LogicMEM: Automatic Profile Generation for Binary-Only Memory Forensics via Logic Inference
Zhenxiao Qi, Yu Qu, Heng Yin
Abstract
—Memory forensic tools rely on the knowledge of kernel symbols and kernel object layouts to retrieve digital evidence and artifacts from memory dumps. This knowledge is called profile. Existing solutions for profile generation are either inconvenient or inaccurate. In this paper, we propose a logic inference approach to automatically generating a profile directly from a memory dump. It leverages the invariants existing in ker- nel data structures across all kernel versions and configurations to precisely locate forensics-required fields in kernel objects. We have implemented a prototype named L OGIC M EM and evaluated it on memory dumps collected from mainstream Linux distribu- tions, customized Linux kernels with random configurations, and operating systems designed for Android smartphones and embed- ded devices. The evaluation results show that the proposed logic inference approach is well-suited for locating forensics-required fields and achieves 100% precision and recall for mainstream Linux distributions and 100% precision and 95% recall for customized kernels with random configurations. Moreover, we show that false negatives can be eliminated with improved logic rules. We also demonstrate that L OGIC M EM can generate profiles when it is otherwise difficult (if not impossible) for existing approaches, and support memory forensics tasks such as rootkit detection.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7f95180c-fa61-49f1-a121-a4750624ed48Cited by top-tier papers3
- 00SEVen - Re-enabling Virtual Machine Forensics: Introspecting Confidential VMs Using Privileged in-VM AgentsFabian Schwarz, Christian RossowUSENIX Security 2024 · 10 citations
- Fool Me If You Can: On the Robustness of Binary Code Similarity Detection Models against Semantics-Preserving TransformationsJiyong Uhm, Minseok Kim, Michalis Polychronakis, Hyungjoon KooFSE 2026 · 1 citation
- An OS-agnostic Approach to Memory ForensicsAndrea Oliveri, Matteo Dell'Amico, Davide BalzarottiNDSS 2023
Builds on4
- DeepMem: Learning Graph Neural Network Models for Fast and Robust Memory Forensic AnalysisWei Song, Heng Yin, Chang Liu, Dawn SongCCS 2018 · 57 citations
- Using Logic Programming to Recover C++ Classes and Methods from Compiled ExecutablesEdward J. Schwartz, Cory F. Cohen, Michael Duggan, Jeffrey Gennari et al.CCS 2018 · 53 citations
- BigMAC: Fine-Grained Policy Analysis of Android FirmwareGrant Hernandez, Dave (Jing) Tian, Anurag Swarnim Yadav, Byron J. Williams et al.USENIX Security 2020
- Datalog DisassemblyAntonio Flores-Montoya, Eric M. SchulteUSENIX Security 2020
Related papers
- Tipped Off by Your Memory Allocator: Device-Wide User Activity Sequencing from Android Memory ImagesRohit Bhatia, Brendan Saltaformaggio, Seung Jei Yang, Aisha I. Ali-Gombe et al.NDSS 2018 · 14 citations
- Screen after Previous Screens: Spatial-Temporal Recreation of Android App Displays from Memory ImagesBrendan Saltaformaggio, Rohit Bhatia, Xiangyu Zhang, Dongyan Xu et al.USENIX Security 2016 · 32 citations
- MCI : Modeling-based Causality Inference in Audit Logging for Attack InvestigationYonghwi Kwon, Fei Wang, Weihang Wang, Kyu Hyung Lee et al.NDSS 2018 · 116 citations
- K-LEAK: Towards Automating the Generation of Multi-Step Infoleak Exploits against the Linux KernelZhengchuan Liang, Xiaochen Zou, Chengyu Song, Zhiyun QianNDSS 2024
- Fine-Grained Kernel Auditing Using Augmented Syscall Reference Behavior Analysis and Virtualized Selective TracingChuqi Zhang, Spencer Faith, Feras Al-Qassas, Theodorus Februanto et al.S&P 2026
