Hybrid Approach for Memory Analysis in Windows System
نویسندگان
چکیده
Random Access Memory (RAM) is an important device in computer system. It can represent the snapshot on how the computer has been used by the user. With the growth of its importance, the computer memory has been an issue that has been discussed in digital forensics. A number of tools have been developed to retrieve the information from the memory. However, most of the tools have their limitation in the ability of retrieving the important information from the computer memory. Hence, this paper is aimed to discuss the limitation and the setback for two main techniques such as process signature search and process enumeration. Then, a new hybrid approach will be presented to minimize the setback in both individual techniques. This new approach combines both techniques with the purpose to retrieve the information from the process block and other objects in the computer memory. Nevertheless, the basic theory in address translation for x86 platforms will be demonstrated in this paper. Keywords—Algorithms, Digital Forensics, Memory Analysis, Signature Search.
منابع مشابه
A New WordNet Enriched Content-Collaborative Recommender System
The recommender systems are models that are to predict the potential interests of users among a number of items. These systems are widespread and they have many applications in real-world. These systems are generally based on one of two structural types: collaborative filtering and content filtering. There are some systems which are based on both of them. These systems are named hybrid recommen...
متن کاملReliability analysis of repairable systems using system dynamics modeling and simulation
Repairable standby system’s study and analysis is an important topic in reliability. Analytical techniques become very complicated and unrealistic especially for modern complex systems. There have been attempts in the literature to evolve more realistic techniques using simulation approach for reliability analysis of systems. This paper proposes a hybrid approach called as Markov system ...
متن کاملCaffeine attenuates paradoxical sleep deprivation induced- memory impairment during paradoxical sleep windows in rats
There is considerable evidence to support the hypothesis of relationship between paradoxical sleep (PS) and learning–memory processing. It has been suggested that PS is important in memory retention at the specific time course called PS windows (PSW). The time of PSWs occurrence and duration of these PSWs following the training sessions and, the neurochemical nature of PSWs has not been well kn...
متن کاملAn Improved Hybrid Cuckoo Search Algorithm for Vehicle Routing Problem with Time Windows
Transportation in economic systems such as services, production and distribution enjoys a special and important position and provides a significant portion of the country's gross domestic product. Improvements in transportation system mean improvements in the traveling routes and the elimination of unnecessary distances in any system. The Vehicle Routing Problem (VRP) is one of the practical co...
متن کاملCaffeine attenuates paradoxical sleep deprivation induced- memory impairment during paradoxical sleep windows in rats
There is considerable evidence to support the hypothesis of relationship between paradoxical sleep (PS) and learning–memory processing. It has been suggested that PS is important in memory retention at the specific time course called PS windows (PSW). The time of PSWs occurrence and duration of these PSWs following the training sessions and, the neurochemical nature of PSWs has not been well kn...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2012