The Next Generation of Robust Linux Memory Acquisition Technique via Sequential Memory Dumps at Designated Time Intervals

The Next Generation of Robust Linux Memory Acquisition Technique via Sequential Memory Dumps at Designated Time Intervals
复制标题

通过按指定时间间隔进行顺序内存转储的下一代稳健 Linux 内存获取技术

DOI:
--
复制
发表时间:
2018
期刊:
International Carnahan Conference on Security Technology
影响因子:
--
通讯作者:
A. Ghorbani
A. Ghorbani
中科院分区:
--
文献类型:
--
作者:
Saeed Shafiee Hasanabadi;Arash Habibi Lashkari;A. Ghorbani

文献摘要

被引文献

相似文献

内存取证技术帮助数字调查人员识别和检测受损系统上的攻击的剩余证据。执行分析的准确性取决于存储器获取输出的完整性、原子性和可靠性。就我们的研究而言,当前内存取证中最关键的挑战是增加物理内存的大小,内存获取所花费的时间,恶意篡改和页面涂抹效应以及反取证技术。通过解决这些挑战,我们提出了一种方法来确定在指定的时间间隔内大约有多少顺序内存采集可以减轻这些挑战。此缓解措施包括减少内存获取中的I/O操作以加快速度,减少恶意篡改和页面拖影效应以及反取证技术的影响。在不同的Linux操作系统上的实验结果表明,在相似率为9%~ 23%的情况下,顺序内存获取的最佳间隔时间为3 min。所提出的方法适用于基于软件和基于硬件的内存获取方法。
The memory forensics techniques assist digital investigators to identify and detect remaining evidence of the attacks on the compromised system. The accuracy of performing the analysis is depend to the completeness, atomicity, and reliability of the memory acquisition output. Regarding to our research, the most current critical challenges in memory forensics are increasing the size of physical memory, the elapsed time of memory acquisition, malicious tampering and page smearing effects, and anti-forensics techniques. By addressing these challenges, we proposed an approach to determine approximately how much sequential memory acquisition at a designated time-intervals can mitigate them. This mitigation includes reducing I/O operations in memory acquisition to speed it up, diminishing malicious tampering and page smearing effects, and impact of anti-forensics techniques. The results of our experiments on different Linux operating system families show the best interval time for sequential memory acquisition is 3 minutes with the similarity ration between 9% to 23%. The proposed approach is applicable to software-based and hardware-based memory acquisition methods.