𝔖 Bobbio Scriptorium
✦   LIBER   ✦

Volatile data vs. data at rest: the requirements of digital forensics

✍ Scribed by Dario V Forte


Publisher
Elsevier Science
Year
2008
Tongue
English
Weight
79 KB
Volume
2008
Category
Article
ISSN
1353-4858

No coin nor oath required. For personal study only.

✦ Synopsis


Data residing in the RAM, system, or internal/external peripheral memory. According to RFC 3227 (a master document issued by the Internet Engineering Task Force), these are the first data that should be acquired during a forensic investigation. 1 β€’ Data at rest: Data in the file system. This article will explain in detail how these data are subdivided and discuss system components and event tracking information, such as that found in the various types of log files.

Recent changes to Italian legislation, following the enactment of the Budapest Convention on Cybercrime, and the federal rules for the management of digital evidence in American civil law (which are sure to have an impact in Europe), demand regulatory measures to address at least two points. 2 The first concerns preservation, or maintenance of the integrity of original data and making faithful copies of the data to be used for analysis purposes. The second concerns the format of presentation and analysis, which relates more to legal users than forensics examiners.


πŸ“œ SIMILAR VOLUMES