首页 | 本学科首页   官方微博 | 高级检索  
     检索      

基于物理内存的注册表逆向重建取证分析算法
引用本文:高元照,李炳龙,吴熙曦.基于物理内存的注册表逆向重建取证分析算法[J].山东大学学报(理学版),2016,51(9):127-136.
作者姓名:高元照  李炳龙  吴熙曦
作者单位:1. 解放军信息工程大学四院, 河南 郑州 450001;2. 数字工程与先进计算国家重点实验室, 河南 郑州 450001
基金项目:国家自然科学基金资助项目(60903220);郑州市科技攻关项目(10PTGG3415)
摘    要:注册表结构重建与分析是Windows物理内存取证分析的重点和难点问题之一。首先通过分析注册表文件在硬盘中的逻辑特性,利用Windows系统调试工具分析注册表在内存中的数据结构特征,确立了在物理内存中定位注册表结构的方法;然后通过分析注册表项之间的树形关系,确定了注册表结构重建算法,并利用Graphviz可视化工具,设计出一种树形结构的可视化算法。实验结果表明,该算法能够实现对物理内存中注册表键名、键值信息的重建,基于获取的数据能够完成对系统中病毒的检测,并通过Graphviz可视化算法有效展示病毒感染系统的过程和结果。

关 键 词:注册表取证  可视化  物理内存  逆向分析  病毒检测  
收稿时间:2015-09-21

A forensic analysis algorithm of registry reverse reconstruction based on physical memory
GAO Yuan-zhao,LI Bing-long,WU Xi-xi.A forensic analysis algorithm of registry reverse reconstruction based on physical memory[J].Journal of Shandong University,2016,51(9):127-136.
Authors:GAO Yuan-zhao  LI Bing-long  WU Xi-xi
Institution:1. College Four of the PLA Information Engineering University, Zhengzhou 450001, Henan, China;2. State Key Laboratory of Digital Engineering and Advanced Computing, Zhengzhou 450001, Henan, China
Abstract:The reconstruction and analysis of the registry is one of the most important and difficult aspects of the Windows physical memory forensics. By analyzing the logical structure of the registry files in the hard disk and exploring the data structure features of the registry in the physical memory based on the Windows debugging tools, we proposed a clear and definite method to locate the registry physical addresses in the memory. Furthermore, by analyzing the tree-structured relationship between the entries of the registry, we designed a registry reconstruction algorithm and implemented a dendrogram visualization algorithm for the reconstructed registry based on Graphviz. The results of the experiment show that we can reconstruct of the names and values of the registry entries, retrieve the virus in the system based on the information we got, and finally display the process and results of the virus infection via the registry visualization.
Keywords:registry forensics  reverse analysis  virus detection  visualization  physical memory  
本文献已被 CNKI 等数据库收录!
点击此处可从《山东大学学报(理学版)》浏览原始摘要信息
点击此处可从《山东大学学报(理学版)》下载免费的PDF全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号