删除或更新信息,请邮件至freekaoyan#163.com(#换成@)

An Approach to Analyze Physical Memory Image File of Mac OS X

本站小编 哈尔滨工业大学/2019-10-23

An Approach to Analyze Physical Memory Image File of Mac OS X

Li-Juan Xu, Lian-Hai Wang

(Shandong Provincial Key Laboratory of Computer Network, Shandong Computer Science Center(National Supercomputer Center in Jinan), Jinan 250101, China)



Abstract:

Memory analysis is one of the key techniques in computer live forensics. Especially, the analysis of a Mac OS X operating system’s memory image file plays an important role in identifying the running status of an apple computer. However, how to analyze the image file without using extra”mach-kernel” file is one of the unsolved difficulties. In this paper, we firstly compare several approaches for physical memory acquisition and analyze the effects of each approach on physical memory. Then, we discuss the traditional methods for the physical memory file analysis of Mac OS X. A novel physical memory image file analysis approach without using extra“mach-kernel” file is proposed base on the discussion. We verify the performance of the new approach on Mac OS X 10.8.2. The experimental results show that the proposed approach is simpler and more practical than previous ones.

Key words:  computer forensics  live forensics  Mac OS X operating system  physical memory analysis

DOI:10.11916/j.issn.1005-9113.2014.04.018

Clc Number:TP309

Fund:


相关话题/An Approach to Analyze Physical