Static Code Analysis on The Effect of Virtual Secure Mode on Memory Acquisition with IDA

Nadja Adryana, Niken Cahyani, Erwid Jadied
{"title":"Static Code Analysis on The Effect of Virtual Secure Mode on Memory Acquisition with IDA","authors":"Nadja Adryana, Niken Cahyani, Erwid Jadied","doi":"10.21108/ijoict.v9i1.688","DOIUrl":null,"url":null,"abstract":"Memory acquisition process is one of digital forensics act. There are several tools that support memory acquisition process. At this time, there is a feature named secure mode that can caused crash or error in memory acquisition tools system and caused the tools to be unusable, also the loss of the computer memory. This research is focusing on analyzing the acquisition tools that has error or crash when the device that is being used for memory acquisition is in secure mode. The analysis is being carried out using static code analysis method, which is one of the techniques of reverse engineering, using IDA. This study aims to find the cause of the crash or error in memory acquisition tools. The purpose of this study is to be useful for digital forensic tester in understanding the potential risk of the secure mode impact in acquisition process. The results of this study indicate that different operating system and different kernel which runs in the device are the reasons that memory acquisition tools cannot run properly on VSM environment being turned on.","PeriodicalId":488588,"journal":{"name":"International journal on information and communication technology","volume":"9 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-06-09","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"International journal on information and communication technology","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.21108/ijoict.v9i1.688","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

Memory acquisition process is one of digital forensics act. There are several tools that support memory acquisition process. At this time, there is a feature named secure mode that can caused crash or error in memory acquisition tools system and caused the tools to be unusable, also the loss of the computer memory. This research is focusing on analyzing the acquisition tools that has error or crash when the device that is being used for memory acquisition is in secure mode. The analysis is being carried out using static code analysis method, which is one of the techniques of reverse engineering, using IDA. This study aims to find the cause of the crash or error in memory acquisition tools. The purpose of this study is to be useful for digital forensic tester in understanding the potential risk of the secure mode impact in acquisition process. The results of this study indicate that different operating system and different kernel which runs in the device are the reasons that memory acquisition tools cannot run properly on VSM environment being turned on.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
虚拟安全模式对IDA内存获取影响的静态代码分析
记忆获取过程是数字取证行为之一。有几个工具支持记忆获取过程。此时,有一种称为安全模式的特性会导致内存获取工具系统崩溃或出错,导致工具无法使用,也会导致计算机内存的丢失。本研究的重点是分析当用于内存采集的设备处于安全模式时出现错误或崩溃的采集工具。使用静态代码分析方法进行分析,这是使用IDA进行逆向工程的技术之一。本研究旨在找出记忆体撷取工具崩溃或出错的原因。本研究的目的是帮助数字取证测试人员了解安全模式影响在采集过程中的潜在风险。本研究结果表明,不同的操作系统和设备运行的不同内核是导致内存采集工具在打开VSM环境下无法正常运行的原因。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
A STOCK PREDICTION SYSTEM USING TEKNIKAL INDICATORS WITH THE LSTM METHOD Portfolio Optimization Based on Return Prediction and Semi Absolute Deviation (SAD) Static Code Analysis on The Effect of Virtual Secure Mode on Memory Acquisition with IDA Comparison of Term Weighting Methods in Sentiment Analysis of the New State Capital of Indonesia with the SVM Method Hoax COVID-19 News Detection Based on Sentiment Analysis in Indonesian using Support Vector Machine (SVM) Method
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1