Matches in SemOpenAlex for { <https://semopenalex.org/work/W1930594640> ?p ?o ?g. }
Showing items 1 to 90 of
90
with 100 items per page.
- W1930594640 abstract "Volatile memory dump and its analysis is an essential part of digital forensics. Among a number of various software and hardware approaches for memory dumping there are authors who point out that some of these approaches are not resilient to various anti-forensic techniques, and others that require a reboot or are highly platform dependent. New resilient tools have certain disadvantages such as low speed or vulnerability to rootkits which directly manipulate kernel structures e.g. page tables. A new memory forensic system - Malware Analysis System for Hidden Knotty Anomalies (MASHKA) is described in this paper. It is resilient to popular anti-forensic techniques. The system can be used for doing a wide range of memory forensics tasks. This paper describes how to apply the system for research and detection of kernel mode rootkits and also presents analysis of the most popular anti-rootkit tools." @default.
- W1930594640 created "2016-06-24" @default.
- W1930594640 creator A5000918958 @default.
- W1930594640 creator A5041862069 @default.
- W1930594640 date "2015-06-12" @default.
- W1930594640 modified "2023-09-22" @default.
- W1930594640 title "Applying Memory Forensics to Rootkit Detection" @default.
- W1930594640 cites W1492832459 @default.
- W1930594640 cites W1499669957 @default.
- W1930594640 cites W1509823614 @default.
- W1930594640 cites W1548319007 @default.
- W1930594640 cites W1968389182 @default.
- W1930594640 cites W1990866901 @default.
- W1930594640 cites W2040527645 @default.
- W1930594640 cites W2054537864 @default.
- W1930594640 cites W2068661019 @default.
- W1930594640 cites W2093126530 @default.
- W1930594640 cites W2113032636 @default.
- W1930594640 cites W2113854927 @default.
- W1930594640 cites W2116256634 @default.
- W1930594640 cites W2139746074 @default.
- W1930594640 cites W2143642500 @default.
- W1930594640 cites W2168202199 @default.
- W1930594640 cites W2482526856 @default.
- W1930594640 cites W420136371 @default.
- W1930594640 cites W1994747466 @default.
- W1930594640 hasPublicationYear "2015" @default.
- W1930594640 type Work @default.
- W1930594640 sameAs 1930594640 @default.
- W1930594640 citedByCount "2" @default.
- W1930594640 countsByYear W19305946402015 @default.
- W1930594640 countsByYear W19305946402017 @default.
- W1930594640 crossrefType "posted-content" @default.
- W1930594640 hasAuthorship W1930594640A5000918958 @default.
- W1930594640 hasAuthorship W1930594640A5041862069 @default.
- W1930594640 hasConcept C10144332 @default.
- W1930594640 hasConcept C111919701 @default.
- W1930594640 hasConcept C120524526 @default.
- W1930594640 hasConcept C176649486 @default.
- W1930594640 hasConcept C18131444 @default.
- W1930594640 hasConcept C2780940931 @default.
- W1930594640 hasConcept C2781357168 @default.
- W1930594640 hasConcept C38652104 @default.
- W1930594640 hasConcept C41008148 @default.
- W1930594640 hasConcept C504728807 @default.
- W1930594640 hasConcept C541664917 @default.
- W1930594640 hasConcept C76399640 @default.
- W1930594640 hasConcept C84418412 @default.
- W1930594640 hasConcept C98986596 @default.
- W1930594640 hasConceptScore W1930594640C10144332 @default.
- W1930594640 hasConceptScore W1930594640C111919701 @default.
- W1930594640 hasConceptScore W1930594640C120524526 @default.
- W1930594640 hasConceptScore W1930594640C176649486 @default.
- W1930594640 hasConceptScore W1930594640C18131444 @default.
- W1930594640 hasConceptScore W1930594640C2780940931 @default.
- W1930594640 hasConceptScore W1930594640C2781357168 @default.
- W1930594640 hasConceptScore W1930594640C38652104 @default.
- W1930594640 hasConceptScore W1930594640C41008148 @default.
- W1930594640 hasConceptScore W1930594640C504728807 @default.
- W1930594640 hasConceptScore W1930594640C541664917 @default.
- W1930594640 hasConceptScore W1930594640C76399640 @default.
- W1930594640 hasConceptScore W1930594640C84418412 @default.
- W1930594640 hasConceptScore W1930594640C98986596 @default.
- W1930594640 hasLocation W19305946401 @default.
- W1930594640 hasOpenAccess W1930594640 @default.
- W1930594640 hasPrimaryLocation W19305946401 @default.
- W1930594640 hasRelatedWork W1422754336 @default.
- W1930594640 hasRelatedWork W2011141045 @default.
- W1930594640 hasRelatedWork W2096269529 @default.
- W1930594640 hasRelatedWork W2103042869 @default.
- W1930594640 hasRelatedWork W2119691727 @default.
- W1930594640 hasRelatedWork W2128487888 @default.
- W1930594640 hasRelatedWork W2135564096 @default.
- W1930594640 hasRelatedWork W2156838504 @default.
- W1930594640 hasRelatedWork W2203922256 @default.
- W1930594640 hasRelatedWork W2460736843 @default.
- W1930594640 hasRelatedWork W2520608828 @default.
- W1930594640 hasRelatedWork W2613661467 @default.
- W1930594640 hasRelatedWork W2623990103 @default.
- W1930594640 hasRelatedWork W2730626270 @default.
- W1930594640 hasRelatedWork W2885309848 @default.
- W1930594640 hasRelatedWork W2962679028 @default.
- W1930594640 hasRelatedWork W3008812935 @default.
- W1930594640 hasRelatedWork W3080363623 @default.
- W1930594640 hasRelatedWork W594120122 @default.
- W1930594640 hasRelatedWork W2054520062 @default.
- W1930594640 isParatext "false" @default.
- W1930594640 isRetracted "false" @default.
- W1930594640 magId "1930594640" @default.
- W1930594640 workType "article" @default.