In this paper, we give a clear description of the running memory acquiring tool on a target system, especially for possibility covering the key trace during capturing volatile memory. Some key trace of offender may still in the running memory after the scene of a crime and have critical role in court and security applications. However, some key trace, such as rootkits in the memory, memory occupied by their corresponding process will probably be covered/reallocated during the procedure of obtaining evidence of the crime. Therefore, the covered ratio (lost data) should be evaluated and investigated after the forensic tools run. Firstly, we model the distribution of key trace exacted in the unallocated memory space, then form a formula to evaluate the coverage rate of the key trace in which the corresponding process has just been killed. At last, we give some cases to analyze the evidence coverage ratio which can be estimated by the new allocated memory space. (C) 2011 Published by Elsevier Ltd. Selection and/or peer-review under responsibility of Harbin University of Science and Technology
This article has been retracted: please see Elsevier Policy on Article Withdrawal (http://www.elsevier.com/locate/withdrawalpolicy). This article has been retracted at the request of the Editor. The authors have plagiarized part of a paper that had already appeared in Digital Investigation, 8 (2011) 3–22. http://dx.doi.org/10.1016/j.diin.2011.06.002. One of the conditions of submission of a paper for publication is that authors declare explicitly that their work is original and has not appeared in a publication elsewhere. Re-use of any data should be appropriately cited. As such this article represents a severe abuse of the scientific publishing system. The scientific community takes a very strong view on this matter and apologies are offered to readers of the journal that this was not detected during the submission process.