Netinfo Security ›› 2015, Vol. 15 ›› Issue (3): 44-47.doi: 10.3969/j.issn.1671-1122.2015.03.009

Previous Articles     Next Articles

Obtaining Sensitive Information in RAM by Using the Structure of KPCR

LUO Wen-hua(), SHEN Cheng-xuan   

  1. Department of Cyber Crime Investigation, China Criminal Police University, Shenyang 110854, China
  • Received:2015-01-21 Online:2015-03-10 Published:2015-05-08

Abstract:

Obtaining sensitive information in traditional RAM analysis uses the structures of realizing software in operating system, which has some certain shortcomings in depth and breadth. This paper finds a new way for tracing and extending key content by control structures of bottom hardware administration, illustrates the method of locating position, discusses the characteristics of digital investigation in inner format, provides new thought and method for investigating RAM space. In the part of case analysis, this paper explains specific application of mentioned method based on extensive used Windows 7 currently.

Key words: RAM, digital investigation, KPCR, KPRCB, Windows 7

CLC Number: