发明申请
- 专利标题: Physical Memory Forensics System and Method
- 专利标题(中): 物理内存取证系统和方法
-
申请号: US13560415申请日: 2012-07-27
-
公开(公告)号: US20140032875A1公开(公告)日: 2014-01-30
- 发明人: James Butler
- 申请人: James Butler
- 主分类号: G06F12/10
- IPC分类号: G06F12/10
摘要:
The method of the present inventive concept is configured to utilize Operating System data structures related to memory-mapped binaries to reconstruct processes. These structures provide a system configured to facilitate the acquisition of data that traditional memory analysis tools fail to identify, including by providing a system configured to traverse a virtual address descriptor, determine a pointer to a control area, traverse a PPTE array, copy binary data identified in the PPTE array, generate markers to determine whether the binary data is compromised, and utilize the binary data to reconstruct a process.
公开/授权文献
- US09268936B2 Physical memory forensics system and method 公开/授权日:2016-02-23
信息查询