Invention Grant
- Patent Title: Physical memory forensics system and method
- Patent Title (中): 物理内存取证系统及方法
-
Application No.: US13560415Application Date: 2012-07-27
-
Publication No.: US09268936B2Publication Date: 2016-02-23
- Inventor: James Butler
- Applicant: James Butler
- Applicant Address: US CA Milpitas
- Assignee: MANDIANT, LLC
- Current Assignee: MANDIANT, LLC
- Current Assignee Address: US CA Milpitas
- Agency: Polsinelli PC
- Agent Adam C. Rehm
- Main IPC: G06F12/10
- IPC: G06F12/10 ; G06F21/55 ; G06F21/64

Abstract:
The method of the present inventive concept is configured to utilize Operating System data structures related to memory-mapped binaries to reconstruct processes. These structures provide a system configured to facilitate the acquisition of data that traditional memory analysis tools fail to identify, including by providing a system configured to traverse a virtual address descriptor, determine a pointer to a control area, traverse a PPTE array, copy binary data identified in the PPTE array, generate markers to determine whether the binary data is compromised, and utilize the binary data to reconstruct a process.
Public/Granted literature
- US20140032875A1 Physical Memory Forensics System and Method Public/Granted day:2014-01-30
Information query