Volume 2 Number 6 (Nov. 2013)
Home > Archive > 2013 > Volume 2 Number 6 (Nov. 2013) >
IJCCE 2013 Vol.2(6): 702-705 ISSN: 2010-3743
DOI: 10.7763/IJCCE.2013.V2.278

Object Signature Search for Capturing Processes Memory

Khairul Akram Zainol Ariffin, Ahmad Kamil Mahmood, Jafreezal Jaafar, and Solahuddin Shamsuddin
Abstract—Over the past few years, memory analysis has been an issue that has been discussed in digital forensics. With the introduction of cloud computing, the analysis on memory has become critical as the hard disk is no longer the primary choice to store information and data on the computer system. The online storages with password protected such as ADrive, Dropbox and Google Cloud Storage are already available to all users. Hence, with the progress of development in this technology, the traditional approach (analysis on hard drive) has become obsolete in obtaining information from those applications. The aim of this paper is to present an algorithm that can be used to trace the processes of the memory image. The algorithm uses the signature search to find the possible process that is stored in the memory dump. Then, by the information in Parent ProcessID (PPID) and ProcessID (PID) the Process Block Tree is constructed. Further, the benchmarking test between Process Enumeration technique and this new algorithm is presented in this paper.

Index Terms—Algorithms, Information Retrieval, Memory Analysis, Signature Search.

K. A. Z. Ariffin is with the Digital Forensic Department, CyberSecurity Malaysia, Mines, Selangor, Malaysia (e-mail: akram@cybersecurity.my).
A. K. Mahmood and J. Jaafar are with the Computer Information Sciences Department, Universiti Teknologi Petronas, Perak, Malaysia (e-mail: kamilmh@petronas.com.my, jafreez@petronas.com.my).
S. Shamsuddin is with the Research Department, Cyber Security Malaysia, Mines, Selangor, Malaysia (e-mail: solahuddin@cybersecurity.my).

Cite:Khairul Akram Zainol Ariffin, Ahmad Kamil Mahmood, Jafreezal Jaafar, and Solahuddin Shamsuddin, "Object Signature Search for Capturing Processes Memory," International Journal of Computer and Communication Engineering vol. 2, no. 6, pp. 页码, 2013.

General Information

ISSN: 2010-3743 (Online)
Abbreviated Title: Int. J. Comput. Commun. Eng.
Frequency: Quarterly
Editor-in-Chief: Dr. Maode Ma
Abstracting/ Indexing: INSPEC, CNKI, Google Scholar, Crossref, EBSCO, ProQuest, and Electronic Journals Library
E-mail: ijcce@iap.org
  • Dec 29, 2021 News!

    IJCCE Vol. 10, No. 1 - Vol. 10, No. 2 have been indexed by Inspec, created by the Institution of Engineering and Tech.!   [Click]

  • Mar 17, 2022 News!

    IJCCE Vol.11, No.2 is published with online version!   [Click]

  • Dec 29, 2021 News!

    The dois of published papers in Vol. 9, No. 3 - Vol. 10, No. 4 have been validated by Crossref.

  • Dec 29, 2021 News!

    IJCCE Vol.11, No.1 is published with online version!   [Click]

  • Sep 16, 2021 News!

    IJCCE Vol.10, No.4 is published with online version!   [Click]

  • Read more>>