首页> 外国专利> Method and program for forensic acquisition of evidence data through security bypass

Method and program for forensic acquisition of evidence data through security bypass

机译:法医通过安全旁路法医获取证据数据的方法和计划

摘要

The present invention relates to a technical idea of acquiring evidence data in a forensic manner through security bypass, and the forensic acquisition method through security bypass according to an embodiment is a link pointed to by the epole data structure that referred to the weight variable in the binder thread data structure. obtaining an access right to the kernel memory area by changing the accessible address restriction variable in the task structure data structure using Searching, overwriting the searched data of the main data structure with a new value to bypass the security function and preparing to execute the desired function, and executing the overwritten new function, evidence recorded in the security area It may include collecting data.
机译:本发明涉及通过安全旁路以取证方式获取证据数据的技术概念,并且根据一个实施例,通过安全旁路的法医采集方法是由漏洞数据结构指向的链路,该漏洞数据结构中引用了重量变量 粘合线程数据结构。 使用搜索更改任务结构数据结构中的可访问地址限制变量来获取到内核内存区域的访问权限,通过新值覆盖主数据结构的搜索到的数据来绕过安全功能并准备执行所需的功能 ,并执行覆盖的新功能,证据记录在安全区域中,其可能包括收集数据。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号