RAM Forensics: The Analysis and Extraction of Malicious Processes from Memory Image Using GUI Based Memory Forensic Toolkit

Vivek Ravindra Sali, Harmeet Kaur Khanuja · 2018

In today's world the use of internet and information technology has grown up very rapidly. Due to increasing use of Internet the amount of cyber crimes have been increased. Hence it's become a very challenging task for the cyber crime investigator to not only finds out the root cause of the crime but also to prove it correctly in the court of law. Computer Forensics is the science of investigating the computer system to obtain the digital evidences to find out the root cause of cyber crimes. Memory forensics is one of the branches of the Computer Forensics. The present techniques of memory forensics like Live Response and Memory Imaging, used by investigators during analysis and seizure operations involves either carrying the live analysis of volatile memory(RAM) of victimized computer system or by making the image of the RAM of suspect as machine and performing post analysis on different machine. In this paper Memory imaging approach of RAM analysis is used to find out the malicious processes using the GUI based tool that can analyze the volatile memory artifacts those are affected by malwares. The architecture of extracting the malicious processes is mentioned.

Read the paper · More papers on PaperTik