首页> 外文会议>International Conference on Intelligent Data Acquisition and Advanced Computing Systems >New possibilities for memory acquisition by enabling DMA using network card
【24h】

New possibilities for memory acquisition by enabling DMA using network card

机译:通过使用网卡启用DMA来获取内存采集的新可能性

获取原文
获取外文期刊封面目录资料

摘要

Direct memory access is one of the techniques used in forensic analysis and rootkit detection. Unfortunately, it can also be misused in various attacks. E.g., the firewire attack enabled bypassing of Windows authorization by reading the user password stored in memory. Thus, for security reasons, firewire port is usually disabled in many computers. This motivates a search for a new ways of enabling direct memory access. Another potential avenue for DMA enabled memory access seems to be the network card. We designed a new solution for direct memory access, based on a custom NDIS protocol driver that can send (on request of the local executable program) the contents of the computer memory over the network. Our new method allows an unexpected type of the direct memory access, which is independent of the processor, and its control capabilities. This is a strong advantage in rootkit detection, because the rootkit cannot take any action to hide itself while the memory is scanned.
机译:直接存储器访问是法医分析和rootkit检测中使用的技术之一。不幸的是,它也可以在各种攻击中滥用。例如,通过读取存储在内存中的用户密码,通过绕过Windows授权,防火防火攻击。因此,出于安全原因,在许多计算机中通常禁用FireWire端口。这激励了一种搜索启用直接内存访问的新方法。 DMA支持的内存访问的另一个潜在大道似乎是网卡。我们设计了一种新的用于直接内存访问的解决方案,基于自定义NDIS协议驱动程序,可以发送(根据本地可执行程序)通过网络上的计算机内存的内容发送(根据本地可执行程序)。我们的新方法允许意外类型的直接内存访问,它与处理器无关及其控制功能。这是rootkit检测中的强大优势,因为rootkit无法在扫描内存时无法采取任何操作来隐藏。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号