Investigating the Hooking Behavior: A Page-Level Memory Monitoring Method for Live Forensics

Author:

Cheng Yingxin,Fu Xiao,Luo Bin,Yang Rui,Ruan Hao

Publisher

Springer International Publishing

Reference31 articles.

1. Adelstein, F.: Live forensics: Diagnosing your system without killing it first. Commun. ACM 49(2), 63–66 (2006)

2. Al-Shaer, E., Jha, S., Keromytis, A.D. (eds.): Proceedings of the 2009 ACM Conference on Computer and Communications Security, CCS 2009, Chicago, Illinois, USA, November 9-13. ACM (2009)

3. AMD: Amd virtualization (2014), http://www.amd.com/us/solutions/servers/virtualization/Pages/virtualization.aspx

4. Arasteh, A.R., Debbabi, M.: Forensic memory analysis: From stack and code to execution history. Digital Investigation 4, 114–125 (2007)

5. Athreya, M.B.: Subverting linux on-the-fly using hardware virtualization technology (2010)

Cited by 4 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. Virtual Machine Introspection in Virtualization: A Security Perspective;2021 Thirteenth International Conference on Contemporary Computing (IC3-2021);2021-08-05

2. Digital Logic and Asynchronous Datapath With Heterogeneous TFET-MOSFET Structure for Ultralow-Energy Electronics;IEEE Journal on Exploratory Solid-State Computational Devices and Circuits;2020-12

3. A lightweight live memory forensic approach based on hardware virtualization;Information Sciences;2017-02

4. Virtual Machine Introspection: Techniques and Applications;2015 10th International Conference on Availability, Reliability and Security;2015-08

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3