Re: Digital forensics of the physical memory

Mariusz Burdach <[email protected]>
Newsgroups gmane.comp.security.incidents
Message-ID <[email protected]>
> The only other thing I would like to mention is the
> difficulty in
> gathering a trustworthy image of physical memory. In
> fact I would go so
> far as saying that this is an impossibility so long
> as the imaging
> process relies on the host operating system. 

Thank you for your useful comments.

The primary drawback to use any user or kernel land
tool as a method of collecting evidence from a live
system is a trustworthy of such evidence in the court.

But technology such FireWire seems to be promising.

Regards,
Mariusz Burdach
http://forensic.seccure.net




		
__________________________________ 
Discover Yahoo! 
Use Yahoo! to plan a weekend, have fun online and more. Check it out! 
http://discover.yahoo.com/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.