期刊文献+

Windows内核变量定位与应用研究

Researches on Windows kernel variable locating and application
下载PDF
导出
摘要 Windows内核变量是内存分析过程中经常需要使用到的数据,但是由于Windows操作系统的封闭性,定位到Windows内核变量的位置非常困难。前人提出了一些内核变量定位的方法,但是在实验后发现,结果并不尽人意。针对这一现状,在前人的算法上进行了改进,提出一种基于虚拟地址转换的算法,使得可以准确定位内核变量位置。另外,也提出了一个基于Windows XP全新的内核变量快速定位方法。最后,以内核变量MmPhysicalMemoryBlock的应用为例,提出了基于MmPhysicalMemoryBlock的内存数据快速导出算法。实验结果表明,2个内核变量定位算法能准确的定位内核变量,内存数据快速导出算法也能准确完整的导出需要的内存数据。 The data of Windows kernel variables was used frequently on the analysis of memory. But locating these kernel variables was limited by the operating system. Former scholars have proposed some algorithms of Windows kernel variables locating. But after experiments, the result was not satisfactory. With an improvement on precedent algorithms, an algorithm based on virtual address translation was proposed for accurately locating kernel variables. It could improve the accuracy of locating the kernel variables. And, an innovative fast locating algorithm based on the Windows XP kernel variables was proposed. At last, a fast memory data export algorithm based on MmPhysicalMemoryBlock was suggested with the example of kernel variable MmPhysicalMemoryBlock application. The experiments showed that, these two kernel variables locating algorithm are able to locate kernel variables preciesty, the fast memory data export algorithm is able to export wanted memory data with accuracy and integrity.
作者 车生兵 易文
出处 《电子测量技术》 2015年第5期27-32,共6页 Electronic Measurement Technology
关键词 内核变量定位 内存取证 MmPhysicalMemoryBlock 内存分析 locate Windows kernel variables memory forensic MmPhysicalMemoryBlock memory analyze
  • 相关文献

参考文献4

二级参考文献27

  • 1姜红艳,那艳.Windows的虚拟内存管理与优化[J].鞍山师范学院学报,2005,7(4):69-71. 被引量:5
  • 2陈龙,王国胤.计算机取证技术综述[J].重庆邮电学院学报(自然科学版),2005,17(6):736-741. 被引量:48
  • 3Schuster A.Searching for processes and threads in microsoft Windows memory dumps[C/OL]//Proceedings of the 2006 Digital Forensic Research Workshop (DFRWS), 2006.http ://www.dfrws.org/2006/proceedings/2-Schuster.pdf.
  • 4Burdach M.Digital forensics of the physical memory[EB/OL].(2005- 03 ).http ://(orensie .seecurc.net/pdf/mburdaeh_digital_forensies of physical_memory.pdf.
  • 5Carvey A.Windows forensic analysis[M/OL]//Sample Chapter:Windows Memory Analysis.[S.l.] : Sgngress, 2007.http ://www.syngress.com/hook_catalog/sample 159749156X.PDF.
  • 6Burdach M.An introduction to Windows memory forensic[EB/OL]. ( 2005 -07 ). http ://forensic. seccure. net/pdf/introduction_to windows_ memory_forensic.pdf.
  • 7Intel Corporation.Intel 64 and IA-32 architectures software developer's manual volume 3A:System programming guide [EB/OL]. (2007-11 ).http://www.intel.com/design/processor/manuals/253668.pdf.
  • 8朱琳.Pentium 4 CPU对系统存储体系的管理分析[J].农业网络信息,2007(9):148-150. 被引量:1
  • 9Mark Russinovich,David Solomon.深入解析WINDOWS操作系统--Microsoft Windows.北京:电子工业出版社,2007
  • 10William S. Davis, T. M. Rajkumar. Operating Systems. A Systematic View(Six edition).北京:中国电力出版社,2007.

共引文献13

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部