Memory-Based antiforensic tools and techniques

Jahankhani, Hamid and Beqiri, Elidon (2008) ‘Memory-Based antiforensic tools and techniques’, International Journal of Information Security and Privacy, 2(2), pp. 1-13.

Jahankhani, H (2008) IJISP 2 (2) 1-13.pdf - Accepted Version
Available under License Creative Commons Attribution No Derivatives.

Download (495Kb) | Preview
Official URL:


Computer forensics is the discipline that deals with the acquisition, investigation, preservation, and presentation of digital evidence in the court of law. Whereas antiforensics is the terminology used to describe malicious activities deployed to delete, alter, or hide digital evidence with the main objective of manipulating, destroying, and preventing the creation of evidence. Various antiforensic methodologies and tools can be used to interfere with digital evidence and computer forensic tools. However, memory-based antiforensic techniques are of particular interest because of their effectiveness, advanced manipulation of digital evidence, and attack on computer forensic tools. These techniques are mainly performed in volatile memory using advanced data alteration and hiding techniques. For these reasons memory-based antiforensic techniques are considered to be unbeatable. This article aims to present some of the current antiforensic approaches and in particular reports on memory-based antiforensic tools and techniques.

Item Type: Article
Additional Information: Citation: Jahankhani, H.; Beqiri, E. (2008) ‘Memory-Based antiforensic tools and techniques’ International Journal of Information Security and Privacy, 2 (2) pp.1-13.
Divisions: Schools > Architecture Computing and Engineering, School of
Depositing User: Mr Stephen Grace
Date Deposited: 04 Jan 2011 11:34
Last Modified: 27 Sep 2012 11:59

Actions (login required)

View Item View Item