LO-PHI: Low-Observable Physical Host Instrumentation for Malware Analysis
Chad Spensky, Hongyi Hu, Kevin Leach
Abstract
Dynamic-analysis techniques have become the linchpins of modern malware analysis. However, software-based methods have been shown to expose numerous artifacts, which can either be detected and subverted, or potentially interfere with the analysis altogether, making their results untrustworthy. The need for less-intrusive methods of analysis has led many researchers to utilize introspection in place of instrumenting the software itself. While most current introspection technologies have focused on virtual-machine introspection, we present a novel system, LO-PHI, which is capable of physical-machine introspection of both non-volatile and volatile memory, i.e., hard disk and system memory. We demonstrate that we are able to provide analysis capabilities comparable to existing solutions, whilst exposing zero software-based artifacts and minimal hardware artifacts. To demonstrate the usefulness of our system, we have developed a framework for performing automated binary analysis. We employ this framework to analyze numerous potentially malicious binaries using both traditional virtual-machine introspection and our new hardware-based instrumentation. Our results show that not only is our analysis on-par with existing software-based counterparts, but that our physical instrumentation is capable of successfully analyzing far more binaries, as it is not foiled by popular anti-analysis techniques. Permission to freely reproduce all or part of this paper for noncommercial purposes is granted provided that copies bear this notice and the full citation on the first page. Reproduction for commercial purposes is strictly prohibited without the prior written consent of the Internet Society, the first-named author (for reproduction of an entire paper only), and the author's employer if the paper was prepared within the scope of employment.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 258833f8-ced5-4b92-8a1e-1198b51b41c8Cited by top-tier papers7
- An Inside Look into the Practice of Malware AnalysisMiuyin Yong Wong, Matthew Landen, Manos Antonakakis, Douglas M. Blough et al.CCS 2021 · 58 citations
- Happer: Unpacking Android Apps via a Hardware-Assisted ApproachLei Xue, Hao Zhou, Xiapu Luo, Yajin Zhou et al.S&P 2021 · 29 citations
- NetTLP: A Development Platform for PCIe devices in Software Interacting with HardwareYohei Kuga, Ryo Nakamura, Takeshi Matsuya, Yuji SekiyaNSDI 2020 · 9 citations
- BlueGuard: Accelerated Host and Guest Introspection Using DPUsMeni Orenbach, Rami Ailabouni, Nael Masalha, Thanh Nguyen et al.USENIX Security 2025
- Nova: Generative Language Models for Assembly Code with Hierarchical Attention and Contrastive LearningNan Jiang, Chengxiao Wang, Kevin Liu, Xiangzhe Xu et al.ICLR 2025
Related papers
- Tackling runtime-based obfuscation in Android with TIROMichelle Y. Wong, David LieUSENIX Security 2018 · 59 citations
- A Novel Dynamic Analysis Infrastructure to Instrument Untrusted Execution Flow Across User-Kernel SpacesJiaqi Hong, Xuhua DingS&P 2021 · 10 citations
- Seeing Through The Same Lens: Introspecting Guest Address Space At Native SpeedSiqi Zhao, Xuhua Ding, Wen Xu, Dawu GuUSENIX Security 2017 · 18 citations
- Spotless Sandboxes: Evading Malware Analysis Systems Using Wear-and-Tear ArtifactsNajmeh Miramirkhani, Mahathi Priya Appini, Nick Nikiforakis, Michalis PolychronakisS&P 2017 · 134 citations
- LEMIX: Enabling Testing of Embedded Applications as Linux ApplicationsSai Ritvik Tanksalkar, Siddharth Muralee, Srihari Danduri, Paschal C. Amusuo et al.USENIX Security 2025
