Identifying the Unknown in User Space Memory
نویسنده
چکیده
The research described in this thesis aims to improve the techniques used to analyse volatile memory, in particular user space memory, such that more generic techniques to identify unknown code such as malware can be produced. Current analysis techniques of user space memory are limited to a focus on the location of specific kernel objects. This focus on the identification of specific artifacts has also been applied in the detection of unknown code, which relies on the location of evidence created from the use of a particular malicious techniques. While such an approach allows the detection of unknown code, such as common malware, it allows a sophisticated attacker the ability to intentionally modify these artifacts to subvert detection. This research presents a generic method of detecting unknown code that does not rely on specific artifacts, allowing such malicious subversion to be overcome. Achieving this has required the creation of three individual contributions to improve the analysis of user space memory. The first is a model for identifying the common structural components that apply to the user space memory of all processes, such that the contents of user space memory can be better understood. The second is a model for distinguishing between code and data in memory, to facilitate the application of code or data specific analysis techniques. The final contribution is the technique for automatically and generically discriminating between known and unknown code in user space memory. This technique was capable of detecting the introduction of all malware samples examined.
منابع مشابه
Revising in the relationship of social behavior and urban space within Islamic Vision (the concept of ideal user and his territory in original Islamic texts)
Identifying ideal user is a basic function of theoretical debates of urban design. Here, the situation of the concept of” Ideal user” is enquired in three main categories of social theories used in urban design discourses (i.e. socialistic theories, ecologistic ones and performance-based theories) and it is shown that none of them is of enough relevance to Islamic model of socio-spatial relati...
متن کاملSurveying the user space through user allocations
Previous research into memory forensics has focused on understanding the structure and contents of the kernel space portions of physical memory, and mostly ignored the contents of the user space. This paper describes the results of a survey of user space virtual address allocations in the Windows XP and Windows 7 operating systems, comprehensively identifying the kernel and user space metadata ...
متن کاملA Model for Identifying and Enhancing the Sense of Place and Collective Memories (Case Study: Dez river)
The lack of sense of belonging to place in urban spaces is one of the problems widely stated. There are objective and subjective factors in space that create sense of place. The combined effect of these factors create meaning for place and endow the environment with identity. This research seeks to find the relationship between the objective and subjective factors of space and the levels of sen...
متن کاملAssessment of user preferences of campus green space at Ferdowsi University of Mashhad-Iran
Researchers have found that a user’s perception of the campus environment is related to quality life and academic accomplishment. In this study, we have analyzed the perceptions of more than 600 users at the Ferdowsi University of Mashhad to evaluate the level of green space use and to understand user preferences from aesthetics and safety aspects. The results show that for most of the responde...
متن کاملIdentifying the components of the Information Resource Selection Behavior of the Members of Public Libraries Using Metasynthesis
Purpose: It is impossible to increase the use of information resources in libraries and provide user-centered information services without understanding how users select and search for information resources. selecting information sources involves identifying a subset of available information sources that best meet the information needs of users. Selecting the right source of information has a s...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2013