发明名称 Physical Memory Forensics System and Method
摘要 The method of the present inventive concept is configured to utilize Operating System data structures related to memory-mapped binaries to reconstruct processes. These structures provide a system configured to facilitate the acquisition of data that traditional memory analysis tools fail to identify, including by providing a system configured to traverse a virtual address descriptor, determine a pointer to a control area, traverse a PPTE array, copy binary data identified in the PPTE array, generate markers to determine whether the binary data is compromised, and utilize the binary data to reconstruct a process.
申请公布号 US2014032875(A1) 申请公布日期 2014.01.30
申请号 US201213560415 申请日期 2012.07.27
申请人 BUTLER JAMES 发明人 BUTLER JAMES
分类号 G06F12/10 主分类号 G06F12/10
代理机构 代理人
主权项
地址