首页> 外文会议>International Conference for Convergence of Technology >Extraction of forensic evidences from windows volatile memory
【24h】

Extraction of forensic evidences from windows volatile memory

机译:从Windows挥发记忆中提取法医证据

获取原文

摘要

The Windows Volatile memory maintains information about the various activities on the system such as processes and its threads running, registry key open, user authentication details. This paper details out the technique to identify and extract the last access time of a registry key based on the key control block of the key objects in use by the running process. The paper also details out the technique to locate and extract the value of a registry key in use by the running process. A framework to reconstruct the user activities based on the registry key accessed by the running process is proposed. The methods discussed in this paper have been verified on the 32-bit Windows 7 and Windows 8 volatile memory dump.
机译:Windows易失性存储器维护有关系统上各种活动的信息,例如正在运行的进程及其线程,注册表项打开,用户身份验证详细信息。本文详细介绍了基于运行过程中使用的关键对象的密钥控制块来识别和提取注册表项的最后访问时间。本文还详细介绍了在运行过程中定位和提取注册表项的值的技术。提出了一种基于运行进程访问的注册表项重建用户活动的框架。本文讨论的方法已经在32位Windows 7和Windows 8易失性存储器转储上验证。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号