Digital forensic method and system based on Android memory dump technology
A memory dump, digital technology, applied in the field of forensic analysis, can solve problems such as difficulties in digital forensics, difficulties in encrypting data by applications and recovering deleted records, etc., achieving a wide range of technical and market application value, and improving effectiveness and integrity.
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment Construction
[0032] The invention will be described in further detail in accordance with the accompanying drawings below.
[0033] Traditional mobile phone forensics technologies mainly include physical image dump and file system analysis. Although these two methods can obtain a lot of user data, they cannot directly analyze encrypted data and they are all post-event analysis, which cannot analyze the data in the current running process. , and rootkits that run in the kernel state cannot be caught. For digital forensics personnel, memory analysis is very important, because all data in the memory RAM is stored in plain text, not only can analyze the data of running applications, but also can determine whether there is maliciousness by analyzing the kernel structure Program running. In view of this, the present invention proposes a digital forensics method and system based on Android memory dump technology.
[0034] Such as figure 1 As shown, the present invention proposes a kind of digit...
PUM
Abstract
Description
Claims
Application Information
- R&D Engineer
- R&D Manager
- IP Professional
- Industry Leading Data Capabilities
- Powerful AI technology
- Patent DNA Extraction
Browse by: Latest US Patents, China's latest patents, Technical Efficacy Thesaurus, Application Domain, Technology Topic, Popular Technical Reports.
© 2024 PatSnap. All rights reserved.Legal|Privacy policy|Modern Slavery Act Transparency Statement|Sitemap|About US| Contact US: help@patsnap.com