کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
10342340 696042 2016 8 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
Pool tag quick scanning for windows memory analysis
ترجمه فارسی عنوان
تجزیه و تحلیل حافظه فلش اسکن سریع استخر
موضوعات مرتبط
مهندسی و علوم پایه مهندسی کامپیوتر شبکه های کامپیوتری و ارتباطات
چکیده انگلیسی
Pool tag scanning is a process commonly used in memory analysis in order to locate kernel object allocations, enabling investigators to discover evidence of artifacts that may have been freed or otherwise maliciously hidden from the operating system. The fastest current scanning techniques require an exhaustive search of physical memory, a process that has a linear time complexity over physical memory size. We propose a novel technique that we are calling “pool tag quick scanning” that is able to reduce the scanning space by 1-2 orders of magnitude, resulting in much faster discovery of targeted kernel data structures, while maintaining a high degree of accuracy.
ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: Digital Investigation - Volume 16, Supplement, 29 March 2016, Pages S25-S32
نویسندگان
, , ,