Physical Memory Forensics

Imagine.

You decide, for whatever reason, to write a particularly sensitive document including secrets about your company or government department.

In the middle of typing this document, however, you are sprung: special agents storm into your office while you are typing, drag you away from your computer and take it for forensic analysis.

Just before they pull you away, however, you have the presence of mind to close down your word processor. You never saved the document, so your damning words were never stored permanently on the hard disk. You had previously taken the precaution of disabling the auto-save feature as well. You’re safe.

At least, that’s what you thought.

A few weeks later you’re indicted, based partly on evidence including “documents retrieved from the defendant’s computer”. How is this possible? The document never existed except as patterns of charge in volatile memory – which was fine because memory is volatile, right?

Perhaps not.

About these ads

About Jeffrey Kemp

I’m a Christian, a husband, a father of three, a database programmer and a pianist. I enjoy programming, playing with technology, losing wrestling matches with my kiddies, and long drives to visit the farmers-in-law. My favourite edible substance is Iced Coffee. I also blog about Oracle-related topics at jeffkemponoracle.com.
This entry was posted in The Geek and tagged , . Bookmark the permalink.

One Response to Physical Memory Forensics

  1. Noons says:

    There is a little used setting in windows that will clear the pagefile before a shutdown. I had to set it up a few years ago when working at a RAAF site. It’s not well known that everything a user runs in windows first exists in the pagefile… ;-)

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Connecting to %s