摘要
为了快速定位目标活动进程,提取对应的物理内存数据,分析了Windows系统中进程运行时其EPROCESS结构的特性及作用,提出了基于EPROCESS特征的物理内存查找方法。该方法利用EPROCESS结构的特性,定位出活动进程的EPROCESS结构,找出进程页目录基地址,并根据虚拟地址描述符的功能,提取活动进程物理内存。实验结果表明,该方法能快速、有效地定位活动进程,提取出活动进程物理内存,缩小取证分析范围,提高取证效率。
To quickly locate the target active processes,and extract the corresponding physical memory data,EPROCESS structure's role and characteristics are analyzed.A method of searching physical memory based on EPROCESS characteristics is proposed.This method uses the characteristics of EPROCESS structure,locates active processes' EPROCESS structure,finds out the process page directory base address,and extracts the corresponding physical memory data according to the virtual address descriptor's function.Experiments show that the proposed method can quickly and efficiently locate the target active processes,and extract the corresponding physical memory data.This method narrows the range of forensic analysis and improves evidence collection efficiency.
出处
《重庆邮电大学学报(自然科学版)》
CSCD
北大核心
2013年第1期122-125,131,共5页
Journal of Chongqing University of Posts and Telecommunications(Natural Science Edition)
基金
重庆市教委科学技术研究项目(KJ110505)
重庆市科技攻关计划项目(CSTC
2011AC2155)~~