期刊文献+

An Approach to Analyze Physical Memory Image File of Mac OS X

An Approach to Analyze Physical Memory Image File of Mac OS X
下载PDF
导出
摘要 Memory analysis is one of the key techniques in computer live forensics. Especially,the analysis of a Mac OS X operating system's memory image file plays an important role in identifying the running status of an apple computer. However,how to analyze the image file without using extra"mach-kernel"file is one of the unsolved difficulties. In this paper,we firstly compare several approaches for physical memory acquisition and analyze the effects of each approach on physical memory. Then,we discuss the traditional methods for the physical memory file analysis of Mac OS X. A novel physical memory image file analysis approach without using extra"mach-kernel"file is proposed base on the discussion. We verify the performance of the new approach on Mac OS X 10. 8. 2. The experimental results show that the proposed approach is simpler and more practical than previous ones. Memory analysis is one of the key techniques in computer live forensics. Especially, the analysis of a Mac OS X operating system' s memory image file plays an important role in identifying the running status of an apple computer. However, how to analyze the image file without using extra" roach_ kernel" file is one of the unsolved difficulties. In this paper, we firstly compare several approaches for physical memory acquisition and analyze the effects of each approach on physical memory. Then, we discuss the traditional methods for the physical memory file analysis of Mac OS X. A novel physical memory image file analysis approach without using extra" mach_kernel" file is proposed base on the discussion. We verify the performance of the new approach on Mac OS X 10. 8. 2. The experimental results show that the proposed approach is simpler and more practical than previous ones.
出处 《Journal of Harbin Institute of Technology(New Series)》 EI CAS 2014年第4期116-120,共5页 哈尔滨工业大学学报(英文版)
基金 Sponsored by the National Natural Science Foundation of China (Grant No.61303199) Natural Science Foundation of Shandong Province (Grant No.ZR2013FQ001 and ZR2011FQ030) Outstanding Research Award Fund for Young Scientists of Shandong Province (Grant No.BS2013DX010) Academy of Sciences Youth Fund Project of Shandong Province (Grant No.2013QN007)
关键词 computer forensics live forensics Mac OS X operating system physical memory analysis computer forensics live forensics Mac OS X operating system physical memory analysis
  • 相关文献

参考文献16

  • 1Matthew J, Warren G, Bill L, et al.Dispelling Common Myths of “Live Digital Forensics”.https://www.dfcb.org/docs/LiveDigitalForensics-MythVersusReality.pdf.2011-01-01.
  • 2Inoue H, Adelstein F, Joyce R A.Visualization in testing a volatile memory forensic tool.Digital Investigation, 1,8(Suppl.): S42-S51.
  • 3Singh A.In Mac OS X Internals: A Systems Approach (Bonus Content).United States of America: Pearson Education, Inc., 2006.
  • 4Suiche M.Mac OS X physical memory analysis.Black Hat DC.https://www.blackhat.com/presentations/bh-dc-10/Suiche-Matthieu/Blackhat-DC-2010-Advanced-Mac-OS-X-Physical-Memory-Analysis-wp.pdf.2010-01-01.
  • 5Cyber Marshal Utilities.Mac Memory Reader.http://www.cybermarshal.com/index.php/cyber-marshal-utilities/mac-memory-reader.2014-03-01.
  • 6Johannes S.OSXPmem.https://code.google.com/p/rekall/source/browse/OSXPmem.2013-02-16.
  • 7Ligh M H, Adair S, Hartstein B, et al.Malware Analyst’S Cookbook and DVD: Tools and Techniques for Fighting Malicious Code.Indianapolis, IN: Wiley, 2011.
  • 8Adam B.Hit by a Bus: Physical Access Attacks with FireWire.http://www.security-assessment.com/files/presentations/ab-firewire-rux2k6-final.pdf.2014-05-01.
  • 9Becher M, Dornseif M, Klein C N.FireWire: All your memory are belong to us .CanSecWest.2005.https://cansecwest.com/core05/2005-firewire-cansecwest.pdf.2005-01-01.
  • 10Hermann U.Physical memory attacks via Firewire/DMA.Personal Blog.http://www.hermann-uwe.de/blog/physical-memory-attacksvia-firewire-dma-part-1-overview-and-mitigation.2008-01-01.

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部