Live Memory Acquisition through FireWire  被引量:2

Live Memory Acquisition through FireWire

在线阅读下载全文

作  者:Zhang Lei Wang Lianhai Zhang Ruichao Zhang Shubui Zhou Yang 

机构地区:[1]Shandong Provincial Key Laboratory of Computer Network, Jinan 250014, P. R. China Shandong Computer Science Center, Jinan 250014, P. R. China

出  处:《China Communications》2010年第6期78-85,共8页中国通信(英文版)

基  金:This work is supported by the National Natural Science Foundation of China (61070163) and Shandong Natural Science Foundation (Y2008G35).

摘  要:Although FireWire-based memory acquisition method has been introduced for several years, the methodologies are not discussed in detail and still lack of practical tools. Besides, the existing method is not working stably when dealing with different versions of Windows. In this paper, we try to compare different memory acquisition methods and discuss their virtues and disadvantages. Then, the methodologies of FireWire-based memory acquisition are discussed. Finally, we give a practical implementation of FireWire-based acquisition tool that can work well with different versions of Windows without causing BSoD problems.

关 键 词:live forensics memory acquisition FIREWIRE memory analysis Windows registry 

分 类 号:TP336[自动化与计算机技术—计算机系统结构] TN949.12[自动化与计算机技术—计算机科学与技术]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象