Home > Published Issues > 2023 > Volume 14, No. 5, 2023 >
JAIT 2023 Vol.14(5): 950-959
doi: 10.12720/jait.14.5.950-959

Live Memory Forensics Investigations: A Comparative Analysis

Irfan Syamsuddin 1,* and Dedy Syamsuar 2
1. CAIR Center for Applied ICT Research, Department of Computer and Network Engineering, State Polytechnic of Ujung Pandang, Makassar, Indonesia
2. Information Systems Department, School of Information Systems, Bina Nusantara University, Jakarta, Indonesia; Email: dedy.syamsuar@binus.ac.id (D.S.)
*Correspondence: irfans@poliupg.ac.id (I.S.)

Manuscript received February 3, 2023; revised May 11, 2023; accepted May 24 2023; published September 22, 2023.

Abstract—The escalating dependence on information technology for daily activities ensures that cybercrime cases continue unabated. Consequently, the role of cyber forensics investigators is becoming increasingly crucial in addressing the surge of cybercrime incidents. Live forensics investigation, a challenging facet of digital evidence investigation, confronts several limitations. This study focuses on the complexities associated with retrieving digital evidence from volatile memory during live forensics investigations, explicitly comparing the efficacy of extracting digital evidence from DDR2 and DDR3 Random Access Memory (RAM). This study aims to analyze and compare potential variations in evidence acquisition outcomes between the two RAM types by applying three distinct scenarios: identifying registry and network activities, catching malicious codes, and obtaining login passwords on Social Media. The results demonstrate that DDR2 RAM exhibits a lower propensity for concealing digital evidence during live forensics investigations compared to DDR3 RAM. The implications of these findings are discussed, along with suggestions for potential ramifications and avenues for future research.
 
Keywords—computer forensics, random access memory, DDR2, DDR3, digital evidence, live forensics investigation

Cite: Irfan Syamsuddin and Dedy Syamsuar, "Live Memory Forensics Investigations: A Comparative Analysis," Journal of Advances in Information Technology, Vol. 14, No. 5, pp. 950-959, 2023.

Copyright © 2023 by the authors. This is an open access article distributed under the Creative Commons Attribution License (CC BY-NC-ND 4.0), which permits use, distribution and reproduction in any medium, provided that the article is properly cited, the use is non-commercial and no modifications or adaptations are made.