Security Incidents mailing list archives

Re: Digital forensics of the physical memory


From: Mariusz Burdach <mariuszburdach () yahoo com>
Date: Thu, 16 Jun 2005 04:43:19 -0700 (PDT)

The only other thing I would like to mention is the
difficulty in
gathering a trustworthy image of physical memory. In
fact I would go so
far as saying that this is an impossibility so long
as the imaging
process relies on the host operating system. 

Thank you for your useful comments.

The primary drawback to use any user or kernel land
tool as a method of collecting evidence from a live
system is a trustworthy of such evidence in the court.

But technology such FireWire seems to be promising.

Regards,
Mariusz Burdach
http://forensic.seccure.net




                
__________________________________ 
Discover Yahoo! 
Use Yahoo! to plan a weekend, have fun online and more. Check it out! 
http://discover.yahoo.com/


Current thread: