首页> 外文会议>2010 3rd International Conference on Advanced Computer Theory and Engineering >Exploratory study on memory analysis of Windows 7 operating system
【24h】

Exploratory study on memory analysis of Windows 7 operating system

机译:Windows 7操作系统内存分析的探索性研究

获取原文

摘要

Several new features of Windows 7 may provide new challenges for memory investigation, and also offer opportunities for acquiring more forensically sensitive information which can be recovered and extracted from the memory image file. This paper analyzed the new features in Windows 7 and developed the memory analysis method according to these new features. The method is based on the data structure in windows which is known as Kernel Processor Control Region (KPCR). Details of address translation from virtual address to physical address are presented, including three steps: acquisition of KPCR structure, acquisition the address of CR3 register and address translation algorithm. Running processes, object type and registry can be extracted by this method. It is verified on 32-bit Windows 7 and 64-bit Windows 7.
机译:Windows 7的几个新功能可能会给内存调查带来新的挑战,也为获取更多可从内存映像文件中恢复和提取的法证敏感信息提供了机会。本文分析了Windows 7中的新功能,并根据这些新功能开发了内存分析方法。该方法基于窗口中的数据结构,该结构称为内核处理器控制区域(KPCR)。详细介绍了从虚拟地址到物理地址的地址转换,包括三个步骤:获取KPCR结构,获取CR3寄存器的地址和地址转换算法。通过此方法可以提取正在运行的进程,对象类型和注册表。已在32位Windows 7和64位Windows 7上进行了验证。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号