...
首页> 外文期刊>Digital investigation >Whitelisting system state in windows forensic memory visualizations
【24h】

Whitelisting system state in windows forensic memory visualizations

机译:在Windows法医内存可视化中将系统状态列入白名单

获取原文
获取原文并翻译 | 示例
           

摘要

Examiners in the field of digital forensics regularly encounter enormous amounts of data and must identify the few artifacts of evidentiary value. One challenge these examiners face is manual reconstruction of complex datasets with both hierarchical and associative relationships. The complexity of this data requires significant knowledge, training, and experience to correctly and efficiently examine. Current methods provide text-based representations or low-level visualizations, but levee the task of maintaining global context of system state on the examiner. This research presents a visualization tool that improves analysis methods through simultaneous representation of the hierarchical and associative relationships and local detailed data within a single page application. A novel whitelisting feature further improves analysis by eliminating items of less interest from view. Results from a pilot study demonstrate that the visualization tool can assist examiners to more accurately and quickly identify artifacts of interest. Published by Elsevier Ltd.
机译:数字取证领域的审查员经常会遇到大量数据,并且必须确定证据价值极少的人工制品。这些审查员面临的挑战之一是手动重建具有层次关系和关联关系的复杂数据集。此数据的复杂性需要大量知识,培训和经验,才能正确有效地进行检查。当前的方法提供了基于文本的表示形式或低级的可视化效果,但是使维护检查者上系统状态的全局上下文的任务告吹。这项研究提出了一种可视化工具,可通过在单个页面应用程序中同时表示层次结构和关联关系以及局部详细数据来改进分析方法。新颖的白名单功能通过消除视图中不那么感兴趣的项进一步改善了分析。一项初步研究的结果表明,可视化工具可以帮助检查员更准确,更快速地识别感兴趣的工件。由Elsevier Ltd.发布

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号