A method to extract information of network connection status information from physical memory on Windows Vista operating system is proposed. Using this method, a forensic examiner can extract accurately the informatio...A method to extract information of network connection status information from physical memory on Windows Vista operating system is proposed. Using this method, a forensic examiner can extract accurately the information of current TCP/ IP network connection information, including IDs of processes which established connections, establishing time, local address, local port, remote address, remote port, etc., from a physical memory on Windows Xflsta operating system. This method is reliable and efficient. It is verified on Windows Vista, Windows Vista SP1, Windows Vista SP2.展开更多
The Network Attachment Subsystem (NASS) is introduced to the Next Generation Network (NGN) architecture to enable services independent from access networks and support nomadism for fixed terminals. The NASS is respons...The Network Attachment Subsystem (NASS) is introduced to the Next Generation Network (NGN) architecture to enable services independent from access networks and support nomadism for fixed terminals. The NASS is responsible for managing the users attached to the access network in terms of user authentication, allocation of the IP address, and location management. In NGN R1, Telecommunications and Internet Converged Services and Protocols for Advanced Networking (TISPAN) studied the internal architecture and external interface protocols of NASS and published the relevant technical specifications. In NGN R2, TISPAN focuses on the study of mobility and nomadism as well as the ability to support various access network architectures. There still remain several issues that need further study.展开更多
基金This work is supported by the National Natural Science Foundation of China (61070163) and Shandong Natural Science Foundation (Y2008G35).
文摘A method to extract information of network connection status information from physical memory on Windows Vista operating system is proposed. Using this method, a forensic examiner can extract accurately the information of current TCP/ IP network connection information, including IDs of processes which established connections, establishing time, local address, local port, remote address, remote port, etc., from a physical memory on Windows Xflsta operating system. This method is reliable and efficient. It is verified on Windows Vista, Windows Vista SP1, Windows Vista SP2.
文摘The Network Attachment Subsystem (NASS) is introduced to the Next Generation Network (NGN) architecture to enable services independent from access networks and support nomadism for fixed terminals. The NASS is responsible for managing the users attached to the access network in terms of user authentication, allocation of the IP address, and location management. In NGN R1, Telecommunications and Internet Converged Services and Protocols for Advanced Networking (TISPAN) studied the internal architecture and external interface protocols of NASS and published the relevant technical specifications. In NGN R2, TISPAN focuses on the study of mobility and nomadism as well as the ability to support various access network architectures. There still remain several issues that need further study.