Automatically Bridging the Semantic Gap using C Interpreter

Automatically Bridging the Semantic Gap using C Interpreter
复制标题

使用 C 解释器自动弥合语义差距

DOI:
--
复制
发表时间:
--
期刊:
影响因子:
--
通讯作者:
Stephen Brueckner
Stephen Brueckner
中科院分区:
--
文献类型:
--
作者:
H. Inoue;F. Adelstein;Matthew Donovan;Stephen Brueckner

文献摘要

被引文献

相似文献

描述min-c,一个C解释器,它解决了“语义鸿沟“的广义问题。语义鸿沟存在于虚拟机内省(VMI)和易失性内存取证中,因为没有本地硬件环境。例如,进程中的数据结构中的指针不能在没有转换为物理地址的情况下使用,这是本机硬件和操作系统的功能。通常的解决方案是构建一个操作系统接口库来提供必要的翻译。这是脆弱的,因为它必须不断跟踪操作系统版本。Min-c通过启用使用本机OS代码本身自动生成OS接口库或在源代码不可用时调试符号来解决此问题。我们描述了设计的min-c和我们的方法,自动构建类型解释所需的语义接口数据库的Linux和Windows操作系统。
describe min-c, a C interpreter that solves the generalized problem of the " semantic gap ". The semantic gap exists in virtual machine introspection (VMI) and in volatile memory forensics because there is not a native hardware environment. For example, a pointer in a data structure in a process cannot be used without translation to a physical address, a function of the native hardware and operating system. The usual solution is to build an OS interface library to provide the necessary translations. This is brittle as it must constantly track OS versions. Min-c solves this problem by enabling automatic generation of the OS interface library using native OS code itself, or debugging symbols when source is not available. We describe the design of min-c and our method for automatically building the semantic interface database required for type interpretation for both Linux and Windows OSs.