将内存取证应用于 Rootkit 检测
密码学与安全
2015-06-15 v1
摘要
易失性内存转储及其分析是数字取证的重要组成部分。在众多用于内存转储的软件和硬件方法中,有作者指出其中一些方法对各种反取证技术缺乏韧性,而另一些则需要重启或高度依赖平台。新型韧性工具存在某些缺点,例如速度慢或易受直接操纵内核结构(如页表)的 rootkit 的攻击。本文描述了一种新型内存取证系统——Malware Analysis System for Hidden Knotty Anomalies (MASHKA)。该系统对流行的反取证技术具有韧性。该系统的用途广泛,可完成多种内存取证任务。本文描述了如何应用该系统研究和检测内核模式 rootkit,并给出了对最流行反 rootkit 工具的分析。
引用
@article{arxiv.1506.04129,
title = {Applying Memory Forensics to Rootkit Detection},
author = {Igor Korkin and Ivan Nesterov},
journal= {arXiv preprint arXiv:1506.04129},
year = {2015}
}
备注
25 pages, 3 figures, 8 tables. Paper presented at the Proceedings of the 9th annual Conference on Digital Forensics, Security and Law (CDFSL), 115-141, Richmond, VA, USA. (2014, May 28-29)