4Prosise C, Mandia K, Pepe M. Incident response & comput- er forensics[D]. McGraw-Hill/Osborne, 2003.
5Technical working Gmup for Electric Crime Scene Investiga- tion[D]. Electronic Crime Scene Investigation: A Guide for First Responders, 2001.
6Zhang L, Wang L and Zhang R, Live memory acquisition through firewire, Forensics in Telecommunications, Informa- tion, and Multimedia[D]. Springer Berlin Heidelberg, 2011.
7Halderman J A, Schoen S D, Heninger N, Lest we remem- ber: cold-boot attacks on encryption keys[J]. Communications of the ACM, 2009, (2):91-98.