DeepMem: Learning Graph Neural Network Models for Fast and Robust Memory Forensic Analysis

DeepMem: Learning Graph Neural Network Models for Fast and Robust Memory Forensic Analysis
复制标题

DOI:
10.1145/3243734.3243813
复制
发表时间:
2018-10
期刊:
Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Wei Song;Heng Yin;Chang Liu;D. Song
Wei Song;Heng Yin;Chang Liu;D. Song
中科院分区:
其他
文献类型:
--
作者:
Wei Song;Heng Yin;Chang Liu;D. Song

文献摘要

被引文献

相似文献

内核数据结构检测是内存取证中的重要任务,旨在从原始内存转储中识别语义上重要的内核数据结构。它主要用于收集恶意或犯罪行为的证据。现有方法有几个局限性:1)列表 - 传播方法容易受到DKOM攻击的影响,2)基于稳健的签名方法不可伸缩或有效,因为它需要使用一种签名来搜索整个内存快照,并且3)列表 - 传播和基于签名的方法都在很大程度上依赖于操作系统的领域知识。基于限制,我们提出了DeepMem,这是一种基于图的深度学习方法,可以自动为内核对象生成抽象表示,我们可以通过快速且可靠的方式从原始内存转储中识别对象。具体而言,我们实现1)重建记忆转储的内容和拓扑信息的新颖存储图模型,2)图形神经网络体系结构将节点嵌入存储器图中,以及3)一种对象检测方法,可以交叉验证该方法从物体的不同部分收集的证据。实验表明,DeepMem从原始内存转储中识别内核对象中达到了高精度和召回率。同样,通过使用中间存储器图表示,检测策略是快速且可扩展的。此外,DeepMem在攻击场景上非常强大,例如池标签操纵和DKOM过程隐藏。
Kernel data structure detection is an important task in memory forensics that aims at identifying semantically important kernel data structures from raw memory dumps. It is primarily used to collect evidence of malicious or criminal behaviors. Existing approaches have several limitations: 1) list-traversal approaches are vulnerable to DKOM attacks, 2) robust signature-based approaches are not scalable or efficient, because it needs to search the entire memory snapshot for one kind of objects using one signature, and 3) both list-traversal and signature-based approaches all heavily rely on domain knowledge of operating system. Based on the limitations, we propose DeepMem, a graph-based deep learning approach to automatically generate abstract representations for kernel objects, with which we could recognize the objects from raw memory dumps in a fast and robust way. Specifically, we implement 1) a novel memory graph model that reconstructs the content and topology information of memory dumps, 2) a graph neural network architecture to embed the nodes in the memory graph, and 3) an object detection method that cross-validates the evidence collected from different parts of objects. Experiments show that DeepMem achieves high precision and recall rate in identify kernel objects from raw memory dumps. Also, the detection strategy is fast and scalable by using the intermediate memory graph representation. Moreover, DeepMem is robust against attack scenarios, like pool tag manipulation and DKOM process hiding.