کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
458054 696098 2007 6 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
Using every part of the buffalo in Windows memory analysis
موضوعات مرتبط
مهندسی و علوم پایه مهندسی کامپیوتر شبکه های کامپیوتری و ارتباطات
پیش نمایش صفحه اول مقاله
Using every part of the buffalo in Windows memory analysis
چکیده انگلیسی

All Windows memory analysis techniques depend on the examiner's ability to translate the virtual addresses used by programs and operating system components into the true locations of data in a memory image. In some memory images up to 20% of all the virtual addresses in use point to so called “invalid” pages that cannot be found using a naive method for address translation. This paper explains virtual address translation, enumerates the different states of invalid memory pages, and presents a more robust strategy for address translation. This new method incorporates invalid pages and even the paging file to greatly increase the completeness of the analysis. By using every available page, every part of the buffalo as it were, the examiner can better recreate the state of the machine as it existed at the time of imaging.

ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: Digital Investigation - Volume 4, Issue 1, March 2007, Pages 24–29
نویسندگان
,