Obtaining method of network information under Vista operating system
A technology of an operating system and an acquisition method, applied in the field of computer forensics, can solve problems such as inability to obtain network connection information, and achieve the effect of a reliable acquisition method and a wide range of applications
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment Construction
[0045] Refer to the attached Figure 4 and 12 , which shows a method for obtaining network information under the Vista operating system, the method for obtaining includes the following steps:
[0046] 1) Obtain the base address virtual address of the tcpip.sys module through physical memory analysis;
[0047] 2) according to step 1) the base address virtual address that obtains adds the address difference of this base address and data structure TcpEndpointPool under the current operating system to obtain the virtual address of TcpEndpointPool;
[0048] 3) convert the virtual address obtained in step 2) into a physical address according to the address translation rule under the current operating system, and locate the first position pointed to by the physical address in the memory image;
[0049] 4) Read the first 4 bytes at the first position pointed to by the obtained step 3) as a virtual address and convert it to a physical address, and locate the second position pointed t...
PUM
Abstract
Description
Claims
Application Information
- R&D Engineer
- R&D Manager
- IP Professional
- Industry Leading Data Capabilities
- Powerful AI technology
- Patent DNA Extraction
Browse by: Latest US Patents, China's latest patents, Technical Efficacy Thesaurus, Application Domain, Technology Topic, Popular Technical Reports.
© 2024 PatSnap. All rights reserved.Legal|Privacy policy|Modern Slavery Act Transparency Statement|Sitemap|About US| Contact US: help@patsnap.com