, operacijski sistemi Windows
Place of publishing:Maribor
Publisher:[S. Garantini]
Year of publishing:2012
PID:20.500.12556/DKUM-21915 New window
UDC:004.6.056:004.451(043.2)
COBISS.SI-ID:16166934 New window
NUK URN:URN:SI:UM:DK:9RCLFHVY
Publication date in DKUM:14.03.2012
Views:2311
Downloads:146
Metadata:XML DC-XML DC-RDF
Categories:KTFMB - FERI
:
Copy citation
  
Average score:(0 votes)
Your score:Voting is allowed only for logged in users.
Share:Bookmark and Share



Hover the mouse pointer over a document title to show the abstract or click on the title to get all document metadata.

Secondary language

Language:English
Title:DIGITAL INVESTIGATION OF WINDOWS OPERATING SYSTEMS VOLATILE DATA
Abstract:Subject of this work covers digital investigation of Windows operating systems volatile data. Causes and actions that lead to initiation of the investigation are different. Independent of the tools used and the operating system under investigation, there is a need for methodology to ensure that volatile data is captured and analyzed in consistent manner. Therefor we always conduct investigation in four phases. The process transforms collected data into evidence. Physical memory is important source of volatile data. We will introduce some theoretical basis, ways for collecting physical memory and perform analysis of produced images.
Keywords:digital investigation, volatile data, physical memory, volatility framework, Windows operating systems


Comments

Leave comment

You must log in to leave a comment.

Comments (0)
0 - 0 / 0
 
There are no comments!

Back
Logos of partners University of Maribor University of Ljubljana University of Primorska University of Nova Gorica