<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "https://jats.nlm.nih.gov/publishing/1.3/JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xml:lang="ru">
  <front xmlns:xlink="http://www.w3.org/1999/xlink">
    <journal-meta>
      <journal-id journal-id-type="elibrary">9004</journal-id>
      <journal-title-group>
        <journal-title>Problems of information security. Computer systems</journal-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Проблемы информационной безопасности. Компьютерные системы</trans-title>
        </trans-title-group>
      </journal-title-group>
      <issn pub-type="epub">2071-8217</issn>
    </journal-meta>
    <article-meta xmlns:xlink="http://www.w3.org/1999/xlink">
      <article-id pub-id-type="publisher-id">5</article-id>
      <article-id pub-id-type="doi">10.48612/jisp/k8d8-uu31-54za</article-id>
      <title-group>
        <article-title>Ways to obtain evidential information from a computer using Open Source</article-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Способы получения доказательной информации с компьютера средствами Open Sourсe</trans-title>
        </trans-title-group>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0000-0002-6419-0072</contrib-id>
          <name>
            <surname>Tatarnikova</surname>
            <given-names>Tatiana</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
          <email>Tm-tatarn@yandex.ru</email>
        </contrib>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0000-0001-6289-3295</contrib-id>
          <contrib-id contrib-id-type="scopus">57200960264</contrib-id>
          <name>
            <surname>Sikarev</surname>
            <given-names>Igor</given-names>
          </name>
          <xref ref-type="aff" rid="aff2"/>
          <email>sikarev@yandex.ru</email>
        </contrib>
        <contrib contrib-type="author">
          <name>
            <surname>Rychikhin</surname>
            <given-names>Daniil</given-names>
          </name>
          <xref ref-type="aff" rid="aff2"/>
        </contrib>
      </contrib-group>
      <aff id="aff1">St. Petersburg State University of Aerospace Instrumentation</aff>
      <aff id="aff2">Russian State Hydrometeorological University</aff>
      <pub-date publication-format="electronic" date-type="pub" iso-8601-date="2024-09-20">
        <day>20</day>
        <month>09</month>
        <year>2024</year>
      </pub-date>
      <issue>3</issue>
      <fpage>58</fpage>
      <lpage>68</lpage>
      <self-uri xmlns:xlink="http://www.w3.org/1999/xlink" content-type="pdf" xlink:href="https://jisp.spbstu.ru/userfiles/files/soderzhaniya/2024_3-5-6.pdf"/>
      <abstract xml:lang="en">
        <p>The current task of obtaining evidentiary information as a direction for the development of digital forensics is considered. The procedure for collecting evidentiary information from computer storage devices is given, including the basic requirements for collecting evidence, its safety and ensuring integrity. An overview of methods for obtaining evidentiary information from a computer is given, among which an accessible and effective method is highlighted using Open Source software to form a snapshot of RAM. The results of an experiment to study the possibility of obtaining and analyzing a snapshot of a computer's RAM using Open Source tools are presented and approximate information is determined that can be obtained when using them in the interests of computer technical expertise</p>
      </abstract>
      <kwd-group xml:lang="en">
        <kwd>digital forensics</kwd>
        <kwd>evidentiary information obtained from a computer</kwd>
        <kwd>the procedure for collecting evidentiary information</kwd>
        <kwd>methods for obtaining evidentiary information</kwd>
        <kwd>an experiment on obtaining evidentiary information from a computer</kwd>
      </kwd-group>
    </article-meta>
  </front>
</article>
