Digital Archaeology of Volatile Data on a Linux Platform

Vanja Korać · Arheologija i prirodne nauke · 2013

It is necessary to gather, analyse and store data on a "live" system in order to detect, in time, whether there is incident/illegal activity taking place.Since it is very important to collect volatile data, in this paper ways of collecting are described as well as tools which are related to them on a Linux platform.In the paper, the following volatile data are named which are gathered from compromised systems:System time and date, the existing network connexions, open TCP and UDP ports, executive files which open TCP and UDP ports, processes and services started, opened files, internet routing and cache tables, read modules and the kernel, memory and memory process content and mounted system file.

Read the paper · More papers on PaperTik