Locating ×86 paging structures in memory images

نویسندگان

  • Karla Saur
  • Julian B. Grizzard
چکیده

Digital memory forensics consists of analyzing various components of a memory image from a compromised host. A memory image consists of data and processes that were running on the system at the time the image was created. Previously running processes are one of the key items in memory images to identify, including potentially hidden processes. Each process has its own paging structures that define its address space, so locating the paging structures can potentially lead to finding all of the processes that were running. In this paper, we describe an algorithm to locate paging structures in a memory image of an 86 platform running either Linux or Windows XP. The algorithm can be used to find paging structures for potential processes that were hidden by rootkits or other malware. Furthermore, if the system was running an 86 virtual machine, the algorithm can locate paging structures associated with both the host kernel and the guest kernel processes. Our algorithm relies more on the constructs of the 86 hardware and less on the operating system running on top of the hardware. This means that the algorithm works for many different operating systems with only minor tweaking. a 2010 Elsevier Ltd. All rights reserved.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

TLB Performance in Multiprocessors by Patricia

This paper compares the performance, in highly-parallel shared-memory multiprocessors, of locating translation-lookaside buffers (TLBs) at processors with that of locating TLBs at memory. Our performance comparison is based on results of trace-driven simulations of multiprocessors with logN-stage networks interconnecting N processors and N memory modules. For the systems and workloads studied, ...

متن کامل

Bloom Filter- Cost Effective Paging Mechanism

In a high-capacity cellular network with limited spectral resources, it is desirable to minimize the radio bandwidth costs associated with paging while locating mobile users. Reduction of communication overhead has become a burning issue of today. It induces the intellects to innovate some means which are cost reducing by nature. Location management aims to reduce this overhead through predicti...

متن کامل

Membrane: A Posteriori Detection of Malicious Code Loading by Memory Paging Analysis

In this paper, we design and implement Membrane, a memory forensics tool to detect code loading behavior by stealthy malware. Instead of trying to detect the code loading itself, we focus on the changes it causes on the memory paging of the Windows operating system. As our method focuses on the anomalies caused by code loading, we are able to detect a wide range of code loading techniques. Our ...

متن کامل

Paging strategy optimization in personal communication systems

Mobility tracking is concerned with finding a mobile subscriber (MS) within the area serviced by the wireless network. The two basic operations for tracking an MS, location updating and paging, constitute additional load on the wireless network. The total cost of updating and paging can be minimized by optimally dividing the cellular area into location registration (LR) areas. In current system...

متن کامل

Flash Memory Shadow Paging Scheme for Portable Computers: Design and Performance Evaluation

Recently, a flash memory has become a major database storage in building portable information devices because of its non-volatile, shock-resistant, power-economic nature, and fast access time for read operations. We propose a new scheme called flash memory shadow paging (FMSP) for efficient page management in a flash memory database environment. We improved traditional shadow paging schemes by ...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:
  • Digital Investigation

دوره 7  شماره 

صفحات  -

تاریخ انتشار 2010