Skip to main navigation Skip to search Skip to main content

A scenario-based quality assessment of memory acquisition tools and its investigative implications

  • Lisa Rzepka*
  • , Jenny Ottmann
  • , Radina Stoykova
  • , Felix Freiling
  • , Harald Baier
  • *Corresponding author for this work

Research output: Contribution to journalArticleAcademicpeer-review

6 Citations (Scopus)
101 Downloads (Pure)

Abstract

During digital forensic investigations volatile data from random-access memory (RAM) can provide crucial information such as access credentials or encryption keys. This data is usually obtained using software that copies contents of RAM to a memory dump file concurrently to normal system operation. It is well-known that this results in many inconsistencies in the copied data. Based on established quality criteria from the literature and on four typical investigative scenarios, we present and evaluate a methodology to assess the quality of memory acquisition tools in these scenarios. The methodology basically relates three factors: (1) the quality criteria of the memory dump, (2) the applied memory forensics analysis technique, and (3) its success in the given investigative scenario. We apply our methodology to four memory acquisition tools (from both the open source and the commercial community). It turns out that all tools have weaknesses but that their inconsistencies appear to be not as bad as anticipated. Another finding is that unstructured memory analysis methods are more robust against low quality (i.e., inconsistent) memory dumps than structured analysis methods. We provide the measurement dataset together with the tool by which it was acquired and also examine our findings in the context of legal and international standards for digital forensics in law enforcement investigations.

Original languageEnglish
Article number301868
Number of pages10
JournalForensic Science International: Digital Investigation
Volume52
Issue numberS
DOIs
Publication statusPublished - Mar-2025

Keywords

  • Criminal investigation
  • Digital forensics
  • Law enforcement
  • RAM acquisition
  • Reliability validation
  • Tool testing
  • Volatile storage acquisition

Fingerprint

Dive into the research topics of 'A scenario-based quality assessment of memory acquisition tools and its investigative implications'. Together they form a unique fingerprint.

Cite this