DeepMem: Learning Graph Neural Network Models for Fast and Robust Memory Forensic Analysis
Wei Song, Heng Yin, Chang Liu, Dawn Song
摘要
Kernel data structure detection is an important task in memory forensics that aims at identifying semantically important kernel data structures from raw memory dumps. It is primarily used to collect evidence of malicious or criminal behaviors. Existing approaches have several limitations: 1) list-traversal approaches are vulnerable to DKOM attacks, 2) robust signature-based approaches are not scalable or efficient, because it needs to search the entire memory snapshot for one kind of objects using one signature, and 3) both list-traversal and signature-based approaches all heavily rely on domain knowledge of operating system. Based on the limitations, we propose DeepMem, a graph-based deep learning approach to automatically generate abstract representations for kernel objects, with which we could recognize the objects from raw memory dumps in a fast and robust way. Specifically, we implement 1) a novel memory graph model that reconstructs the content and topology information of memory dumps, 2) a graph neural network architecture to embed the nodes in the memory graph, and 3) an object detection method that cross-validates the evidence collected from different parts of objects. Experiments show that DeepMem achieves high precision and recall rate in identify kernel objects from raw memory dumps. Also, the detection strategy is fast and scalable by using the intermediate memory graph representation. Moreover, DeepMem is robust against attack scenarios, like pool tag manipulation and DKOM process hiding.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper11
- ATTACK2VEC: Leveraging Temporal Word Embeddings to Understand the Evolution of CyberattacksYun Shen, Gianluca StringhiniUSENIX Security 2019 · 被引用 77 次
- DEEPVSA: Facilitating Value-set Analysis with Deep Learning for Postmortem Program AnalysisWenbo Guo, Dongliang Mu, Xinyu Xing, Min Du 等USENIX Security 2019 · 被引用 67 次
- Attack as defense: characterizing adversarial examples using robustnessZhe Zhao, Guangke Chen, Jingyi Wang, Yiwei Yang 等ISSTA 2021 · 被引用 34 次
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren 等CCS 2023 · 被引用 19 次
- DangZero: Efficient Use-After-Free Detection via Direct Page Table AccessFloris Gorter, Koen Koning, Herbert Bos, Cristiano GiuffridaCCS 2022 · 被引用 15 次
它引用的顶会 Paper2
- Neural Network-based Graph Embedding for Cross-Platform Binary Code Similarity DetectionXiaojun Xu, Chang Liu, Qian Feng, Heng Yin 等CCS 2017 · 被引用 682 次
- Screen after Previous Screens: Spatial-Temporal Recreation of Android App Displays from Memory ImagesBrendan Saltaformaggio, Rohit Bhatia, Xiangyu Zhang, Dongyan Xu 等USENIX Security 2016 · 被引用 32 次
相关 Paper
- An OS-agnostic Approach to Memory ForensicsAndrea Oliveri, Matteo Dell'Amico, Davide BalzarottiNDSS 2023
- LogicMEM: Automatic Profile Generation for Binary-Only Memory Forensics via Logic InferenceZhenxiao Qi, Yu Qu, Heng YinNDSS 2022
- MVD: Memory-Related Vulnerability Detection Based on Flow-Sensitive Graph Neural NetworksSicong Cao, Xiaobing Sun, Lili Bo, Rongxin Wu 等ICSE 2022 · 被引用 100 次
- The Case for Learned Provenance Graph Storage SystemsHailun Ding, Juan Zhai, Dong Deng, Shiqing MaUSENIX Security 2023
- AlphaEXP: An Expert System for Identifying Security-Sensitive Kernel ObjectsRuipeng Wang, Kaixiang Chen, Chao Zhang, Zulie Pan 等USENIX Security 2023
