<?xml version="1.0" encoding="UTF-8"?><marc:collection xmlns:marc="http://www.loc.gov/MARC21/slim">
  <marc:record>
    <marc:leader>00000nam  2200000za 4500</marc:leader>
    <marc:controlfield tag="001">9.821407</marc:controlfield>
    <marc:controlfield tag="003">CaOODSP</marc:controlfield>
    <marc:controlfield tag="005">20240219183451</marc:controlfield>
    <marc:controlfield tag="007">cr |||||||||||</marc:controlfield>
    <marc:controlfield tag="008">160720s2013    onc|||||o    f000 0 eng d</marc:controlfield>
    <marc:datafield tag="040" ind1=" " ind2=" ">
      <marc:subfield code="a">CaOODSP</marc:subfield>
      <marc:subfield code="b">eng</marc:subfield>
    </marc:datafield>
    <marc:datafield tag="041" ind1=" " ind2=" ">
      <marc:subfield code="a">eng</marc:subfield>
      <marc:subfield code="b">fre</marc:subfield>
    </marc:datafield>
    <marc:datafield tag="043" ind1=" " ind2=" ">
      <marc:subfield code="a">n-cn---</marc:subfield>
    </marc:datafield>
    <marc:datafield tag="086" ind1="1" ind2=" ">
      <marc:subfield code="a">D68-6/319-2012E-PDF</marc:subfield>
    </marc:datafield>
    <marc:datafield tag="100" ind1="1" ind2=" ">
      <marc:subfield code="a">Carbone, Richard.</marc:subfield>
    </marc:datafield>
    <marc:datafield tag="245" ind1="1" ind2="4">
      <marc:subfield code="a">The definitive guide to Linux-based live memory acquisition tools</marc:subfield>
      <marc:subfield code="h">[electronic resource] : </marc:subfield>
      <marc:subfield code="b">an addendum to "State fo the art concerning memory acquisition software : a detailed examination of Linux, BSD and Solaris live memory acquisition" / </marc:subfield>
      <marc:subfield code="c">by Richard Carbone and Sébastien Bourdon-Richard.</marc:subfield>
    </marc:datafield>
    <marc:datafield tag="260" ind1=" " ind2=" ">
      <marc:subfield code="a">[Ottawa] : </marc:subfield>
      <marc:subfield code="b">Defence Research and Development Canada, </marc:subfield>
      <marc:subfield code="c">c2013.</marc:subfield>
    </marc:datafield>
    <marc:datafield tag="300" ind1=" " ind2=" ">
      <marc:subfield code="a">xviii, 100 p. : </marc:subfield>
      <marc:subfield code="b">tables, figures.</marc:subfield>
    </marc:datafield>
    <marc:datafield tag="490" ind1="1" ind2=" ">
      <marc:subfield code="a">Technical Memorandum ; </marc:subfield>
      <marc:subfield code="v">2012-319</marc:subfield>
    </marc:datafield>
    <marc:datafield tag="500" ind1=" " ind2=" ">
      <marc:subfield code="a">"September 2013."</marc:subfield>
    </marc:datafield>
    <marc:datafield tag="504" ind1=" " ind2=" ">
      <marc:subfield code="a">Includes bibliographical references.</marc:subfield>
    </marc:datafield>
    <marc:datafield tag="520" ind1=" " ind2=" ">
      <marc:subfield code="a">This technical memorandum is an addendum to TM 2012-008, “State of the art concerning memory acquisition: A detailed examination of Linux, BSD and Solaris live memory acquisition.” It examines in detail two additional software tools, Volatility’s Pmem and LiME’s Linux kernel memory drivers, both of which can be used for the memory acquisition of Linuxbased live computer systems. The authors then compare them with Fmem and Second Look, the two best Linux-based memory acquisition tools as per TM 2012-008. Fmem and Second Look are analysed using the same methodology as for Pmem and LiME. This memorandum also amends information pertaining to the faulty memory acquisition of Fmem as conducted in the previous study. Additionally, certain inaccuracies were made in TM 2012-008. This specific text corrects them. As such, it should now be considered the authoritative reference concerning Linux, UNIX and BSD memory acquisition, although the experiments as conducted in TM 2012- 008 will continue to remain valid. Finally, upon completing the analysis of these tools, the authors recommend the use of LiME for investigative fieldwork. However, other tool-specific recommendations are found and examined in the Conclusion.</marc:subfield>
    </marc:datafield>
    <marc:datafield tag="692" ind1="0" ind2="7">
      <marc:subfield code="2">gccst</marc:subfield>
      <marc:subfield code="a">Technical reports</marc:subfield>
    </marc:datafield>
    <marc:datafield tag="693" ind1=" " ind2="4">
      <marc:subfield code="a">Computer forensics</marc:subfield>
    </marc:datafield>
    <marc:datafield tag="693" ind1=" " ind2="4">
      <marc:subfield code="a">Crash driver</marc:subfield>
    </marc:datafield>
    <marc:datafield tag="693" ind1=" " ind2="4">
      <marc:subfield code="a">Memory acquisition</marc:subfield>
    </marc:datafield>
    <marc:datafield tag="710" ind1="2" ind2=" ">
      <marc:subfield code="a">Defence R&amp;D Canada.</marc:subfield>
    </marc:datafield>
    <marc:datafield tag="830" ind1="#" ind2="0">
      <marc:subfield code="a">Technical memorandum (Defence R&amp;D Canada)</marc:subfield>
      <marc:subfield code="v">2012-319</marc:subfield>
      <marc:subfield code="w">(CaOODSP)9.820564</marc:subfield>
    </marc:datafield>
    <marc:datafield tag="856" ind1="4" ind2="0">
      <marc:subfield code="q">PDF</marc:subfield>
      <marc:subfield code="s">688 KB</marc:subfield>
      <marc:subfield code="u">https://publications.gc.ca/collections/collection_2016/rddc-drdc/D68-6-319-2012-eng.pdf</marc:subfield>
    </marc:datafield>
  </marc:record>
</marc:collection>
