首页> 外文会议>2011 IEEE Sixth International Workshop on Systematic Approaches to Digital Forensic Engineering >Firmware-assisted Memory Acquisition and Analysis tools for Digital Forensics
【24h】

Firmware-assisted Memory Acquisition and Analysis tools for Digital Forensics

机译:固件辅助的数字取证存储器获取和分析工具

获取原文
获取原文并翻译 | 示例
获取外文期刊封面目录资料

摘要

Being able to inspect and analyze the operational state of commodity machines is crucial for modern digital forensics. Indeed, volatile system state including memory data and CPU registers contain information that cannot be directly inferred or reconstructed by acquiring the contents of the nonvolatile storage. Unfortunately, it still remains an open problem how to reliably and consistently retrieve the volatile machine state without disrupting its operation. In this paper, we propose to leverage commercial PCI network cards and the current x86 implementation of System Management Mode to reliably replicate the physical memory and critical CPU registers from commodity hardware. Furthermore, we demonstrate how remote state replication can be used for semantic reconstruction, where the analysis of memory structures enables us to interactively perform forensic analysis of the machine's memory content.
机译:能够检查和分析商品机器的运行状态对于现代数字取证至关重要。实际上,包括存储器数据和CPU寄存器在内的易失性系统状态包含无法通过获取非易失性存储的内容直接推断或重构的信息。不幸的是,如何可靠且一致地恢复易失性机器状态而不中断其操作仍然是一个悬而未决的问题。在本文中,我们建议利用商业PCI网卡和系统管理模式的当前x86实施来可靠地复制商品硬件中的物理内存和关键CPU寄存器。此外,我们演示了如何将远程状态复制用于语义重建,其中对内存结构的分析使我们能够交互地执行对计算机内存内容的取证分析。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号