کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
458014 696093 2006 7 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
Searching for processes and threads in Microsoft Windows memory dumps
موضوعات مرتبط
مهندسی و علوم پایه مهندسی کامپیوتر شبکه های کامپیوتری و ارتباطات
پیش نمایش صفحه اول مقاله
Searching for processes and threads in Microsoft Windows memory dumps
چکیده انگلیسی

Current tools to analyze memory dumps of systems running Microsoft Windows usually build on the concept of enumerating lists maintained by the kernel to keep track of processes, threads and other objects. Therefore they will frequently fail to detect objects that are already terminated or which have been hidden by Direct Kernel Object Manipulation techniques.This article analyzes the in-memory structures which represent processes and threads. It develops search patterns which will then be used to scan the whole memory dump for traces of said objects, independent from the aforementioned lists. As demonstrated by a proof-of-concept implementation this approach could reveal hidden and terminated processes and threads, under some circumstances even after the system under examination has been rebooted.

ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: Digital Investigation - Volume 3, Supplement, September 2006, Pages 10–16
نویسندگان
,