TY - JOUR
T1 - A partially reconstructed previous Gmail session by live digital evidences investigation through volatile data acquisition
AU - Chu, Hai Cheng
AU - Yang, Szu Wei
AU - Park, Jong Hyuk
PY - 2012/10
Y1 - 2012/10
N2 - The essence of this paper is to illustrate live data acquisition within the random access memory of a notebook trying to utilize the collected digital evidences in order to partially reconstruct previous Gmail session, which could be probative digital evidence in a court of law. The proposed framework is essentially crucial for the investigation of certain related cybercrimes on the basis of the digital breadcrumb trails being professionally disclosed and appropriately handled. Without loss of generality, the volatile data would vanish forever when the power of the computing devices is no longer sustainable. This research pinpoints the imminent threat of IT savvy cyber criminals and the corresponding counter procedures used to crack criminal cases if web-based e-mail utilities are essentially involved. This paper is focused on the prevalent e-mail utility, Gmail, as the research subject. At last, live digital evidence acquisition must be accurately fulfilled before the seizure of the computing devices in the crime scene to avoid irreversible investigation procedures which mean the digital evidences could be deleted, resulting in the loss of probative evidence.
AB - The essence of this paper is to illustrate live data acquisition within the random access memory of a notebook trying to utilize the collected digital evidences in order to partially reconstruct previous Gmail session, which could be probative digital evidence in a court of law. The proposed framework is essentially crucial for the investigation of certain related cybercrimes on the basis of the digital breadcrumb trails being professionally disclosed and appropriately handled. Without loss of generality, the volatile data would vanish forever when the power of the computing devices is no longer sustainable. This research pinpoints the imminent threat of IT savvy cyber criminals and the corresponding counter procedures used to crack criminal cases if web-based e-mail utilities are essentially involved. This paper is focused on the prevalent e-mail utility, Gmail, as the research subject. At last, live digital evidence acquisition must be accurately fulfilled before the seizure of the computing devices in the crime scene to avoid irreversible investigation procedures which mean the digital evidences could be deleted, resulting in the loss of probative evidence.
KW - Digital evidence
KW - Digital forensics
KW - Gmail session reconstruction
KW - Volatile memory acquisition
UR - https://www.scopus.com/pages/publications/84867614353
U2 - 10.1002/sec.511
DO - 10.1002/sec.511
M3 - Article
AN - SCOPUS:84867614353
SN - 1939-0114
VL - 5
SP - 1193
EP - 1198
JO - Security and Communication Networks
JF - Security and Communication Networks
IS - 10
ER -