Acquisition of Network Connection Status Information from Physical Memory on Windows Vista Operating System  

Acquisition of Network Connection Status Information from Physical Memory on Windows Vista Operating System

在线阅读下载全文

作  者:Xu Lijuan Wang Lianhai Zhang Lei Kong Zhigang 

机构地区:[1]Shandong Provincial Key Laboratory of Computer Network, Jinan 250014, P. R. China Shandong Computer Science Center, Jinan 250014, P. R. China

出  处:《China Communications》2010年第6期71-77,共7页中国通信(英文版)

基  金:This work is supported by the National Natural Science Foundation of China (61070163) and Shandong Natural Science Foundation (Y2008G35).

摘  要:A method to extract information of network connection status information from physical memory on Windows Vista operating system is proposed. Using this method, a forensic examiner can extract accurately the information of current TCP/ IP network connection information, including IDs of processes which established connections, establishing time, local address, local port, remote address, remote port, etc., from a physical memory on Windows Xflsta operating system. This method is reliable and efficient. It is verified on Windows Vista, Windows Vista SP1, Windows Vista SP2.

关 键 词:computer forensic memory analysis network connection status information 

分 类 号:TP316.7[自动化与计算机技术—计算机软件与理论] TN965.5[自动化与计算机技术—计算机科学与技术]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象