首页|基于FireWire总线的动态内存获取

基于FireWire总线的动态内存获取

扫码查看
Live Memory Acquisition through FireWire
Although FireWire-based memory acquisition method has been introduced for several years,the methodologies are not discussed in detail and still lack of practical tools.Besides,the existing method is not working stably when dealing with different versions of Windows.In this paper,we try to compare different memory acquisition methods and discuss their virtues and disadvantages.Then,the methodologies of FireWire-based memory acquisition are discussed.Finally,we give a practical implementation of FireWire-based acquisition tool that can work well with different versions of Windows without causing BSoD problems.

live forensicsmemory acquisitionFireWirememory analysisWindows registry

张磊、王连海、张睿超、张淑慧、周洋

展开 >

Shandong Provincial Key Laboratory of Computer Network,Jinan 250014,P.R.China

Shandong Computer Science Center,Jinan 250014,P.R.China

live forensics memory acquisition FireWire memory analysis Windows registry

国家自然科学基金Shandong Natural Science Foundation

61070163Y2008G35

2010

中国通信(英文版)

中国通信(英文版)

CSCDSCI
影响因子:0.463
ISSN:1673-5447
年,卷(期):2010.(6)
  • 2
  • 10