Netinfo Security ›› 2015, Vol. 15 ›› Issue (3): 44-47.doi: 10.3969/j.issn.1671-1122.2015.03.009
Previous Articles Next Articles
LUO Wen-hua(), SHEN Cheng-xuan
Received:
Online:
Published:
Abstract:
Obtaining sensitive information in traditional RAM analysis uses the structures of realizing software in operating system, which has some certain shortcomings in depth and breadth. This paper finds a new way for tracing and extending key content by control structures of bottom hardware administration, illustrates the method of locating position, discusses the characteristics of digital investigation in inner format, provides new thought and method for investigating RAM space. In the part of case analysis, this paper explains specific application of mentioned method based on extensive used Windows 7 currently.
Key words: RAM, digital investigation, KPCR, KPRCB, Windows 7
CLC Number:
TP309
LUO Wen-hua, SHEN Cheng-xuan. Obtaining Sensitive Information in RAM by Using the Structure of KPCR[J]. Netinfo Security, 2015, 15(3): 44-47.
0 / / Recommend
Add to citation manager EndNote|Ris|BibTeX
URL: http://netinfo-security.org/EN/10.3969/j.issn.1671-1122.2015.03.009
http://netinfo-security.org/EN/Y2015/V15/I3/44