Sciweavers

CACM
2006

Live forensics: diagnosing your system without killing it first

13 years 11 months ago
Live forensics: diagnosing your system without killing it first
: Traditional methods of digital forensics analyze a static disk image--a bitstream copy of a disk created while the system is offline. Recent trends--including greatly increased disk capacity and the proliferation of mission-critical systems requiring continuous uptime--have limited the effectiveness and applicability of this approach. Live forensics gathers data from running systems, providing additional contextual information that is not available in a disk-only forensic analysis. This article describes what information live forensics can gather, how to use that information as evidence, and what information is best obtained by live forensic analysis.
Frank Adelstein
Added 11 Dec 2010
Updated 11 Dec 2010
Type Journal
Year 2006
Where CACM
Authors Frank Adelstein
Comments (0)