摘要
在取证分析中,从物理镜像恢复有关数据具有重要意义。本文分析和总结镜像中Word文本的规律,采用一种物理地址搜索的方法,可以从内存镜像中提取不同大小的Word文本内容,并且可以重复镜像提取。
In forensic analysis, there is great significance restoring the data from the physical image. This paper analyzes and summarizes the rules of Word text in physical image, proposes a method of searching physical address in physical image, in which different size of Word text can be extracted from, and repeats image extraction.
出处
《计算机与现代化》
2013年第8期165-167,共3页
Computer and Modernization
关键词
内存取证
文本分析
恢复
memory forensics
text analysis
recovery