A Remote Forensics System Based on Physical Memory Analysis

A physical memory and memory analysis technology, which is applied in the field of cloud forensics analysis, can solve problems such as data tampering, inability to transmit in real time, difficulty in proving integrity and authenticity, etc., to shield hardware structure differences, improve work efficiency, and ensure The effect of reliability and validity

Inactive Publication Date: 2017-02-22
SHANDONG COMP SCI CENTNAT SUPERCOMP CENT IN JINAN
View PDF1 Cites 0 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

Third, the current traditional online forensics method requires all kinds of forensics tools to run in the target computer system to complete the data collection and analysis, which makes the evidence collection activities seriously affect the credibility of the certificate, even if it is obtained It is also difficult to prove the integrity and authenticity of some evidence, especially with the development of core state Trojan horses and anti-forensics technology, the data obtained by many online tools may have been tampered with
This patent only transmits information such as voice calls and videos. The specific content may have been changed before transmission, and such information cannot be transmitted in real time.

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • A Remote Forensics System Based on Physical Memory Analysis

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0039] Below in conjunction with embodiment, further illustrate the present invention.

[0040] see figure 1 , the present invention includes:

[0041] Client: mirror the physical memory of the client, store it locally, and calculate the hash value of the image file, then call the physical memory analysis command line program to analyze the image file, and send the analysis result together with the image file to the server;

[0042] Server: listen to the client, if there is a client connection request, the server connection is confirmed, and the connection is successful, the server will start to receive the client information after receiving the identification string sent by the client to start sending information, mainly collecting client information The physical memory image file and the corresponding image file analysis results on the client side, the server adopts multi-threading, can collect the physical memory image files and memory analysis results information of sever...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

PUM

No PUM Login to view more

Abstract

The invention provides a remote evidence taking system based on physical memory analysis. The remote evidence taking system is characterized by comprising a client and a server, wherein a physical memory of the client is mirrored and stored locally, and a mirror image file is subjected to hash value calculation; the mirror image file is analyzed by calling a physical memory analysis line program, and an analysis result and the mirror image file are sent to the server together; the server is used for monitoring the client; if a client connection request is provided, a client fixing character string is sent, and the physical memory mirror image file and the corresponding mirror image file analysis result of the client are mainly collected; the server collects multiple threads and can simultaneously collect the physical memory mirror image files of multiple clients and memory analysis result information and store the memory analysis results into a database; on the other hand, the server is connected with a remote control terminal to mainly send log information of the client to the remote control terminal; retrieval information meeting retrieval conditions are searched from the database according to the conditions of the remote control terminal.

Description

technical field [0001] The present invention relates to the field of cloud forensics and analysis, in particular to a forensics and analysis of physical memory image files of remote target terminals, and specifically refers to a remote forensics system based on physical memory analysis. Background technique [0002] In the process of electronic data forensics, the analysis process of forensic data often depends on the personal experience and thinking and judgment of the forensics personnel to select the appropriate analysis method to realize the detection and analysis of electronic forensics data, because the analysis of forensics data by forensics personnel often has A variety of analysis methods are involved. This personal subjective choice of forensic analysis method is not only not conducive to the full and effective use of forensic data, but also has a negative impact on the efficiency of forensics. In addition, the number of cases requiring evidence collection has inc...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

Application Information

Patent Timeline
no application Login to view more
Patent Type & Authority Patents(China)
IPC IPC(8): G06F17/30H04L29/08
CPCG06F16/168G06F16/1815G06F16/183H04L67/025H04L67/1095
Inventor 杨淑棉王连海韩晓晖赵大伟张淑慧刘广起
Owner SHANDONG COMP SCI CENTNAT SUPERCOMP CENT IN JINAN
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products