2025/05/21 by Jenny Ottmann, Ottmann, Jenny, Frank Breitinger +3
Computer Science · #Advanced Malware Detection Techniques #Cloud Data Security Solutions #Cryptography and Security (cs.CR) #Digital and Cyber Forensics #FOS: Computer and information sciences
paper · doi:10.48550/arxiv.2505.15921
openalex publication_date 2025/05/21 · openalex created_date 2025/10/10 · openalex updated_date 2026/08/01
The acquisition of data from main memory or from hard disk storage is usually one of the first steps in a forensic investigation. We revisit the discussion on quality criteria for "forensically sound" acquisition of such storage and propose a new way to capture the intent to acquire an instantaneous snapshot from a single target system. The idea of our definition is to allow a certain flexibility into when individual portions of memory are acquired, but at the same time require being consistent with causality (i.e., cause/effect relations). Our concept is much stronger than the original notion of atomicity defined by Vomel and Freiling (2012) but still attainable using copy-on-write mechanisms. As a minor result, we also fix a conceptual problem within the original definition of integrity.