13.09.2013 Views

Post-Mortem RAM Forensics - CanSecWest

Post-Mortem RAM Forensics - CanSecWest

Post-Mortem RAM Forensics - CanSecWest

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

T = 0: “Pre” state<br />

T = 1: copy is made<br />

T = 2: “<strong>Post</strong>” state<br />

Objects in the last half<br />

were both removed and<br />

created before being<br />

copied, and an object in<br />

the first half was removed<br />

after it was copied (but<br />

before the copy completed<br />

<strong>CanSecWest</strong>2007<br />

T = 3: copy reflects<br />

neither state<br />

11<br />

Time Sliding Window<br />

VIDAS

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!