【24h】

Windows Memory Analysis Based on KPCR

机译:基于KPCR的Windows内存分析

获取原文
获取原文并翻译 | 示例

摘要

This paper briefiy introduces the challenges facing collection of volatile data in a target computer. Resons to favor physical memory analysis are also given. After describing the related work of the memory analysis, details of a windows memory analysing method are given through which it is possible to extract useful information, such as running processes, current network connections, file contents, etc., from a memory image. The method is based on a data structure in windows known as Kernel Processor Control Region, or KPCR. Besides, details of address translation from virtual address to physical address are thoroughly discussed and an algorithm of address translation for practice is given. This method is verified on Windows XP SP2, Windows 2003 Server SP2 and Windows Vista Home Basic.
机译:本文简要介绍了目标计算机中易失性数据收集所面临的挑战。还提供了支持物理内存分析的方法。在描述了内存分析的相关工作之后,给出了Windows内存分析方法的详细信息,通过该方法可以从内存映像中提取有用的信息,例如运行进程,当前网络连接,文件内容等。该方法基于称为内核处理器控制区域或KPCR的窗口中的数据结构。此外,还详细讨论了从虚拟地址到物理地址的地址转换的细节,并给出了一种实用的地址转换算法。在Windows XP SP2,Windows 2003 Server SP2和Windows Vista Home Basic上已验证此方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号