扫描手机二维码

欢迎您的访问
您是第 位访客

开通时间:..

最后更新时间:..

  • 庄毅 ( 教授 )

    的个人主页 http://faculty.nuaa.edu.cn/zy8/zh_CN/index.htm

  •   教授   博士生导师
论文成果 当前位置: 中文主页 >> 科学研究 >> 论文成果
PMCAP: A Threat Model of Process Memory Data on the Windows Operating System

点击次数:
所属单位:计算机科学与技术学院/人工智能学院/软件学院
发表刊物:SECURITY AND COMMUNICATION NETWORKS
摘要:Research on endpoint security involves both traditional PC platform and prevalent mobile platform, among which the analysis of software vulnerability and malware is one of the important contents. For researchers, it is necessary to carry out nonstop exploration of the insecure factors in order to better protect the endpoints. Driven by this motivation, we propose a new threat model named Process Memory Captor (PMCAP) on the Windows operating system which threatens the live process volatile memory data. Compared with other threats, PMCAP aims at dynamic data in the process memory and uses a noninvasive approach for data extraction. In this paper we describe and analyze the model and then give a detailed implementation taking four popular web browsers IE, Edge, Chrome, and Firefox as examples. Finally, the model is verified through real experiments and case studies. Compared with existing technologies, PMCAP can extract valuable data at a lower cost; some techniques in the model are also suitable for memory forensics and malware analysis.
ISSN号:1939-0114
是否译文:否
发表时间:2017-01-01
合写作者:Pan, Jiaye
通讯作者:庄毅

 

版权所有©2018- 南京航空航天大学·信息化处(信息化技术中心)