scholarly journals BitBlaze: A New Approach to Computer Security via Binary Analysis

Author(s):  
Dawn Song ◽  
David Brumley ◽  
Heng Yin ◽  
Juan Caballero ◽  
Ivan Jager ◽  
...  
2022 ◽  
Vol 25 (1) ◽  
pp. 1-26
Author(s):  
Fabio Pagani ◽  
Davide Balzarotti

Despite a considerable number of approaches that have been proposed to protect computer systems, cyber-criminal activities are on the rise and forensic analysis of compromised machines and seized devices is becoming essential in computer security. This article focuses on memory forensics, a branch of digital forensics that extract artifacts from the volatile memory. In particular, this article looks at a key ingredient required by memory forensics frameworks: a precise model of the OS kernel under analysis, also known as profile . By using the information stored in the profile, memory forensics tools are able to bridge the semantic gap and interpret raw bytes to extract evidences from a memory dump. A big problem with profile-based solutions is that custom profiles must be created for each and every system under analysis. This is especially problematic for Linux systems, because profiles are not generic : they are strictly tied to a specific kernel version and to the configuration used to build the kernel. Failing to create a valid profile means that an analyst cannot unleash the true power of memory forensics and is limited to primitive carving strategies. For this reason, in this article we present a novel approach that combines source code and binary analysis techniques to automatically generate a profile from a memory dump, without relying on any non-public information. Our experiments show that this is a viable solution and that profiles reconstructed by our framework can be used to run many plugins, which are essential for a successful forensics investigation.


1999 ◽  
Vol 173 ◽  
pp. 185-188
Author(s):  
Gy. Szabó ◽  
K. Sárneczky ◽  
L.L. Kiss

AbstractA widely used tool in studying quasi-monoperiodic processes is the O–C diagram. This paper deals with the application of this diagram in minor planet studies. The main difference between our approach and the classical O–C diagram is that we transform the epoch (=time) dependence into the geocentric longitude domain. We outline a rotation modelling using this modified O–C and illustrate the abilities with detailed error analysis. The primary assumption, that the monotonity and the shape of this diagram is (almost) independent of the geometry of the asteroids is discussed and tested. The monotonity enables an unambiguous distinction between the prograde and retrograde rotation, thus the four-fold (or in some cases the two-fold) ambiguities can be avoided. This turned out to be the main advantage of the O–C examination. As an extension to the theoretical work, we present some preliminary results on 1727 Mette based on new CCD observations.


Author(s):  
V. Mizuhira ◽  
Y. Futaesaku

Previously we reported that tannic acid is a very effective fixative for proteins including polypeptides. Especially, in the cross section of microtubules, thirteen submits in A-tubule and eleven in B-tubule could be observed very clearly. An elastic fiber could be demonstrated very clearly, as an electron opaque, homogeneous fiber. However, tannic acid did not penetrate into the deep portion of the tissue-block. So we tried Catechin. This shows almost the same chemical natures as that of proteins, as tannic acid. Moreover, we thought that catechin should have two active-reaction sites, one is phenol,and the other is catechole. Catechole site should react with osmium, to make Os- black. Phenol-site should react with peroxidase existing perhydroxide.


Author(s):  
K. Chien ◽  
R. Van de Velde ◽  
I.P. Shintaku ◽  
A.F. Sassoon

Immunoelectron microscopy of neoplastic lymphoma cells is valuable for precise localization of surface antigens and identification of cell types. We have developed a new approach in which the immunohistochemical staining can be evaluated prior to embedding for EM and desired area subsequently selected for ultrathin sectioning.A freshly prepared lymphoma cell suspension is spun onto polylysine hydrobromide- coated glass slides by cytocentrifugation and immediately fixed without air drying in polylysine paraformaldehyde (PLP) fixative. After rinsing in PBS, slides are stained by a 3-step immunoperoxidase method. Cell monolayer is then fixed in buffered 3% glutaraldehyde prior to DAB reaction. After the DAB reaction step, wet monolayers can be examined under LM for presence of brown reaction product and selected monolayers then processed by routine methods for EM and embedded with the Chien Re-embedding Mold. After the polymerization, the epoxy blocks are easily separated from the glass slides by heatingon a 100°C hot plate for 20 seconds.


Author(s):  
W. A. Chiou ◽  
N. Kohyama ◽  
B. Little ◽  
P. Wagner ◽  
M. Meshii

The corrosion of copper and copper alloys in a marine environment is of great concern because of their widespread use in heat exchangers and steam condensers in which natural seawater is the coolant. It has become increasingly evident that microorganisms play an important role in the corrosion of a number of metals and alloys under a variety of environments. For the past 15 years the use of SEM has proven to be useful in studying biofilms and spatial relationships between bacteria and localized corrosion of metals. Little information, however, has been obtained using TEM capitalizing on its higher spacial resolution and the transmission observation of interfaces. The research presented herein is the first step of this new approach in studying the corrosion with biological influence in pure copper.Commercially produced copper (Cu, 99%) foils of approximately 120 μm thick exposed to a copper-tolerant marine bacterium, Oceanospirillum, and an abiotic culture medium were subsampled (1 cm × 1 cm) for this study along with unexposed control samples.


Author(s):  
Arthur V. Jones

With the introduction of field-emission sources and “immersion-type” objective lenses, the resolution obtainable with modern scanning electron microscopes is approaching that obtainable in STEM and TEM-but only with specific types of specimens. Bulk specimens still suffer from the restrictions imposed by internal scattering and the need to be conducting. Advances in coating techniques have largely overcome these problems but for a sizeable body of specimens, the restrictions imposed by coating are unacceptable.For such specimens, low voltage operation, with its low beam penetration and freedom from charging artifacts, is the method of choice.Unfortunately the technical dificulties in producing an electron beam sufficiently small and of sufficient intensity are considerably greater at low beam energies — so much so that a radical reevaluation of convential design concepts is needed.The probe diameter is usually given by


1968 ◽  
Vol 32 (3) ◽  
pp. 279-282
Author(s):  
JI Mock ◽  
JW Grenfell ◽  
WA Richter
Keyword(s):  

1969 ◽  
Vol 34 (2) ◽  
pp. 176-176

In the November 1968 issue of this journal, Margaret M. Martyn’s name was misspelled Martin on page 315. In the same issue, page 325, column 2 (Jerger, Speaks, and Trammell, “A New Approach to Speech Audiometry”), the sentence reading “Whenever the loss is sloping, however, the PB area underestimates and the SSI area overestimates the amount of handicap” should read as follows: “Whenever the loss is sloping, however, the PB area overestimates and the SSI area underestimates the amount of the handicap.”


Sign in / Sign up

Export Citation Format

Share Document