کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
456538 695733 2008 9 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
Recovering deleted data from the Windows registry
موضوعات مرتبط
مهندسی و علوم پایه مهندسی کامپیوتر شبکه های کامپیوتری و ارتباطات
پیش نمایش صفحه اول مقاله
Recovering deleted data from the Windows registry
چکیده انگلیسی

The Windows registry serves as a primary storage location for system configurations and as such provides a wealth of information to investigators. Numerous researchers have worked to interpret the information stored in the registry from a digital forensic standpoint, but no definitive resource is yet available which describes how Windows deletes registry data structures under NT-based systems. This paper explores this topic and provides an algorithm for recovering deleted keys, values, and other structures in the context of the registry as a whole.

ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: Digital Investigation - Volume 5, Supplement, September 2008, Pages S33–S41
نویسندگان
,