کد مقاله | کد نشریه | سال انتشار | مقاله انگلیسی | نسخه تمام متن |
---|---|---|---|---|
458054 | 696098 | 2007 | 6 صفحه PDF | دانلود رایگان |
![عکس صفحه اول مقاله: Using every part of the buffalo in Windows memory analysis Using every part of the buffalo in Windows memory analysis](/preview/png/458054.png)
All Windows memory analysis techniques depend on the examiner's ability to translate the virtual addresses used by programs and operating system components into the true locations of data in a memory image. In some memory images up to 20% of all the virtual addresses in use point to so called “invalid” pages that cannot be found using a naive method for address translation. This paper explains virtual address translation, enumerates the different states of invalid memory pages, and presents a more robust strategy for address translation. This new method incorporates invalid pages and even the paging file to greatly increase the completeness of the analysis. By using every available page, every part of the buffalo as it were, the examiner can better recreate the state of the machine as it existed at the time of imaging.
Journal: Digital Investigation - Volume 4, Issue 1, March 2007, Pages 24–29