
http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.
변환된 중국어를 복사하여 사용하시면 됩니다.
Windows 10 내의 hiberfil.sys 파일에 대한 포렌식 활용 방안
방수민(Sumin Bang),진필근(Philgeun Jin),김동현(Donghyun Kim),박정흠(Jungheum Park),이상진(Sangjin Lee),박아란(Aran Park),조병모(Byoungmo Cho),정일훈(Ilhoon Jung) 한국디지털포렌식학회 2021 디지털 포렌식 연구 Vol.15 No.1
Windows provides a variety of power saving options and store volatile memory data as the hiberfil.sys file in a auxiliary memory according to option selection. Especially, when the fast start option is activated, the memory area of the Windows kernel and driver loaded in the volatile memory just before the end of the system is backed up in the auxiliary memory, so that the memory data can be secured in not only the active system but also the inactive state. This has led to the possibility of memory forensics through memory data obtained from the hiberfil.sys file in the inactive system. Based on this possibility, in this paper, we propose a method to track file copy traces to external storage devices that were performed just before the end of the system based on file system driver-related objects managed in the kernel area of memory data.