The Research of Computer Forensics Technology Based on Physical Memory of Windows System

Cao Ji-dong · Computer Knowledge and Technology · 2011

The paper describes the structure of physical memory of Windows system,details of the user address space distribution and the system address space distribution,focuses on the steps of obtain the physical memory mirroring by drivers.In the end,the deficiencies of current forensics and the further work in this is discussed.

Read the paper · More papers on PaperTik