【24h】

Research on Windows Physical Memory Forensic Analysis

机译:Windows物理内存取证分析研究

获取原文
获取原文并翻译 | 示例

摘要

A plenty of computer evidence cannot be seized from hard disks, they must be seized from physical memory of the computer system, once the computer system is powered off, they will all be disappeared. In this paper, the basic concepts and related works of physical memory forensic analysis are presented, and the key technology of physical memory forensic analysis of Windows systems is investigated. An example about physical memory forensic analysis of Windows system is also given. Finally based on the analysis of the deficiency for the current work on physical memory forensic analysis, future work on the improvement of physical memory forensic analysis is discussed.
机译:无法从硬盘上捕获大量计算机证据,必须从计算机系统的物理内存中捕获它们,一旦计算机系统断电,它们都将消失。本文介绍了物理内存取证分析的基本概念和相关工作,并对Windows系统的物理内存取证分析的关键技术进行了研究。还给出了有关Windows系统的物理内存取证分析的示例。最后,在对当前物理记忆法医学分析工作的不足进行分析的基础上,讨论了未来物理记忆法医学分析工作的改进工作。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号