Yüksek LisansAçık Erişim

Ram image retrieval in Linux using protected mode architecture's paging technique

Bu tez size mi ait?

Bu kayıt toplu arşivden geldi. Sizinse profilinize bağlayın.

2023
0 görüntülenme
0 i̇ndirme

Özet (EN)

Collecting evidence from cyber sources in forensic science is critical and essential work. One of these methods is collecting evidence from RAM (Random Access Memory) in digital devices. Since data is temporarily stored in RAM, evidence collection methods such as acquisition for the hard disk may not be sufficient. Therefore, RAM image acquisition techniques are frequently used. In this research, a RAM image was taken from a computer with a Linux operating system. Operating systems are divided into two user space and kernel space, and access from user space to kernel space is subject to certain restrictions. Kernel space has been developed to overcome this limitation. In the research, the protected mode architecture in the Linux operating system was examined, and the paging technique of the architecture was used. Using this technique, a kernel driver has been developed that reaches the addresses of the RAM and saves them to the disk as a file, and this kernel driver has been tested between kernel versions 2.6 and 5.18 and successfully copied to RAM. The tables and access methods used in the paging technique in the operating system are explained in detail. During the research, the Ubuntu 20.04 version operating system, one of the most widely used distributions of Linux, was preferred.

Yazar

Sedat Aktaş

Bu Yayına Nasıl Atıf Yapılır

Sedat Aktaş (Master Thesis). Ram image retrieval in Linux using protected mode architecture's paging technique, 2023, Ankara Yıldırım Beyazıt University.

Lisans

Tüm Hakları Saklıdır

Bu eser belirtilen lisans koşulları altında paylaşılmaktadır.

Ankara Yıldırım Beyazıt University tezlerinden daha fazlası