Hidden Process Offline Forensic Based on Memory Analysis in Windows

来源 :Wuhan University Journal of Natural Sciences | 被引量 : 0次 | 上传用户:lili123456li
下载到本地 , 更方便阅读
声明 : 本文档内容版权归属内容提供方 , 如果您对本文有版权争议 , 可与客服联系进行内容授权或下架
论文部分内容阅读
Malicious software programs usually bypass the detection of anti-virus software by hiding themselves among apparently legitimate programs.In this work,we propose Windows Virtual Machine Introspection(WVMI)to accurately detect those hidden processes by analyzing memory data.WVMI dumps in-memory data of the target Windows operating systems from hypervisor and retrieves EPROCESS structures’address of process linked list first,and then generates Data Type Confidence Table(DTCT).Next,it traverses the memory and identifies the similarities between the nodes in process linked list and the corresponding segments in the memory by utilizing DTCT.Finally,it locates the segments of Windows’EPROCESS and identifies the hidden processes by further comparison.Through extensive experiments,our experiment shows that the WVMI detects the hidden process with high identification rate,and it is independent of different versions of Windows operating system. Malicious software programs usually bypass the detection of anti-virus software by hiding themselves among apparently legitimate programs. In this work, we propose Windows Virtual Machine Introspection (WVMI) to accurately detect those hidden processes by analyzing memory data. WVMI dumps in-memory data of the target Windows operating systems from hypervisor and retrieves EPROCESS structures’ appendix of process linked list first, and then generates Data Type Confidence Table (DTCT) .Next, it traverses the memory and identifies the similarities between the nodes in process linked list and the corresponding segments in the memory by utilizing DTCT.Finally, it locates the segments of Windows’EPROCESS and identifies the hidden processes by further. 13.hrough extensive experiments, our experiment that that the WVMI detects the hidden process with high identification rate, and it is independent of different versions of Windows operating system.
其他文献
群众工作能力是党员干部的基本功,是不可或缺的“第一能力”。当前,为使一些党员干部在群众工作中尽快克服“新办法不会用,老办法不管用,硬办法不敢用,软办法不顶用”的难题,
This paper proposes an unequal error protection(UEP)coding method to improve the transmission performance of three-dimensional(3D)audio based on expanding windo
期刊
雷公藤内酯醇(triptolide,TP),是从植物雷公藤(Tripterygium wilfordii Hook F)中提取的环氧二萜内酯类化合物,具有抗癌、抗老年痴呆、抗类风湿及抗炎免疫抑制等作用。但是,研究发现TP的有效剂量与中毒剂量极为相近,这大大的限制了其临床使用。因此,如何减少TP所致毒性并保持其良好的药理作用,成为近年来研究的一大热点。茅苍术为菊科植物茅苍术Atractylodes
每当看到一部好的作品时,总是会被作品的美而吸引。可为什么有时自己做出的作品本以为可以锁住观众的视线,却得不到欣赏,无法产生共鸣。在今天这样一个读图时代里,人们总是乐
请下载后查看,本文暂不支持在线获取查看简介。 Please download to view, this article does not support online access to view profile.
期刊
杜尔伯特县教育系统党委为办好人民满意教育,深刻理解马克思主义群众观点和党的群众路线,全力加以践行和落实,不断提升基础设施建设水平,逐渐完善工作机制,尽快提升教师业务
Wearable devices usually work together with smart phones.To ensure only legitimate smart phones can read the data,they must conduct pairing to establish a share
期刊
伴随着社会经济的快速发展,水文测验工作也面临了一些新的问题和挑战,这就需要我们对新时期的水文测验工作有个全新的认识,积极地、创造性地面对水文测验工作。本文详细地阐述了
目的:初步探讨自体脐带血血清(humanumbilicalcordbloodserum,hCBS)培养对人羊膜间充质干细胞(humanamnioticmesenchymalstemcells,hAMSCs)增殖、表面分子和某些特征性蛋白表达的影
由于食品和药品中基质成分比较复杂,而待测定的有机化合物的含量通常又是痕量的,所以在样品分析之前必须要对样品进行前处理。固相萃取和液相萃取已经被广泛用于样品前处理的过程,但是由于其操作复杂、萃取耗时长、不经济、以及会对环境造成二次污染等缺点,它们已经难以满足社会和人们对样品前处理的需求,所以在此基础上建立一种快速、环保、低廉、高效、自动化的新型样品前处理技术是社会和人们共同的需求。本论文以离子液体和