发明申请
US20140032875A1 Physical Memory Forensics System and Method 有权
物理内存取证系统和方法

  • 专利标题: Physical Memory Forensics System and Method
  • 专利标题(中): 物理内存取证系统和方法
  • 申请号: US13560415
    申请日: 2012-07-27
  • 公开(公告)号: US20140032875A1
    公开(公告)日: 2014-01-30
  • 发明人: James Butler
  • 申请人: James Butler
  • 主分类号: G06F12/10
  • IPC分类号: G06F12/10
Physical Memory Forensics System and Method
摘要:
The method of the present inventive concept is configured to utilize Operating System data structures related to memory-mapped binaries to reconstruct processes. These structures provide a system configured to facilitate the acquisition of data that traditional memory analysis tools fail to identify, including by providing a system configured to traverse a virtual address descriptor, determine a pointer to a control area, traverse a PPTE array, copy binary data identified in the PPTE array, generate markers to determine whether the binary data is compromised, and utilize the binary data to reconstruct a process.
公开/授权文献
信息查询
0/0